logo
search
License & Subscription Issues

How to Find Unlicensed Users in Microsoft 365 with PowerShell

Phi Hung VoPhi Hung Vo Sep 30, 2026 868 views

Question details

The user wants to identify and list all unlicensed user accounts within their Microsoft 365 tenant using PowerShell.

How to Find Unlicensed Users in Microsoft 365 with PowerShell
Product
Microsoft 365
Device & OS
not provided
Scenario
An IT administrator needs to audit user licenses to find which active accounts currently do not have a Microsoft 365 license assigned.
Observed behavior
Unlicensed users are visible in the Microsoft 365 admin center but do not appear in the Exchange admin center, requiring a PowerShell script to query the complete list.
Before you start

Ensure you have the Microsoft Graph PowerShell module installed on your device and that you hold the necessary global admin or user management permissions in your Microsoft 365 tenant.

Solution 1Recommended

Use Microsoft Graph PowerShell to Filter Unlicensed Users

Execute the Get-MgUser cmdlet via Microsoft Graph PowerShell to reliably identify all accounts without assigned licenses in your tenant directory.

Microsoft Graph PowerShell is the recommended tool for querying Microsoft 365 directories. It allows administrators to bypass the visibility limitations of the Exchange admin center, which generally only lists users with active Exchange mailbox licenses, providing a comprehensive view of all identities.

1
Connect to Microsoft 365 Tenant

Launch PowerShell as an administrator. Connect to your tenant by executing the command: Connect-MgGraph -Scopes "User.Read.All" and following the prompt to authenticate.

2
Run the Filter Command

Type the following command to retrieve users without licenses and store the count: Get-MgUser -Filter 'assignedLicenses/$count eq 0' -ConsistencyLevel eventual -CountVariable unlicensedUserCount -All

3
Display the Total Count

To see how many unlicensed users were found, run the following command: Write-Host "Found $unlicensedUserCount unlicensed users."

Use Microsoft Graph PowerShell to Filter Unlicensed Users
Script Executed: The PowerShell console will now successfully display the total number of unlicensed accounts and load them into memory.
Free Microsoft Office alternative

Looking to Reduce Microsoft 365 Licensing Costs?

Managing Microsoft 365 licenses can be complex and expensive for growing teams. If you have unlicensed users who still need powerful document editing tools, WPS Office provides a lightweight, highly compatible alternative to Microsoft Office. It offers robust tools for word processing, spreadsheets, and presentations without the heavy subscription fees.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free version suited for your operating system.
  2. 2. Install WPS Office: Run the setup file and follow the simple on-screen instructions to quickly install the suite.
  3. 3. Edit Documents Instantly: Open WPS Office to view, edit, and collaborate on your existing Microsoft Office files without needing a licensed account.
Completely free alternative to costly Microsoft 365 subscriptionsHighly compatible with Microsoft Office formats (DOCX, XLSX, PPTX)Lightweight design ensures fast installation and smooth operation on any deviceRequires no complex license management or PowerShell scripts to deploy
QA img-9

Frequently Asked Questions

Why do unlicensed Microsoft 365 users not show up in the Exchange admin center?

The Exchange admin center is specifically designed to manage email infrastructure. It typically only displays users who have an active Exchange Online license and a provisioned mailbox, automatically hiding unlicensed directory users.

Do I need to install a specific module to run the Get-MgUser command?

Yes, the Get-MgUser command relies on the Microsoft Graph PowerShell module. You can install it by running 'Install-Module Microsoft.Graph' in an elevated PowerShell window before connecting.

Can I export the list of unlicensed users to a CSV file?

Yes, you can easily export the results. Simply pipe the Get-MgUser command into an export cmdlet, like this: Get-MgUser -Filter 'assignedLicenses/$count eq 0' -ConsistencyLevel eventual -All | Select-Object DisplayName, UserPrincipalName | Export-Csv -Path "C:\unlicensed_users.csv" -NoTypeInformation.