I also wanted to have the following scenario clarified.
I'm an IT-Service Provider and i have my own Tenant (tenantA.onmicrosoft.com). In this Tenant I have my workforce, contracters (also seen as kind of "internal staff some times) and some other personas (auditors etc.) that have entra licenses assigned - mostly E3 and E5s. All humans are synchronized from an onpremise forest. I also have dedicated Admin Users (cloud only as well as synchronized from that forest).
I also have a second Tenant (tenantB.onmicroosft.com). In this Tenant I have also my workforce and also some contractors - but this time, as this tenant is basically to be used as our Administration Tenant (CSP) and therefore the users don't have an E3, E5 licences assigned. There is also no Multi Tenant Configuration in place between TenantA and B. The users in TenantB are synchornized from another onpremises Forest - completely separated.
Now to following questions arrises as im able to bend the words of "One person, one license" very far. For example:
* Do I require additonal licences for my auditors in Tenant A - as they will probably already be licensed in their own corp. tenant (but EXO, Teams, SPO etc. is required during their working period)
* Do I require additional licenses for my admin users in Tenant A - as the same person already has an E5 licences with his "office user".
* Do I require additional licenes fro my admin users in my Tenant B - to be able to create conditional access policies with sign-in risks, user risk detection (as these require Entra ID P2 licencing) but as the same users are already licensed with an E5 in Tenant A... one person, one license, right?
Thanks for clarification 😉