I'm deploying a Conditional Access policy for a customer that requires MFA for medium- and high-risk sign-ins, plus password reset and MFA for users with a high user-risk level. The tenant currently has only 35 Entra ID P2 licenses. In report-only mode, the policy appears to detect risk for users who don't have a P2 license. How will enforcement work for those users? Will the policy apply to everyone in scope, only to licensed users, or detect the risk without taking action? I also want to understand whether all users affected by the policy must be licensed.
3 Answers
Microsoft licensing is largely based on trust and doesn’t necessarily block the policy when a user lacks the license. However, every user affected by the policy is expected to be properly licensed. If the customer doesn’t want to license the entire tenant, scope the policy specifically to the licensed users rather than applying it broadly.
Create a dedicated group for the risk-based Conditional Access policies and add only users who have the required Entra ID P2 license. That makes the policy scope and licensing responsibility clear, instead of relying on what happens to work technically.
The licensing guidance is generally one qualifying license for each user protected by the risk-based Conditional Access policy. Although the policy may technically evaluate and enforce for unlicensed users, that does not mean the deployment is properly licensed. Scoping the policy to a group containing only licensed users is the safer approach.

So if I target everyone with the policy, could it enforce for unlicensed users too, or is enforcement automatically limited to the users with P2? I’m trying to avoid both unexpected behavior and a licensing violation.