Azure Active Directory Premium P1 plan

When i only need to use the extra Dynamic groups or/and Conditional Access features in Azure AD i need at least Azure AD Premium P1 plan. Therefor i need to pay for each user in my tenant who authenticate, right?


So I have a test environment with only Enterprise Mobility + Security E5 license. This license model includes Azure AD Premium P2. So my test tenant has a Azure AD Premium P2 plan.  I do not understand why it is possible to assign a P1 and/or P2 license per user if the whole Azure AD already has a Premium P2 plan. I can still use the Conditional Acces features even for users without a license. 

As far as I have understood;  Azure AD comes in 4 license models: Free, O365, Premium P1, Premium P2. License plans for the Azure Ad tenant. I therefore do not understand why I can still select P1 or P2 per user if the features for the Azure AD with P1 or P2 already enabled (eq Condition Acces, Dynamic groups). 


Microsoft does not enforce licensing requirements in code for many of the features, thus making them available even when no direct license assignments exist. This doesnt mean that you are allowed to go that route, it still counts as license violation.
So if I understand correctly, it is my own responsibility to determine which user uses, for example, Conditional Access Policy and for this I have to activate the p1 license.

Do I only pay for the activated users or do I pay for the entire Azure AD tenant with all my users in it?
You pay for the number of licenses purchased, it's your responsibility to make sure this number is sufficient to cover all users taking advantage of specific feature(s).

@Vasil Michev Thank you for your answers. I do understand the responsibility part. But i don't understand why there is an option to update the license assignment per user and enable or disable the Azure AD Premium 1 (or 2). If what you say is true then I already payed for the number of licenses and the extra features is already enabled on the Azure AD tenant. In this case an Azure AD Premium 2 tenant. 




So why is there an option to enable or disable Azure AD license plan per user(s)?

Why wouldnt there be one, most services can be toggled on a per-user basis. This is no different from having the Exchange Online service listed in the M365 SKU. Although in that example, removing the service will actually affect functionality. Different teams within MS have different views on how to handle licensing requirements in code, that's just something you'll have to get used to.