Jackie Ramsey September 9, 2026 0

A shared workstation can expose weak licensing, identity and access, and endpoint controls faster than a quarterly security review. Advanced licensing adds powerful capabilities, but it doesn’t change the discipline required to manage Office on shared PCs, RDS hosts, or VDI.

For IT leaders, the question isn’t whether a higher tier has more features than the current plan. The question is whether its added governance and control capabilities solve a business problem that your current licensing and operating model can’t handle.

I start every review with users, devices, data flows, and financial exposure, then test whether the proposed license supports the operating model.

Key Takeaways

  • Microsoft 365 E7 pricing isn’t publicly confirmed here. A current Microsoft source must verify the SKU, effective date, price, and status as generally available before you use the $99 per user per month figure. Treat May 1, 2026 as unverified until then. Licensing covers only the subscription; Azure compute, model consumption, and message consumption are billed separately.
  • The Frontier Suite is described as combining Microsoft 365 E5, Microsoft 365 Copilot, Microsoft Entra Suite, and Agent 365, subject to confirmation on the current Microsoft product page or announcement. That component serves as a governance and control plane for AI agents, not an agent runtime, development environment, or agent-building tool.
  • Shared Computer Activation may be available as an E5-based Microsoft 365 Apps capability when current Microsoft documentation and the customer agreement support that entitlement. E7 may inherit it because it includes E5, but E7-specific SCA documentation may be absent, so don’t treat the right as guaranteed.
  • A useful review produces a seat model, shared-device inventory, policy gap register, risk-ranked roadmap, and licensing recommendation.

What Microsoft 365 E7 Adds Beyond E5

Microsoft presents the Frontier Suite as a commercial offer for organizations moving toward human-led, agent-operated work. It changes both the commercial discussion and the operational workload. Its exact components should be confirmed against current Microsoft licensing documentation.

The license bundle and its operating impact

Microsoft 365 E5 remains the base layer for productivity, security and compliance, and endpoint management. Microsoft 365 Copilot provides the AI layer, while Entra Suite can strengthen identity capabilities. Check current licensing documentation before treating those names as a fixed bundle.

The identity layer can strengthen identity and access, including identity governance, when employees, contractors, shared devices, and external users touch the same cloud services. In a hybrid identity environment, I review Microsoft Entra Connect health, privileged accounts, Conditional Access coverage, guest access, and break-glass accounts before recommending a broader license change.

For many organizations, this Digital Transformation purchase supports a Frontier Transformation only when agentic AI and AI agents address measurable needs. That phrase is a business framing, not necessarily an official SKU or entitlement name. Microsoft’s published intelligence and trust positioning still needs operating evidence, or E5 may remain the better fit.

Blue panels link shared computers with identity and cloud controls.

Agent 365 is governance, not an AI runtime

Microsoft’s Agent 365 overview is clear about that role: it is a control plane for agents operating across the organization.

That distinction prevents a costly planning mistake. It doesn’t replace Copilot Studio, Azure AI services, model hosting, orchestration, or an application runtime. It helps operators observe, secure, inventory, and govern agents across the organization.

Microsoft currently lists the service as generally available, but I’d confirm whether the claimed package includes it. I’d also validate standalone eligibility, pricing, and commercial terms before using the $15 per user per month figure for budgeting.

Shared Computer Activation Under Microsoft 365 E7

Shared Computer Activation, often called SCA, supports Microsoft 365 Apps on a computer used by several licensed people. It is common in branch offices, call centers, dispatch desks, clinical work areas, retail back offices, and virtual desktop environments.

Why E5 is the licensing foundation

Microsoft’s Shared Computer Activation guidance identifies Microsoft 365 E5 as an eligible plan because it includes Microsoft 365 Apps for enterprise. Each person signs in with their own account, and the device doesn’t consume a separate Office license because multiple people use it.

The suite includes E5 rights, so SCA may inherit through those rights. I document that conclusion as an inheritance assessment, not a separately documented entitlement. Confirm it against current product terms with licensing stakeholders, then validate it in the tenant.

That distinction matters during renewals. Your licensing record should show that every person using the shared computer has an eligible assigned license. A device count isn’t a substitute for this user-based licensing model.

Device controls matter as much as activation

SCA solves Office activation. It doesn’t secure the endpoint, control session data, prevent data leakage, or stop users from accessing material beyond their job role.

A sound review checks these items:

  • Shared PCs have clear ownership, supported Windows versions, patching, endpoint detection, and device hardening standards.
  • Users authenticate with named accounts, MFA, and Conditional Access policies that match the device’s risk profile. Identity and access controls should apply Zero Trust through device health, least privilege, and session isolation.
  • OneDrive sync, browser profiles, cached credentials, Teams sign-in, and local downloads have rules that fit shared use.
  • RDS and VDI hosts use the correct Office deployment configuration and retain enough profile capacity for activation tokens.

Microsoft identifies SCA as the preferred configuration for RDS and VDI. Its troubleshooting guidance is also useful when activation failures appear after profile, network, or token changes.

A successful Office activation doesn’t prove a shared device is safe. The real test is whether the next user can access only their own session, files, tokens, and applications.

What an E7 Shared-Device Review Assesses

A licensing conversation without an operational assessment often produces shelfware. I treat the review as an Infrastructure Optimization engagement that connects licensing, security controls, cloud operations, and workforce patterns.

The technical assessment scope

First, I identify every shared workstation, RDS host, VDI pool, kiosk, and nonpersistent desktop. Then I map each device to its users, installed Microsoft 365 Apps channel, management platform, local admin model, profile technology, and network dependency. I use those roles and requirements to select the appropriate licensing tier, rather than assigning premium licenses broadly.

The review also examines Endpoint Security, Defender coverage, patch compliance, encryption, USB controls, browser configuration, and local data persistence. It tests device trust, identity verification, least privilege, and session controls against a Zero Trust model, protecting uptime and confidential information. Where relevant, I assess the separate Intune Suite add-on for management and endpoint capabilities.

For organizations with multiple sites, I include Cloud Infrastructure dependencies, WAN stability, wireless coverage, and Data Center Technology that still supports identity or line-of-business applications. This matters at enterprise scale, where weak network design can mimic an identity or profile failure and disrupt shared activation.

The deliverables your team should receive

At the end, your team should have a current-state report that separates licensing defects from configuration defects. It should include a shared-device inventory, an E3, E5, and E7 seat model, named user groups, and accounts that shouldn’t receive premium licensing. If Agent 365 is in scope, deliverables should also include an agent inventory, ownership register, data-access review, and policy-control assessment.

Your team should also receive a policy gap register, risk-ranked roadmap, and licensing recommendation.

I also deliver a risk register with business consequences. It covers identity governance, including privileged accounts, guest access, entitlement reviews, and ownership of access policies. Excessive guest permissions can lead to data leakage, while incomplete audit retention can complicate an audit finding. Unmanaged endpoints can raise cyber-insurance renewal questions, and poorly protected shared devices can create downtime and productivity loss at the worst possible time.

This approach combines Technology Consulting with practical Cybersecurity Services to strengthen governance and security. It gives executives a decision document, not a feature inventory.

Building the E7 Business Case

The right comparison depends on your starting position. Compare Microsoft 365 E7 with Microsoft 365 E3 to test the full cost of moving to an advanced security, identity, Copilot, and agent-governance stack. Compare the proposed bundle with Microsoft 365 E5 to isolate the added value of Microsoft 365 Copilot, Entra Suite, and Agent 365. Finally, compare Microsoft 365 E5 plus Copilot under a standalone license to isolate the premium for enhanced identity and agent governance.

Count people, not only devices

Shared devices can make a small deployment look cheap because one computer supports several shifts. Yet the proposed bundle remains a per-user license. The licensing model should follow active identities, role requirements, seasonal workers, contractors, service accounts, frontline users, and data access, not PC count. The right licensing tier may be E3, E5, E7, or another fit-for-purpose option.

A restaurant group is a useful example. Restaurant POS Support and Kitchen Technology Solutions may depend on shared back-office workstations, but cashiers and kitchen staff don’t automatically need the proposed bundle. The licensing decision should follow their Microsoft 365 use, data access, and agent exposure.

Technical dashboard comparing enterprise licenses, costs, endpoints, and shared-device policies.

Separate license cost from AI consumption

The proposed bundle’s per user per month charge covers licensing only; Azure compute, model, and message consumption are billed separately. Those variable costs belong in the financial model before an AI pilot becomes a broad deployment.

I recommend assigning the proposed bundle to a defined group first: security administrators, daily Copilot users, approved agent operators, and high-risk data owners. The pilot tests the copilot and agents workstream. It validates enterprise AI governance, adoption, support demand, data boundaries, and measurable business outcomes before you deploy enterprise AI broadly.

For a commercial tenant handling Controlled Unclassified Information, the review must also address cloud eligibility. The offer doesn’t turn commercial Microsoft 365 into GCC High. A defense contractor should confirm its DFARS, CMMC, data residency, and US-person access obligations before treating any commercial bundle as a secure cloud architecture for CUI.

When This Engagement Isn’t Worth It

An E7 review isn’t worth the investment when there are no approved AI use cases or agent inventory. It also isn’t justified when there’s no intent to deploy Copilot beyond a small test group. In that situation, an E5 optimization review and targeted pilot will produce a cleaner decision.

It may not fit an organization still struggling with MFA adoption, unmanaged endpoints, unsupported devices, or basic incident response. Fix those foundations first. Managed IT for Small Business, IT Strategy for SMBs, and Tailored Technology Services should match the actual maturity of the environment.

However, the engagement has clear value when license renewals are approaching, departments are building agents without governance, or cyber-insurance questions expose gaps in Business Continuity & Security. A capable Business Technology Partner can align licensing, Cloud Management, and policy ownership with the operating plan.

Frequently Asked Questions

Does Microsoft 365 E7 include Shared Computer Activation?

The bundle includes E5, but that doesn’t automatically establish separate Shared Computer Activation eligibility. Microsoft documents SCA eligibility through Microsoft 365 Apps for enterprise, including eligible E5 plans. There is no separate guidance for this bundle, so validate the agreement and tenant configuration before deployment.

What does Agent 365 do for IT operators?

Agent 365 is a governance and control plane for observing ownership, data access, policy alignment, and operational risk across AI agents. It focuses on oversight rather than execution or agent development.

Should every employee move to the higher-tier plan?

Usually, no. Use a role-based licensing model. Assign the plan based on Copilot needs, advanced identity requirements, approved agent responsibilities, data sensitivity, and actual job duties. Others may remain on E3, E5, or another license that fits their work.

A Better Licensing Decision Starts With the Operating Model

Microsoft 365 E7 can be a strong package when E5 security, Microsoft 365 Copilot, and Entra Suite controls matter. Governed AI agents add value when enterprise AI meets a defined operating need, not a generic transformation goal. Shared Computer Activation remains a user-license and device-configuration discipline, even under the new bundle.

I recommend a low-pressure readiness assessment or licensing review before assigning E7 broadly. You should leave with a defensible seat model, a shared-device remediation plan, and a clear decision about whether the offer solves a current business problem.


Discover more from Guide to Technology

Subscribe to get the latest posts sent to your email.

Category: 

Leave a Reply