I'm deploying a Conditional Access policy that requires MFA for medium- and high-risk sign-ins, plus password reset and MFA for users identified as high risk. The tenant currently has only 35 Entra ID P2 licenses. In report-only mode, the policy appears to identify risk for users who don't have a P2 license. How will enforcement work for those unlicensed users? Will the policy apply to everyone in scope, only to licensed users, or detect risk without taking action? I also want to understand the licensing implications of assigning the policy broadly.
3 Answers
Microsoft licensing is effectively trust-based, so the technical controls may continue to work for unlicensed accounts. However, every user affected by the policy is expected to be licensed. If you don’t plan to license the entire tenant, scope the policy only to the users who have the required P2 entitlement.
The licensing requirement is generally based on each user who is protected by the risk-based Conditional Access policy, so users affected by it should have the appropriate Entra ID P2 licensing. Although the policy may technically evaluate users across the tenant and appear to work with only one license, relying on that would not comply with the licensing terms and some features may not behave as expected.
A safer approach is to create a dedicated group containing the users who have Entra ID P2 licenses and scope the risk-based Conditional Access policy to that group. That makes the intended coverage clear and avoids unintentionally protecting unlicensed users.

If I target the policy at everyone, does that mean it will be enforced for all users or only the users with P2 licenses? I’m trying to determine whether the policy is automatically limited by licensing or whether I need to scope it myself.