If your D365 Finance & Supply Chain tenant hasn't been through a licensing self-audit recently, this is the article that should move it to the top of the list. Microsoft has confirmed a staged rollout of mandatory per-user license validation, tied to each customer's contract anniversary or renewal date. Starting from that date, users without an assigned license will lose access, not just show up on a report.

This isn't a future proposal. It's an active rollout with dates attached. Here's what's actually changing, who's affected, and the four-step prep sequence Microsoft itself recommends.

What actually changed

On March 28, 2025, Microsoft published the update outlining this shift. Two dates matter most:

Key point: this is a rolling deployment, not a single flag-day. Your tenant's exposure date is your own contract anniversary or renewal date, not January 15 itself, unless that happens to be your renewal date.

The enforcement timeline

Microsoft's own milestone structure runs on a T-minus/T-plus schedule relative to your contract anniversary or renewal date:

MilestoneWhat happens
T-90 days Customers begin anniversary preparation, typically supported by their seller or partner.
T-30 days In-app notifications appear, alerting users who don't have an assigned license.
T+15 days License validation begins in earnest, a 15-day window to assign correct licenses before enforcement.

Users who already have the correct license assigned see no disruption and need no action. This is squarely aimed at the gap between who's actually using the system and who has a license on file for it.

Which applications are in scope

The requirement to assign licenses through the Microsoft 365 admin center currently covers:

Validation applies to commercial cloud solutions only, and only to production environments: sandbox, dev, test, and UAT environments are out of scope. Government and sovereign cloud customers (GCC, GCC High, DoD, Azure China 21Vianet) are currently excluded as well, though Microsoft notes the underlying requirement to hold valid licenses still applies to them; enforcement timing will follow separately.

How the check actually works

A few mechanics worth understanding before you assume you know how this applies to your tenant:

Service accounts and integrations: the part people miss

Every integration or batch process touching your F&SC environment runs under some kind of account, and the natural instinct is to license it defensively "just in case." Microsoft's guidance is more specific than that: service accounts assigned only to non-interactive, system-function roles are excluded from license reporting. That list includes roles like Batch job manager, Data management operations user, System administrator, Business events security role, and about forty others covering integration, diagnostics, and platform-management functions.

Where this bites: the exclusion only holds if the service account is scoped to only those roles. The moment a "service account" also gets a business-functional role bolted on for convenience, even temporarily, during a migration or a one-off fix, it becomes a licensable user like any other. This is one of the fastest ways a self-audit turns up a surprise.

The four-step prep sequence Microsoft recommends

  1. Review licensing requirements. Understand how security roles, duties, and privileges map to license tiers. This is what the Dynamics 365 Licensing Guide's role tables are for.
  2. Assess user roles and license mapping. Use PPAC or Lifecycle Services reporting to get a summary of active users and what they're licensed to require.
  3. Optimize assignments. Run the License Usage Summary Report inside D365 F&SC (System administration → Security governance → License usage summary) to spot unnecessary entitlements before they get flagged for you.
  4. Update assignments in the Microsoft 365 admin center. This is the system of record for license assignment. PPAC and LCS report on requirements, but the actual assignment happens here. Microsoft recommends doing this at least 24 hours before a user needs access, to let the assignment propagate across Dynamics 365, Power Platform, and Microsoft Entra ID.

Two known rollout issues worth knowing about

As of this writing, Microsoft has flagged two reporting quirks during the rollout:

What to do this quarter

If you don't already know your tenant's contract anniversary or renewal date, that's step zero. Everything else in this rollout is scheduled relative to it. From there, the self-audit steps in our companion article on D365 F&SC licensing types and where the money leaks double as validation prep: the same overbuying patterns that inflate your bill are exactly what a per-user validation pass will surface as gaps, just in the other direction, underlicensed rather than overlicensed.