If your D365 Finance & Supply Chain tenant hasn't been through a licensing self-audit recently, this is the article that should move it to the top of the list. Microsoft has confirmed a staged rollout of mandatory per-user license validation, tied to each customer's contract anniversary or renewal date. Starting from that date, users without an assigned license will lose access, not just show up on a report.
This isn't a future proposal. It's an active rollout with dates attached. Here's what's actually changing, who's affected, and the four-step prep sequence Microsoft itself recommends.
What actually changed
On March 28, 2025, Microsoft published the update outlining this shift. Two dates matter most:
- May 15, 2025: administrators gained access to improved license usage reporting in the Power Platform admin center (PPAC) and Dynamics Lifecycle Services (LCS), showing seats available vs. seats assigned.
- January 15, 2026: staged per-user license validation began rolling out, aligned to each customer's own contract anniversary or renewal date rather than a single hard cutover for everyone.
The enforcement timeline
Microsoft's own milestone structure runs on a T-minus/T-plus schedule relative to your contract anniversary or renewal date:
| Milestone | What happens |
|---|---|
| T-90 days | Customers begin anniversary preparation, typically supported by their seller or partner. |
| T-30 days | In-app notifications appear, alerting users who don't have an assigned license. |
| T+15 days | License validation begins in earnest, a 15-day window to assign correct licenses before enforcement. |
Users who already have the correct license assigned see no disruption and need no action. This is squarely aimed at the gap between who's actually using the system and who has a license on file for it.
Which applications are in scope
The requirement to assign licenses through the Microsoft 365 admin center currently covers:
- Dynamics 365 Finance
- Dynamics 365 Supply Chain Management
- Dynamics 365 Commerce
- Dynamics 365 Project Operations
- Dynamics 365 Human Resources
Validation applies to commercial cloud solutions only, and only to production environments: sandbox, dev, test, and UAT environments are out of scope. Government and sovereign cloud customers (GCC, GCC High, DoD, Azure China 21Vianet) are currently excluded as well, though Microsoft notes the underlying requirement to hold valid licenses still applies to them; enforcement timing will follow separately.
How the check actually works
A few mechanics worth understanding before you assume you know how this applies to your tenant:
- Validation is per-tenant, not per-agreement. If you have multiple Microsoft agreements, validation defaults to the earliest anniversary date among them. Multiple tenants each get their own validation date.
- Multiple production environments reconcile together. You don't need a separate license per production environment in the same tenant, but the licenses required are the union across all of them. If a user touches Finance in one environment and Supply Chain Management in another, they need both licenses, not one.
- Multiple roles stack to the highest requirement. A user holding both a Buying Agent role and an Accounts Payable role, for example, needs both a Supply Chain Management (base) license and a Finance (attach) license. Microsoft's own FAQ uses this exact example.
- System administrators are exempt. Users with the Power Platform administrator, Dynamics 365 service administrator, or System Administrator role don't require a license to administer the application.
Service accounts and integrations: the part people miss
Every integration or batch process touching your F&SC environment runs under some kind of account, and the natural instinct is to license it defensively "just in case." Microsoft's guidance is more specific than that: service accounts assigned only to non-interactive, system-function roles are excluded from license reporting. That list includes roles like Batch job manager, Data management operations user, System administrator, Business events security role, and about forty others covering integration, diagnostics, and platform-management functions.
The four-step prep sequence Microsoft recommends
- Review licensing requirements. Understand how security roles, duties, and privileges map to license tiers. This is what the Dynamics 365 Licensing Guide's role tables are for.
- Assess user roles and license mapping. Use PPAC or Lifecycle Services reporting to get a summary of active users and what they're licensed to require.
- Optimize assignments. Run the License Usage Summary Report inside D365 F&SC (System administration → Security governance → License usage summary) to spot unnecessary entitlements before they get flagged for you.
- Update assignments in the Microsoft 365 admin center. This is the system of record for license assignment. PPAC and LCS report on requirements, but the actual assignment happens here. Microsoft recommends doing this at least 24 hours before a user needs access, to let the assignment propagate across Dynamics 365, Power Platform, and Microsoft Entra ID.
Two known rollout issues worth knowing about
As of this writing, Microsoft has flagged two reporting quirks during the rollout:
- Entra ID group-provisioned users go missing from reports until they sign in for the first time. The provisioning pipeline doesn't fully register them until then. If your headcount looks lower than expected in PPAC, this is the first thing to check.
- "Total Users Requiring License" can display as zero on tenants not yet on the latest quality update, a known display bug, not an actual entitlement gap. Applying the current Platform Quality Update resolves it.
What to do this quarter
If you don't already know your tenant's contract anniversary or renewal date, that's step zero. Everything else in this rollout is scheduled relative to it. From there, the self-audit steps in our companion article on D365 F&SC licensing types and where the money leaks double as validation prep: the same overbuying patterns that inflate your bill are exactly what a per-user validation pass will surface as gaps, just in the other direction, underlicensed rather than overlicensed.