License Optimization Round 2: What Changed Since Named User Enforcement Hit
- Beau Schwieso
- Jul 13
- 3 min read
If you’ve been managing D365 Finance & Operations for the last year or two or ten, Microsoft’s licensing enforcement deadlines have felt a lot like my kids promising they’ll clean the playroom "tomorrow." You hear it enough times, you see the date come and go, and eventually, you just stop believing it's ever going to happen.
Well, the playroom is finally getting cleaned, whether we like it or not.

Microsoft pushed the enforcement deadline a few times—first dodging a bullet in late 2025, and then finally drawing a line in the sand starting January 15, 2026. But here is the kicker that caught a lot of people off guard: it wasn't a blanket switch. The enforcement hits on a rolling schedule based on your specific contract renewal or anniversary date.
If your renewal is coming up in the fall of 2026, consider this your final warning. Microsoft has made it incredibly clear that there are no more global postponements. When your date hits, you get a 15-day grace period. After that, any user who doesn't have the exact right license assigned in the Microsoft 365 Admin Center gets a cold, hard error message at login, and your phone starts ringing.
Addressing the Rumor: Can You "Turn It On" Early?
I’ve had a few peeps ask me recently: "I heard we can just turn the enforcement on ourselves before our fall deadline so we can see what breaks. Is that true?"
The short answer is no, you can't manually trigger the actual system lock-out ahead of your contract date.
And frankly, why would you want to unleash that kind of chaos on purpose?
However, what you can and absolutely must do right now is turn on the exact telemetry Microsoft is using to judge you. The old in-app license estimation reports were notoriously unreliable and used legacy logic. To see the real data, you need to go into Feature Management in F&O and enable two things in this exact order:
User security governance
User security governance license usage summary report (This was in preview for a while, but it's what you need).
Turning this on is the equivalent of hitting the "test" button on your smoke detector. It pulls the data into the Power Platform Admin Center (PPAC) and shows you exactly who is under-licensed, over-licensed, or completely unlicensed.
Where Companies Are Getting Burned in Round 2
Now that we are actually living in the enforcement era for the early 2026 renewals, we are seeing exactly where the bodies are buried. If you are auditing your roles before a fall deadline, look here first.
The "Attach" License Trap
The base-to-attach license model is great for saving money, but it requires surgical precision with security roles. Let’s say you have a user with a Finance Base license and a Supply Chain Attach license. If someone accidentally assigns them a single menu item that requires a Commerce license, the system will flag them as non-compliant. The enforcement engine does not care about their job title; it cares about the highest-level privilege they have access to.
The Over-Privileged Team Member
Team Member licenses are cheap for a reason. They are meant for basic read access, time entry, and light approvals. We are seeing companies get hit hard because they took a standard Team Member role, duplicated it, and added "just a few" write privileges to solve a helpdesk ticket. The moment you cross that line, PPAC flags them as needing a full enterprise license, and suddenly your $8/month user costs $180/month.
The Offboarding Ghost Town
Under the old honor system, if a user left the company, you just disabled them in F&O and went about your day. Under the new model, if you don't actually remove the assigned D365 license from their profile in the Microsoft 365 Admin Center, you are still consuming that license. It sounds basic, but I am seeing enterprise clients wasting thousands of dollars a month on licenses assigned to people who quit in 2024.
The Bottom Line
If your anniversary date is this fall, stop relying on spreadsheets to guess your license counts. Get the User Security Governance features turned on, get into PPAC, and start cleaning up your roles now.
Fixing a customized security role takes time, testing, and business approval. If you wait until users start seeing the warning banners 30 days before your renewal, you are going to be buying a lot of expensive enterprise licenses just to keep the lights on.
Keep it real,
DynamicsDad



Comments