Power Platform

Power Platform managed environments: the licence check is already running

August 13, 2026

If you have enabled managed environments, some of your users are probably already seeing licence notifications inside your apps. Not soon. Now.

Microsoft began showing in-app notifications to unlicensed users in managed environments in June 2026, with administrator warnings running from March. That date has passed. The notifications escalate on a seven-day clock and they do not stop escalating until somebody assigns a licence.

The important thing to understand before anyone panics: the licensing requirement is not new. Microsoft is explicit that this requirement always existed. What is new is that it is now visible, to your end users, inside the app.

What your users actually see

The escalation runs in three states, and it is worth knowing where it ends before you decide how urgent this is.

StageMessageEscalates after
Informational“This app requires a valid Power Apps license. Request a license from your admin.”7 days
WarningSame message, elevated presentation7 days
Error“Action required: This app requires a valid Power Apps license. Request a license from your admin for continued access.”Stays until licensed

Two weeks from first notification to a permanent error state on a business application. The message is aimed at the user, not the administrator, which means the escalation path runs through your service desk whether or not anyone told your service desk this was happening.

Users can request a licence directly from the notification. Those requests surface in the Power Platform admin centre under Actions > Recommendations, and in the Microsoft 365 admin centre under Billing > Licenses > Requests.

Only environments you have explicitly enabled as managed environments are in scope. If you never turned it on, none of this applies to you.

What actually happens when you switch this on

The first impact is not technical friction. It is visibility shock.

It almost never hits the usual suspects. What it routinely exposes is the long tail: operational apps built by former employees, or by quiet departmental super-users, that key business functions have depended on for years without IT ever realising they required premium licensing.

That is the real finding here, and it is worth more than the licence count. An organisation that runs this report is not just sizing a purchase, it is discovering which parts of the business are quietly load-bearing.

What counts as a licence

The list is wider than “buy everyone Power Apps Premium”, and the distinctions save real money.

Managed environments are included as an entitlement in Power Apps Premium, Power Automate Premium, Microsoft Copilot Studio, Copilot Studio for Microsoft 365 Copilot (for Copilot Studio features), Power Pages, Dynamics 365 Premium, Enterprise, Team Members and Dynamics 365 Customer Insights. Pay-as-you-go meters for Power Apps per app, Power Pages and Copilot Studio also qualify.

Three details are worth pulling out because they are the ones that get missed.

One premium licence covers both apps and flows for that user. A user running an app and a cloud flow in a managed environment does not need both Power Apps Premium and Power Automate Premium. Either satisfies the requirement.

Dynamics 365 Enterprise licences carry premium rights, and the qualifying list is long: Sales Enterprise and Premium, Customer Service Enterprise and Premium, Field Service, Finance, Finance Premium, Supply Chain Management and Premium, Project Operations, Commerce, Human Resources, Business Central, Team Members and Intelligent Order Management. If your estate already runs Dynamics, a meaningful share of your users may already be covered by something you bought for another reason entirely.

The Developer Plan does not include the entitlement. Developers running their own assets in a managed environment are not licensed by it. That is the one that catches technical teams.

There is a trap in the pay-as-you-go route as well. The Power Apps per app meter satisfies Power Apps usage in the environment, but it covers Power Apps only. Any Power Automate flow usage still needs standalone Power Automate licences or per-flow plans. An estate that moved to the per-app meter thinking it was comprehensive will find the flows uncovered.

The report that tells you the size of it

There is a purpose-built report, and most administrators do not know it exists.

In the Power Platform admin centre: Licensing, then Power Apps, then the Summary tab, then Download report. Choose Users requiring licenses in Managed Environments and a lookback month.

Read its caveats before you act on the number, because they all push in the same direction, which is that the report understates your exposure:

  • It lists only users who launched at least one app in a managed environment during the selected month.
  • Anyone who did not launch an app that month is excluded entirely.
  • A user who has since been assigned a licence keeps appearing until they next launch an app.

So a quiet month produces a small number, and a quarterly process is more honest than a monthly snapshot. Pull several months and take the union, not the latest.

This is the second deadline this quarter

Worth putting the two together, because they land on the same estates and the same people.

The AI Builder seeded credits disappear on 1 November 2026, and the managed environments licence check is running now. Both are Microsoft closing the gap between what organisations were entitled to and what they were actually consuming. Neither is a price rise. Both are enforcement of terms that already applied.

The common factor is that in both cases the consumption was invisible, so nobody managed it. Credits that arrived bundled with a licence got spent by flows nobody owned. Managed environments got enabled for the governance features and the licensing implication went unexamined.

That pairing is worth holding onto, because it says something about how Power Platform managed environments tend to get adopted. Nobody turns them on for the licensing.

They get enabled for the capability set, and it is a genuinely strong one: environment groups, sharing limits, weekly usage insights, data policies, pipelines, solution checker, IP firewall and cookie binding, customer-managed keys, Lockbox, extended backup, virtual network support, conditional access on individual apps, and data masking rules. Every one of those is a good reason. The entitlement requirement travels along quietly with the decision.

Eighteen months later the estate has grown, the person who enabled it has moved on, and the first anyone hears about the requirement is a notification inside an app.

Trial licences are worth a specific warning here. They do license users in Power Platform managed environments, but only for thirty days, so an estate that looks compliant during a pilot can fall out of compliance the month afterwards without anything appearing to change.

Our position: not on by default, but the enforcement is right

Two things that sound contradictory and are not.

Managed environments should not be on by default. Blanket enforcement operates as a penalty on the mature IT teams already running clean, well-governed environments, and it hands Microsoft a seamless upsell mechanism. A team that did the work properly gets the same bill as a team that never looked.

And yet the enforcement itself is a necessary long-term good. Across the estate as a whole, it forces organisations to confront their actual technical debt and risk exposure rather than sheltering behind passive compliance gaps. The requirement was always there. What changed is that it is no longer possible to not know.

Those two positions sit together because the objection is to the default, not to the direction. Switch it on deliberately, with a plan, and it is one of the better things you can do to an estate. Have it switched on for you, and it is a bill.

What to do in the next fortnight

The work is small and the sequence matters.

Pull the report for the last three months, not one, and take the union of users. That is your real exposure rather than the flattering version.

Cross-reference against Dynamics entitlements before buying anything. Given how many Dynamics 365 Enterprise licences carry premium Power Platform rights, some proportion of the list is likely already covered. Buying Power Apps Premium for a user who holds Dynamics 365 Finance is money spent to solve a problem that does not exist.

Check your flows separately if you use the per-app meter. The meter does not cover Power Automate, and flow usage is easy to overlook because nobody launches a flow the way they launch an app.

Turn on the auto-claim policy in the Microsoft 365 admin centre if you have licence capacity in the tenant, so active users are assigned automatically rather than through a ticket each time.

Then decide what should not be licensed at all. Some of the apps generating these notifications will be things that ran for years without an owner. A licence is one answer. Decommissioning is the other, and for a proof of concept that never ended it is usually the right one.

On the size of the gap, we do not publish a figure because we do not hold one we would stand behind. What we can say is the shape of it: in almost every client review, the discrepancy between the expected number of unlicensed users and the actual number spans multiple entire teams. Not a handful of individuals who slipped through, but whole functions nobody had counted.

Which is why the three-month union matters more than the arithmetic. If your estimate is out by a team, it is out by a team in the report as well.

Where to start

Run the report. It takes ten minutes and it is the only way to know whether this is an administrative tidy-up or a budget conversation.

If the number is small, assign the licences and move on. If it is large, the useful question is not how quickly you can buy your way out of it, but how an estate ended up with that many users on apps nobody had budgeted for.

Veratas runs Power Platform governance and licensing reviews, and for estates we run under managed services, this check is already scheduled.

If your users are seeing licence notifications and nobody can tell you how many are affected, talk to our team. That answer exists in a report, and it takes an afternoon to act on.

Frequently asked questions

When did managed environments licence notifications start? End-user in-app notifications began in June 2026. Administrators received advance notice through the Microsoft 365 Message centre and the Power Platform admin centre from March 2026, with further admin notifications after April.

Is this a new licensing requirement? No. Microsoft is explicit that the requirement is not new: activating managed environments always required every active user to hold a premium licence or capacity add-on. The notifications are what changed.

What happens if a user ignores the notification? It escalates from informational to warning after seven days, then to an error state after a further seven, and remains there until an appropriate licence is assigned.

Which licences satisfy the requirement? Power Apps Premium, Power Automate Premium, Copilot Studio, Power Pages, Dynamics 365 Premium, Enterprise, Team Members and Customer Insights, plus pay-as-you-go meters for Power Apps per app, Power Pages and Copilot Studio. One premium licence covers both apps and flows for the same user.

Does the Power Apps per app meter cover flows? No. It satisfies Power Apps usage only. Power Automate flow usage still needs standalone Power Automate licences or per-flow plans.

How do I find out who is affected? Download the “Users requiring licenses in Managed Environments” report from the Power Platform admin centre under Licensing, Power Apps, Summary. Pull several months rather than one, because it only counts users who launched an app during the month you select.