Microsoft + Claude—One partner for the cloud you run and the AI you put on top of it.
Avalon Web ServicesMicrosoft · Claude · Security

Why 'not licensed' beats an empty chart

A blank chart in a Microsoft 365 security dashboard usually gets read as good news. It often is not. A query can come back empty for at least four different reasons: the tenant is not licensed for that data, the connecting app was never granted the permission, its credential expired, or there is genuinely nothing to report. Microsoft Graph does not reliably tell these apart. Sometimes it names the cause; more often the same generic error covers a licensing problem and a permissions problem alike. A dashboard that shows one blank for all four is not simplifying. It is guessing, and letting the reader assume the best case.

Written by
Arif Ali Mughal
Published
Reading time
8 min

01 / 10

A dashboard that never had bad news

Consider a fictional 40-person non-profit that inherited a security dashboard from its previous IT provider. For two years, the tile for risky users sat at zero. Nobody investigated, because zero is the number everyone hopes for.

When a different provider finally looked at the tenant itself, the explanation was simpler than a hidden breach, and worse in its own way. The tenant had never carried the Microsoft Entra ID P2 license that full risk detection requires. The chart was not reporting zero risk. It was reporting zero license.

Nobody lied. The dashboard just could not tell the difference between nothing happened and we are not licensed to see whether anything happened — and it defaulted, silently, to the version that looks like good news.

02 / 10

Four different reasons a chart can be empty

In a Microsoft 365 tenant, a query can come back with nothing to show for at least four unrelated reasons, and only one of them means the thing you were worried about did not happen.

  • Not licensed. The tenant does not carry the subscription tier that unlocks that data, or unlocks the fuller version of it.
  • Not granted. The application asking the question was never given the Microsoft Graph permission it needs, or nobody consented to it.
  • Credential expired. The application's client secret or certificate lapsed, so every request now fails authentication before licensing or permissions are even checked.
  • Genuinely nothing. The license is present, the permission is granted, the credential is valid, and the honest answer is zero.

03 / 10

The gates hiding inside identity charts

Licence gates are the least visible of the four causes, because they rarely look like a gate. Nothing announces that a chart is capped. It simply renders fewer rows, or a lower-detail version of the same screen, and looks complete.

Microsoft's own licensing reference is specific about where the caps sit. On Microsoft Entra ID P1, the risky users report is, in Microsoft's words, Limited Information. Only users with medium and high risk are shown. No details drawer or risk history. The risky sign-ins report on P1 is Limited Information. No risk detail or risk level is shown. Full detail on both needs Microsoft Entra ID P2.

Risk detections sit behind a sharper line. Below P1, Microsoft's own table lists the capability outright as No — nothing renders, not even a limited view. Risk-based Conditional Access policies, the feature that acts on a risk score rather than just reporting it, need P2 specifically; P1 does not reach that far, no matter how complete the report looks. (Checked against the licensing page's 18 June 2026 update.)

A related gate sits behind any chart of dormant or inactive accounts. Microsoft's guidance on managing inactive user accounts states plainly: To access the lastSuccessfulSignInDateTime property using Microsoft Graph, you need a Microsoft Entra ID P1 or P2 license. The Graph API reference for listing users gives the same requirement for the broader signInActivity property. Below P1, that property is not degraded. It cannot be queried at all.

04 / 10

Two more gates, further from identity

Microsoft Defender XDR's unified incident queue works the same way, though the gate is a plan rather than a tier inside one product. Microsoft lists more than a dozen qualifying licenses that unlock it at no extra cost — Microsoft 365 E5, Business Premium, Defender for Endpoint on its own, and several add-on combinations among them — and a bare Microsoft 365 E3 with no add-on is not on that list. A chart wired to the incidents API on such a tenant has nothing to show, and nothing about the chart says the tenant was never eligible to begin with.

Intune device compliance runs into the same wall from a different direction. Microsoft's licensing guidance is unambiguous: an Intune license is required for any user or device that benefits directly or indirectly from the Microsoft Intune service, including access through a Microsoft API. A compliance chart querying an unlicensed tenant is not asking a question Intune will ever answer.

Shadow-AI discovery from network traffic has its own two-tier version of the same gate. The entry tier, Cloud App Discovery, ships at no extra cost with Microsoft Entra ID P1, Enterprise Mobility + Security E3, or Microsoft 365 E3, and already supports manual and automatic log upload. The native integration with Microsoft Defender for Endpoint — the piece that makes device-level discovery practical without standing up a log collector — belongs to the full Defender for Cloud Apps tier, one step up. A chart advertising connected AI apps found on the network, on a Cloud-App-Discovery-only tenant, is asking for a capability that tier was never sold to provide.

05 / 10

What Microsoft Graph actually tells you when you ask

If licence gaps were at least loud, this would be a smaller problem — a dashboard could catch the error and label it correctly. Microsoft's own troubleshooting guidance says that, mostly, they are not.

Describing a plain 403 Forbidden response from Microsoft Graph, Microsoft's guide to resolving authorization errors puts it directly: Generally, this error indicates that the user is not privileged enough to perform the request or the user is not licensed for the data being accessed. Only users with the required permissions or licenses can make the request successfully.

Read that the way a piece of software has to read it: the same HTTP status code, the same generic wording, covers two of the four causes above. A 403 does not, on its own, tell you whether the tenant needs a different licence or the application needs a different consent grant. Both failures look identical on the wire.

There is one documented exception, worth naming because it shows Microsoft can do better when it chooses to. Query signInActivity or the sign-in log without Entra ID Premium, and Graph returns a distinct error code, Authentication_RequestFromNonPremiumTenantOrB2CTenant, with a message that names the licence problem directly rather than a bare permissions-or-licence 403: Neither tenant is B2C or tenant doesn't have premium license. That one endpoint tells you which of the two happened. Most do not.

Our reading, not a design principle Microsoft states: this inconsistency looks less like a flaw than a fact of a platform built from many teams' APIs over many years. A dashboard cannot assume Microsoft will name the cause. It has to work out the cause itself, per licence, ahead of the query, rather than trust the response to explain itself.

06 / 10

The fourth cause looks exactly like the other three

The frustrating part is that the good outcome — a licensed, permissioned, correctly authenticated system reporting a true zero — renders identically to the three bad ones. A zero-row risky-users table and a P1-capped risky-users table can be pixel-for-pixel the same image. Nothing in the chart itself carries the difference; the difference lives in metadata the chart is choosing whether to show.

Our judgement, not something documented: most dashboards build the happy path first and treat the other three causes as edge cases to handle later, if at all. They do not feel like edge cases to the business owner who has been staring at a flat line for two years.

07 / 10

Four causes, one chart, four honest answers

Put together, the pattern behind the four causes above looks like this.

What the chart should showLicence that gates itWhat Graph returns without itWhat an honest status should say
Risky users, full detailEntra ID P2Limited view, no errorNot licensed (P2 needed)
Risk detections at allEntra ID P1 or P2Nothing shown, no errorNot licensed (P1 needed)
Last sign-in / inactivityEntra ID P1 or P2Specific, self-naming error codeNot licensed (P1 needed)
Defender XDR incidentsA qualifying Defender planEmpty result, no error foundNot licensed, check the plan
Device compliance statusIntune licenceNo record for that deviceNot licensed (Intune needed)
AI apps found on networkDefender for Cloud AppsFeature unavailable in UINot licensed, upgrade tier

08 / 10

Status before data

The fix is not a smarter chart. It is a status that renders before the data does, using a small, fixed vocabulary, checked against what the tenant is actually entitled to before a single content query runs.

That means checking licence SKUs and service plans against a known list for every module a dashboard offers, rather than inferring the answer from whatever the query happens to return. It means treating a credential failure as its own state, separate from both licensing and permissions, because an expired client secret has nothing to do with what the tenant is entitled to. And it means reserving an actual zero for the one case where the licence is present, the permission is granted, the credential is valid, and the answer really is nothing.

Our recommendation, not a Microsoft requirement: four labels are enough for a small-business dashboard to be honest without becoming unreadable — Healthy, Not licensed, Permission required, and Auth error, shown ahead of any chart they would otherwise leave blank. A fifth label for a confirmed true zero is tempting, but it usually collapses back into Healthy: a module reporting fifty rows and one reporting zero are the same state, correctly checked, with different data. Splitting them further would just be a second way of hiding the fact this piece argues against.

FOUR THINGS A BLANK CHART CAN MEAN THE UNDERLYING CAUSE NOT LICENSED tenant lacks the SKU NOT GRANTED app lacks the Graph scope CREDENTIAL EXPIRED client secret or cert lapsed TRUE ZERO answer really is nothing IF NOTHING CHECKS STATUS FIRST RAW CHART: SAME BLANK LINE for all four causes above IF STATUS RENDERS FIRST NOT LICENSED PERMISSION REQUIRED AUTH ERROR HEALTHY (ZERO) Four different causes render as the same blank chart unless a status is decided before the data is queried. Checked against Microsoft Learn, 20 September 2026.
Four unrelated causes and only one path tells them apart. Route a dashboard straight to the chart and a missing licence, a missing permission, an expired credential and a genuine zero all render as the same blank line. Check status first, against what the tenant is actually entitled to, and the same four causes come out as four different labels.

09 / 10

Not licensed is not a verdict on you

None of this means every business should buy Microsoft Entra ID P2, upgrade to full Defender for Cloud Apps, or add Intune seats it does not need. Plenty of 40-person organisations run comfortably on Microsoft 365 E3 or Business Premium and never need P2's risk-based Conditional Access policies. The point is not that every gate should be unlocked. It is that a chart which cannot see past a gate should say so, rather than quietly reporting the free-tier view as if it were the whole picture.

A Not licensed label is not bad news about your security. It is an accurate description of what a screen is and is not allowed to see — and it is the only version of that screen that lets you decide, on purpose, whether to buy the missing tier or accept the smaller view.

10 / 10

Where to start

Before your next licence renewal, pick the three charts your team actually looks at — risky users, inactive accounts, and device compliance are common ones — and ask what each shows when the underlying licence is missing, not just when it is working. If the honest answer is the same thing it shows when everything is fine, that is the gap worth fixing first, and asking the question costs nothing.

Disclosure: this is a category we sell into. Avalon Web Services runs Avalon CloudSec, a Microsoft 365 and Azure monitoring service built around exactly this problem: every module reports one of four explicit states — Healthy, Not licensed, Permission required, or Auth error — so a missing Entra ID P2 license or an expired app credential shows up as itself instead of as a blank chart. The honest limitation: because the integration holds only read permissions, it can tell you a license is missing but cannot buy or assign one for you — that step, like every change, stays in your own Microsoft admin center. To see what your own tenant's gaps look like labelled this way, email support@awservices.org.

Microsoft, Microsoft 365, Azure, Entra, Intune and Defender are trademarks of the Microsoft group of companies. Avalon CloudSec is an independent service and is not endorsed by Microsoft.

Primary sources

Want us to run this for you?

Start here

Tell us what'skeeping you upat night.

Most engagements start with a Cloud Health Check — one week, full audit, top-10 findings, 90-day roadmap. Many turn into a longer engagement; either way, you walk away with a prioritized plan you own.