For IT Directors, Finance Directors, and Business Central administrators, managing the employee offboarding lifecycle is a critical component of both ITGC compliance and cloud cost optimization. A pervasive governance failure occurs during this lifecycle when users are disabled within the ERP application, but the underlying subscription licensing is left active.
Microsoft bills your organisation based on the licenses assigned within the Microsoft 365 Admin Center — not on the active or inactive status of the user profile within the Business Central database. This structural disconnect results in organisations paying for phantom users. Furthermore, dormant accounts with active licenses pose a latent security threat that complicates compliance audits.
The Architecture: Two Separate Systems
To understand why this disconnect occurs, administrators must look at the two separate systems governing identity and licensing for Business Central SaaS.
The identity and licensing layer — controlled by Entra ID and the Microsoft 365 Admin Center. This is where you purchase subscriptions, create user identities, and allocate product licenses to those identities.
The application layer — Business Central itself. BC authenticates users against Entra ID. When a user logs in for the first time, Business Central reads the Entra ID payload. If the user holds a valid BC Essentials or Premium license, the application provisions a user record within the ERP database.
This synchronisation is a one-way street. The application layer consumes data from the identity layer but does not dictate terms back to it. When an administrator takes action within Business Central, the Microsoft 365 Admin Center remains completely unaware of the application-level status change.
The Process Disconnect
The standard — but flawed — offboarding procedure looks like this: an employee leaves, a helpdesk technician opens Business Central, navigates to the user record, and changes the state from Enabled to Disabled. Inside BC, the objective appears achieved. The user can no longer authenticate into the ERP.
However, in the Microsoft 365 Admin Center, the Business Central license remains permanently assigned to that user's Entra ID object. Microsoft's billing engine does not query the BC Users table to verify if the account is actively allowed to log in — it only queries Entra ID to see if the license is assigned. Because the license remains assigned, the organisation is invoiced for it at the end of the month.
A routine governance review of a live BC Cloud environment with 65 users found 23 inactive users still consuming paid licenses — a 35% waste in the licensing budget. All 23 had been disabled in BC but never removed from M365 Admin Center.
Identifying Inactive Users Consuming Licenses
Reconcile active users in Business Central against assigned licenses in Microsoft 365:
/?page=9800. Review the State column — users marked Disabled cannot log in but may still be licensed.admin.microsoft.com → Reports → Usage → Dynamics 365 Business Central. Review sign-in activity over the past 90 or 180 days. Any user with no sign-in activity for 90+ days is a candidate for license review.Calculating the Financial Impact
Exact Remediation Steps
admin.microsoft.com. Log in with Global Administrator or User Administrator privileges.Users → Active users. Search for the employee disabled in Business Central.Billing → Your products → Business Central subscription → Remove licenses. Reduce the total quantity to stop paying for it.Once the license is removed in M365, the next time Business Central syncs with Entra ID, it will read the updated state and strip system-level access — aligning the application with the identity layer.
Closing Recommendation
License management should never be treated as a set and forget operation. IT Directors and Finance Directors must mandate a quarterly license reconciliation review — cross-referencing HR termination lists with M365 Admin Center license assignments and Business Central user states. Executing this review every 90 days guarantees that ERP expenditure reflects the actual active workforce and that permission set governance remains tied to authenticated employees.
A complete BC governance review identifies inactive users, shared accounts, permission set overlaps, and license waste — delivered within 48 hours from two standard exports. No system access required.