The terms below are the vocabulary a D365 Finance & Supply Chain license bill is actually written in. Most of them get re-explained from scratch in every licensing conversation, so this is the one place they are all defined together, in plain English, each linked to the full article where it is worked through in depth. If a single idea underpins the whole set, it is this: your license cost is decided by your security configuration, not by your headcount.
License types · The security model that drives the license · Analysis concepts · Compliance and risk
License types
Subscription License (SL)
A named-user license in D365 Finance & Supply Chain. Each user needs exactly one SL, and it has to match the highest level of functionality that user is capable of touching, not the functionality their department uses most often. Covered in the fundamentals guide.
Named user
A specific, individual person a license is assigned to, as opposed to a shared device or a non-interactive service account. Most D365 F&SC licensing is per named user, which is why device and integration accounts have to be separated out before any count is trustworthy.
Base license
When a user needs more than one Dynamics 365 application, the highest-priced application has to be bought as their base license. It is the anchor every other license for that user attaches to.
Attach license
Any additional Dynamics 365 application for a user who already holds a qualifying base license. It is functionally identical to a standalone license but priced lower, and it can only be assigned on top of a base. Get the base and attach ordering backwards and you either can't assign it or you pay full price for both.
Team Members
The lightest F&SC subscription tier: read access across most modules plus light self-service, such as recording your own time and expenses, approving your own items, and creating requisitions.
Operations - Activity
The tier for day-to-day transactional staff such as AP/AR clerks, warehouse workers, and planners. It includes everything Team Members gets plus creating and editing operational records like warehousing, receiving, shipping, and vendor maintenance.
Operations - Device
A shared-device license tied to a terminal rather than a person, for point-of-sale, warehouse, or production-floor devices that several people use in turn. It can replace multiple named-user licenses, but only for genuine shared-device work.
Finance / Supply Chain Management
A full-function named-user license for its module, with full transactional access to core financials or core supply chain. List price is $210 per user per month per the current licensing guide.
Finance Premium / SCM Premium
Everything in the base Finance or Supply Chain tier plus business performance planning (budgets, forecasts, financial analysis) and higher default capacity. List price is $300 per user per month. A user who is merely capable of a Premium action needs this tier even if they use it twice a year.
Operations - Order Lines
A per-tenant, transaction-based license covering specific automated table updates (sales and purchase order lines, journal entries, IoT messages, and a defined list of others) without needing a license for each actor behind them. It is Microsoft's designed answer to a large share of integration multiplexing scenarios.
The security model that drives the license
Entry point
The lowest-level securable object in D365: a specific menu item, form, or action that a privilege grants access to. Each entry point qualifies for its own set of licenses, and the entry points a role touches are what actually drive its license requirement. See how a requirement rolls up from an entry point.
Privilege
A group of entry points bundled together with an access level (read, update, create, delete, or correct). Privileges are the building block a duty is assembled from, and a single privilege only requires the license set shared across all of its entry points, not the most expensive one any single entry point could justify.
Duty
A collection of privileges that represents a task someone performs in the business. Duties are grouped into roles, and a Deny on a duty always suppresses a Grant elsewhere, even though licensing still charges for the suppressed Grant.
Security role
The unit of access assigned to a user, built from duties and their underlying privileges and entry points. A role's name rarely explains its license cost; the entry points buried underneath it do. See finding your most expensive roles.
License roll-up
The way D365 calculates a license requirement, upward from a single entry point through privilege, duty, and role to the user who holds them. The requirement at each level is the license set shared across everything beneath it. Walked through in the roll-up series.
Analysis concepts
License analysis
Determining what a security configuration currently requires in licenses, and tracing each requirement back to the specific role, duty, privilege, or entry point driving it. It answers what you are paying for and why.
License optimization
Determining what has to change in the security configuration to bring the license requirement down, and by how much. It is a different lever from a discount, which lowers the price per license but never the count. See why they are two different savings.
Telemetry
Usage data showing what access users actually exercised, used to compare what a role grants against what its holders actually do. It has real blind spots and can't be trusted on its own. See what telemetry can and can't tell you.
Audit trail (audit stamp)
The CreatedBy, ModifiedBy, and matching date fields D365 writes onto records: evidence that a specific user created or changed data. It is a second usage source alongside telemetry, because some actions telemetry never captures. See the privileges that are audit-blind by design.
Disposition (keep / downgrade / drop)
The verdict assigned to each privilege in an evidence-based review: keep it as-is, downgrade it to read-only, or drop it, based strictly on what the usage evidence showed. A blank record only means "drop" when the action could have been observed in the first place. See how we decide what stays and what goes.
Compliance and risk
Segregation of Duties (SoD)
A control that prevents one person from holding a combination of access that would let them commit and conceal an error or fraud, such as both creating a vendor and paying it. The conflicts most often hide inside inherited roles, not the roles you would think to check first. See finding SoD conflicts before your auditor does.
Multiplexing
Funneling transactions from many distinct people through a single licensed account, device, or integration to avoid licensing them individually. Microsoft's terms still require the underlying users to be licensed, and it is one of the first things a compliance review checks. Covered in the fundamentals guide.
Per-user license validation
Microsoft's enforcement, rolling out from January 15, 2026 and tied to each customer's renewal or anniversary date, that checks each user actually holds a license matching the access they are assigned. It turns "we are probably overpaying" into a dated compliance question. See what changes and how to prepare.
Every term here connects back to a single mechanism: a license requirement rolls up from the individual entry points a user can reach, through privileges, duties, and roles, to the person. Change what is reachable and you change the bill. That is what a license analysis measures and what an optimization acts on.