Forum Discussion
Azure AD Premium Licensing & permission to use MFA, SSPR, ConditionalAccess, etc.
Hey folks,
i'm wondering on how to deal with the following scenario correctly: (i know how to use the techniques, it's just about the correct licensing)
- Contoso has e.g. 100 Users (Members)
- 50 Users are licensed with sth. that includes Azure AD Premium P1
- 30 Users are licensed with sth. that includes P2
- 20 Users are not licensed (Service accounts, administrative accounts, test accounts, ..)
- In addition there are e.g. 40 invited guest accounts, which are not licensed at all.
- (I guess this is a very common scenaraio)

- Contoso wants to use different technologies like
- SSPR (SelfService Password Reset)
- Azure AD Identity Protection: MFA Registration Policy
- Conditional Access Policies to require MFA
- Conditional Access Policies to react to User-Risk or SignIn Risk
- (Very common, too i guess)
Question: How to "use" these techniques correctly?
- SSPR (SelfService Password Reset)
- Allow for anyone?
- Only allow for a dynamic group which includes all AAD P1 licensed users?
- Azure AD Identity Protection: MFA Registration Policy
- Allow for anyone?
- Dynamic group with AAD P2 Users?
- Conditional Access Policies to require MFA
- Allow for anyone?
- Dynamic group with AAD P1 Users?
- Conditional Access Policies to react to User-Risk or SignIn Risk
- Allow for anyone?
- Dynamic group with AAD P2 Users?
Of course im fine with using dynamic groups including AADP1/P2 Users, but what about all the guest users for example.
What is allowed, what isn't allowed?
Thank you very much for any help in advance. ![]()
Regards,
Patrick
PatrickF11 your guest users are covered under the monthly active user MAU licencing MAU billing model for Azure AD External Identities - Microsoft Entra | Microsoft Learn so can make use of P1 and P1 functionality. Just make sure the tenant is set up for MAU billing.
I wrote on blog on guest governance you may find useful. Use Azure AD Premium 1 or 2 licence functionality with your Guest users (nikkichapple.com)
2 Replies
PatrickF11 your guest users are covered under the monthly active user MAU licencing MAU billing model for Azure AD External Identities - Microsoft Entra | Microsoft Learn so can make use of P1 and P1 functionality. Just make sure the tenant is set up for MAU billing.
I wrote on blog on guest governance you may find useful. Use Azure AD Premium 1 or 2 licence functionality with your Guest users (nikkichapple.com)
nikkichapple Thank you very much, these are great information.
One last question: Do you know a way to count the MAU?