4.2 · Microsoft 365 administration (users, licences)

Level 4 · Expert: cloud & Microsoft 365 administration

4.2Microsoft 365 administration (users, licences)

Objective: administer Microsoft 365 from the cloud: create accounts, assign licences, and manage groups centrally rather than device by device.
Estimated time: 12 min

Microsoft 365 is the SaaS suite many organizations run their work on — email, documents, Teams, storage — and it is administered centrally from the cloud through the Microsoft 365 admin center. The core daily tasks are creating and managing user accounts, assigning licences (each licence unlocks a set of services for a user), and organizing people into groups. Crucially, all of this is done from one console, from anywhere, without touching each person's device — the essence of cloud administration.

The workflow is straightforward: add a user, give them a licence appropriate to their role, and place them in the right groups so they get the correct access, distribution lists and settings. Licence management matters both financially (you pay per assigned licence, so unused ones waste money) and operationally (a user without the right licence cannot use a service). When someone leaves, you block or remove the account and reclaim the licence — a step easy to forget and costly to skip. Group-based assignment keeps this manageable as the organization grows. Mastering the admin center means you can onboard, offboard and reorganize people in minutes, centrally, which is exactly why organizations move to the cloud in the first place.

Section vocabulary

Microsoft 365 admin center
The cloud console for administering users, licences, groups and services.
User account
A person's cloud identity, managed centrally rather than per device.
Licence
An assignment that unlocks a set of Microsoft 365 services for a user; you pay per assigned licence.
Group
A collection of users for shared access, distribution and settings.
Offboarding
Blocking or removing a departing user's account and reclaiming the licence.
Check your understanding

How are users administered in Microsoft 365?

Tutorial 4.2
Tutorials: « 4.2 » Microsoft 365 admin center add users assign licenses (search)
Click to see up-to-date results ↗

In practice — Onboard and offboard centrally

  1. Describe the steps to add a new user: create the account, assign a role-appropriate licence, add to the right groups.
  2. Explain how group membership shapes what the user can access.
  3. List what to do when the person leaves, including reclaiming the licence.
  4. Note why unused licences are worth reviewing periodically.
You can create, licence and organize Microsoft 365 users centrally, and offboard them cleanly to reclaim licences.

Key takeaways

  • Microsoft 365 is administered centrally from the cloud admin center — no per-device work.
  • Core tasks: create accounts, assign licences, organize into groups.
  • Licences cost money per assignment and gate service access — manage them deliberately.
  • Offboard departing users promptly: block the account and reclaim the licence.

Frequently asked questions

How is administering Microsoft 365 different from managing local machines?

The biggest shift is that you manage identities and services centrally, from a web console, rather than configuring each device. Onboarding a person is a few clicks — create the account, assign a licence, add to groups — and their access follows them to any device they sign into. There is no local server to maintain and no need to visit machines. That convenience comes with its own discipline: because everything is central and internet-facing, strong sign-in security (covered in the MFA section) and careful licence and access management become essential. You trade physical, per-machine work for centralized, identity-focused administration.

Why bother reclaiming licences when someone leaves — isn't the account harmless once they're gone?

Two reasons: cost and security. Financially, Microsoft 365 is billed per assigned licence, so every dormant account with a licence quietly wastes money month after month; reclaiming it is free savings. Security-wise, a lingering active account for a former employee is exactly the kind of forgotten door attackers look for — still able to sign in, still holding access, but no longer watched by anyone. Prompt offboarding (blocking sign-in, removing or reassigning the licence, and handling their data) closes that door and tidies the books. It is a small, routine step that prevents both a recurring bill and a real risk.

More resources