How to Add Users and Assign Licenses in Microsoft 365 (Complete Guide for 2026)

If you’ve just set up a Microsoft 365 subscription for your business, one of the first things you’ll need to do is add your team as users. The process itself is quick — but if you get the license wrong, skip MFA, or hand out admin roles carelessly, you’ll be cleaning up those mistakes for months.

This guide walks you through everything: prerequisites, licenses, step-by-step user creation, bulk methods, MFA, offboarding, and the mistakes most admins make but never talk about.

Before You Start — Prerequisites

Before you open the Admin Center, make sure you have:

  • An active Microsoft 365 subscription with available licenses (check under Billing → Licenses)
  • Global Administrator or User Administrator access — if you can’t see admin options, your account doesn’t have the right role
  • A verified domain — your company email domain must be added and verified in Microsoft 365 before you can create addresses on it
  • The new user’s name, job title, department, and manager
  • A decided naming convention — firstname.lastname@, flastname@, or another format. Decide before your first user and stick to it. Inconsistency is painful to fix later.

Understanding Microsoft 365 Licenses

Licenses are the most misunderstood part of Microsoft 365 for new admins. People often pick the cheapest option without checking whether it covers what the employee actually needs.

LicenseDesktop Office Apps?Email?Best For
Microsoft 365 Business Basic❌ Web/mobile only✅ YesLight users who work in a browser or on mobile
Microsoft 365 Business Standard✅ Yes✅ YesMost employees — the most common pick for SMBs
Microsoft 365 Business Premium✅ Yes✅ YesTeams handling sensitive data; includes Intune and Defender
Microsoft 365 E3✅ Yes✅ YesEnterprise: compliance, eDiscovery, 100 GB mailbox
Microsoft 365 E5✅ Yes✅ YesEnterprise with advanced security and Power BI Pro

The most common mistake: Assigning Business Basic to employees who need to install Word, Excel, or PowerPoint on a laptop. Basic only includes web and mobile versions — no desktop apps. If they use Office on a computer, they need Business Standard or higher.

A quick rule: ask “Does this person need to install Office on a PC or Mac?” If yes, don’t use Basic.

Step-by-Step: Adding a Single User

Step 1: Sign In to the Admin Center

Go to admin.microsoft.com and sign in with your admin credentials — not your regular email account.

Step 2: Go to Active Users

In the left sidebar, click Users → Active Users. This is where all user accounts are created and managed.

Step 3: Click “Add a User”

Click + Add a user at the top of the page. A setup panel opens on the right side.

Step 4: Enter Basic Information

Fill in the user’s first and last name, display name, and username. The username becomes their email address — double-check it before moving on. Changing a username later can break sign-in and some integrations.

Step 5: Set the Password

Choose to auto-generate a password or set one manually. Always tick “Require this user to change their password when they first sign in” — this is a basic security standard, not optional.

Step 6: Set Usage Location and Assign a License

Select the user’s country (required for licensing compliance), then choose the appropriate license. If no licenses are available, go to Billing → Purchase Services to buy more first.

Step 7: Add Profile Details

Don’t skip this tab. Add the user’s job title, department, office location, and manager. This populates the company directory in Teams and Outlook — new employees use it constantly to figure out who’s who.

Step 8: Set Admin Roles (Only If Needed)

By default, users get no admin access — which is correct for most people. Only assign admin roles if the job actually requires them. See the Roles and Permissions section below.

Step 9: Review and Finish

Check the username, license, and role one more time, then click Finish adding. The account is active immediately. Most services provision within 1–2 minutes; OneDrive and SharePoint may take up to 30 minutes on first sign-in.

Assigning or Changing a License

If you created a user without a license, or need to change one:

  1. Go to Users → Active Users and click the user’s name
  2. Click the Licenses and apps tab
  3. Check or uncheck the license you want
  4. Optionally expand Apps to enable or disable specific services within the license
  5. Click Save changes

When you remove a license, the user immediately loses access to those services. Their data isn’t deleted right away — Microsoft retains mailbox data for 30 days and OneDrive data for 180 days — but don’t treat this as a backup. Use a proper Microsoft 365 Backup solution if you need reliable long-term retention.

Setting Up Roles and Permissions

Give people only the access they need — nothing more. Admin roles are high-value targets and the fewer accounts that have them, the lower your risk.

RoleWhat It DoesAssign To
Global AdministratorFull access to everything1–2 senior IT staff only
User AdministratorCreate/edit/delete users, assign licensesIT helpdesk or HR
Billing AdministratorManage subscriptions and licensesFinance or IT procurement
Exchange AdministratorManage mailboxes and email policiesEmail admin
Helpdesk AdministratorReset passwords for non-admin usersLevel 1 support

Global Admin accounts should always have MFA enforced and use dedicated admin email addresses separate from daily email. A compromised Global Admin account gives an attacker complete control of your entire tenant.

Adding Multiple Users at Once

For onboarding more than a handful of people, the bulk CSV method saves significant time:

  1. Go to Active Users and select Add multiple users
  2. Download Microsoft’s sample CSV template
  3. Fill in the template with your users’ data
  4. Upload the CSV — Microsoft validates it and flags any errors
  5. Review the results and click Add users

Important: The CSV method does not assign licenses automatically. You’ll need to assign licenses after upload, either individually through the UI or via PowerShell for large groups.

For IT admins comfortable with scripting, Microsoft Graph PowerShell is the most powerful option — it lets you create users, assign licenses, and set profile details all in one repeatable script. It’s also excellent for reporting: you can export all users, their licenses, and last sign-in dates to a CSV in seconds, which is invaluable for quarterly audits.

Enabling Multi-Factor Authentication (MFA)

This is the step most guides skip, and it’s arguably the most important. Microsoft’s own data shows MFA blocks over 99.9% of account compromise attacks. If you’re adding users without enabling it, you’re leaving the most effective security control on the table.

Three ways to enable MFA:

  • Security Defaults — Go to Azure Active Directory → Properties → Manage Security Defaults and turn it on. Simplest option; good for small organizations.
  • Per-User MFA — Go to Users → Active Users → Multi-factor authentication. Enable user by user. Fine for small teams, tedious at scale.
  • Conditional Access Policies — The most flexible approach, available on Business Premium, E3, and E5. Lets you require MFA based on conditions — always for admins, only outside the office for standard users, etc.

Always enable MFA on admin accounts first. And always create at least one break-glass emergency admin account that’s excluded from Conditional Access — if your policies lock all admins out, recovering access is a slow and painful process with Microsoft Support.

Offboarding — Removing a User the Right Way

When someone leaves, how you handle their account matters as much as how you created it. Moving too fast risks data loss; moving too slow leaves active credentials that could be exploited.

Recommended sequence:

  1. Reset the user’s password and revoke active sessions immediately
  2. Remove any admin roles
  3. Set an Out of Office reply and forward their email to a manager or shared mailbox
  4. Transfer their OneDrive files to their manager
  5. Remove them from Teams channels, SharePoint sites, and distribution lists
  6. Convert to a Shared Mailbox if others need ongoing access (no license required)
  7. Disable the account (block sign-in) — don’t delete yet
  8. After 30 days, confirm all data is accounted for, then delete
  9. Reclaim the license

Best practice: disable first, delete later. Rushing the deletion is one of the most common causes of permanent data loss during offboarding.

Common Mistakes to Avoid

MistakeWhat Goes WrongFix
Business Basic for desktop usersCan’t install Office on their computerAsk upfront if they need desktop apps
Forgetting usage locationLicense assignment fails silentlyAlways set the country during creation
Handing out admin roles casuallySecurity risk; hard to trackAssign only what’s needed; review quarterly
Skipping MFA at onboardingAccount is vulnerable from day oneMake MFA part of the onboarding checklist
Deleting a user account immediatelyPermanent data lossDisable first, delete after 30 days
Not reclaiming licenses after departurePaying for unused seatsBuild license review into offboarding

Don’t Overlook Data Backup

Here’s something most Microsoft 365 setup guides don’t mention: Microsoft 365 is not a backup solution. It protects against infrastructure failure — not against accidental deletion, ransomware, or mistakes made by your own admins.

What can still go wrong without a backup:

  • A user permanently deletes an important email thread — gone after 30 days
  • Ransomware encrypts OneDrive and SharePoint files across your organization
  • An admin makes an error and wipes a mailbox
  • Compliance requirements demand longer retention than Microsoft’s defaults

Microsoft themselves recommend supplementing Microsoft 365 with a third-party backup. SkyMigrate’s Microsoft 365 Backup covers email, OneDrive, SharePoint, and Teams with point-in-time recovery and long-term retention.

Migrating to Microsoft 365?

If you’re adding users as part of a migration — from Google Workspace, Exchange on-premises, Amazon WorkMail, or another system — there are a few things to know beyond the standard setup.

Create accounts and assign licenses before migration day. Migration tools need active, licensed mailboxes to deliver data to. Many projects stall because accounts were created but not licensed, and the tool can’t find the target mailbox.

Pre-creating accounts also gives users time to set up MFA and get familiar with the interface before their data arrives. It reduces confusion on cutover day significantly.

Map usernames carefully. If your source system uses email addresses as identifiers, make sure they align correctly with Microsoft 365 usernames to avoid misrouted data.

Depending on where you’re migrating from, SkyMigrate covers the full process:

Best Practices for Long-Term Management

Run quarterly license audits. Check Billing → Licenses for users who haven’t signed in for 90+ days. Former employees with active licenses are a common source of wasted spend.

Use groups, not individual permissions. Assign SharePoint and Teams access through Microsoft 365 Groups or Security Groups. When someone’s role changes, update the group once — all permissions update automatically.

Set up retention policies early. Don’t wait until something is accidentally deleted to think about retention. Our guide on How to Create Retention Policy in Office 365 Exchange Online walks through the setup in detail.

Enable audit logging. Go to Security → Audit and confirm logging is active. These logs are invaluable during incidents and compliance reviews — but only if they were running before the incident.

Document everything. Your naming conventions, license assignment rules, and offboarding checklist should live in a shared document that any IT team member can follow. If it’s not written down, the next admin will make different decisions.

FAQs

Can I create a user without a license? Yes, but they won’t be able to access any Microsoft 365 services until one is assigned. Useful when pre-creating accounts before a migration.

How long does account creation take? Users can usually sign in within 1–2 minutes. OneDrive and SharePoint may take up to 30 minutes to fully provision on first sign-in.

What if I assign the wrong license? Change it anytime from the user’s Licenses and apps tab. Downgrading from Standard to Basic removes desktop app access — the user will need to uninstall Office.

How do I onboard a large team efficiently? Use the CSV bulk upload in Active Users for quick account creation, then assign licenses manually or via PowerShell. PowerShell is better for large groups as it handles creation and licensing in one step.

What happens to data when I delete a user? Mailbox data is retained for 30 days, OneDrive for 180 days. After those windows, it’s permanently gone. Use Microsoft 365 Backup if you need reliable long-term retention beyond Microsoft’s defaults.

What’s the difference between disabling and deleting a user? Disabling blocks sign-in but keeps the account, data, and license active. Deleting starts the data retention clock. Always disable first during offboarding, confirm data is handled, then delete after 30 days.

Was this article helpful?
YesNo
Scroll to Top