A security solution that detects identity-based threats and suspicious activities in on-premises Active Directory environments
Short answer: no to both. You don't need MDI licenses for service accounts or for disabled accounts kept for compliance.
The thing that trips people up here is that monitoring and licensing are two different levers. MDI is licensed per protected user, but the sensor watches the whole domain on its own. It reads the domain controller traffic and events and monitors every account and entity it sees, including computer accounts, service accounts, and disabled ones. Microsoft's FAQ even says it provides security value for AD accounts that aren't synced to Entra ID at all, which is the giveaway: those accounts have no cloud license to assign, yet they're still covered. So a license isn't what turns signal collection on for a given account.
There's also a practical side. On-prem-only service and disabled accounts that aren't synced to Entra don't show up in the M365 admin center, so there's no object there to license even if you wanted to.
For your setup: your users already on M365 E5 are covered, so you only need standalone MDI for the remaining human users you want protected. Leave the service and disabled accounts out of the count. They're monitored either way.
That said, licensing terms shift and every tenant's agreement is a little different, so I'd treat the above as the working model and confirm it with your Microsoft account team before you buy. They can validate the exact count against your Product Terms and make sure nothing in your specific agreement changes the picture. Worth a quick note to them so you have it in writing.
FAQ reference: https://learn.microsoft.com/en-us/defender-for-identity/technical-faq