Group-based licensing: finding and fixing assignment errors
Group-based licensing is the right way to assign Microsoft 365 licences, until a user silently doesn't get one. Here's where the errors hide.
On this page
Assigning licences through security groups keeps things tidy: join the group, get the licence. When a new SKU arrives, the usual approach is to mirror the existing setup with a new group. Most of the time it just works. When it doesn't, the user simply ends up without the licence, and nothing tells them why.
Where errors show up
In the Entra admin center, open the licensing group and check its Licenses blade. Groups with problems show a warning, and you can drill into the users affected and the error for each. To find every group with errors across the tenant:
Connect-MgGraph -Scopes "Group.Read.All"
Get-MgGroup -All -Filter "hasMembersWithLicenseErrors eq true" |
Select-Object DisplayName, IdThe usual causes
- Not enough licences. The group has more members than you have seats. Users beyond the limit get nothing.
- Conflicting service plans. Some service plans can't be assigned alongside each other. If a user is in two licensing groups with overlapping or conflicting plans, the second assignment can fail.
- Missing dependencies. Some add-ons need a base plan to be enabled. If you disabled that plan in the group's licence options, the add-on fails.
- No usage location. Users need a usage location set before a licence can be assigned.
| Error | Meaning | Fix |
|---|---|---|
CountViolation | Not enough licences | Buy more or remove unused assignments |
MutuallyExclusiveViolation | Conflicting service plans | Remove the user from one group, or disable the clashing plan |
DependencyViolation | Add-on needs a base plan that's disabled | Enable the required plan in the group's licence options |
UsageLocationNotAllowed | No usage location on the user | Set it, ideally from HR data or a default in provisioning |
ProhibitedInUsageLocationViolation | Service not available in the user's country | Check the usage location is correct |
You can check the licence finder at /tools/licences/ to see which SKUs include which service plans.
Moving users between SKUs cleanly
- Create the new licensing group and configure its service plans to match the old one.
- Test with a small pilot group of users first.
- Add users to the new group, check for errors, then remove them from the old one.
- Use Reprocess on the group after fixing a problem, so Entra retries the assignments.
- New group created, service plans matched
- Pilot users added, errors checked
- Everyone added to the new group: users hold both licences
- Removed from the old group
- Old SKU count reduced at renewal
Reprocessing after a fix
Fixing the cause doesn't always clear the error straight away. Reprocess the affected users:
Connect-MgGraph -Scopes "User.ReadWrite.All"
$g = Get-MgGroup -Filter "displayName eq 'LIC-M365-E5'"
Get-MgGroupMember -GroupId $g.Id -All | ForEach-Object {
Invoke-MgLicenseUser -UserId $_.Id
}Why does the user have the licence directly and through a group?
Direct and group assignments can coexist. Remove the direct one once the group has applied, so the group is the only thing to manage.
Can a user be in two groups for the same SKU?
Yes. They consume one licence, and the enabled plans are combined across the groups.
This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.