Disabling Office 365 License Management in the Work 365 Self-Service Portal
Applies to: Work 365 Self-Service Portal, Azure Active Directory
Audience: Administrators, IT Teams
Overview
The Work 365 Self-Service Portal allows end-users to manage Office 365 licenses through an application configured in Azure Active Directory (Azure AD). If you wish to disable this functionality, follow the steps outlined below.
Procedure
1. Access Azure Active Directory
✅ Log in to the Azure Portal using your Global Administrator account.
✅ Click on the Azure Active Directory icon within the Azure Services section.
✅ If you don’t see the Azure Active Directory icon, click on More Services to locate it.
2. Locate the Application
✅ Open the application you initially created to enable Azure AD authentication for the portal.
✅ The application is typically named "Dynamics 365 Portals Customer Login", following the naming convention in the Azure AD integration article.
3. Modify Authentication Settings
✅ Click on the Authentication menu in the left-hand navigation.
✅ On the right-hand pane, identify and delete all URL records with the following formats by clicking the bin icon next to each:
[PORTAL URL]/managelicenses [PORTAL URL]/licenses [PORTAL URL]/[LANG]/licenses
✅ Ensure the checkboxes for Access tokens and ID tokens remain checked.
✅ Click Save.
4. Adjust API Permissions
✅ Click on API Permissions in the left-hand navigation.
✅ On the right-hand pane, locate the permission labeled Directory.ReadWrite.All.
✅ Click the ellipsis (...) next to this permission and select Remove permission.
✅ Confirm the removal by clicking Yes, Remove when prompted.
Conclusion
By following these steps, you have successfully disabled Office 365 license management in your Work 365 Self-Service Portal. This action prevents end-users from managing Office 365 licenses through the portal.