Knowledge for better technology decisions
Knowledge BaseMicrosoft licensing

MICROSOFT LICENSING · MODULE 10 · COMPLIANCE, LICENCE RECONCILIATION & POSITION

Microsoft licence reconciliation and licence position:
Are we really compliant?

A licence reconciliation compares the licences an organisation has purchased with the rights required for installed software, users, devices, or cloud services. The documented result forms the basis of a defensible Microsoft licence position.

Licence reconciliation shows whether purchased rights match actual requirements.

Documented licence rights are compared with the requirement calculated under the relevant product rules. The result shows sufficient coverage, overlicensing, underlicensing, or a matter that remains unresolved.

  1. 01Licence reconciliation = available licence rights minus correctly calculated licence requirements.
  2. 02Agreement programme, SKU, acquisition date, and term determine the usable rights.
  3. 03Microsoft 365 assignments, Azure resources, and server inventories provide different pieces of the picture.
  4. 04Unclear data is recorded as an open assumption—not silently classified as compliant.
  5. 05The result needs an effective date, sources, owners, and a concrete action plan.

Three terms that make licence reconciliation easy to understand

Licence reconciliation shows whether purchased rights cover installed software or actual use. The licence position documents that result clearly.

Entitlement

A licence right that can be evidenced through the agreement, purchase, and applicable Product Terms.

Licence requirement

The quantity and type of rights needed for actual users, devices, cores, servers, access, or cloud scenarios.

Licence reconciliation and position

Reconciliation compares rights with requirements. The licence position documents the result together with its effective date and supporting evidence.

A practical example: 100 device licences are available, but the software is installed on 115 licensable devices. The licence reconciliation shows a shortfall of 15 licences.

01

What is licence reconciliation?

A licence reconciliation answers three practical questions: What have we purchased? What have we installed or are we using? And do the available rights cover that use?

1 · PURCHASED

What have we purchased?

Agreements, orders, subscriptions, and Product Terms show which Microsoft licences were purchased and which usage rights actually apply.

2 · INSTALLED OR USED

What have we installed or are we using?

Depending on the product, count installed devices, licensable users, servers, cores, access, or cloud resources. Installation alone does not determine every licence metric.

3 · RECONCILIATION

Do both sides match?

Available licence rights minus actual licence requirements show sufficient coverage, a surplus, a shortfall, or a position that remains unresolved.

Simple example: 100 device licences purchased, software installed on 115 devices.

If the product is licensed per device, 15 additional licences are required. For Microsoft 365, compare the available user licences with the individuals who actually require the relevant rights.

The licence position is the documented result of the reconciliation.

It adds the effective date, agreements, product rules, evidence, assumptions, and actions to the numerical comparison. That is why both concepts belong together.

02

Define the review scope first

Without scope, data from different legal entities, tenants, agreements, and periods becomes mixed. The result may look precise but is not defensible.

ORGANISATION

Legal entities and affiliates

Define which entities and locations are included and which agreements actually cover their use.

SYSTEMS

Tenants, Azure scopes, and datacentres

Include all relevant Microsoft 365 tenants, Azure subscriptions, physical hosts, clusters, and outsourced environments.

PRODUCTS

Products, editions, and versions

Cover not only Microsoft 365 but also Windows, SQL, server products, CALs, Visual Studio, and existing hybrid rights.

TIME

Effective date and period

Define whether the review covers only today's state or also historical use, true-up, renewal, or an agreement term.

USE

Production, Dev/Test, and disaster recovery

Identify production, passive, test, and recovery systems separately because different rights may apply.

03

Which evidence belongs in the entitlement inventory?

Not every licence appears in the same portal. A complete rights view therefore connects several acquisition routes and records.

Acquisition or evidenceWhat to captureWhat to watch
EA/EAS and traditional volume licensingLicence IDs, agreements, enrolments, orders, licence summary, and active SAInclude only agreements whose access and legal ownership are understood.
MCA through CSP/partners and online subscriptionsSubscription, SKU, quantity, term, renewal, invoice, and partner confirmationCSP, MCA, OEM, and retail rights are not displayed in the traditional VL contract view.
MPSAPurchase Accounts, orders, software, downloads, and keysMPSA data is maintained separately and is not part of the normal VL licence summary.
OEM and retailInvoice, device, COA or digital evidence, and transfer conditionsDo not infer device binding or transferability from activation.
Agreement and product rulesProgramme, Product Terms, acquisition date, version, edition, and additional rightsProduct Terms visible today do not automatically apply unchanged to every historical purchase.
A product key is not complete proof of entitlement.

Activation is a technical process. Successful activation alone does not prove the correct acquisition route or all usage rights for the specific scenario.

04

Which Microsoft system answers which question?

Portals provide valuable raw data, but no single portal automatically calculates the complete Microsoft licence position.

SystemUseful forNot sufficient alone for
Microsoft 365 admin centre · Billing > LicencesPurchased quantities, direct and group assignments, and errorsBenefiting users, tenant-wide capabilities, agreement rights, and on-premises requirements
Admin centre · Volume licensingVL agreements, licence summaries, orders, agreement dates, and product keysDeployments; Microsoft expressly states that the licence summary does not show deployment details
Microsoft Entra and Microsoft GraphAccounts, groups, SKU and service-plan status, and assignment logicContractual entitlement and full requirements behind shared or indirect use
Azure Resource GraphResources across subscriptions, such as VMs, type, region, and configurationHistorical rights, on-premises inventory, and every entitlement required for AHB
Azure Cost ManagementCost, usage, reservation, and savings-plan dataThe legal BYOL or hybrid entitlement behind an applied pricing benefit
Technical inventoriesHosts, clusters, VMs, cores, editions, versions, and installed softwareProof of purchase, agreement programme, and Software Assurance status
05

Normalise rights and use before comparison

An invoice with product names cannot be compared directly with a server or user export. Both sides must be mapped to the same attributes.

  1. 01Record the exact SKU or product name rather than a broad label.
  2. 02Identify the metric: user, device, core, server, CAL, capacity, or consumption.
  3. 03Document edition, version, upgrade, downgrade, and extended-use rights.
  4. 04Verify subscription or Software Assurance status and expiry date.
  5. 05Map the agreement programme, legal entity, country, and permitted unit of use.
  6. 06For historical purchases, retain the applicable Product Terms; Microsoft lets users select an earlier Effective Date and compare it with current terms.
06

Do not only count installations—apply the licensing metric

Technical inventory becomes a licence requirement only through the appropriate product rule. One system can trigger user, core, server, and access licences at the same time.

USER AND DEVICE

Who uses or benefits?

Assess direct assignments, groups, frontline or shared-device scenarios, guests, and tenant-wide beneficiaries by product.

CORE AND SERVER

Where does the software run?

Include physical hosts, virtual cores, minimums, editions, clusters, licence mobility, and permitted reassignments.

ACCESS

Who accesses directly or indirectly?

Assess CALs, RDS, External Connectors, multiplexing, service accounts, and application chains separately from server rights.

CLOUD AND HYBRID

Which rights are used in Azure?

Link Azure Hybrid Benefit, BYOL, reservations, Dev/Test, and passive scenarios to the underlying entitlement.

CAPABILITY

Which additional capability is actually used?

Evaluate add-ons, premium capabilities, and tenant-wide features according to prerequisites and the benefiting population.

Inactive does not automatically mean no licence is required.

An activity report is an important optimisation signal. Whether a licence can be removed still depends on assignment, provisioning, access, capability, and the applicable product rule.

07

Purchased, assigned, enabled, and used are four different values

An online-services position therefore has to connect several layers.

PURCHASED

Subscriptions and terms

Quantity, SKU, billing and agreement term, plus cancellation or renewal date, determine available inventory.

ASSIGNED

Direct and group-based licences

Capture both assignment methods and review errors. Microsoft lists insufficient licences, conflicts, and invalid usage locations among possible causes.

SERVICE PLANS

Enabled or disabled services

Service-plan status shows which components are provisioned for an account. It does not automatically split a purchased suite into separately usable licences.

BENEFITING USERS

Tenant-wide and indirect effect

With centrally enabled security, compliance, or AI capabilities, the licensable population can be larger than the assigned add-on list.

ACCOUNT TYPES

Shared, service, guest, and former users

Do not classify account types as universally free or licensable. Product, provisioning, access, and actual benefit decide the scenario.

08

Build a separate sub-position for each product

A single infrastructure export rarely shows every required right. Build positions by product and then connect them along the application chain.

WINDOWS SERVER

Cores, edition, and CALs

Calculate physical and virtual licensing, Standard or Datacenter, virtualisation rights, and User, Device, or RDS CALs separately.

SQL SERVER

Core or Server/CAL

Capture edition, licensing model, physical or virtual cores, minimums, passive instances, and indirect users.

SERVER PRODUCTS

Instance plus access

Exchange, SharePoint, Project, and other products can require server licences, base CALs, and additive CALs.

CLUSTERS AND MOBILITY

Document movement

Do not treat VM movement only as a technical event. Evidence timing, host coverage, active SA, and relevant mobility rights.

DEV/TEST AND DR

Evidence special rights

Count Visual Studio, passive, or disaster-recovery rights only when prerequisites and separation from production are documented.

09

What a defensible evidence register looks like

Every number in the licence position should be traceable to a source, date, and decision.

RecordAt minimum retainWhy
Agreement and orderAgreement ID, programme, legal entity, SKU, quantity, date, term, and document linkEvidences acquisition and ownership.
Applicable ruleProduct Terms version, Effective Date, product section, and documented interpretationExplains why a right or requirement was counted.
Portal exportTenant or scope, export date, filters, owner, and unchanged source fileMakes assignments and resources reproducible.
Technical inventoryDevice, host, VM, core, instance, edition, version, environment, and discovery timeEvidences the actual deployment scope.
CalculationMetric, formula, minimums, assumptions, exceptions, and reviewerConnects raw data to the calculated requirement.
ActionVariance, decision, owner, due date, cost, and closure evidenceTurns analysis into a managed position.
10

1,000 users, two tenants, and a hybrid server estate

A company owns 1,000 Microsoft 365 E3 licences. The admin centre shows 930 assigned, while 870 users were active in the latest report. Windows and SQL systems also run in a virtualised cluster.

ObservationHasty conclusionCorrect review
70 unassigned E3 licences70 licences are definitely freeCheck term, second tenant, assignment errors, upcoming starters, and required base rights.
60 more users are inactiveAnother 60 licences can be removed immediatelyClarify assignment, role, absence, provisioned services, and actual benefit.
18 group-licensing errorsThe users are fine because the group is correctResolve missing inventory, conflicts, dependencies, or usage location and evidence successful assignment.
25 former accounts still have E3Only a cost issueReview offboarding, data retention, access blocking, and required licence state together.
Windows and SQL VMs move between hostsActivated VMs are automatically licensedCalculate host and VM cores, editions, SA, mobility rights, passive systems, and CALs separately.
The answer is neither 1,000 minus 930 nor 1,000 minus 870.

A defensible position emerges only after every difference is explained and the server estate is assessed under its own metrics.

11

Four possible states—four different actions

StatusMeaningNext step
CoveredEvidenced rights cover the calculated requirement.Approve the position, retain evidence, and monitor change.
ShortfallRequirement exceeds usable rights.Validate the calculation, correct use, or acquire the appropriate rights.
SurplusUsable rights exceed current requirement.Reuse, consider a lower plan, or reduce at renewal.
UnresolvedData, agreement, or rule is insufficient for a conclusion.Record the open assumption with an owner and due date; do not mark it covered.
12

Twelve steps to a Microsoft licence position

  1. 01Define the date, legal entities, countries, tenants, Azure scopes, and datacentres.
  2. 02Collect all agreements, orders, subscriptions, invoices, and terms.
  3. 03Normalise programme, SKU, edition, version, metric, and acquisition date for every right.
  4. 04Retain applicable Product Terms and historical versions where required.
  5. 05Export Microsoft 365 assignments, service plans, and group errors.
  6. 06Capture Azure resources, Hybrid Benefit use, costs, and commitment data.
  7. 07Inventory physical hosts, clusters, VMs, cores, instances, and versions.
  8. 08Assess direct and indirect user, device, and server access, including CALs.
  9. 09Compare entitlement and requirement by product using a documented formula.
  10. 10Validate assumptions with IT, procurement, security, business teams, and legal.
  11. 11Assign owners, dates, and costs to shortfalls, surpluses, and unresolved items.
  12. 12Repeat regularly and before renewal, architectural change, M&A, or tenant migration.

Licence reconciliation and position make purchased rights and actual requirements traceable.

It connects the right agreement and product rules with complete data, documented assumptions, and concrete actions. That makes compliance a foundation for renewals, cost optimisation, and better architecture decisions.

Explore the foundation: What does software licence compliance mean in general?

The general compliance article explains the vendor-neutral logic of entitlement, consumption, ELP, controls, and responsibilities. Read the foundation article →

Official Microsoft sources used for this article

Microsoft updates the Product Terms continuously. The specific agreement, acquisition date, product, programme, and actual use always remain decisive.

Note: This article provides clear orientation and does not replace an individual contractual, licensing, or legal review.