MICROSOFT LICENSING · MODULE 10 · COMPLIANCE, LICENCE RECONCILIATION & POSITION
Microsoft licence reconciliation and licence position:
Are we really compliant?
A licence reconciliation compares the licences an organisation has purchased with the rights required for installed software, users, devices, or cloud services. The documented result forms the basis of a defensible Microsoft licence position.
The short answer
Licence reconciliation shows whether purchased rights match actual requirements.
Documented licence rights are compared with the requirement calculated under the relevant product rules. The result shows sufficient coverage, overlicensing, underlicensing, or a matter that remains unresolved.
- 01Licence reconciliation = available licence rights minus correctly calculated licence requirements.
- 02Agreement programme, SKU, acquisition date, and term determine the usable rights.
- 03Microsoft 365 assignments, Azure resources, and server inventories provide different pieces of the picture.
- 04Unclear data is recorded as an open assumption—not silently classified as compliant.
- 05The result needs an effective date, sources, owners, and a concrete action plan.
Explained simply · The essential terms
Three terms that make licence reconciliation easy to understand
Licence reconciliation shows whether purchased rights cover installed software or actual use. The licence position documents that result clearly.
Entitlement
A licence right that can be evidenced through the agreement, purchase, and applicable Product Terms.
Licence requirement
The quantity and type of rights needed for actual users, devices, cores, servers, access, or cloud scenarios.
Licence reconciliation and position
Reconciliation compares rights with requirements. The licence position documents the result together with its effective date and supporting evidence.
A practical example: 100 device licences are available, but the software is installed on 115 licensable devices. The licence reconciliation shows a shortfall of 15 licences.
Explained simply
What is licence reconciliation?
A licence reconciliation answers three practical questions: What have we purchased? What have we installed or are we using? And do the available rights cover that use?
What have we purchased?
Agreements, orders, subscriptions, and Product Terms show which Microsoft licences were purchased and which usage rights actually apply.
What have we installed or are we using?
Depending on the product, count installed devices, licensable users, servers, cores, access, or cloud resources. Installation alone does not determine every licence metric.
Do both sides match?
Available licence rights minus actual licence requirements show sufficient coverage, a surplus, a shortfall, or a position that remains unresolved.
If the product is licensed per device, 15 additional licences are required. For Microsoft 365, compare the available user licences with the individuals who actually require the relevant rights.
It adds the effective date, agreements, product rules, evidence, assumptions, and actions to the numerical comparison. That is why both concepts belong together.
Before collecting data
Define the review scope first
Without scope, data from different legal entities, tenants, agreements, and periods becomes mixed. The result may look precise but is not defensible.
Legal entities and affiliates
Define which entities and locations are included and which agreements actually cover their use.
Tenants, Azure scopes, and datacentres
Include all relevant Microsoft 365 tenants, Azure subscriptions, physical hosts, clusters, and outsourced environments.
Products, editions, and versions
Cover not only Microsoft 365 but also Windows, SQL, server products, CALs, Visual Studio, and existing hybrid rights.
Effective date and period
Define whether the review covers only today's state or also historical use, true-up, renewal, or an agreement term.
Production, Dev/Test, and disaster recovery
Identify production, passive, test, and recovery systems separately because different rights may apply.
The entitlement side
Which evidence belongs in the entitlement inventory?
Not every licence appears in the same portal. A complete rights view therefore connects several acquisition routes and records.
| Acquisition or evidence | What to capture | What to watch |
|---|---|---|
| EA/EAS and traditional volume licensing | Licence IDs, agreements, enrolments, orders, licence summary, and active SA | Include only agreements whose access and legal ownership are understood. |
| MCA through CSP/partners and online subscriptions | Subscription, SKU, quantity, term, renewal, invoice, and partner confirmation | CSP, MCA, OEM, and retail rights are not displayed in the traditional VL contract view. |
| MPSA | Purchase Accounts, orders, software, downloads, and keys | MPSA data is maintained separately and is not part of the normal VL licence summary. |
| OEM and retail | Invoice, device, COA or digital evidence, and transfer conditions | Do not infer device binding or transferability from activation. |
| Agreement and product rules | Programme, Product Terms, acquisition date, version, edition, and additional rights | Product Terms visible today do not automatically apply unchanged to every historical purchase. |
Activation is a technical process. Successful activation alone does not prove the correct acquisition route or all usage rights for the specific scenario.
Classify data correctly
Which Microsoft system answers which question?
Portals provide valuable raw data, but no single portal automatically calculates the complete Microsoft licence position.
| System | Useful for | Not sufficient alone for |
|---|---|---|
| Microsoft 365 admin centre · Billing > Licences | Purchased quantities, direct and group assignments, and errors | Benefiting users, tenant-wide capabilities, agreement rights, and on-premises requirements |
| Admin centre · Volume licensing | VL agreements, licence summaries, orders, agreement dates, and product keys | Deployments; Microsoft expressly states that the licence summary does not show deployment details |
| Microsoft Entra and Microsoft Graph | Accounts, groups, SKU and service-plan status, and assignment logic | Contractual entitlement and full requirements behind shared or indirect use |
| Azure Resource Graph | Resources across subscriptions, such as VMs, type, region, and configuration | Historical rights, on-premises inventory, and every entitlement required for AHB |
| Azure Cost Management | Cost, usage, reservation, and savings-plan data | The legal BYOL or hybrid entitlement behind an applied pricing benefit |
| Technical inventories | Hosts, clusters, VMs, cores, editions, versions, and installed software | Proof of purchase, agreement programme, and Software Assurance status |
A common language for all data
Normalise rights and use before comparison
An invoice with product names cannot be compared directly with a server or user export. Both sides must be mapped to the same attributes.
- 01Record the exact SKU or product name rather than a broad label.
- 02Identify the metric: user, device, core, server, CAL, capacity, or consumption.
- 03Document edition, version, upgrade, downgrade, and extended-use rights.
- 04Verify subscription or Software Assurance status and expiry date.
- 05Map the agreement programme, legal entity, country, and permitted unit of use.
- 06For historical purchases, retain the applicable Product Terms; Microsoft lets users select an earlier Effective Date and compare it with current terms.
The requirement side
Do not only count installations—apply the licensing metric
Technical inventory becomes a licence requirement only through the appropriate product rule. One system can trigger user, core, server, and access licences at the same time.
Who uses or benefits?
Assess direct assignments, groups, frontline or shared-device scenarios, guests, and tenant-wide beneficiaries by product.
Where does the software run?
Include physical hosts, virtual cores, minimums, editions, clusters, licence mobility, and permitted reassignments.
Who accesses directly or indirectly?
Assess CALs, RDS, External Connectors, multiplexing, service accounts, and application chains separately from server rights.
Which rights are used in Azure?
Link Azure Hybrid Benefit, BYOL, reservations, Dev/Test, and passive scenarios to the underlying entitlement.
Which additional capability is actually used?
Evaluate add-ons, premium capabilities, and tenant-wide features according to prerequisites and the benefiting population.
An activity report is an important optimisation signal. Whether a licence can be removed still depends on assignment, provisioning, access, capability, and the applicable product rule.
Assess Microsoft 365 correctly
Purchased, assigned, enabled, and used are four different values
An online-services position therefore has to connect several layers.
Subscriptions and terms
Quantity, SKU, billing and agreement term, plus cancellation or renewal date, determine available inventory.
Direct and group-based licences
Capture both assignment methods and review errors. Microsoft lists insufficient licences, conflicts, and invalid usage locations among possible causes.
Enabled or disabled services
Service-plan status shows which components are provisioned for an account. It does not automatically split a purchased suite into separately usable licences.
Tenant-wide and indirect effect
With centrally enabled security, compliance, or AI capabilities, the licensable population can be larger than the assigned add-on list.
Shared, service, guest, and former users
Do not classify account types as universally free or licensable. Product, provisioning, access, and actual benefit decide the scenario.
On-premises and servers
Build a separate sub-position for each product
A single infrastructure export rarely shows every required right. Build positions by product and then connect them along the application chain.
Cores, edition, and CALs
Calculate physical and virtual licensing, Standard or Datacenter, virtualisation rights, and User, Device, or RDS CALs separately.
Core or Server/CAL
Capture edition, licensing model, physical or virtual cores, minimums, passive instances, and indirect users.
Instance plus access
Exchange, SharePoint, Project, and other products can require server licences, base CALs, and additive CALs.
Document movement
Do not treat VM movement only as a technical event. Evidence timing, host coverage, active SA, and relevant mobility rights.
Evidence special rights
Count Visual Studio, passive, or disaster-recovery rights only when prerequisites and separation from production are documented.
Traceable, not merely plausible
What a defensible evidence register looks like
Every number in the licence position should be traceable to a source, date, and decision.
| Record | At minimum retain | Why |
|---|---|---|
| Agreement and order | Agreement ID, programme, legal entity, SKU, quantity, date, term, and document link | Evidences acquisition and ownership. |
| Applicable rule | Product Terms version, Effective Date, product section, and documented interpretation | Explains why a right or requirement was counted. |
| Portal export | Tenant or scope, export date, filters, owner, and unchanged source file | Makes assignments and resources reproducible. |
| Technical inventory | Device, host, VM, core, instance, edition, version, environment, and discovery time | Evidences the actual deployment scope. |
| Calculation | Metric, formula, minimums, assumptions, exceptions, and reviewer | Connects raw data to the calculated requirement. |
| Action | Variance, decision, owner, due date, cost, and closure evidence | Turns analysis into a managed position. |
Practical example
1,000 users, two tenants, and a hybrid server estate
A company owns 1,000 Microsoft 365 E3 licences. The admin centre shows 930 assigned, while 870 users were active in the latest report. Windows and SQL systems also run in a virtualised cluster.
| Observation | Hasty conclusion | Correct review |
|---|---|---|
| 70 unassigned E3 licences | 70 licences are definitely free | Check term, second tenant, assignment errors, upcoming starters, and required base rights. |
| 60 more users are inactive | Another 60 licences can be removed immediately | Clarify assignment, role, absence, provisioned services, and actual benefit. |
| 18 group-licensing errors | The users are fine because the group is correct | Resolve missing inventory, conflicts, dependencies, or usage location and evidence successful assignment. |
| 25 former accounts still have E3 | Only a cost issue | Review offboarding, data retention, access blocking, and required licence state together. |
| Windows and SQL VMs move between hosts | Activated VMs are automatically licensed | Calculate host and VM cores, editions, SA, mobility rights, passive systems, and CALs separately. |
A defensible position emerges only after every difference is explained and the server estate is assessed under its own metrics.
From result to decision
Four possible states—four different actions
| Status | Meaning | Next step |
|---|---|---|
| Covered | Evidenced rights cover the calculated requirement. | Approve the position, retain evidence, and monitor change. |
| Shortfall | Requirement exceeds usable rights. | Validate the calculation, correct use, or acquire the appropriate rights. |
| Surplus | Usable rights exceed current requirement. | Reuse, consider a lower plan, or reduce at renewal. |
| Unresolved | Data, agreement, or rule is insufficient for a conclusion. | Record the open assumption with an owner and due date; do not mark it covered. |
The complete process
Twelve steps to a Microsoft licence position
- 01Define the date, legal entities, countries, tenants, Azure scopes, and datacentres.
- 02Collect all agreements, orders, subscriptions, invoices, and terms.
- 03Normalise programme, SKU, edition, version, metric, and acquisition date for every right.
- 04Retain applicable Product Terms and historical versions where required.
- 05Export Microsoft 365 assignments, service plans, and group errors.
- 06Capture Azure resources, Hybrid Benefit use, costs, and commitment data.
- 07Inventory physical hosts, clusters, VMs, cores, instances, and versions.
- 08Assess direct and indirect user, device, and server access, including CALs.
- 09Compare entitlement and requirement by product using a documented formula.
- 10Validate assumptions with IT, procurement, security, business teams, and legal.
- 11Assign owners, dates, and costs to shortfalls, surpluses, and unresolved items.
- 12Repeat regularly and before renewal, architectural change, M&A, or tenant migration.
The key point
Licence reconciliation and position make purchased rights and actual requirements traceable.
It connects the right agreement and product rules with complete data, documented assumptions, and concrete actions. That makes compliance a foundation for renewals, cost optimisation, and better architecture decisions.
The general compliance article explains the vendor-neutral logic of entitlement, consumption, ELP, controls, and responsibilities. Read the foundation article →
Current and traceable
Official Microsoft sources used for this article
Microsoft updates the Product Terms continuously. The specific agreement, acquisition date, product, programme, and actual use always remain decisive.
- 01Microsoft Product Terms↗ (opens in a new tab)
- 02Microsoft Licensing FAQ: Product Terms and effective dates↗ (opens in a new tab)
- 03Microsoft Licensing: Archived Product Terms documents↗ (opens in a new tab)
- 04Microsoft Learn: View volume licensing contracts in the Microsoft 365 admin center↗ (opens in a new tab)
- 05Microsoft Learn: Assign or unassign licences for users↗ (opens in a new tab)
- 06Microsoft Learn: Assign or unassign licences to a group↗ (opens in a new tab)
- 07Microsoft Learn: View Microsoft 365 account licence and service details↗ (opens in a new tab)
- 08Microsoft Learn: Azure Resource Graph overview↗ (opens in a new tab)
- 09Microsoft Learn: Create and manage Cost Management exports↗ (opens in a new tab)
- 10Microsoft Support: Activate Windows↗ (opens in a new tab)
Note: This article provides clear orientation and does not replace an individual contractual, licensing, or legal review.