To set up group-based licensing in Microsoft 365, put users in a security group, mail-enabled security group or Microsoft 365 group, then go to Billing > Licenses in the Microsoft 365 admin center, select Assign licenses, choose the group and the subscription, and turn off any apps you don't want. Members then get the licence automatically and lose it when they leave the group. When something goes wrong, open the product's Errors & issues tab, fix the cause (not enough licences, conflicting or dependent service plans, missing usage location or a duplicate proxy address) and reprocess the affected users.
Who this is for and what you will have
This guide is for Microsoft 365 and Entra ID administrators who still assign licences user by user, or who have group-based licensing in place but keep finding users in an error state. At the end you will have:
- A group design that maps one group to one licence configuration.
- Licences assigned to groups in the admin center and with
Set-MgGroupLicense, including disabled service plans. - A safe sequence for moving users from direct assignment to group assignment.
- Scripts that list every user with a group licensing error and why.
- A fix for each documented error type.
Group-based licensing is also the cleanest way to licence users in bulk ahead of a migration, such as a Google Workspace to Microsoft 365 move or a tenant-to-tenant consolidation.
How group-based licensing behaves
Microsoft's documentation describes these rules, and most errors come from forgetting one of them:
- Supported groups. You can assign licences to security groups, mail-enabled security groups and Microsoft 365 groups. Groups synced from on-premises Active Directory work too.
- Membership drives the licence. New members get the group's licences and members who leave lose them. Changes are typically effective within minutes, but large groups can take much longer.
- No nested groups. Only direct members of the licensed group receive licences.
- Licences combine. A user can hold licences from several groups plus direct assignments. The result is the combination of all of them, and a licence assigned from multiple sources is consumed once.
- All or nothing per group. If a group carries several products and one of them fails for a user (for example, not enough licences), the other products from that group aren't assigned to that user either.
- No automatic conflict resolution. When two products conflict, Microsoft Entra ID records an error. The admin decides how to resolve it.
- Usage location fallback. Users without a usage location inherit the tenant's location when a group assigns the licence. Set the correct value at user creation if you have users in several countries.
Microsoft's Entra documentation for group-based licensing listed the licensing prerequisite as a paid or trial Microsoft Entra ID P1 (or higher) subscription, or a paid or trial edition of Microsoft 365 Business Premium, Office 365 Enterprise E3 or Office 365 A3 (or higher), for every user who benefits from group-based licensing. Check your agreement if you plan to licence users who only hold Business Basic or Standard.
Prerequisites
- An admin account with at least the Groups Administrator, License Administrator or User Administrator role. Reprocessing through the Graph API requires License Administrator, User Administrator or Directory Writers.
- Microsoft Graph PowerShell for the scripted steps.
- A usage location on every user, especially in multi-country tenants.
- A decision on which apps each population should get. Write it down as a table before you create groups.
A simple design that scales:
| Group | Product | Disabled service plans | Membership |
|---|---|---|---|
| LIC-O365-E3-Standard | Office 365 E3 | None | Assigned or dynamic |
| LIC-O365-E3-NoTeams-Pilot | Office 365 E3 | Microsoft Teams | Assigned |
| LIC-AddOn-TeamsPhone | Teams Phone Standard | None | Assigned |
Keep one product configuration per group. Mixing many products in one group makes the all-or-nothing behaviour harder to troubleshoot.
Step 1: Assign licences to a group in the admin center
- Sign in to the Microsoft 365 admin center as at least a License Administrator.
- Go to Billing > Licenses.
- Select Assign licenses.
- In the side panel, search for the group and select it from the list.
- Select the subscription that the licences should come from.
- To turn individual apps off, select Turn apps and services on or off.
- Select Assign licenses.
The admin center can assign licences to a maximum of 20 groups at a time. To remove a group assignment, open the product on the Licenses page, find the group, select the three dots on its row, then Unassign.
Step 2: Assign licences with Microsoft Graph PowerShell
Set-MgGroupLicense adds or removes licences on a group and supports disabled plans per SKU. First find the SKU ID and the service plan IDs you want to disable:
Connect-MgGraph -Scopes 'LicenseAssignment.ReadWrite.All','Group.Read.All','Organization.Read.All'
$sku = Get-MgSubscribedSku -All | Where-Object SkuPartNumber -eq 'ENTERPRISEPACK'
$sku.ServicePlans | Select-Object ServicePlanName, ServicePlanId | Sort-Object ServicePlanNameENTERPRISEPACK is the part number Microsoft's examples show for Office 365 E3; replace it with the part number of your product. Then assign it to the group with the plans you want switched off:
$groupId = (Get-MgGroup -Filter "displayName eq 'LIC-O365-E3-NoTeams-Pilot'").Id
$teamsPlan = ($sku.ServicePlans | Where-Object ServicePlanName -eq 'TEAMS1').ServicePlanId
$params = @{
AddLicenses = @(
@{
SkuId = $sku.SkuId
DisabledPlans = @($teamsPlan)
}
)
RemoveLicenses = @()
}
Set-MgGroupLicense -GroupId $groupId -BodyParameter $paramsTEAMS1 is the service plan name Microsoft documents for Microsoft Teams. The same pattern works for any plan in the SKU's ServicePlans list.
To remove a product from a group, pass its SKU ID in RemoveLicenses with an empty AddLicenses array.
Step 3: Move users from direct to group assignment
Users who already have a direct licence keep it when you add them to a licensed group. The same product assigned directly and through a group consumes only one licence, but if you leave the direct assignment in place, users keep that licence when they later leave the group, which defeats the point of group-based licensing. Clean them up in this order:
- Add the users to the licensed group.
- Wait until the group's processing finishes and confirm the users show the licence as inherited from the group.
- Remove the direct assignment only for SKUs that the group also assigns.
Microsoft publishes a script for step 3 in its group-based licensing PowerShell examples. It compares each member's directly assigned SKUs with the group's SKUs and calls Set-MgUserLicense -RemoveLicenses for the overlap. Microsoft's own caution applies: confirm the direct licence doesn't enable more service plans than the inherited one, because PowerShell can't currently tell you which services come from which assignment, and removing a richer direct licence can switch a service off.
The same ordering applies when you move a user between two licensed groups. Add the user to the destination group, confirm the new licence on the user's Licenses page, then remove them from the old group. If you remove first, the user is unlicensed until processing of the new group completes, which can be a long time in a large tenant.
Step 4: Verify
In the admin center, open Billing > Licenses, select the product, and check the group's status. Microsoft documents three values: All licenses assigned, In progress and Errors and issues.
With PowerShell, check the group's processing state:
Get-MgGroup -GroupId $groupId -Property DisplayName, LicenseProcessingState |
Select-Object DisplayName -ExpandProperty LicenseProcessingStateWait for ProcessingComplete before you judge the result. Then check how a user got each licence. The licenseAssignmentStates property shows assignedByGroup (null for direct assignments, the group ID for inherited ones), disabledPlans, state and error:
$user = Get-MgUser -UserId 'adele.vance@contoso.com' -Property DisplayName, LicenseAssignmentStates
$user.LicenseAssignmentStates | Format-Table SkuId, AssignedByGroup, State, Error, LastUpdatedDateTimestate can be Active, ActiveWithError, Disabled or Error.
Find every user with a group licensing error
Errors from group-based licensing happen in the background, so nothing pops up when they occur. They are recorded on the user object. In the admin center, select the product and open the Errors & issues tab. For a whole tenant, script it:
Connect-MgGraph -Scopes 'Group.Read.All','User.Read.All'
$licensedGroups = Get-MgGroup -All -Property Id, DisplayName, AssignedLicenses |
Where-Object { $_.AssignedLicenses }
$report = foreach ($group in $licensedGroups) {
$members = Get-MgGroupMemberWithLicenseError -GroupId $group.Id -All
foreach ($member in $members) {
$user = Get-MgUser -UserId $member.Id -Property UserPrincipalName, LicenseAssignmentStates
$user.LicenseAssignmentStates |
Where-Object { $_.AssignedByGroup -eq $group.Id -and $_.Error -and $_.Error -ne 'None' } |
ForEach-Object {
[pscustomobject]@{
Group = $group.DisplayName
User = $user.UserPrincipalName
SkuId = $_.SkuId
State = $_.State
Error = $_.Error
}
}
}
}
$report | Export-Csv -Path 'C:\Temp\GroupLicenseErrors.csv' -NoTypeInformationGet-MgGroupMemberWithLicenseError returns the members of a group that have licence errors, and filtering on AssignedByGroup keeps errors from other groups out of each row.
Troubleshooting licence assignment errors
The error property uses a fixed set of values: CountViolation, MutuallyExclusiveViolation, DependencyViolation, ProhibitedInUsageLocationViolation, UniquenessViolation and Other.
CountViolation: not enough licences
There aren't enough available licences for one of the products on the group. Buy more, or free licences held by users or groups that no longer need them. Because of the all-or-nothing rule, this also blocks every other product on the same group for the affected users.
MutuallyExclusiveViolation: conflicting service plans
A product on the group contains a service plan that can't coexist with a plan the user already has from another product. The audit log records "License assignment failed because service plans [...] are mutually exclusive." Microsoft's example is a user with Office 365 E1 assigned directly who is added to a group with Office 365 E3. Fix it by disabling the conflicting plan on one side, or by removing the redundant product from the user.
DependencyViolation: missing dependent plan
A service plan needs another plan, in another product, to stay enabled. This typically appears when a user is removed from a group and the removal would take away a plan that a different licence depends on. The audit message reads "License assignment failed because service plan [...] depends on the service plan(s) [...]". Make sure the required plan stays assigned some other way, or disable the dependent service for the user, then reprocess.
Add-on products have the same constraint on the way in: an add-on can only be assigned to a group that also carries its prerequisite plan. If you want to licence an add-on for a subset of users, create a group that carries the add-on plus the prerequisite product with only the required plan enabled. Those users consume a licence of each, and still consume only one licence of the base product if another group gives them the full version.
ProhibitedInUsageLocationViolation: service not allowed in that location
Some services aren't available in every country. If a user's usage location doesn't allow a product, assignment fails. Correct the usage location if it is wrong, or take the user out of that licensed group.
Proxy address is already being used
In Exchange Online, two recipients can end up with the same proxy address, and licence assignment fails with "Proxy address is already being used". Find the duplicate in Exchange Online PowerShell:
Get-Recipient -Filter "EmailAddresses -eq 'adele.vance@contoso.com'" |
Format-List DisplayName, RecipientType, EmailAddressesRemove the address from the wrong object, then reprocess the user.
LicenseAssignmentAttributeConcurrencyException
This usually appears when a user is in more than one group with the same licence. The service retries automatically and no action is needed.
Other
Other errors are usually caused by a failure on another licence assigned by the same group. Check the user's licences and the audit log. Failed group licence operations appear with Activity type "Change user license", Status "failure" and the initiator Microsoft Entra ID Group-Based Licensing.
Reprocess after you fix the cause
Some fixes, such as resolving a dependency, need a manual trigger. In the admin center, go to Billing > Licenses, select the product and the group, select the users and choose Reprocess (up to 20 users at a time). In PowerShell:
Connect-MgGraph -Scopes 'User.ReadWrite.All'
Import-Csv 'C:\Temp\GroupLicenseErrors.csv' |
Select-Object -ExpandProperty User -Unique |
ForEach-Object { Invoke-MgLicenseUser -UserId $_ }Deleting a licensed group
You must remove all licences from a group before you can delete it. Removal can fail for users with dependent licences or proxy address conflicts, and those users stay in an error state for every licence from that group until the dependency is resolved and they are reprocessed. Clear errors first, then unassign, then delete.
Checklist
- Usage location set on every user before they join a licensed group.
- One licence configuration per group, documented with its disabled plans.
- No nested groups used for licensing.
- Licences assigned in the admin center or with
Set-MgGroupLicense. - Users moved from direct to group assignment in the order add, confirm, remove.
- Group
LicenseProcessingStateshowsProcessingComplete. - A scheduled report of users with group licensing errors, with each error resolved and the user reprocessed.
- Licences removed from a group before the group is deleted.
If you are still choosing which suite to assign, the Business Premium vs E3 vs E5 comparison covers what each plan includes after the July 2026 changes.
References
- Assign or unassign licenses to a group in the Microsoft 365 admin center
- PowerShell examples for group-based licensing
- Set-MgGroupLicense
- licenseAssignmentState resource type
- servicePlanInfo resource type
- user: reprocessLicenseAssignment
- Get-MgGroupMemberWithLicenseError
- Manage user access to Microsoft Teams
- Identify and resolve license assignment problems for a group (archived Microsoft Entra docs source)
- What is group-based licensing in Microsoft Entra ID (archived docs source)
- Exercise: change group license assignments (Microsoft Learn training)
- group: assignLicense - Microsoft Graph v1.0