Plan inventory
Identify which combination of Business Premium, E3, E5, Entra ID, and Defender add-ons the organization currently holds.
Independent IT security review
A security recommendation that assumes the wrong licence is not useful advice. The review reads current subscriptions before connecting a finding to a specific control.
Microsoft 365 plans bundle identity, device, and information-protection capabilities differently. The review starts from what is actually licensed, not a generic best-practice list.
Identify which combination of Business Premium, E3, E5, Entra ID, and Defender add-ons the organization currently holds.
Check whether every user actually holds the licence a policy assumes, since mixed licensing is common after growth or acquisitions.
Confirm whether a capability depends on a trial, a promotional add-on, or a licence that may lapse.
Capabilities referenced elsewhere on this site-Conditional Access, compliance policy, Defender protection, and data retention-depend on specific licence tiers.
Confirm which Conditional Access, risk-based policy, and privileged identity features require Entra ID P1 or P2.
Check which Intune and Defender for Business or Defender for Endpoint capabilities the current plan actually includes.
Identify whether sensitivity labels, data loss prevention, and extended retention require an add-on beyond the base plan.
A missing capability does not always require an upgrade. The review documents the trade-off so the organization decides deliberately.
State the specific risk or requirement an upgrade would address, not licensing for its own sake.
Where an upgrade is not chosen, document what interim control or process reduces the gap.
Set a condition-growth, a new regulatory requirement, or an incident-that should prompt revisiting the decision.
A finding that recommends an unlicensed feature without saying so creates false confidence. The review states licence dependency plainly next to every relevant recommendation.
Attach the required licence tier directly to any recommendation that depends on one.
Avoid treating a licence change as already decided; it remains the organization’s commercial decision.
Keep the mapping between finding, licence requirement, and decision available for the next reviewer or renewal cycle.
Next step
Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.