How to Remove Directly Assigned Office 365 E3 Licenses After Group-Based E5 Assignment?

Create, configure, and manage Microsoft Entra identities
Answer Correct answer: C — use Set-MgUserLicense with -RemoveLicenses to strip the directly assigned Office 365 E3 licenses from every user in one automated pass.

You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users. From the Groups blade in the Microsoft Entra admin center, you assign Microsoft Office 365 Enterprise E5 licenses to a group that includes all users. You need to remove the Office 365 Enterprise E3 licenses from the users by using the least amount of administrative effort. What should you use?

  1. the Set-WindowsProductKey cmdlet
  2. the Update-MgGroup cmdlet
  3. the Set-MgUserLicense cmdlet Correct Answer
  4. the Update-MgUser cmdlet

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you know that only Set-MgUserLicense can remove a license SKU from a user — the trap is assuming that assigning E5 via a group, or updating the group or user object, automatically clears the leftover direct E3 assignment.

This SC-300 scenario asks how to strip individually assigned Office 365 E3 licenses from 2,500 users after E5 was granted through group-based licensing, using the least administrative effort. It establishes that Set-MgUserLicense (C) is the cmdlet that removes per-user license SKUs, because a group assignment never deletes a license a user already holds directly.

Picking Update-MgUser (D) because it sounds like 'updating the user's licenses'; Update-MgUser edits profile attributes such as department or usage location and is not the cmdlet used to remove license SKU assignments.

Community Discussion (3 comments)

dzdz 👍 5 Selected: C
C. the Set-MgUserLicense cmdlet To remove the Office 365 Enterprise E3 licenses from the users who are now part of a group with Office 365 Enterprise E5 licenses assigned, you should use the Set-MgUserLicense cmdlet. This cmdlet allows you to modify the licenses assigned to a user. By using this cmdlet, you can remove the Office 365 Enterprise E3 licenses from all users who are part of the group where you assigned the Office 365 Enterprise E5 licenses.
Trader6 👍 3 Selected: C
https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.users.actions/set-mguserlicense?view=graph-powershell-1.0
klayytech 👍 3 Selected: C
C. the Set-MgUserLicense cmdlet

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Set-MgUserLicense is the Microsoft Graph PowerShell cmdlet that wraps the Graph assignLicense action for a user, and its -RemoveLicenses parameter accepts the SKU IDs to take away — exactly what is needed to drop the directly assigned Office 365 E3 license. Group-based licensing is additive: joining the E5 group grants E5 but leaves the existing direct E3 assignment untouched, so the direct assignment must be removed separately. Because the cmdlet targets one user at a time, you enumerate the 2,500 users (for example Get-MgUser -All) and pipeline them into Set-MgUserLicense -RemoveLicenses <E3 skuId> -AddLicenses @, which is a single automated pass rather than thousands of portal clicks. That scripted, single-command approach is why it satisfies "least amount of administrative effort" among the listed options.

Why the Other Options Are Wrong

Option A, Set-WindowsProductKey, is a Windows activation cmdlet that sets a product key on an operating system; it has no relationship to Microsoft 365 service-plan licensing. Option B, Update-MgGroup, modifies group properties, membership, or the licenses assigned to the group — but the group already carries the E5 assignment, and changing or re-updating that group cannot reach the E3 licenses that sit on each user object individually. Option D, Update-MgUser, changes user profile properties and is not the supported path for removing license SKUs, so it would leave the E3 assignments in place. Only Set-MgUserLicense exposes the -RemoveLicenses parameter that deletes a specific SKU from a user.

Community Comment Notes

Every learner in the thread landed on the same option, with dzdz explaining that "this cmdlet allows you to modify the licenses assigned to a user" and that it can remove the E3 licenses from users "who are now part of a group with Office 365 Enterprise E5 licenses." Trader6 reinforced this by pasting the official Microsoft Learn page for the cmdlet, and klayytech simply recorded C. There is no dissent in the comment set, and the vote tally is unanimous, so the community position and the vendor documentation agree with the verdict on this page.

Official Reference

Exam Strategy

When a scenario says "least administrative effort" about license changes, hunt for the cmdlet that manipulates license SKUs directly rather than one that edits a group or user profile. Also remember the licensing doctrine Microsoft repeats in its docs: group-based licensing adds licenses but never removes a license a user already has through a direct assignment.

Frequently Asked Questions

Why doesn't assigning E5 through the group automatically remove the E3 licenses?

Group-based licensing is additive: the group grants E5, but a license a user already holds through a direct assignment stays until someone removes that SKU explicitly.

Can Update-MgUser remove the Office 365 E3 license instead?

No. Update-MgUser edits profile attributes; license SKU removal requires Set-MgUserLicense's -RemoveLicenses parameter against the E3 service plan ID.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide