Entra admin center flags Conditional Access policies covering unlicensed users

Tenants are starting to see a message in the Microsoft Entra admin center saying some Conditional Access policies are protecting more users than their current licensing entitlements. Conditional Access requires an Entra ID P1 or P2 licence for the users it covers, and the banner appears when Microsoft's comparison finds a gap. Tony Redmond's write-up on 13 August 2026 is clear that the message is informational: it does not disable policies, enforce anything, or trigger a bill. He also notes the comparison appears to look at which users actually use the feature rather than simply counting licences.
Conditional Access spread through most tenants the same way. Microsoft pushed multi-factor authentication hard, someone wrote the policy scoped to All users because that is the safe way to write it, and nobody went back afterwards to compare that scope with who actually holds a P1 or P2 licence. It worked, so there was no reason to look at it again. A banner in the admin center turns that into something an auditor, a licensing reseller or a finance review can point at, and "we scoped it to everyone to be safe" is a hard sentence to say in that meeting. The useful move is not to buy licences off the back of a warning. It is to find out what your policies genuinely cover, because a tenant full of guests, shared mailboxes, service accounts and unlicensed identities can look far larger than the protection you meant to pay for. Better to know the number before someone else quotes it at you.
Analysis
Check which of your Conditional Access policies are scoped to All users, then compare that against actual sign-ins for those policies before anyone treats the banner as a purchase order.
Source note
Pulse published by Collab365 Spaces, reviewed by Collab365 editorial team on . Cite as "Entra now warns when Conditional Access covers more users than you licensed", Collab365 Spaces.