Defender for Identity licensing

Łukasz Bielicki 0 Reputation points
2026-06-13T18:53:40.45+00:00

Hello everyone,

Hopefully someone can clarify to me Defender for Identity licensing.

90% of our users have E5 license. I want to buy standalone MDI licenses to cover our needs.

Questions:

Do we need licenses for Service Accounts?

Do we need licenses for disabled accounts in AD? (Kept for compliance reasons)

thank you in advance

Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
0 comments No comments

2 answers

Sort by: Oldest
  1. AI answer

    2026-06-13T18:53:50.3333333+00:00

    Microsoft Defender for Identity (MDI) is licensed per protected user, not per server or sensor.

    From the documented requirements, deploying Defender for Identity requires that protected users have one of the following:

    • Enterprise Mobility + Security E5 (EMS E5/A5)
    • Microsoft 365 E5/A5/G5 or Microsoft 365 E5/A5/G5/F5 Security
    • Microsoft 365 F5 Security + Compliance (with the noted prerequisites)
    • A standalone Defender for Identity license

    Since 90% of users already have Microsoft 365 E5, those users are already covered for MDI and do not need additional standalone MDI licenses.

    For the remaining users, standalone MDI licenses are needed only for identities that are in scope for protection (that is, human users whose activities and identities are being monitored/protected by Defender for Identity). The documentation does not call out separate licensing for:

    • Service accounts
    • Disabled accounts retained only for compliance

    Licensing guidance is framed around per-user subscription rights, so service accounts and disabled accounts kept purely for historical/compliance purposes are not separately listed as requiring MDI licenses.

    If more precise tenant-level or edge-case licensing interpretation is needed (for example, special treatment of certain non-human accounts), the detailed licensing guidance referenced in the docs and the Product Terms should be consulted, or the Microsoft account team should be engaged.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. Derek Morgan II 85 Reputation points
    2026-06-23T14:21:32.8166667+00:00

    Hi @Łukasz Bielicki

    Short answer: no to both. You don't need MDI licenses for service accounts or for disabled accounts kept for compliance.

    The thing that trips people up here is that monitoring and licensing are two different levers. MDI is licensed per protected user, but the sensor watches the whole domain on its own. It reads the domain controller traffic and events and monitors every account and entity it sees, including computer accounts, service accounts, and disabled ones. Microsoft's FAQ even says it provides security value for AD accounts that aren't synced to Entra ID at all, which is the giveaway: those accounts have no cloud license to assign, yet they're still covered. So a license isn't what turns signal collection on for a given account.

    There's also a practical side. On-prem-only service and disabled accounts that aren't synced to Entra don't show up in the M365 admin center, so there's no object there to license even if you wanted to.

    For your setup: your users already on M365 E5 are covered, so you only need standalone MDI for the remaining human users you want protected. Leave the service and disabled accounts out of the count. They're monitored either way.

    That said, licensing terms shift and every tenant's agreement is a little different, so I'd treat the above as the working model and confirm it with your Microsoft account team before you buy. They can validate the exact count against your Product Terms and make sure nothing in your specific agreement changes the picture. Worth a quick note to them so you have it in writing.

    FAQ reference: https://learn.microsoft.com/en-us/defender-for-identity/technical-faq

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.