licensing & activation
203 TopicsHow much of your Microsoft 365 environment can you actually see at once?
Not how many users you have. Not how many sites, teams, apps or flows you have. How much of it can you actually see connected together? I've been working across Microsoft 365 environments for a while, and I kept running into the same thing. There is no shortage of information. If anything, there is probably too much of it. Users, groups, permissions, SharePoint, Teams, Power Apps, Power Automate, Power BI, Dataverse, OneDrive, Exchange, Intune, licensing, configuration... It's all there. But when you're actually trying to understand how everything fits together, it can be a different story. You open one blade. Find something. Open another. Cross-check it. Go back. Open something else. Before long, you're jumping between different parts of the tenant trying to build the bigger picture in your head. And if you're working with larger environments, that gets difficult pretty quickly. The information isn't necessarily missing. The relationships between the information are what can be difficult to see. That got me thinking about a slightly different question: Instead of "where do I find this information?" "Show me what's connected to this." That's where VisibleState started. Start anywhere. Follow the connections. Imagine starting with a single user. Instead of seeing that user simply as a record with a list of properties, imagine being able to explore the relationships around them: User → Groups → SharePoint → Teams → Power Apps → Power Automate → Power BI → Dataverse → OneDrive → Exchange → Intune Then the questions become different: What does this user have access to? Is that access direct or coming through a group? What resources are connected to them? What depends on something they're associated with? Which licenses are involved? Are there relationships that look unusual? If something changes, what else might be affected? Those questions aren't necessarily about finding another piece of information. They're about putting information that already exists into context. A report can tell you that something exists. A connected view helps you understand what it is connected to. Illustrative example below — not a real customer environment. I'm not suggesting Microsoft 365 doesn't already give us this information Quite the opposite. Microsoft 365 already gives administrators an incredible amount of information and tooling. The thing I've been thinking about is what happens when you want to look across those boundaries. Sometimes I don't want another export. I don't want another list. I don't necessarily want another dashboard. I want to start with something I'm looking at and ask: "What's connected to this?" And then keep following the trail. That's the idea I'm exploring with VisibleState. The interesting part is what happens when you change the viewpoint The same relationships can be useful for completely different reasons. For example: Administrators may want to understand access, permissions and dependencies. Security and governance teams may want to find unusual relationships or exceptions. Compliance teams may need to understand who can access something and why. People managing multiple environments may want a consistent way to understand what's there without rebuilding the picture manually every time. Leadership may not need to see the graph at all. They may simply want to know what's important, what's exposed and what could be affected. It's still the same underlying environment. You're just looking at it from a different angle. And that's where I think things get interesting. Where I'm at with it VisibleState started as something I was building to make my own work easier. I was spending a lot of time investigating environments, tracing access and putting information together for reports. The individual tasks weren't necessarily difficult. It was the jumping between different places and reconstructing the bigger picture that took the time. So I started building something that would let me approach the environment through the relationships instead. It's grown quite a bit from where it started, and I'm continuing to build it. I'm not posting this as a product launch, and I'm not looking for people to sign up. I'm genuinely interested in whether the problem I'm seeing is familiar to other people working with Microsoft 365. So I'm curious... If you could start with any object in your Microsoft 365 environment and immediately see what it's connected to, where would you start? Would it be: Users and access Groups and permissions SharePoint and Teams Power Apps, Power Automate, Power BI and Dataverse Licensing and resources Governance and unusual relationships Something completely different Maybe you've already got a good way of doing this. Maybe you still find yourself jumping between different services and piecing things together manually. Or maybe I'm looking at the problem from the wrong direction. What's the one relationship in your Microsoft 365 environment that you wish you could see instantly?58Views0likes0CommentsEntra Admin Center Flags Licensing Problems with Conditional Access
The Entra admin center is flagging licensing gaps for conditional access. The messages are informational, not the beginning of a new automated billing procedure to charge tenants when Entra ID notices that some accounts use conditional access policies when they don’t have a license. In this article, we discuss the product license insight and how Microsoft measures conditional access usage, and show how to use PowerShell to find who’s using conditional access. https://office365itpros.com/2026/08/13/licensing-gaps-entra-id/179Views0likes0CommentsCost Savings In Microsoft 365
Long story short, I had a client say, "We have more M365 licensed users than employees. Please help us find them." It took me about a week to find all the waste (first time always takes forever). Now I've run the same steps for a dozen other clients (takes less than an hour now). On average, I've been able to save clients 22% of their budget. Thought I'd share exactly how I do it. There are 5 areas of waste in Microsoft 365: Remove licenses from disabled users. Remove licenses from inactive users. Downgrade licenses on over-licensed users. Stop paying for unassigned licenses. Redefine the license terms. NOTE: I have the steps using the admin center, PowerShell, and a third-party app, but it's too long to re-post in Reddit. Go to Microsoft 365 License Audit to see all the steps. Find Disabled Users Log in to the Microsoft 365 admin center. Users > Active Users > Export > Continue. Open the spreadsheet. In the Home Ribbon, click Sort & Filter > Filter Click the dropdown in the Licensed column > uncheck Unlicensed > click OK Click the dropdown in the Block credential column > uncheck FALSE > click OK. Find Inactive Users NOTE: You need to either have a Microsoft Entra P1 license or use a third-party app to get this data. Open Microsoft Entra Admin Center Users > Manage view > Edit columns. Remove, replace, or add so the only columns you can see are: Display name, User principal name, User type, Identities, Assign licenses, and Last interactive sign-in time. Click Save. Click Download users > Start bulk operation Wait for the success pop-up message to appear, then click the notification bell at the top of the page. Under the notifications menu, click Success!, and then select the [report name]. Open the downloaded spreadsheet. Click Sort & Filter > Filter to enable the column filters. Click the drop-down in the assignedLicenses column. Uncheck any empty options, i.e., []. Click OK. Click the drop-down in the signInActivity column. Click Sort A to Z. Any users who have an empty signInActivity or a sign-in that was over 30 days ago can be safely disabled, and the license removed after the data is properly secured. Find Downgradable Users Review the report located on the website, then click Export. Open the CSV in Excel. Next, download the Microsoft 365 apps spreadsheet by going back to Reports > Usage and clicking View More located under “Active users - Microsoft 365 Apps” Review the report and click Export. You can start by deleting everyone that you’ve already determined hasn’t logged on or is currently disabled. Add the filter by clicking Sort & Filter in the home ribbon > Filter. Add a column for Current Licenses. Copy the licenses from the How To Use The Admin Center To Find Inactive Users spreadsheet you downloaded earlier into the new column. Be sure to align the user names in both spreadsheets. Add a column for Microsoft 365 Apps. Copy the Last Activity Date column from the Pro Plus Usage report you downloaded above in step 7 into the Office 365 app usage spreadsheet you’ve been using. Be sure to align the new data with the appropriate users in the Office 365 app usage report. For each of the following columns, click the drop-down next to the column name and filter out any logins that have happened in the last month. OneDrive Last Activity Date SharePoint Last Activity Date Skype For Business Last Activity Date Yammer Last Activity Date Team’s Last Activity Date Microsoft 365 Apps The users who have not been filtered out are excellent candidates for Exchange Online-only licenses. You may want to double-check their usage of other apps before making any license changes on their accounts. Find Unassigned Licenses Open the Microsoft 365 admin center. Click Show All > Billing > Licenses. On that webpage, you’ll see a list of all your licenses in your organization, along with a column labeled “Available Licenses”. Any number above 0 in the Available Licenses column is typically safe to remove from your organization with two caveats. Some licenses aren’t assigned to users through the Microsoft 365 admin center. NOTE: Some licenses are consumed as they are used. For example, additional storage licenses for SharePoint Online may show as available, but removing them will decrease the amount of free space available in SharePoint Online and possibly cause a disruption to SharePoint Online usage. Redefine The License Terms Microsoft adjusted its pricing model, charging different rates for the same license based on commitment terms, billing frequency, or sector-specific eligibility. The subscription length Billing Frequency Go to the Microsoft 365 admin center Click Billing > Licenses > Select the license you want to review. Click ellipsis (…) next to the subscription > Manage subscription settings. You can view the billing settings right on this page.194Views1like3CommentsActivation failed
I have been running MS 365 on my Mac laptop for years with no issue. Suddenly I cannot save an Excel file. I saw the activation button, but activation failed with the code OxO....unknown cause. I cannot find any way to contact MS for support or chat. I checked on my desktop and I do have an active subscription. I am running Tahoe 26.5.2. Excel is 16.7.1. Any suggesstions.3.8KViews0likes9CommentsHow to Find Inactive (Stale) User Accounts
Inactive accounts can soak up a lot of paid-for but unused product licenses. With increases for Microsoft 365 licenses due to come into effect from 1 July 2026, it’s time to find and remove unused licenses from inactive user accounts. We discuss two approaches by using the Microsoft 365 Licensing Report or a PowerShell script that assesses inactivity based on sign-in dates and refresh token baselines. https://office365itpros.com/2026/06/09/find-inactive-accounts/158Views0likes1CommentHow Much Will the July 2026 License Increases Cost Your Microsoft 365 Tenant?
July 1, 2026, sees a bunch of monthly price increases that will affect Microsoft 365 tenants. How much will the increases cost your tenant? One way to find out is to use PowerShell to find which licenses assigned to user are affected by the price increases and compute the effect of the monthly increase (which varies across products). It’s a great example of how flexible PowerShell is for tenant management. https://office365itpros.com/2026/06/16/monthly-license-increase-july-2026/173Views0likes2CommentsMoving Office 365 Mailboxes to IMAP Servers - What’s the Best Approach
I’ve recently been looking into scenarios where organizations need to move mailboxes from Microsoft 365 to IMAP based email servers, and I noticed this is still a common requirement in many migrations. In most cases, the challenge is not just moving emails, but making sure everything like folder structure, old emails, and user data stays intact without creating too much disruption for users. From what I’ve seen, doing this manually can get very complex, especially when there are multiple mailboxes or large data volumes involved. That’s where migration tools usually come into the picture. Most tools simplify things by handling: 1. Secure connection to Microsoft 365 accounts 2. Bulk mailbox migration 3. Preserving folder hierarchy 4. Reducing downtime during the move 5. Avoiding duplicate data issues One thing I’ve noticed is that running a small pilot migration first always helps. It gives a clear idea of how the actual migration will behave before moving all users. Has anyone here worked on Office 365 to IMAP migration at scale? Would be good to know what approaches or tools worked best in your case and what challenges you faced during the process.245Views0likes2CommentsMicrosoft 365 Developer E5 license lacking endpoints and device ON defender portal
Dear Support Team, I am a microsoft certified trainer (MCT). I currently have a Microsoft 365 Developer E5 license assigned to my tenant. However, I have noticed that my Microsoft Defender portal (security.microsoft.com) is missing several critical features. For example, I cannot see the Endpoints or Devices menus, which is preventing me from implementing and testing Microsoft Defender for Endpoint. Additionally, my Azure tenant and Microsoft 365 tenant are separate. This has created challenges when configuring security services such as Microsoft Sentinel (SIEM), as certain prerequisites and integrations require configuration through the Microsoft Defender portal. Due to the missing Defender features, I am unable to complete the necessary setup. I would appreciate your assistance in understanding: Why the Endpoints and Devices sections are unavailable in my Defender portal despite having a Microsoft 365 Developer E5 license. Whether additional licensing, onboarding steps, or tenant configurations are required to enable Microsoft Defender for Endpoint features. How best to integrate or align my separate Azure and Microsoft 365 tenants to support services such as Microsoft Sentinel and Defender XDR. These issues are significantly impacting my ability to evaluate and implement Microsoft's security solutions. I would appreciate any guidance or recommendations to resolve them.229Views1like1CommentNo licenses or products showing on my newly created standard business account
Yesterday, more than a day and a half from now, I created a Microsoft 365 business standard account, started the one month free trial. "bought" it for 3 accounts. Linked it to my domain. Then i started noticing some issues: - I couldn't log in to outlook, it said error 500, too many redirections. - I tried to create two accounts for my two workers, but no licenses were showing. I created their accounts without licenses, then I checked the licenses list and product list and they are both empty. Maybe I'm doing something wrong, but I expected to see there the apps that are "included" with the subscription. I think that's also why I can't log in to outlook. - I can't go into "my sign ins or security information" , they both go to a blank page. - And I thought the process of linking my domain to Microsoft 365 was done, because it said "the configuration is completed", but whenever I check on "domains", the domain shows in state "configuration incomplete", then after clicking on that domain and into "continue configuration ", it goes again to "configuration is complete" (but in domains, still it shows "configuration incomplete". I called support yesterday, but got no response on any of the 3 tries. Today I got a response, they told me they raised a ticket with my issues, but even though they say it could take from 30 minutes to a full day, it's been almost 18 hours and still I got no response. I'm inclined to not trust the help service because the responder kept telling me a notification would be sent to my email even after I explained to him multiple times that one of the things that wasn't working was outlook.2KViews0likes5Commentsneed exchange se for hybrid environment
We have a hybrid Office 365 environment with an Exchange Server 2016 that no longer performs any role. It does not host any mailboxes and is not used as an SMTP relay. We would like to keep an Exchange installation solely for administrative purposes through the GUI. Questions: 1. Can we keep Exchange Server 2016 installed? 2. If we need to install Exchange Server Subscription Edition (SE), do we need licenses for this installation, considering that all our Office 365 licenses are Business licenses? Thank you.103Views0likes1Comment