Why 'not licensed' beats an empty chart
A blank chart in a Microsoft 365 security dashboard usually gets read as good news. It often is not. A query can come back empty for at least four different reasons: the tenant is not licensed for that data, the connecting app was never granted the permission, its credential expired, or there is genuinely nothing to report. Microsoft Graph does not reliably tell these apart. Sometimes it names the cause; more often the same generic error covers a licensing problem and a permissions problem alike. A dashboard that shows one blank for all four is not simplifying. It is guessing, and letting the reader assume the best case.
01 / 10
A dashboard that never had bad news
Consider a fictional 40-person non-profit that inherited a security dashboard from its previous IT provider. For two years, the tile for risky users sat at zero. Nobody investigated, because zero is the number everyone hopes for.
When a different provider finally looked at the tenant itself, the explanation was simpler than a hidden breach, and worse in its own way. The tenant had never carried the Microsoft Entra ID P2 license that full risk detection requires. The chart was not reporting zero risk. It was reporting zero license.
Nobody lied. The dashboard just could not tell the difference between nothing happened and we are not licensed to see whether anything happened — and it defaulted, silently, to the version that looks like good news.
02 / 10
Four different reasons a chart can be empty
In a Microsoft 365 tenant, a query can come back with nothing to show for at least four unrelated reasons, and only one of them means the thing you were worried about did not happen.
- Not licensed. The tenant does not carry the subscription tier that unlocks that data, or unlocks the fuller version of it.
- Not granted. The application asking the question was never given the Microsoft Graph permission it needs, or nobody consented to it.
- Credential expired. The application's client secret or certificate lapsed, so every request now fails authentication before licensing or permissions are even checked.
- Genuinely nothing. The license is present, the permission is granted, the credential is valid, and the honest answer is zero.
03 / 10
The gates hiding inside identity charts
Licence gates are the least visible of the four causes, because they rarely look like a gate. Nothing announces that a chart is capped. It simply renders fewer rows, or a lower-detail version of the same screen, and looks complete.
Microsoft's own licensing reference is specific about where the caps sit. On Microsoft Entra ID P1, the risky users report is, in Microsoft's words, Limited Information. Only users with medium and high risk are shown. No details drawer or risk history. The risky sign-ins report on P1 is Limited Information. No risk detail or risk level is shown. Full detail on both needs Microsoft Entra ID P2.
Risk detections sit behind a sharper line. Below P1, Microsoft's own table lists the capability outright as No — nothing renders, not even a limited view. Risk-based Conditional Access policies, the feature that acts on a risk score rather than just reporting it, need P2 specifically; P1 does not reach that far, no matter how complete the report looks. (Checked against the licensing page's 18 June 2026 update.)
A related gate sits behind any chart of dormant or inactive accounts. Microsoft's guidance on managing inactive user accounts states plainly: To access the lastSuccessfulSignInDateTime property using Microsoft Graph, you need a Microsoft Entra ID P1 or P2 license. The Graph API reference for listing users gives the same requirement for the broader signInActivity property. Below P1, that property is not degraded. It cannot be queried at all.
04 / 10
Two more gates, further from identity
Microsoft Defender XDR's unified incident queue works the same way, though the gate is a plan rather than a tier inside one product. Microsoft lists more than a dozen qualifying licenses that unlock it at no extra cost — Microsoft 365 E5, Business Premium, Defender for Endpoint on its own, and several add-on combinations among them — and a bare Microsoft 365 E3 with no add-on is not on that list. A chart wired to the incidents API on such a tenant has nothing to show, and nothing about the chart says the tenant was never eligible to begin with.
Intune device compliance runs into the same wall from a different direction. Microsoft's licensing guidance is unambiguous: an Intune license is required for any user or device that benefits directly or indirectly from the Microsoft Intune service, including access through a Microsoft API. A compliance chart querying an unlicensed tenant is not asking a question Intune will ever answer.
Shadow-AI discovery from network traffic has its own two-tier version of the same gate. The entry tier, Cloud App Discovery, ships at no extra cost with Microsoft Entra ID P1, Enterprise Mobility + Security E3, or Microsoft 365 E3, and already supports manual and automatic log upload. The native integration with Microsoft Defender for Endpoint — the piece that makes device-level discovery practical without standing up a log collector — belongs to the full Defender for Cloud Apps tier, one step up. A chart advertising connected AI apps found on the network, on a Cloud-App-Discovery-only tenant, is asking for a capability that tier was never sold to provide.
05 / 10
What Microsoft Graph actually tells you when you ask
If licence gaps were at least loud, this would be a smaller problem — a dashboard could catch the error and label it correctly. Microsoft's own troubleshooting guidance says that, mostly, they are not.
Describing a plain 403 Forbidden response from Microsoft Graph, Microsoft's guide to resolving authorization errors puts it directly: Generally, this error indicates that the user is not privileged enough to perform the request or the user is not licensed for the data being accessed. Only users with the required permissions or licenses can make the request successfully.
Read that the way a piece of software has to read it: the same HTTP status code, the same generic wording, covers two of the four causes above. A 403 does not, on its own, tell you whether the tenant needs a different licence or the application needs a different consent grant. Both failures look identical on the wire.
There is one documented exception, worth naming because it shows Microsoft can do better when it chooses to. Query signInActivity or the sign-in log without Entra ID Premium, and Graph returns a distinct error code, Authentication_RequestFromNonPremiumTenantOrB2CTenant, with a message that names the licence problem directly rather than a bare permissions-or-licence 403: Neither tenant is B2C or tenant doesn't have premium license. That one endpoint tells you which of the two happened. Most do not.
Our reading, not a design principle Microsoft states: this inconsistency looks less like a flaw than a fact of a platform built from many teams' APIs over many years. A dashboard cannot assume Microsoft will name the cause. It has to work out the cause itself, per licence, ahead of the query, rather than trust the response to explain itself.
06 / 10
The fourth cause looks exactly like the other three
The frustrating part is that the good outcome — a licensed, permissioned, correctly authenticated system reporting a true zero — renders identically to the three bad ones. A zero-row risky-users table and a P1-capped risky-users table can be pixel-for-pixel the same image. Nothing in the chart itself carries the difference; the difference lives in metadata the chart is choosing whether to show.
Our judgement, not something documented: most dashboards build the happy path first and treat the other three causes as edge cases to handle later, if at all. They do not feel like edge cases to the business owner who has been staring at a flat line for two years.
07 / 10
Four causes, one chart, four honest answers
Put together, the pattern behind the four causes above looks like this.
| What the chart should show | Licence that gates it | What Graph returns without it | What an honest status should say |
|---|---|---|---|
| Risky users, full detail | Entra ID P2 | Limited view, no error | Not licensed (P2 needed) |
| Risk detections at all | Entra ID P1 or P2 | Nothing shown, no error | Not licensed (P1 needed) |
| Last sign-in / inactivity | Entra ID P1 or P2 | Specific, self-naming error code | Not licensed (P1 needed) |
| Defender XDR incidents | A qualifying Defender plan | Empty result, no error found | Not licensed, check the plan |
| Device compliance status | Intune licence | No record for that device | Not licensed (Intune needed) |
| AI apps found on network | Defender for Cloud Apps | Feature unavailable in UI | Not licensed, upgrade tier |
08 / 10
Status before data
The fix is not a smarter chart. It is a status that renders before the data does, using a small, fixed vocabulary, checked against what the tenant is actually entitled to before a single content query runs.
That means checking licence SKUs and service plans against a known list for every module a dashboard offers, rather than inferring the answer from whatever the query happens to return. It means treating a credential failure as its own state, separate from both licensing and permissions, because an expired client secret has nothing to do with what the tenant is entitled to. And it means reserving an actual zero for the one case where the licence is present, the permission is granted, the credential is valid, and the answer really is nothing.
Our recommendation, not a Microsoft requirement: four labels are enough for a small-business dashboard to be honest without becoming unreadable — Healthy, Not licensed, Permission required, and Auth error, shown ahead of any chart they would otherwise leave blank. A fifth label for a confirmed true zero is tempting, but it usually collapses back into Healthy: a module reporting fifty rows and one reporting zero are the same state, correctly checked, with different data. Splitting them further would just be a second way of hiding the fact this piece argues against.
09 / 10
Not licensed is not a verdict on you
None of this means every business should buy Microsoft Entra ID P2, upgrade to full Defender for Cloud Apps, or add Intune seats it does not need. Plenty of 40-person organisations run comfortably on Microsoft 365 E3 or Business Premium and never need P2's risk-based Conditional Access policies. The point is not that every gate should be unlocked. It is that a chart which cannot see past a gate should say so, rather than quietly reporting the free-tier view as if it were the whole picture.
A Not licensed label is not bad news about your security. It is an accurate description of what a screen is and is not allowed to see — and it is the only version of that screen that lets you decide, on purpose, whether to buy the missing tier or accept the smaller view.
10 / 10
Where to start
Before your next licence renewal, pick the three charts your team actually looks at — risky users, inactive accounts, and device compliance are common ones — and ask what each shows when the underlying licence is missing, not just when it is working. If the honest answer is the same thing it shows when everything is fine, that is the gap worth fixing first, and asking the question costs nothing.
Disclosure: this is a category we sell into. Avalon Web Services runs Avalon CloudSec, a Microsoft 365 and Azure monitoring service built around exactly this problem: every module reports one of four explicit states — Healthy, Not licensed, Permission required, or Auth error — so a missing Entra ID P2 license or an expired app credential shows up as itself instead of as a blank chart. The honest limitation: because the integration holds only read permissions, it can tell you a license is missing but cannot buy or assign one for you — that step, like every change, stays in your own Microsoft admin center. To see what your own tenant's gaps look like labelled this way, email support@awservices.org.
Microsoft, Microsoft 365, Azure, Entra, Intune and Defender are trademarks of the Microsoft group of companies. Avalon CloudSec is an independent service and is not endorsed by Microsoft.
Primary sources
- Microsoft — Microsoft Entra ID licensing and feature availability
- Microsoft — Neither tenant is B2C or tenant doesn't have premium license error when you query sign-in activities
- Microsoft Graph — List users (v1.0)
- Microsoft — How to manage inactive user accounts
- Microsoft — Resolve Microsoft Graph authorization errors
- Microsoft — Microsoft Defender XDR prerequisites
- Microsoft — Microsoft Intune licensing plans and options
- Microsoft — Discovery capability differences for Defender for Cloud Apps and Cloud App Discovery