Skip to content

Commit c1e6c6f

Browse files
Merge pull request #250765 from OWinfreyATL/owinfreyATL-LicensingByFeatures
Governance License fixes.
2 parents 002588a + d41d9f9 commit c1e6c6f

File tree

3 files changed

+35
-56
lines changed

3 files changed

+35
-56
lines changed

articles/active-directory/governance/entitlement-management-overview.md

Lines changed: 0 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -140,41 +140,6 @@ To better understand entitlement management and its documentation, you can refer
140140

141141
[!INCLUDE [active-directory-p2-governance-license.md](../../../includes/active-directory-p2-governance-license.md)]
142142

143-
### How many licenses must you have?
144-
145-
Ensure that your directory has at least as many Microsoft Azure AD Premium P2 or Microsoft Entra ID Governance licenses as you have:
146-
147-
- Member users who *can* request an access package.
148-
- Member users who *request* an access package.
149-
- Member users who *approve requests* for an access package.
150-
- Member users who *review assignments* for an access package.
151-
- Member users who have a *direct assignment* or an *automatic assignment* to an access package.
152-
153-
For guest users, licensing needs will depend on the [licensing model](../external-identities/external-identities-pricing.md) you’re using. However, the below guest users’ activities are considered Microsoft Azure AD Premium P2 or Microsoft Entra ID Governance usage:
154-
- Guest users who *request* an access package.
155-
- Guest users who *approve requests* for an access package.
156-
- Guest users who *review assignments* for an access package.
157-
- Guest users who have a *direct assignment* to an access package.
158-
159-
Microsoft Azure AD Premium P2 or Microsoft Entra ID Governance licenses are **not** required for the following tasks:
160-
161-
- No licenses are required for users with the Global Administrator role who set up the initial catalogs, access packages, and policies, and delegate administrative tasks to other users.
162-
- No licenses are required for users who have been delegated administrative tasks, such as catalog creator, catalog owner, and access package manager.
163-
- No licenses are required for guests who have **a privilege to request access packages** but they **do not choose** to request them.
164-
165-
For more information about licenses, see [Assign or remove licenses using the Azure portal](../fundamentals/license-users-groups.md).
166-
167-
### Example license scenarios
168-
169-
Here are some example license scenarios to help you determine the number of licenses you must have.
170-
171-
| Scenario | Calculation | Number of licenses |
172-
| --- | --- | --- |
173-
| A Global Administrator at Woodgrove Bank creates initial catalogs and delegates administrative tasks to six other users. One of the policies specifies that **All employees** (2,000 employees) can request a specific set of access packages. 150 employees request the access packages. | 2,000 employees who **can** request the access packages | 2,000 |
174-
| A Global Administrator at Woodgrove Bank creates initial catalogs and delegates administrative tasks to six other users. One of the policies specifies that **All employees** (2,000 employees) can request a specific set of access packages. Another policy specifies that some users from **Users from partner Contoso** (guests) can request the same access packages subject to approval. Contoso has 30,000 users. 150 employees request the access packages and 10,500 users from Contoso request access. | 2,000 employees need licenses, guest users are billed on a monthly active user basis and no additional licenses are required for them. * | 2,000 |
175-
176-
\* Azure AD External Identities (guest user) pricing is based on monthly active users (MAU), which is the count of unique users with authentication activity within a calendar month. This model replaces the 1:5 ratio billing model, which allowed up to five guest users for each Azure AD Premium license in your tenant. When your tenant is linked to a subscription and you use External Identities features to collaborate with guest users, you'll be automatically billed using the MAU-based billing model. For more information, see [Billing model for Azure AD External Identities](../external-identities/external-identities-pricing.md).
177-
178143

179144
## Next steps
180145

articles/active-directory/governance/licensing-fundamentals.md

Lines changed: 34 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ ms.author: billmath
2020
The following tables show the licensing requirements for Microsoft Entra ID Governance features
2121

2222
## Types of licenses
23-
The following licenses are available for use with Microsoft Entra ID Governance. The choice of licenses you need in a tenant will depend on the features you're using in that tenant.
23+
The following licenses are available for use with Microsoft Entra ID Governance. The choice of licenses you need in a tenant depends on the features you're using in that tenant.
2424

2525
- **Free** - Included with Microsoft cloud subscriptions such as Microsoft Azure, Microsoft 365, and others.
2626
- **Microsoft Azure AD P1** - Azure Active Directory Premium P1 (becoming Microsoft Entra ID P1) is available as a standalone product or included with Microsoft 365 E3 for enterprise customers and Microsoft 365 Business Premium for small to medium businesses.
@@ -102,44 +102,58 @@ The following table shows what features are available with each license. Note t
102102
|Insights and reporting - Inactive guest accounts (Preview)||||x|
103103

104104

105-
## Privileged Identity Management
105+
## Entitlement Management
106+
107+
### Example license scenarios
108+
109+
Here are some example license scenarios to help you determine the number of licenses you must have.
110+
111+
| Scenario | Calculation | Number of licenses |
112+
| --- | --- | --- |
113+
| An Identity Governance Administrator at Woodgrove Bank creates initial catalogs. One of the policies specifies that **All employees** (2,000 employees) can request a specific set of access packages. 150 employees request the access packages. | 2,000 employees who **can** request the access packages | 2,000 |
114+
| An Identity Governance Administrator at Woodgrove Bank creates initial catalogs. One of the policies specifies that **All employees** (2,000 employees) can request a specific set of access packages. 150 employees request the access packages. | 2,000 employees need licenses. | 2,000 |
115+
| An Identity Governance Administrator at Woodgrove Bank creates initial catalogs. They create an auto-assignment policy that grants **All members of the Sales department** (350 employees) access to a specific set of access packages. 350 employees are auto-assigned to the access packages. | 350 employees need licenses. | 351 |
116+
117+
## Access reviews
106118

107-
To use Privileged Identity Management (PIM) in Azure Active Directory (Azure AD), part of Microsoft Entra, a tenant must have a valid license. Licenses must also be assigned to the administrators and relevant users. This article describes the license requirements to use Privileged Identity Management. To use Privileged Identity Management, you must have one of the following licenses:
119+
### Example license scenarios
108120

121+
Here are some example license scenarios to help you determine the number of licenses you must have.
109122

110-
### Valid licenses for PIM
123+
| Scenario | Calculation | Number of licenses |
124+
| --- | --- | --- |
125+
| An administrator creates an access review of Group A with 75 users and 1 group owner, and assigns the group owner as the reviewer. | 1 license for the group owner as reviewer | 1 |
126+
| An administrator creates an access review of Group B with 500 users and 3 group owners, and assigns the 3 group owners as reviewers. | 3 licenses for each group owner as reviewers | 3 |
127+
| An administrator creates an access review of Group B with 500 users. Makes it a self-review. | 500 licenses for each user as self-reviewers | 500 |
128+
| An administrator creates an access review of Group C with 50 member users. Makes it a self-review. | 50 licenses for each user as self-reviewers.* | 50 |
129+
| An administrator creates an access review of Group D with 6 member users. Makes it a self-review. | 6 licenses for each user as self-reviewers. No additional licenses are required. * | 6 |
111130

112-
You'll need either Microsoft Entra ID Governance licenses or Azure AD Premium P2 licenses to use PIM and all of its settings. Currently, you can scope an access review to service principals with access to Azure AD and Azure resource roles with a Microsoft Entra Premium P2 or Microsoft Entra ID Governance edition active in your tenant. The licensing model for service principals will be finalized for general availability of this feature and additional licenses may be required.
131+
## Lifecycle Workflows
113132

114-
### Licenses you must have for PIM
115-
Ensure that your directory has Microsoft Entra Premium P2 or Microsoft Entra ID Governance licenses for the following categories of users:
133+
With Entra Governance licenses for Lifecycle Workflows, you can:
116134

117-
- Users with eligible and/or time-bound assignments to Azure AD or Azure roles managed using PIM
118-
- Users with eligible and/or time-bound assignments as members or owners of PIM for Groups
119-
- Users able to approve or reject activation requests in PIM
120-
- Users assigned to an access review
121-
- Users who perform access reviews
135+
- Create, manage, and delete workflows up to the total limit of 50 workflows.
136+
- Trigger on-demand and scheduled workflow execution.
137+
- Manage and configure existing tasks to create workflows that are specific to your needs.
138+
- Create up to 100 custom task extensions to be used in your workflows.
122139

140+
## Privileged Identity Management
123141

124142
### Example license scenarios for PIM
125143

126144
Here are some example license scenarios to help you determine the number of licenses you must have.
127145

128146
| Scenario | Calculation | Number of licenses |
129147
| --- | --- | --- |
130-
| Woodgrove Bank has 10 administrators for different departments and 2 Global Administrators that configure and manage PIM. They make five administrators eligible. | Five licenses for the administrators who are eligible | 5 |
148+
| Woodgrove Bank has 10 administrators for different departments and 2 Identity Governance Administrators that configure and manage PIM. They make five administrators eligible. | Five licenses for the administrators who are eligible | 5 |
131149
| Graphic Design Institute has 25 administrators of which 14 are managed through PIM. Role activation requires approval and there are three different users in the organization who can approve activations. | 14 licenses for the eligible roles + three approvers | 17 |
132150
| Contoso has 50 administrators of which 42 are managed through PIM. Role activation requires approval and there are five different users in the organization who can approve activations. Contoso also does monthly reviews of users assigned to administrator roles and reviewers are the users’ managers of which six aren't in administrator roles managed by PIM. | 42 licenses for the eligible roles + five approvers + six reviewers | 53 |
133151

134-
### When a license expires for PIM
152+
## Licensing FAQs
135153

136-
If a Microsoft Azure AD Premium P2, Microsoft Entra ID Governance, or trial license expires, Privileged Identity Management features will no longer be available in your directory:
154+
### Do licenses need to be assigned to users to use Identity Governance features?
137155

138-
- Permanent role assignments to Azure AD roles will be unaffected.
139-
- The Privileged Identity Management service in the Azure portal, as well as the Graph API cmdlets and PowerShell interfaces of Privileged Identity Management, will no longer be available for users to activate privileged roles, manage privileged access, or perform access reviews of privileged roles.
140-
- Eligible role assignments of Azure AD roles will be removed, as users will no longer be able to activate privileged roles.
141-
- Any ongoing access reviews of Azure AD roles will end, and Privileged Identity Management configuration settings will be removed.
142-
- Privileged Identity Management will no longer send emails on role assignment changes.
156+
Users do not need to be assigned an Identity Governance license, but there needs to be as many licenses in the tenant to include all users in scope of, or who configures, the Identity Governance features.
143157

144158
## Next steps
145159
- [What is Microsoft Entra ID Governance?](identity-governance-overview.md)

includes/active-directory-p2-governance-license.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,4 +6,4 @@ ms.date: 09/15/2022
66
ms.author: joflore
77
---
88

9-
Using this feature requires Microsoft Entra ID Governance subscriptions for your organization's users. Some capabilities within this feature may operate with a Microsoft Azure AD Premium P2 subscription, see the articles of each capability for more details. To find the right license for your requirements, see [Compare generally available features of Microsoft Azure AD](https://www.microsoft.com/security/business/identity-access-management/azure-ad-pricing).
9+
Using this feature requires Microsoft Entra ID Governance subscriptions for your organization's users. Some capabilities within this feature may operate with a Microsoft Azure AD Premium P2 subscription, see the articles of each capability for more details. To find the right license for your requirements, see [Microsoft Entra ID Governance licensing fundamentals](../articles/active-directory/governance/licensing-fundamentals.md).

0 commit comments

Comments
 (0)