Skip to main content

Assign Microsoft Entra ID Licenses with Filters and Roles

Microsoft Entra ID guide

Use NIM filters and roles to apply the right Microsoft Entra ID license to each user automatically.

Before you beginDirect link to Before you begin

  • Confirm that NIM can collect Microsoft Entra ID users and licenses.
  • Identify the source-system data that distinguishes each license population, such as job title, department, or user type.
  • Identify the Entra ID SKU IDs for the licenses you plan to assign.

Configure Entra license relationshipsDirect link to Configure Entra license relationships

  1. Go to Systems > Entra > users > Columns. Ensure id is configured as the Key.

  2. Go to Systems > Entra > licenses > Columns. Ensure skuId is configured as the Reference.

  3. Go to Systems > Entra > users_assignedLicenses > Relations and configure the following relationships:

    • users_assignedLicenses.users_id to users.id as a Key.
    • users_assignedLicenses.skuId to licenses.id as a Key.
    • The many-to-many relationship between users and licenses, using users_id and skuId.

    The many-to-many relationship is required for licensing roles to work correctly.

Create license filtersDirect link to Create license filters

Create a new filter for each license population, or add the Entra ID conditions to an existing filter that already selects the same users. For example, extend a role filter that identifies Active Directory job titles requiring a specific Entra license.

In the filter's column selection, enable at least the following values:

  • Entra.users.id
  • Entra.license_members.id
  • skuId

Create the Entra licensing roleDirect link to Create the Entra licensing role

  1. Create a role for the license population, or use an existing role that selects the same users.
  2. Under Role items, select Add until Entra > licenses > users_assignedLicenses > id appears.
  3. Remove any role items that do not apply to this license assignment.
  4. Configure the remaining Entra license role item with the license that should apply to users in the role.

Verify the resultDirect link to Verify the result

Run the appropriate synchronization or licensing job, then confirm that users matching each filter have the expected Microsoft Entra ID license assignment.