Microsoft 365 is licensed on a per-user model through User Subscription Licenses, and the plan family you choose depends almost entirely on headcount and compliance need. Organizations with 300 or fewer users typically evaluate the Business family, while larger or more regulated organizations move to Enterprise E plans. The first practical step is an inventory: count seats, flag regulated workloads, then map the result to Business Premium or an E3/E5 tier.
TL;DR:
- Licenses for organizations over 300 users generally require an Enterprise plan, as the Business family caps at 300 users and involves reassigning seats during growth.
- User licenses follow the individual, not devices, with restrictions on reassignments and no license reduction through multiplexing efforts, which still require actual licenses for indirect access.
- Setting the UsageLocation correctly is a critical step for license assignment, as region-specific service restrictions depend on accurate country codes.
- Licensing costs can be optimized by managing shared mailboxes under 50 GB without licenses and governing SKU drift through regular reconciliation and group-based assignment policies.
- Changes effective after July 1, 2026, will alter packaging and pricing, requiring organizations to plan renewals carefully and model costs for upcoming upgrades or subscriptions.
Table of Contents
- How Microsoft 365 licensing works: USLs, device licensing, and reassignment rules
- Business vs Enterprise: the practical decision framework
- Plan breakdown: Business and Enterprise tiers at a glance
- Administration and license assignment: UsageLocation, roles, and PowerShell
- Pricing, packaging, and buying channels for 2026
- Cost optimization and license governance
- Security and compliance entitlements and using Secure Score effectively
- Deployment and migration checklist for license changes
- Publisher perspective: what most licensing reviews get wrong
- How Secure Techies can help with Microsoft 365 licensing
- Authoritative Microsoft docs and product terms to bookmark
- FAQ
How Microsoft 365 licensing works: USLs, device licensing, and reassignment rules
A User Subscription License, or USL, assigns Microsoft 365 rights to a named individual rather than to a machine. That person can typically install and activate the associated apps on up to five devices under Microsoft's guideline, which covers a common scenario: an employee with a work laptop, a home desktop, and a phone, all running the same licensed copy of Microsoft 365 Apps.
Device-based licensing works differently and applies to a narrower use case. Instead of tying rights to a person, Microsoft 365 Apps for enterprise can be licensed to a specific Entra-joined device, which suits shared workstations in labs, front desks, or manufacturing floors where multiple employees rotate through the same machine. Device licensing removes the need to track individual users on that hardware, but it requires the device to be properly joined to Entra ID and configured before activation succeeds.
A concept administrators frequently misunderstand is multiplexing. Pooling connections through a middle-tier application, a shared database account, or an API gateway does not reduce the number of required licenses. If ten employees indirectly consume Microsoft 365 data or functionality through one shared service account, Microsoft's enterprise licensing guidance still treats each of those ten as a licensed user. Technical enforcement gaps, meaning the absence of a system that blocks unlicensed access, do not remove the underlying licensing obligation.
Reassignment carries its own rule. A license can generally be moved from one user to another, but Microsoft applies a 90-day waiting period before the same license can be reassigned again after certain changes. This matters operationally during layoffs, role changes, or seasonal staffing: an admin who reassigns a license today may not be able to reassign it again immediately if circumstances shift again shortly after.
Before assigning any license, keep these mechanics in mind:
- A USL license follows the person, with installation rights on multiple devices under the standard guideline.
- Device-based licensing suits shared or kiosk-style Windows machines rather than individual employees.
- Multiplexing never lowers the license count required, even when access is indirect or pooled.
- Reassigned licenses are subject to a 90-day cooldown that affects rapid staffing changes.
Understanding these fundamentals prevents the two most common licensing mistakes: under-licensing shared access paths and assuming a reassigned seat is immediately available again.
Business vs Enterprise: the practical decision framework
The clearest dividing line between Microsoft's two plan families is headcount. Microsoft 365 Business Premium and the rest of the Business family are capped at 300 users, a hard ceiling that Microsoft enforces at the tenant level. Once an organization crosses that threshold, or expects to within a budget cycle, planning should shift toward Enterprise licensing rather than treating the cap as a problem to solve later.
Several entitlements typically push organizations toward Enterprise even below 300 seats. Windows Enterprise upgrade rights, available on qualifying E3 and E5 SKUs, matter for organizations standardizing device images across a larger fleet. Advanced data loss prevention policies that span Exchange, SharePoint, and endpoint locations are an E5 or add-on capability rather than a Business Premium feature. Organizations with regulated data, such as healthcare or financial records, often need the deeper audit and analytics tools bundled into E5 rather than the security stack in Business Premium.
A simple set of decision rules helps most IT leaders move faster:
- Under 100 seats with no heavy compliance obligation: Business Premium covers identity protection, device management, and Defender for Business at a lower administrative overhead.
- Between 100 and 300 seats with moderate compliance needs, such as a professional services firm handling client contracts: Business Premium still works, but plan a compliance review before renewal.
- Above 300 seats, or any regulated workload requiring advanced DLP, insider risk management, or eDiscovery: move to E3 as a baseline and evaluate E5 for the security and analytics layer.
- Organizations already licensed for Windows Enterprise upgrade rights through another agreement: confirm whether Enterprise E plans are more cost-effective than stacking Business Premium with separate Windows entitlements.
The 300-user cap is not just a licensing technicality. It shapes how an organization structures its tenant, its group policies, and its long-term budget model, because migrating from Business to Enterprise mid-year involves reassigning every seat rather than simply adding new ones. Organizations expecting growth past 300 users within 12 to 18 months often benefit from starting on Enterprise early, even at a higher per-seat cost, to avoid a disruptive mid-cycle migration.
For a deeper side-by-side of feature tradeoffs between the two most commonly compared tiers, Secure Techies has published a detailed comparison of Business Premium and E3 that walks through security and administrative differences in more depth than a general licensing overview can cover.

Plan breakdown: Business and Enterprise tiers at a glance
Each tier in the Business and Enterprise families adds a distinct layer of capability rather than simply scaling the same features. Matching user groups to the right SKU, rather than defaulting everyone to the top tier, is where most licensing budgets are won or lost.
- Business Basic covers web and mobile versions of Office apps plus Exchange, SharePoint, and Teams, suited to frontline or lightweight users who rarely need desktop installs.
- Business Standard adds desktop installs of the full Office apps, useful for knowledge workers who need offline editing and advanced formatting.
- Business Premium layers on Defender for Business, Defender for Office 365 Plan 1, Intune device management, and conditional access, making it the practical floor for any organization handling sensitive client data.
- E1 provides the cloud productivity stack, Exchange, SharePoint, and Teams, without desktop app installs, often used for frontline staff in larger enterprises.
- E3 adds desktop Office apps, Windows Enterprise upgrade rights on qualifying devices, and stronger information protection than the Business family offers.
- E5 adds the deepest security and analytics layer: Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Microsoft Purview compliance tools, Power BI Pro, and advanced threat analytics.
Add-ons round out most enterprise budgets. Defender for Endpoint Plan 1 or Plan 2 can be purchased separately for organizations on E3 that need endpoint detection without a full E5 upgrade. Intune Plan 2 extends mobile device management beyond the baseline included in E3 and Business Premium. Microsoft Purview add-ons cover insider risk management and advanced eDiscovery for organizations that need those specific capabilities without paying for the entire E5 bundle. Copilot licensing sits outside the standard tiers entirely: it is sold as a separate per-user add-on with its own eligibility requirements tied to an existing qualifying Microsoft 365 license, so admins should confirm current eligibility rules before budgeting for it.
None of these summaries replace a direct read of the Product Terms, which is the binding document for server rights, desktop installation limits, and any special program entitlements tied to nonprofit, education, or government pricing. Feature comparisons change between fiscal years, and the Product Terms is the only source that carries contractual weight when a dispute arises over what a SKU actually includes.
Administration and license assignment: UsageLocation, roles, and PowerShell
Every user account needs a UsageLocation set before a license can be assigned, and this single step is the most common cause of failed assignments across tenants of every size. Microsoft's own guidance on assigning licenses confirms that UsageLocation, expressed as an ISO 3166-1 alpha-2 country code, determines which services are even available to that account, since some Microsoft 365 services are restricted by region.
Admin roles carry different levels of licensing control:
- Global admin can assign, remove, and purchase licenses across the entire tenant, plus manage all other admin roles.
- Billing admin can purchase licenses and manage subscriptions but cannot assign licenses to individual users.
- License admin can assign and remove licenses for specific users or groups without full billing or tenant-wide control.
For bulk operations, PowerShell remains the fastest path. A typical pattern starts with Get-MgSubscribedSku to list available SKUs and remaining unit counts, followed by Set-MgUserLicense to assign a specific SKU to a user or group of users. Microsoft's reference documentation for license assignment via PowerShell walks through the full cmdlet sequence, including how to filter by service plan when only certain features need to be disabled for a subset of users.
Pro Tip: Set UsageLocation automatically during account provisioning, rather than as a manual step, so failed license assignments never trace back to a missing country code.
When assignment fails, work through this checklist before escalating:
- Confirm the tenant has enough unused units of the target SKU.
- Verify UsageLocation is set on the account before retrying the assignment.
- Check whether the SKU is restricted in the user's region.
- Rule out conflicting group-based licensing rules assigning a different SKU to the same account.
For a broader set of operational checks beyond licensing, Secure Techies maintains a Global Admin best practices guide covering the wider set of tenant-level controls an admin role touches day to day.
Pricing, packaging, and buying channels for 2026
How an organization buys Microsoft 365 depends on its size and negotiating leverage. Cloud Solution Provider, or CSP, channels suit small and mid-size organizations that want a partner handling billing and support without a direct Microsoft contract. Enterprise Agreement and Enterprise Agreement Subscription channels fit larger organizations with the volume to negotiate multi-year pricing directly with Microsoft. The Microsoft Customer Agreement, or MCA, has become the default for many organizations buying through a partner or reseller, offering monthly billing flexibility. Web Direct purchases suit small teams buying a handful of seats without any negotiated terms.
Microsoft's pricing and packaging changes take effect July 1, 2026, with packaging rollouts beginning in June 2026 and continuing through August. This is the detail every renewal-planning admin needs on the calendar this year.
Existing customers keep their current pricing until their next renewal date, so the practical planning steps are:
- Confirm your tenant's renewal date and whether it falls before or after July 2026.
- Watch the Microsoft 365 Message Center for tenant-specific notices, since Microsoft provides at least 30 days notice ahead of changes that affect a given account.
- Model the new packaging against current add-on spend before assuming a like-for-like renewal.
- Stagger any packaging-driven changes by business unit rather than rolling them out tenant-wide on day one.
Organizations renewing in the second half of 2026 should treat this packaging update as a budgeting exercise, not just a procurement notice. Add-ons that were bundled differently before the change may shift a renewal's total cost even when headcount stays flat.
Cost optimization and license governance
Shared mailboxes are one of the most overlooked cost levers in a Microsoft 365 tenant. A shared mailbox under 50 GB does not require a license at all, but once it grows past that threshold, or needs litigation hold or archiving, Microsoft requires an Exchange Online Plan 2 license to be attached. A handful of oversized shared mailboxes discovered during a tenant consolidation can add unplanned licensing cost if nobody checked mailbox size beforehand.
Device-based licensing saves money in specific, narrow scenarios: shared kiosks, classroom computers, and front-desk workstations where multiple employees rotate through the same machine each day. Licensing the device once, rather than licensing every rotating user, avoids paying for redundant per-user rights on hardware nobody exclusively owns.
Mixing Business and Enterprise SKUs in a single tenant is allowed and common, but it needs governance to avoid drift:
- Tag every user group by SKU tier in your identity provider so license assignment stays predictable during onboarding.
- Run a monthly reconciliation comparing assigned licenses against active employee records to catch orphaned seats.
- Set alerts for unused unit counts approaching zero, so purchasing has lead time before a hiring wave stalls on missing licenses.
- Review group-based licensing rules quarterly, since role changes often leave users on a SKU tier that no longer matches their job.
Pro Tip: Build a simple monthly report pairing your HR system's active employee list against Microsoft 365 assigned licenses, since license drift almost always starts with an offboarding step that got skipped.
A written policy helps more than any single technical control. Define who can approve a new SKU purchase, who reviews shared mailbox size quarterly, and who owns the reconciliation report, so cost creep does not depend on one person remembering to check.
Security and compliance entitlements and using Secure Score effectively
Security features scale sharply between Business Premium and the Enterprise tiers. Business Premium includes Defender for Business and Defender for Office 365 Plan 1, covering endpoint protection and phishing defense suited to smaller organizations. E3 raises the baseline information protection tools but still requires an add-on for full endpoint detection and response. E5 includes Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, insider risk management, and the deeper data loss prevention policies that regulated organizations often need.
Microsoft Secure Score measures how completely an organization has implemented Microsoft's recommended security controls, and it matters because the score is a posture indicator, not a guarantee against a breach. Scoring works in a largely binary fashion: a control is either configured to Microsoft's recommendation or it is not, with partial credit rarely available.
The practical use of Secure Score is as a prioritized backlog rather than a report card. Each unimplemented recommendation ties to a specific configuration, and many of the highest-impact recommendations are gated behind a specific license tier, such as conditional access policies requiring Entra ID P1 or advanced DLP requiring an E5 or Purview add-on. Reviewing Secure Score alongside your current SKU mix shows exactly which recommendations are achievable today versus which ones require a licensing upgrade first.
Security features worth mapping directly to licensing decisions:
- Defender for Business and Defender for Office 365 Plan 1 come standard with Business Premium.
- Defender for Endpoint Plan 2 and Defender for Office 365 Plan 2 are E5 entitlements or standalone add-ons on E3.
- Insider Risk Management and advanced DLP require E5 or a Purview add-on purchase.
- Conditional access policies depend on Entra ID plan level, not the Microsoft 365 SKU alone.
For a structured walkthrough of interpreting Secure Score recommendations against real tenant settings, Secure Techies has published a Microsoft 365 security checklist that pairs each common recommendation with the configuration steps behind it.
Deployment and migration checklist for license changes
Executing a licensing change without disrupting daily operations depends on sequencing, not speed. Rushing an assignment change across an entire tenant in one afternoon is how shared mailboxes lose access and third-party integrations break without warning.
- Inventory current state: export every assigned SKU, list shared mailboxes and their sizes, document device groups using device-based licensing, and flag any third-party app that relies on a specific Microsoft 365 service plan.
- Confirm renewal timing: check the tenant's renewal date against the July 2026 packaging changes, and note any Message Center notices affecting the target SKUs.
- Build a phased rollout plan: group users by department or role rather than changing the entire tenant simultaneously, starting with a pilot group of 10 to 20 users.
- Set UsageLocation for every account in the rollout before attempting any assignment, confirming the country code matches each user's actual location.
- Assign licenses by group, using group-based licensing rules rather than individual assignments, to keep the process auditable and reversible.
- Test critical services immediately after each phase: mail flow, Teams calling if applicable, and SharePoint access for the pilot group.
- Monitor sign-in and license assignment logs for the 48 hours following each phase to catch failures before they reach the next group.
- Keep a documented rollback step for each phase, since a license downgrade can be applied as quickly as the original assignment if a critical feature breaks.
A real migration rarely goes exactly to plan, and Secure Techies has documented one such Microsoft 365 email migration case study showing how a phased approach caught a shared mailbox licensing gap before it affected the full user base.
Publisher perspective: what most licensing reviews get wrong
The biggest licensing mistake we see is not choosing the wrong plan tier. It is letting license assignment drift for months after the initial rollout, so a tenant ends up paying for a mix of SKUs that no longer maps to what any team actually uses. A licensing assessment done once at purchase time and never revisited is functionally the same as no governance at all.
A sound engagement moves through four phases: an assessment of current SKU assignment against actual usage, a rightsizing pass that reassigns users to the correct tier, a migration phase for any SKU changes that require sequencing, and ongoing governance that catches drift before it compounds into a renewal surprise. Skipping the fourth phase is the most common shortcut, and it is the one that costs the most over a two-year contract term.

The same four-phase structure can be applied across managed IT engagements for small and mid-size organizations, with outcomes including more predictable renewal costs and improved compliance readiness, particularly for regulated industries that require licensing tiers matching their DLP and audit requirements.
The lesson we would give any IT leader evaluating this on their own: licensing is not a one-time purchasing decision. It is an ongoing reconciliation problem, and it rewards whoever checks it monthly rather than annually.
— Alex
How Secure Techies can help with Microsoft 365 licensing

Licensing decisions get harder as a tenant grows, and getting them wrong shows up as either overspending on unused seats or under-licensing a compliance-critical workload. Secure Techies works with small and mid-size organizations to run license assessments that map actual usage against current SKU assignment, then handle the migration and rightsizing that follows. Ongoing governance, including monthly reconciliation and 24/7 monitoring, catches license drift before it turns into a renewal surprise. For organizations in regulated industries, our compliance audit work checks that the licensing tier in place actually supports the HIPAA, GDPR, or SOC 2 obligations the business carries. Our managed help desk also handles the day-to-day assignment errors, like a missing UsageLocation or a group policy conflict, that otherwise pile up between reviews. If your organization is planning a Microsoft 365 licensing change or a renewal in the coming year, visit our Managed IT Services page to talk through what a rightsizing assessment would look like for your tenant.
Authoritative Microsoft docs and product terms to bookmark
For anything contractual or SKU-specific, treat the Microsoft Product Terms site as the source of record rather than any third-party summary, including this one. Bookmark Microsoft's licensing guidance for Enterprise plans, the PowerShell license assignment reference, and the Microsoft 365 pricing and packaging updates page for renewal season. Organizations evaluating hosted or outsourced infrastructure alongside their licensing plan may also want to review a partner like AceRDP for Windows RDP and VPS hosting options that pair with a Microsoft 365 deployment.
FAQ
What are the different types of Microsoft 365 licenses?
Microsoft 365 licenses fall into two main families: Business plans, capped at 300 users, and Enterprise plans, which have no user cap. Within each family, tiers range from basic productivity access up through advanced security and compliance features, with Business Premium and E3 or E5 representing the most feature-complete options in each.
Can you buy Microsoft 365 for a lifetime?
No, Microsoft 365 is sold as a recurring subscription rather than a one-time lifetime purchase. Microsoft's standalone Office products, like Office Home & Student, are sold as one-time purchases, but they are a separate product line from Microsoft 365 and lack the cloud services, security features, and ongoing updates bundled into a subscription.
What licenses are included in Microsoft Office 365?
Office 365 was Microsoft's earlier branding for what is now sold as Microsoft 365, and it included the same core productivity apps alongside Exchange, SharePoint, and Teams. Today those plans are branded under the Microsoft 365 Business and Enterprise families described above, with the same tiered structure from Basic through Premium and E1 through E5.
What is an E1, E3, and E5 license?
E1 provides cloud-based Exchange, SharePoint, and Teams without desktop app installs, suited to frontline users. E3 adds desktop Office apps and Windows Enterprise upgrade rights, while E5 adds the deepest security and compliance layer, including Defender for Endpoint Plan 2 and advanced Purview tools.
Do shared mailboxes need a Microsoft 365 license?
A shared mailbox needs no license as long as it stays under 50 GB and does not require litigation hold or archiving. Once it exceeds that size or needs those features, Microsoft requires an Exchange Online Plan 2 license to be assigned to it.
