As long as they have the perms, they can direct assign.
You could always create a scheduled task that removes any direct assignment:
More:
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
We use group-based M365 licensing rather than assigning directly to users, but occasionally an IT admin will incorrectly assign directly to the user. Is it possible to block the ability to directly assign to a user while allowing license assignment to a security group? Thanks.
As long as they have the perms, they can direct assign.
You could always create a scheduled task that removes any direct assignment:
More: