Skip to main content

Licensing and configuration prerequisites

Specific requirements when applying policies

D
Written by David McCandless

Overe Protect policies safeguard your tenant's security posture by enforcing best practices to maintain a secure and healthy environment.


Because policy controls impact various Microsoft systems, certain requirements may arise during their evaluation. If a control cannot be evaluated, the interface will indicate the reason, which will fall into one of two categories:

Missing Microsoft Licenses

Some of Overe's Policy Controls require integration with Microsoft Conditional Access Policies, which are available with specific Microsoft Entra ID plans. Others may depend on features included in higher-tier licenses.

The interface will identify controls that cannot be evaluated due to a missing license and will specify the required Microsoft product.

If you don’t intend to acquire the missing license, you can prevent Overe from flagging this issue or generating errors in policy evaluation by disabling the specific control that requires it.

Pending Configuration Actions

Beyond having the appropriate licenses to evaluate all policy controls, some controls may also require specific tenant configurations. These are general settings that Overe does not enforce automatically, as doing so would require maintaining elevated access permissions solely for these tasks. Additionally, these configurations may be subjective, leaving it up to the tenant administrator to decide whether they should be applied.

The potential system configuration prerequisites include:

  • Assigning Entra roles to the Overe app

    Overe requires the following two roles to operate:

    • Exchange Administrator: This role is necessary to enable email security-related controls.

    • Teams Administrator: This role is necessary to enable Microsoft Teams security-related controls.

    Learn how to grant these roles in the following video:

    Note: Overe checks for this configuration periodically, but it may take a few minutes before the next check occurs. To force an immediate check, you can manually trigger an integration sync.

  • Disabling Security Defaults

    Microsoft Security Defaults provide baseline protections against identity-related threats. However, they are incompatible with Conditional Access Policies, which Overe relies on for enforcing advanced policy controls. While Overe can still function with Security Defaults enabled, some Policy Controls may fail as a result.

Overe recommends following the suggested configuration to ensure full access to all available Policy Controls. However, similar to licensing requirements, if you choose not to adopt a required configuration, you can disable the conflicting controls to prevent inaccurate evaluations and error messages.

Per-user licensing when policies are applied

The two categories above describe controls Overe cannot evaluate. There is a third case worth understanding: controls that apply successfully but carry a per-user licensing obligation.

Conditional Access is the main example. Entra applies a Conditional Access policy to any user in its scope, whether or not that user holds a licence that includes Conditional Access. Overe does not override this behaviour, and Microsoft does not block it. The obligation to license every targeted user sits with the tenant.

If your tenant contains a mix of licence types, scope policies to the licensed population and exclude the rest. Overe surfaces licence information per user to help you do this. See Which Microsoft Licenses does Overe require? for the per-user requirements, and Third-party licensing and policy scope for where this responsibility sits.

Did this answer your question?