Skip to content

Commit 3761f4c

Browse files
Merge pull request #251722 from rwike77/faq
Updated licensing FAQ
2 parents 6a3a326 + e92bfeb commit 3761f4c

File tree

1 file changed

+6
-20
lines changed

1 file changed

+6
-20
lines changed

articles/active-directory/workload-identities/workload-identities-faqs.md

Lines changed: 6 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: workload-identities
99
ms.workload: identity
1010
ms.topic: conceptual
11-
ms.date: 8/28/2023
11+
ms.date: 9/15/2023
1212
ms.author: gasinh
1313
ms.reviewer:
1414
ms.custom: aaddev
@@ -94,26 +94,12 @@ applications for connecting resources that support Azure AD authentication.
9494

9595
## How many licenses do I need to purchase? Do I need to license all workload identities including Microsoft and Managed Service Identities?
9696

97-
All workload identities - service principles, apps and managed identities, configured in your directory for a Microsoft Entra
98-
Workload Identities Premium feature require a license. Select and prioritize the identities based on the available licenses. Remove
99-
the workload identities from the directory that are no longer required.
97+
All workload identities - service principles, apps and managed identities, configured in your directory for a Microsoft Entra Workload Identities Premium feature require a license. Customers don’t need to license all the workload identities. You can find the right number of Workload ID licenses with the following guidance:
10098

101-
The following identity functionalities are currently available to view
102-
in a directory:
103-
104-
- Identity Protection: All single-tenant and multi-tenant service
105-
principals excluding managed identities and Microsoft apps.
106-
107-
- Conditional Access: Single-tenant service principals (excluding
108-
managed identities) capable of acting as a subject/client, having a
109-
defined credential.
110-
111-
- Access reviews: All single-tenant and multi-tenant service
112-
principals assigned to privileged roles.
113-
114-
>[!NOTE]
115-
>Functionality is subject to change, and feature coverage is
116-
intended to expand.
99+
1. Customer will need to license enterprise applications or service principals ONLY if they set up Conditional Access policies or use Identity Protection for them.
100+
2. Customers don't need to license applications at all, even if they are using Conditional Access policies.
101+
3. Customers will need to license managed identities, only when they set up access reviews for managed identities.
102+
You can find the number of each workload identity type (enterprise apps/service principals, apps, managed identities) on the product landing page at the [Microsoft Entra admin center](https://entra.microsoft.com).
117103

118104
## Do these licenses require individual workload identities assignment?
119105

0 commit comments

Comments
 (0)