SV-007

Microsoft Licence and Subscription Optimisation

Microsoft-specific optimisation across Microsoft 365, Entra ID and the hybrid on-premises estate — service-plan activation, duplicate and overlapping assignment, mover and leaver recovery, SQL and Windows Server, and Azure Hybrid Benefit.

Software Value 16 min read 11-stage operating workflow Illustrative — outcomes not guaranteed
At a glance
Challenge
Microsoft licensing waste hides inside the tenant — inactive licences, duplicate assignments, SKU overlap and leavers who never lost their subscription.
Approach
Correlate tenant subscription data with Entra ID identity and service-plan activity, then rightsize, reclaim and model the renewal from validated demand.
Primary KPI
% of Microsoft licences aligned to a validated user or workload requirement.
Impact
Wastage removed at source, identity lifecycle wired to licence recovery, and a renewal baseline built from evidence.
01

Executive Summary

Microsoft licensing waste is rarely dramatic. It accumulates: a user who moved from a field role to a desk role and kept both an F3 and an E3; a project team given E5 for a compliance feature that was never configured; a leaver whose account was disabled but whose licence was never removed because disablement and licence release are two different processes owned by two different teams. Individually trivial, collectively material.

This playbook goes deeper into Microsoft-specific constructs than the general SaaS governance playbook. The distinction that matters most is between a licence being assigned and a service plan being used. A user can hold E5 and use nothing beyond Exchange and Teams; the tenant reports a fully assigned licence, and the E5 premium is pure waste. Service-plan-level activity analysis is where the real optimisation sits.

It also covers the hybrid estate, which is where the largest single opportunities usually are: SQL Server and Windows Server entitlements with Software Assurance, Azure Hybrid Benefit application, and edition alignment between what is deployed and what the workload requires.

02

Business Challenge

The tenant makes assignment visible and usage opaque. Admin centre reporting shows licences assigned and, at a coarse level, whether a user has been active. It does not readily show that a user holding E5 has never opened a Power BI report, never triggered a compliance hold and never used Advanced Threat Protection — which is precisely the analysis that determines whether the E5 premium is justified.

The identity lifecycle is the second failure. Joiner processes are usually automated; mover and leaver processes are usually not. A mover keeps their old licence set and gains a new one. A leaver's account is disabled, which stops the user but not the billing. Unless licence release is an explicit step in the identity workflow, recovered licences depend on someone remembering to run a report.

On-premises adds a third dimension. Windows Server and SQL Server entitlements with Software Assurance may be eligible for Azure Hybrid Benefit, and frequently are not applied because the team provisioning Azure resources does not know what the on-premises agreement contains.

03

Typical Symptoms

Organisations that need this playbook usually recognise several of the following.

  • Users hold both a higher and a lower SKU — for example E3 and F3 — with no rule preventing the overlap.
  • E5 is assigned broadly but its premium service plans show little or no activation.
  • Disabled accounts retain assigned licences because disablement and licence release are separate processes.
  • Movers accumulate licences: the new role's licence is added and the old one is never removed.
  • Purchased licences sit unassigned in the tenant with no owner and no reclaim trigger.
  • Add-on SKUs duplicate entitlement already included in the base subscription.
  • Azure Hybrid Benefit is unapplied on eligible Windows Server and SQL Server workloads.
  • The renewal quantity is taken from current assigned seats without any usage validation.
04

Business Risks

Business risks by domain, with the risk and its impact
DomainRiskImpact if unaddressed
Operational Licence release absent from the mover and leaver identity workflow Recovered licences depend on periodic manual reports rather than on process. Recovery lags departures by months, and the tenant carries permanent excess.
Commercial Renewal quantity anchored to assigned seats rather than validated usage The organisation renews its own accumulated waste at a negotiated discount, locking the excess in for the full agreement term.
Compliance Duplicate and overlapping SKU assignment across the tenant Assignment records do not reflect a coherent entitlement position, which complicates any true-up conversation and undermines confidence in the tenant data.
Technology On-premises entitlement invisible to the teams provisioning cloud workloads Azure Hybrid Benefit goes unapplied on eligible workloads, and full-price cloud consumption is paid for capacity the organisation has already licensed.
05

Operating Workflow and Reference Architecture

Operating workflow

11 stages, each producing a defined output. This workflow is specific to this playbook; the category lifecycle on the Software Value index is an overview of how the playbooks relate, not how any one of them runs.

Wide diagram — scroll horizontally, or use the arrow keys once it has focus. A text description is available to screen readers.

Microsoft Licence and Subscription Optimisation — operating workflowA 11-stage operating workflow for microsoft licence and subscription optimisation: Microsoft Entitlement Baseline, Tenant & Subscription Data, User & Device Identity Correlation, Licence & Service-Plan Mapping, Usage & Activity Analysis, Duplicate & Overlap Detection, Mover & Leaver Validation, Rightsizing & Reclamation, Workload & On-Prem Review, Renewal Scenario Modelling, Action Tracking & Governance. Each stage shows the output it produces.01MicrosoftEntitlement BaselineOUTPUTAgreements, SKUs,quantities and SoftwareAssurance positionestablished02Tenant &Subscription DataOUTPUTAssigned, purchased andunassigned licencesextracted per SKU03User & DeviceIdentity CorrelationOUTPUTEntra ID accounts, statusand lifecycle statecorrelated04Licence &Service-Plan MappingOUTPUTEach licence resolved toits constituent serviceplans05Usage & ActivityAnalysisOUTPUTService-plan levelactivity assessed, notjust sign-in activity06Duplicate & OverlapDetectionOUTPUTHigher/lower SKU overlapsand redundant add-onsidentified07Mover & LeaverValidationOUTPUTDisabled, departed androle-changed accountschecked for retention08Rightsizing &ReclamationOUTPUTDowngrade and reclaimactions raised with thebusiness owner09Workload & On-PremReviewOUTPUTSQL, Windows Server andAzure Hybrid Benefiteligibility assessed10Renewal ScenarioModellingOUTPUTRenewal quantitiesmodelled from validateddemand and growth11Action Tracking &GovernanceOUTPUTActions tracked tocompletion with realisedbenefit recorded

Illustrative Microsoft optimisation workflow. The analysis operates at service-plan level rather than licence level, since an assigned licence with unused premium service plans is the most common form of waste. Outcomes are not guaranteed.

Reference architecture

The systems, data and controls the workflow above runs on.

Wide diagram — scroll horizontally, or use the arrow keys once it has focus. A text description is available to screen readers.

Reference architecture — Microsoft estate optimisationA four-layer reference architecture. Layer one, Microsoft sources, covers the Microsoft 365 admin centre and tenant subscription data, Entra ID users, groups and account status, service-plan activation and usage reporting, Azure subscription and resource data, and on-premises Windows Server and SQL Server inventory. Layer two, commercial inputs, covers the enterprise agreement or CSP agreement, SKU and price list data, Software Assurance coverage and true-up history. Layer three, analysis, covers identity correlation, service-plan activity analysis, duplicate and overlap detection, mover and leaver validation, role-based licence profiling and Azure Hybrid Benefit eligibility assessment. Layer four, action and governance, covers the rightsizing and reclamation backlog, downgrade recommendations, renewal scenario models, the identity lifecycle integration and benefit tracking.LAYER 1Microsoft sourcesTenant and hybridestateMicrosoft 365 admincentre subscriptionsEntra ID users, groupsand statusService-plan activationand usage reportsAzure subscription andresource dataOn-premises WindowsServer and SQL ServerinventoryLAYER 2Commercial inputsWhat is contractedEnterprise Agreement / CSPagreementSKU and price list dataSoftware Assurance coverageTrue-up history and anniversarydatesLAYER 3AnalysisService-plan level,not licence levelIdentity correlation andlifecycle stateService-plan activityanalysisDuplicate and overlappingSKU detectionMover and leavervalidationRole-based licenceprofilingAzure Hybrid BenefiteligibilityLAYER 4Action andgovernanceTracked to realisedbenefitRightsizing andreclamation backlogDowngrade recommendationsRenewal scenario modelsIdentity lifecycleintegrationBenefit tracking

Illustrative reference architecture. The service-plan activity feed is the component that distinguishes real Microsoft optimisation from seat counting; without it, an assigned E5 and a used E5 look identical.

06

Implementation Approach

A representative implementation sequences in 5 phases. Duration and overlap vary with estate size, data quality and the number of source systems in scope.

Phase 1

Entitlement and tenant baseline

Establish what is contracted and what is assigned, as two separate datasets that will later be compared.

  • Agreement baseline. Establish contracted SKUs, quantities, anniversary dates, Software Assurance coverage and true-up history from the agreement rather than from the tenant.
  • Tenant extraction. Extract purchased, assigned and unassigned licence counts per SKU, and reconcile the tenant position against the contracted position.
  • Unassigned licence review. Identify purchased-but-unassigned licences and establish whether they are held deliberately for growth or simply forgotten.
  • Service-plan decomposition. Decompose each SKU into its constituent service plans, since this is the level at which overlap and non-use become visible.
Business value

A reconciled view of contracted versus assigned versus available, decomposed to the service-plan level where optimisation decisions are actually made.

Phase 2

Identity correlation and usage analysis

Connect licences to people and to what those people actually use. This is where the optimisation case is built.

  • Entra ID correlation. Correlate every assigned licence to an Entra ID account with its current status — active, disabled, guest, shared mailbox, service account.
  • Service-plan activity analysis. Assess activity at service-plan level rather than at sign-in level, so an active user who uses none of the premium plans is correctly identified.
  • Inactivity definition. Agree what inactivity means per service plan with the business, since a 90-day threshold that is right for Teams may be wrong for a compliance feature.
  • Role-based profiling. Build licence profiles per role so that the right SKU for a role is defined once rather than argued per user.
  • Non-human account review. Identify service accounts, shared mailboxes and resource accounts holding full user licences unnecessarily.
Business value

Waste becomes specific and attributable — a named user, a named service plan, a stated period of non-use — which is what makes the reclaim conversation possible.

Phase 3

Overlap, duplicate and lifecycle recovery

Remove the structural waste: overlapping SKUs, redundant add-ons and licences held by people who have left or moved.

  • Higher and lower SKU overlap. Detect users holding both a higher and a lower SKU — E3 with F3, E5 with E3 — and resolve to a single appropriate licence.
  • Add-on redundancy. Identify add-on SKUs providing entitlement already included in the base subscription, which typically accumulate after a base SKU upgrade.
  • Leaver recovery. Identify disabled and departed accounts still holding licences, and recover them.
  • Mover validation. Identify accounts that gained a licence on role change without releasing the previous one.
  • Identity lifecycle integration. Wire licence release into the joiner-mover-leaver workflow so recovery becomes a process step rather than a periodic clean-up.
Business value

Structural waste is removed once, and the lifecycle integration stops it accumulating again — which is the difference between a project and a capability.

Phase 4

Hybrid and on-premises workload review

Address the hybrid estate, where single opportunities are usually largest.

  • SQL Server review. Assess deployed editions against workload requirement, and identify Enterprise deployments where Standard would serve.
  • Windows Server review. Assess core-based entitlement against deployed hosts, including virtualisation rights and datacenter-versus-standard edition alignment.
  • Azure Hybrid Benefit eligibility. Identify Azure workloads eligible for Hybrid Benefit under existing Software Assurance coverage and quantify the unapplied entitlement.
  • Application of benefit. Work with the cloud platform team to apply Hybrid Benefit where eligible, and put a control in place so new eligible workloads apply it at provisioning.
  • Software Assurance value review. Assess whether Software Assurance coverage is being used for the rights it provides, rather than renewed by default.
Business value

Entitlement already paid for is actually applied, and the largest single line items in the Microsoft estate are aligned to what the workload requires.

Phase 5

Renewal modelling and sustained governance

Convert the optimised position into a renewal baseline, and keep it optimised.

  • Validated demand baseline. Build the renewal quantity from post-optimisation validated demand rather than from current assigned seats.
  • Scenario modelling. Model renewal scenarios across SKU mix, term and growth assumptions, with each scenario's assumptions stated.
  • Action tracking. Track every rightsizing and reclaim action to completion and record the realised benefit against the modelled benefit.
  • Standing controls. Implement overlap detection, inactivity alerting and unassigned-licence thresholds as continuous controls rather than a periodic review.
  • Governance reporting. Report alignment, reclaim, overlap and Hybrid Benefit application to the software governance forum each cycle.
Business value

The renewal is negotiated against a validated, optimised baseline, and standing controls prevent the waste re-accumulating during the agreement term.

07

Technology Components

Microsoft product and service names are used because this playbook is specifically about the Microsoft estate. They are named as the subject of the analysis, not as recommendations, and no partnership or certification is implied. Licence terms and SKU composition change frequently and should be validated against current agreement documents.

Microsoft 365 and identity

  • Microsoft 365 admin centre
  • Microsoft Entra ID
  • Microsoft Graph API
  • Service-plan usage reports
  • Entra ID access reviews

Azure and hybrid

  • Azure subscriptions and resource graph
  • Azure Hybrid Benefit
  • Windows Server inventory
  • SQL Server inventory
  • Software Assurance records

Commercial

  • Enterprise Agreement / CSP records
  • SKU and price list data
  • True-up and anniversary tracking
  • Renewal scenario model

Process and reporting

  • Joiner-mover-leaver workflow (e.g. ServiceNow)
  • SAM platform Microsoft connectors
  • Power BI reporting
  • Reclaim action backlog
08

Governance Considerations

Governance should be proportionate. The six areas below are the minimum set that has to be explicit for this capability to hold up under internal review.

Ownership

A named Microsoft licence owner accountable for tenant alignment; the identity team accountable for lifecycle-triggered release; the cloud platform team accountable for Hybrid Benefit application.

Decision rights

The licence owner approves role-based licence profiles; business owners approve downgrades affecting their users; renewal quantity is approved jointly by the licence owner and procurement.

Policies

Role-based licence assignment policy, no-overlap policy prohibiting concurrent higher and lower SKUs, licence release on leaver and mover, and a Hybrid Benefit application policy at provisioning.

Approvals

Exceptions to the role-based profile require named approval; unassigned licence pools above a threshold require justification; E5 and premium SKU assignment requires a stated use case.

Evidence

Service-plan activity evidence supporting each downgrade or reclaim decision, retained alongside the business owner's acceptance and the date of action.

Controls

Automated overlap detection, inactivity alerting per service plan, licence release triggered by identity lifecycle events, unassigned-licence threshold alerts, and Hybrid Benefit checks at provisioning.

09

Success Metrics

Primary KPI

Licence-to-requirement alignment

Microsoft licences aligned to a validated user or workload requirement, assessed at service-plan level rather than at licence level.

≥ 95%

Operational KPIs

Inactive licences < 3% of assigned Assigned licences with no meaningful service-plan activity.
Duplicate assignments Zero standing Users holding both a higher and a lower SKU.
Unassigned purchased licences < 5% of purchased Licences bought and never allocated.
Inactive service plans Tracked per SKU Premium plans provisioned but unused.
M365 active-use rate Tracked per service plan Users actively using each plan they are licensed for.

Governance KPIs

Leaver recovery rate ≥ 98% within 5 days Licences released after account disablement.
Mover validation completion 100% of role changes Role changes with licence set revalidated.
Role-profile exceptions Tracked with justification Assignments outside the approved role profile.
Remediation completion ≥ 90% of raised actions Rightsizing actions closed within the cycle.

Value KPIs

Reclaimed licences Count per cycle Licences returned to the available pool.
Downgrade opportunities realised Against identified SKU downgrades completed.
Hybrid Benefit applied ≥ 95% of eligible workloads Eligible Azure workloads with benefit applied.
Cost avoidance Tracked against baseline Avoided purchase from reclaim and rightsizing.
Renewal baseline accuracy Within ±5% Modelled renewal quantity against realised demand.
Indicative targets

Every target above is an indicative KPI for a typical enterprise, intended to support planning discussions. Baselines should be measured in the first operating cycle and targets set from them. These are not benchmarks, commitments or achieved client results.

10

Positive Business Impact

Waste removed at service-plan level

Optimisation acts on what people actually use, not on whether they logged in — which is where the E5-premium and add-on redundancy waste actually sits.

Identity lifecycle wired to licence recovery

Leaver and mover events release licences automatically, so recovery stops depending on someone remembering to run a report.

Structural overlap eliminated

Concurrent higher and lower SKUs and redundant add-ons are removed and then prevented by standing detection rather than periodic clean-up.

Entitlement already paid for actually applied

Azure Hybrid Benefit is applied to eligible workloads and checked at provisioning, so the on-premises Software Assurance investment is realised.

A renewal baseline built from evidence

The renewal quantity comes from validated post-optimisation demand rather than from current assigned seats, so accumulated waste is not renewed at a discount.

Defensible optimisation decisions

Every downgrade and reclaim carries service-plan activity evidence and a business owner's acceptance, so decisions withstand challenge.

Outcomes depend on estate, contracts, data quality and organisational context, and are not guaranteed.

11

Related Playbooks

Playbooks commonly delivered alongside, before or after this one.

Important — please read

This playbook describes a typical implementation approach and a representative operating model. It is illustrative guidance, not a statement of results. Any figures, targets or ranges shown are illustrative and are intended to support planning discussions rather than to predict or promise an outcome. Outcomes are not guaranteed and depend on the estate, contracts, data quality and organisational context of each engagement.

No client names, client data, engagement detail or confidential delivery material is disclosed anywhere in this library. Technology named in these pages appears only as an illustrative example of a capability category and does not imply a partnership, certification or recommendation.

Book a Value Discovery

A free 30-minute session to pressure-test where the value actually sits in your software, SaaS and AI estate — and what it would take to get to it.