Almost every Dynamics 365 Business Central costing conversation SCSB is invited into opens the same way: a headcount, and a question about cost. SCSB's answer is consistently that headcount is the wrong unit of measurement. What governs whether a Business Central deployment works for the people using it is the licence type assigned to each person — and that type is enforced by the platform itself, not by configuration an administrator can adjust afterwards.
This article sets out what each licence type permits, the constraints that most often surprise administrators, and what SCSB asks an organisation to establish before a quotation means anything. It states no prices, deliberately: licence terms and pricing are set by Microsoft, published in Microsoft's own Dynamics 365 licensing guide, and revised periodically. A figure copied onto a consultancy's website ages badly and misleads the reader who relies on it.
The licence types, and the single purchase route
Microsoft's licensing documentation for Business Central states that Business Central licences can only be purchased through CSP, and lists the paid licences for business users as:
- Essentials and Premium — full write access, differing in functional scope;
- Team Member — limited write access;
- External Accountant — a distinct licence type for an external accounting adviser invited into the tenant.
Microsoft additionally offers read-only access through Microsoft 365 licences, described explicitly as an addition to Premium or Essentials plans rather than a substitute for them. A separate Device licence covers shared-device scenarios, discussed below.
The CSP-only route shapes the commercial conversation more than most organisations expect. Because licences are bought through a Cloud Solution Provider partner rather than directly, licensing and implementation tend to be discussed together. SCSB's view is that this is an advantage where it is used to size the licence mix against the work people actually do, and a trap where the licence count is simply set to headcount and settled before anyone has examined that work.
One operational detail catches new tenants regularly. Where a business is converting a 30-day trial company into its production company, Microsoft notes that the first user to sign in after the licence is applied must be a user with that licence assigned. If an unlicensed administrator signs in first, the trial simply continues until it expires.
Entitlements override permissions — the rule that costs the most time
This is the most important licensing mechanic in Business Central, and in SCSB's experience the most frequently misdiagnosed.
Business Central online does not use the classic Dynamics NAV licence files. Permissions are generated from entitlements, which Microsoft describes as permissions defining which objects a user is entitled to use according to their Microsoft Entra role or the licence purchased. Each entitlement set is associated with a Microsoft Entra ID service plan. When a user signs in, the service applies the intersection of the entitlements attached to their service plan and the permissions defined for that user — and, in Microsoft's words, entitlements always have higher priority over permissions.
Microsoft states the consequence directly: even where an administrator grants a user SUPER permissions, a user holding a Team Member licence can still only access the objects defined by the Team Member entitlements.
The practical significance is that a licensing problem and a permissions problem present identically to the person experiencing them — a page that will not open, an action that is not there. SCSB's standing advice to administrators is to check the licence before rebuilding permission sets, and to use the Effective Permissions page, reachable from the User page, to see how entitlements, licences and permissions resolve for a specific person. No amount of permission configuration will grant access the licence does not carry, and a great many hours are spent proving that.
One point matters for anyone testing before go-live. Microsoft records that entitlements were once enforced only in production, but since 2020 release wave 2 licence checks are enforced in sandbox environments too. Behaviour observed in a current sandbox is therefore a fair test of entitlement.
Essentials and Premium are not interchangeable at company level
The distinction is not only about which features an individual can reach. Microsoft's guidance on creating users according to licences records two asymmetric rules tied to the Experience field on the Company Information page:
- a user with a Premium licence can sign in to a company whose Experience is set to Essentials, but cannot use Premium features there; and
- a user with an Essentials licence cannot sign in at all to a company whose Experience is set to Premium.
For a group running several companies in one environment, the Experience setting therefore interacts directly with licence assignment across the whole group. Switching one company to Premium locks every Essentials-licensed user out of that company. SCSB treats this as a question to settle during design rather than a setting to discover after the switch, because the remedy afterwards is either a licence upgrade or a reversal, and both are disruptive at month end.
Read-only access through Microsoft 365, and its real boundaries
Microsoft documents that a person accessing Business Central with a Microsoft 365 licence is entitled to read, but not write, Business Central data through a simplified interface in Microsoft Teams. The platform automatically prevents writing to data tables, so this is not a restriction that could be relaxed by configuration.
What is less widely understood is how narrow the route is. Microsoft's use-rights table permits the Business Central app for Microsoft Teams and nothing else: the web client, the mobile apps, the APIs, integrations with other Office applications, and embedding elsewhere all sit outside the entitlement. Within Microsoft Teams the interface is reduced — users can view cards and card details, drill from a list to a card, search, sort and copy, but cannot edit, create or delete, cannot use the filter pane or views, cannot reach related tables through the FactBox, and cannot open or edit in Excel.
Three conditions are easy to miss. Users must be internal, because guest and external identities are not supported. The Microsoft 365 licence must come from one of the plans Microsoft publishes as supported, with the Microsoft Teams app enabled within it. And the organisation must have at least one other user holding a Dynamics 365 Business Central licence.
SCSB's practical reading is that this is genuinely useful for colleagues who need to look a figure up in the flow of a conversation, and that it is not a route to reducing a Team Member count. Where a person needs to act on a record rather than read it, the entitlement does not reach.
Device licences and the concurrent-use model
The Device licence is structured differently from the user licences and is easy to overlook. It allows multiple users to use a covered device simultaneously — Microsoft cites point-of-sale, shop-floor and warehouse devices. Where several device licences are held, up to that number of users assigned to the Dynamics 365 Business Central Device Users group can sign in at the same time, and members of that group do not need an individual Business Central licence assigned.
Two constraints follow. The group must be created in the Microsoft 365 admin center with that name spelled exactly in English, whatever language the tenant otherwise uses. And a device user cannot be the first to sign in: an Administrator, Full User or External Accountant must sign in first to set Business Central up.
Permission sets, licence configuration and security groups
Each licence carries default permission sets. Microsoft documents that the Team Member licence carries D365 READ, D365 TEAM MEMBER, EDIT IN EXCEL - VIEW, EXPORT REPORT EXCEL and LOCAL, with further sets added according to the groups assigned.
Administrators can customise these defaults on the License Configuration page, subject to a timing constraint SCSB raises on every deployment: the customisation takes effect only for new users subsequently assigned that licence. Existing users are not updated. Any customisation therefore has to be decided before licences are assigned in the Microsoft 365 admin center, not after the fact.
Separately, user groups have been replaced by security groups. Microsoft records that security groups replace user groups from 2023 release wave 1 (version 22), and that from version 25.0 user groups are deprecated in favour of composable permission sets and security groups. Guidance written against the older model will not match the current interface.
Reassignment is constrained, not free
Organisations frequently assume a licence can be moved between people as roles shift. Microsoft's terms restrict this. A licence cannot be reassigned on a short-term basis — meaning within 90 days of the latest assignment — except to cover a user's absence or a device that is out of service. Reassignment for any other purpose must be permanent, and temporary assignment of one user's licence to another is not permitted. This matters for seasonal and project-based planning, where an assumption of free rotation can quietly become a contractual exposure rather than a saving.
What SCSB asks an organisation to settle before requesting a quotation
- List users by what they need to do — post, approve, read, or operate a shared device — rather than by department or seniority.
- Identify who genuinely only reads. Those people may sit on Team Member or, within Microsoft Teams, on Microsoft 365 read-only access.
- Decide the Experience setting intended for each company, and test it against the licences those companies' users will hold.
- Confirm whether any shared-device scenario exists, and whether the Device licence model fits it.
- Decide any License Configuration customisation before assigning licences, because it will not apply retrospectively.
- Confirm current licence terms, entitlements, supported plans and pricing against Microsoft's current Dynamics 365 licensing guide and with a CSP partner.
Not every organisation needs external help with this. A single-company deployment with a clear split between people who post and people who read is a decision an experienced finance or IT lead can make directly from Microsoft's documentation, and SCSB would say so rather than manufacture a scoping exercise. Outside help earns its place on a multi-company group, a mixed Essentials and Premium estate, or a migration mapping existing permission structures onto entitlements. Where wider implementation scope is the question rather than licensing alone, that is addressed under SCSB's Business Central implementation service.
General-information limitation
This article is general information about Microsoft licensing concepts. It is not licensing, legal or pricing advice for a particular organisation, and it does not determine which licences an organisation requires, what they cost, or what any agreement permits. Licence terms, entitlements, supported plans and platform behaviour are set by Microsoft and change over time. Confirm the current position against Microsoft's published material and your CSP partner before purchase.
Dynamics 365 Business Central, Dynamics NAV, Microsoft, Microsoft 365, Microsoft Entra ID and Microsoft Teams are trademarks of the Microsoft group of companies.