Most organisations pay for Microsoft licences nobody uses. A 3-5 day audit shows you exactly which ones, and what to do before renewal.
We compare every assigned licence against real usage data from your own tenant: leavers still licensed, duplicate assignments, premium plans used only for mail, add-ons that duplicate a bundled feature. Fully remote, reporting access only, no downtime. Across typical Indian tenants, 10-30% of licence spend is commonly recoverable or re-deployable.
- 3-5 daysTypical audit duration
- 10-30%Of licence spend commonly recoverable
- 100%Remote, reporting access only
- ZeroDowntime or user impact
Nine places where licence waste hides in a Microsoft tenant.
Assigned vs active licences
Every licence assignment reconciled against sign-in and activity data. Licences attached to accounts that are blocked, dormant, or have never signed in are the fastest finding and the least contentious, because nobody defends paying for an account that does not log in.
Duplicate and orphaned assignments
Users holding two overlapping licences after a plan change, shared mailboxes that were licensed when they no longer need to be, and service accounts carrying full user bundles. These accumulate quietly after every migration and every plan switch, and no report flags them by default.
Leavers still licensed
Disabling an account in the directory does not release its licence. Where exit processing stops at "disable and forward the mailbox", licences stay assigned for months or years. We reconcile assignment against account status and last activity so every leaver licence is identified for release or archival conversion.
Plan-level right-sizing
Users on premium plans who use only mail and files do not need the premium plan. We measure which services inside each bundle are actually used per user, so the population that genuinely needs the higher tier is separated from the population that inherited it when everyone was standardised.
Add-on overlap
The most commonly missed finding: a standalone add-on purchased for a capability that a bundle already includes. Audio conferencing, advanced threat protection, and storage add-ons frequently duplicate what the assigned suite already carries. The overlap is invisible unless someone maps add-ons against bundle contents.
E-plan vs Business-plan fit
Business plans carry a seat cap; enterprise plans do not, and the feature sets differ in specific, checkable ways. Organisations near the cap often move everyone to E-plans when a mixed assignment would serve. We model which population needs which tier against the features each actually uses.
Inactive service usage
A bundle where the collaboration, telephony, or analytics workloads have near-zero adoption is either an adoption problem or an over-specification problem. The usage data tells you which, per workload, so the decision to train users up or step the plan down is made on evidence rather than assumption.
True-up and compliance exposure
The audit runs the other direction too. Where headcount grew faster than licence counts, or a feature is configured that the assigned plan does not include, that gap surfaces at true-up or at a vendor review, on someone else's schedule. Finding it yourself first is always the cheaper route.
Renewal timing and terms
When your agreement or CSP term renews, what the notice periods are, and whether reductions are permitted at anniversary or only at term end. The audit is timed to land its findings before that date, because a right-sizing plan delivered after renewal waits a full cycle to pay back.
Why 10-30% of licence spend is commonly recoverable.
The waste is not one big mistake. It is the compound of many small, reasonable decisions that were never revisited: licences follow joiners reliably because someone is waiting for access, and follow leavers unreliably because nobody is.
- After two to three years of staff turnover without licence-aware exit processing, the gap between assigned and active seats alone typically reaches a meaningful share of the estate.
- Standardising everyone on one premium tier is administratively simple and commercially generous. Usage data almost always shows a population that needs a fraction of the bundle.
- Add-ons bought during projects rarely get reviewed when plans change underneath them, so the same capability ends up paid for twice.
- None of this needs new tooling to find. It needs someone to run the reconciliation, workload by workload, and put the findings in front of the person who signs the renewal.
Four things this audit does that a seat count does not.
Evidence, not opinion
Every finding is tied to a tenant report you can re-run yourself: the account list, the per-service usage data, the assignment export. Nothing in the deliverable rests on our say-so, which is exactly what makes it usable in a renewal negotiation.
Per-workload usage, not per-bundle counts
The question is never "is the licence used" but "which parts of it are used". We measure activity per service over a representative period, so a right-sizing recommendation is made per population with the data attached, never as a blanket downgrade.
Both directions, stated plainly
Over-licensing is the comfortable finding. If the data shows under-licensing or a configured feature the plan does not cover, we state it plainly and sequence the correction, because knowing before a true-up or vendor review is the entire point of auditing yourself.
The process fix, not just the snapshot
A cleaned-up tenant drifts back within one joiner-leaver cycle if nothing changes. Every engagement ships the process correction: licence release inside exit processing, assignment through approval, and a quarterly reconciliation your own team can run in an hour.
Three deliverables, each written to be acted on.
Licence utilisation report
The evidence base. Every assigned licence mapped against activity, per user and per workload, over a representative period.
- Assigned vs active reconciliation with account status
- Per-workload usage for every bundle in the tenant
- Duplicate, orphaned, and leaver assignments listed by account
- Add-on overlap mapped against bundle entitlements
- Waste expressed as a percentage of current licence count and spend
Right-sizing plan
The action list. Which licences to release, which to downgrade, which to keep, and in what order, with the risk noted per step.
- Recommended assignment per user population, with rationale
- Reclaim-first sequencing so nothing is downgraded before it is measured
- Mailbox and data handling steps for leaver licence release
- E-plan vs Business-plan recommendation where the fit question is open
- A process fix for joiners and leavers so the position holds
Renewal negotiation preparation
The commercial half. What to ask your CSP partner or Microsoft for at renewal, backed by your own usage evidence.
- Target licence counts per SKU for the next term
- Term and billing-frequency options that fit your reduction plan
- Questions to put to your current partner, in writing
- GST invoicing consolidation options where purchases are scattered
- A timeline working back from your renewal date
Six situations where the audit pays for itself quickly.
Finance leaders ahead of a renewal
The renewal conversation is far stronger with usage evidence than with last year's count plus growth. A CFO who walks in knowing exactly which share of the estate is unused negotiates a different agreement from one who accepts the proposed quantities.
Companies that grew fast, then reduced
Hiring waves add licences instantly because someone is waiting for access. Reductions rarely remove them, because nobody is. After a restructuring or layoff cycle, the gap between assigned seats and working staff is usually the single largest finding in the audit.
Mergers running two tenants
Two tenants means two agreements, duplicate assignments for anyone who exists in both, and two sets of add-ons bought independently. The audit maps the combined estate before consolidation, so the merged agreement is sized to the real population rather than the sum of two padded ones.
Teams unsure what their E-plan includes
Organisations frequently buy standalone security, compliance, or telephony products that their enterprise bundle already carries, simply because nobody mapped the bundle contents. If you cannot say precisely what your current plan includes, you are very likely paying for something twice.
CSP transfer candidates
Companies buying direct, or through a partner that only forwards invoices, often gain flexibility by moving to a CSP partner: monthly or annual terms per SKU, consolidated GST invoicing through one partner, and licence changes handled as a service. The audit establishes the right counts before any transfer.
Purchases scattered across partners
Different departments buying through different resellers produces overlapping subscriptions, inconsistent terms, and GST invoices that finance reconciles by hand every month. Consolidating through one partner starts with knowing exactly what is held where, which is what the audit inventory provides.
What right-sizing changes, in descriptors and percentages.
| Feature | Before the audit Typical unmanaged tenant | After right-sizing Evidence-based assignment |
|---|---|---|
Unused and leaver licences Licences on blocked, dormant, or departed accounts. | Commonly 10-30% of the estate | Released or reassigned to new joiners |
Premium plan fit Share of premium-tier users who use the premium workloads. | Assigned by default, unmeasured | Assigned per population, measured per workload |
Add-on overlap | Unknown, nobody has mapped it | Zero, mapped against bundle contents |
Leaver licence release | Manual, often skipped | Built into exit processing |
Renewal position | Last year's count plus growth | Usage-evidenced counts per SKU |
True-up surprises | Possible, found on the vendor's schedule | Unlikely, checked on yours |
Invoice consolidation | Multiple partners, scattered GST invoices | One partner, one consolidated invoice |
Ongoing drift | Rebuilds within a year | Quarterly reconciliation, one hour per run |
Five waste patterns, and how each is found.
| Pattern | How it happens | How the audit finds it | |
|---|---|---|---|
| Leaver licences | Exit processing disables the account but never releases the licence | Assignment reconciled against account status and last-activity date | |
| Duplicate assignments | Plan migrations and group-based assignment leave the old licence behind | Per-user assignment list checked for overlapping SKUs and service plans | |
| Over-specified plans | Everyone standardised on the premium tier during a past project | Per-workload usage separates the population that needs the tier from the one that inherited it | |
| Add-on overlap | A standalone add-on bought for a capability the bundle later included | Add-on inventory mapped against the service plans inside each assigned bundle | |
| Silent under-licensing | Headcount or configured features grew faster than the agreement | Configured capabilities and active headcount checked against entitlements held |
Fully remote, 3-5 days, reporting access only.
- 1
Kick-off and access
Day 1
A 30-minute call to confirm scope, your renewal date, and the questions you want answered. You grant a read-only reporting role, never Global Administrator, and share your agreement or CSP invoices so findings reconcile against what you actually pay.
- 2
Data collection
Days 1-2
We export licence assignments, account status, sign-in activity, and per-service usage over a representative period. Collection is pure reporting: zero configuration changes, zero load on users, and your admin team does not need to be involved beyond the access grant.
- 3
Analysis and right-sizing model
Days 2-4
Assignments reconciled against activity, bundles decomposed into workloads, add-ons mapped against bundle contents, and populations modelled against the plans that fit them. Anything ambiguous is flagged as a question rather than guessed, and checked with you before the report is final.
- 4
Read-out and renewal preparation
Day 5
A working session with IT and finance together: the utilisation report, the right-sizing plan in execution order, and the renewal preparation pack. You leave knowing exactly which licences to release, which to downgrade, and what to ask your partner for, with evidence attached to each line.
Microsoft licence audit, the questions that decide it.
What we need from you, and what we never need.
What we need
- Reporting access to the tenantA read-only reporting role. Not Global Administrator.
- Your agreement or CSP invoicesSo findings reconcile against what you actually pay for.
- Your renewal dateThe plan is sequenced to land before it.
- A 30-minute kick-off callScope, access, and the questions you want answered.
What we never need
- Admin write accessWe change nothing during the audit. Findings are yours to action.
- Access to mailbox or file contentsUsage reports show activity volumes, not content.
- Downtime or a change windowReporting queries have zero impact on users.
- A long engagementTypical tenants complete in 3-5 days.
The pages around this one.
Microsoft 365 Security Audit India
The security counterpart to this audit: identity, device, and data protection posture across the same tenant, with a prioritised remediation plan.
Learn moreCybersecurity Audit & Compliance
The wider audit practice: independent security audits, penetration testing, and compliance gap analysis against recognised frameworks.
Learn moreManaged IT Services India
Ongoing licence administration as part of full IT operations: joiner-leaver handling, quarterly reconciliation, and renewal preparation every cycle.
Learn moreStart with one number: licences assigned to accounts that no longer sign in.
Book the audit and we establish that number in the first two days, from your own tenant data. Three-minute form, first reply within 4 business hours, and the full report lands within a week of access.
Related Services
Explore more solutions that work great with this service