A round-up of the licensing, contractual and regulatory changes that landed in June and early July 2025, and what each one means for the people who have to reconcile them.
Microsoft licensing terms update
Microsoft’s June Product Terms update made a number of modifications across the product suite.
The most consequential clarification: only Cloud Add-ons to Software Assurance require the same agreement as the base licence, not all prerequisite add-ons. If you have been treating every add-on as agreement-bound, that assumption is now formally wrong and worth re-checking against your renewals. Dragon Copilot was added to the Core Online Services security terms and to Microsoft’s educational benefits commitments.
Azure changes include App Service Plan added to the MCA table, a new microphone access disclosure for Azure Communication Services, and clarification of Entra ID Governance for external users. Azure AI Foundry now replaces Azure AI Studio, with models renamed accordingly. Power Platform’s Copilot Studio was added to the Customer Copyright Commitment.
What to do: Product Terms changes are cumulative and rarely announced loudly. If your entitlement records are reconstructed at renewal rather than maintained continuously, each of these is a small drift that only surfaces when someone asks you to prove a position.
SAMOSA returns: software oversight in the US federal sector
The US Senate reintroduced the SAMOSA Act — the Strengthening Agency Management and Oversight of Software Assets Act — signalling renewed focus on software mismanagement across federal agencies. Although it targets public sector efficiency, the implications extend to contractors and vendors doing federal business.
The legislation mandates comprehensive software audits, elimination of redundant licences, and formal reporting to oversight bodies including the OMB and GSA. It has bipartisan backing, and it follows the MEGABYTE Act, which already obliges agencies to track software licences and report on their management.
What to do: organisations interacting with federal entities face both compliance and financial risk if they cannot produce clear records of what software is deployed, what is actually used, and what is licensed. Those are three different questions and most reporting answers only the first. Deployment comes from inventory; usage comes from metering; entitlement comes from your contract records. If they live in three systems, you do not have an answer, you have a project.
Microsoft 365 Business Premium grant ends for nonprofits
Microsoft confirmed that its Microsoft 365 Business Premium grant for nonprofits ends from 1 July 2025. At each organisation’s next renewal after that date, free Business Premium licences cease to be available.
Eligible nonprofits instead receive up to 300 free Business Basic licences, with discounts of up to 75% on other plans. Business Basic includes only the web and mobile Office applications — it excludes desktop Office, Intune, Defender for Business and other premium security tooling.
The transition is manual. Administrators must acquire Business Basic licences within the tenant, reassign users, and cancel unused Premium licences. Leftover Premium seats that are not removed will generate charges after renewal.
What to do: this is a licence assignment problem and a capability problem at once. Model which users genuinely need desktop Office, Intune or Defender before the reassignment, not after — and plan against your actual subscription end dates. The seats you forget to cancel are the ones you pay for.
Adobe licensing updates
Rebranding and entitlement changes. From 17 June 2025, Adobe rebranded Creative Cloud Pro to Creative Cloud Pro Plus, and increased monthly Firefly generative AI credits from 3,000 to 4,000 per user. No pricing adjustment was announced alongside it.
AI credits cut for Single App plans. From 1 July 2025, generative AI credit allocations for Single App entitlements changed significantly. New purchases receive 25 credits per user per month, down from 500. Existing customers on active Single App subscriptions or three-year committed term agreements retain 500 credits and may continue adding seats under their current entitlement.
Creative Cloud Edition 4 price adjustment. From 1 July 2025, Adobe applied an 8% price increase to Creative Cloud Edition 4. Customers under active three-year committed term agreements are protected from the increase.
What to do: the Single App change creates a two-tier population inside the same organisation — existing seats at 500 credits, new seats at 25 — and the difference is invisible in a seat count. Anyone buying new Single App licences on the assumption they behave like the existing ones will get a support ticket rather than a renewal conversation. Note also that the protection for three-year committed terms only holds while the term is active.
Dutch court enforces VMware support continuity
A Dutch court ruled that Broadcom must continue providing VMware support to Rijkswaterstaat, the Dutch government agency responsible for public infrastructure and water management. The case follows Broadcom’s acquisition of VMware and the licensing restructuring that came with it.
The court found that Broadcom must honour pre-acquisition support terms until the agency can transition to alternatives, citing the critical nature of the services and the public interest in uninterrupted IT operations. While specific to Rijkswaterstaat, the ruling may set a precedent for other public sector and critical infrastructure organisations facing similar pressure after a vendor acquisition.
What to do: organisations in regulated or public service sectors should review the contractual protections in their software agreements ahead of any vendor transition, document support dependencies so continuity clauses are enforceable, and involve legal and licensing expertise early rather than after a unilateral change lands.
Expect more Java audits in Oracle’s new fiscal year
Oracle’s Java SE licensing overhaul has introduced new cost structures and a marked increase in audit activity. The Java SE Universal Subscription model, introduced on 23 January 2023, licenses per employee rather than per actual Java user.
That metric is the whole story. An organisation with a small number of Java developers can find itself required to license its entire employee population, and the resulting exposure bears no relationship to how much Java it runs. Migration to non-Oracle distributions has become a common and widely discussed response.
Oracle’s Global License Advisory Services has intensified audit effort against Java deployments, tracking downloads, patch updates and IP or domain activity, and drawing on multi-year download histories going back to January 2022 to identify unlicensed use.
Several Java versions have moved from the free-use terms to OTN licensing rules:
- Java 8, from the April 2019 update (8u211 and later)
- Java 17, from the October 2024 update (17.0.13 and later)
- Java 21 is scheduled to make the same transition — confirm the exact update against Oracle’s published schedule before you plan around it
What to do: inventory Java across every environment, including the copies bundled inside other applications, which is where most organisations are surprised. Compare employee headcount against actual Java users to understand exposure under the Universal Subscription metric. Evaluate alternative distributions such as OpenJDK, Amazon Corretto and Azul Zulu. Then document historical usage and entitlement coverage using tooling Oracle recognises: Certero is a verified third-party toolset, meaning Oracle’s audit team can accept data from Certero during an official audit as an alternative to installing Oracle’s own measurement tools.
Exiting an Oracle ULA: planning implications
As an Oracle Unlimited License Agreement approaches its end, the decision to certify, renew or rescope carries significant financial and operational consequences. Internal audit work done in advance is what makes that decision a negotiation rather than a disclosure.
A ULA grants unlimited deployment rights for specified products over a fixed term, typically three to five years. At term end you choose to certify — declare actual usage and convert to perpetual licences — renew the term under revised commercial conditions, or expand the scope at additional cost.
Leaving the preparation late creates three specific risks: under-reporting, which produces non-compliance and audit exposure; over-reporting, which locks in entitlements you do not need and invites dispute; and missed optimisation, where you certify a position you could have reduced first.
Running the internal audit nine to twelve months before expiry gives you time to quantify deployments across every environment, identify unused or underutilised entitlements, validate that deployments were eligible under the ULA terms, model certification against renewal, and negotiate from verified data.
What to do: the detail is where the money is. Options and packs need evidence and, where appropriate, override. Processor types and core factors need to be right. Licence pools need their hosting rights and geographic rules applied, and Enterprise Edition cover-down logic needs to be understood before you count anything. CerteroX SAM computes that continuously rather than reconstructing it at certification.
Trend: freemium and open core licensing
Publishers increasingly adopt freemium and open core models to expand reach and accelerate adoption. Both create new risks for asset management and procurement.
Freemium offers a fully functional product at no cost with premium features gated behind paid tiers — Slack, Zoom and Trello are familiar examples. Open core provides a free, open-source base with advanced enterprise features commercialised under proprietary terms; GitLab, Elastic and Redis are examples.
The challenges are consistent. Freemium tools get deployed with no IT oversight, producing unmanaged risk and data spread across places nobody has mapped. Users activate premium features without realising they have triggered a commercial obligation. Open core blurs the line between the open-source and proprietary components in a way that is genuinely hard to reason about. And the cost of moving from a free tier to an enterprise agreement is rarely visible at the point the tool was adopted.
What to do: discovery has to come first, because none of these tools announce themselves. CerteroX SaaS Management converges identity provider sync, 47 vendor connectors and a browser extension that records which SaaS domains people actually open — so free-tier tools show up on usage evidence even when there is no invoice and no licence record to find them by. From there, set governance policy for evaluating and approving freemium tools, watch for feature usage that crosses into commercial territory, and review open-source terms for redistribution and usage obligations.
Trend: legal and compliance pressure intensifies
Regulatory scrutiny and vendor enforcement are together reshaping how organisations manage entitlement, negotiate contracts and prepare for audit. Data protection, cybersecurity and digital sovereignty legislation — GDPR, NIS2, the DSA — increasingly influences how software may be licensed, accessed and monitored.
Vendors are raising audit frequency and widening audit scope, with particular attention to cloud usage, indirect access and mixed on-premises and cloud deployments. Licensing agreements now carry more granular terms on usage rights, geographic restriction and termination, and those terms generally favour the vendor.
The failure modes are predictable: audit exposure from inadequate entitlement tracking or undocumented usage; contractual traps from ambiguous or one-sided terms; and operational disruption when a dispute or an audit escalation delays a project.
What to do: run internal audits regularly rather than reactively, validating usage against entitlement. Centralise contract management so renewal terms and compliance obligations are visible in one place. Bring legal counsel into negotiation early enough to clarify ambiguous clauses. And automate the monitoring, so audit-ready reporting is a by-product of normal operation rather than a fire drill.
Siebel CRM on-premises licensing risks
Siebel CRM’s on-premises licensing is unusually granular and attracts strict audit scrutiny. Five risks account for most findings.
Custom integration exposure. Bespoke integrations can trigger additional licensing obligations under Oracle’s access policies. Review integration architecture for licensing implications and document every third-party access point.
Indirect access. Excluding users who reach Siebel data through integrations, middleware or portals under-reports your user count. Every user or device consuming Siebel data must be included, regardless of how they reach it.
No usage visibility. Without real-time usage data, entitlement and consumption drift apart and you find out at audit. File-based usage metering with first-used and last-used tracking, and a percentage-used metric over a rolling 90-day window, gives you the evidence to align licensing with what is genuinely needed.
Inactive user inflation. Dormant and legacy accounts that remain enabled are counted at audit. Deprovision or retire unused IDs on a schedule — and make offboarding something you can prove finished, with the status of every licence a leaver held rather than a tick in a checklist.
Audit preparedness gaps. Incomplete documentation and missing audit trails produce bad audit outcomes almost independently of the underlying compliance position. Maintain comprehensive records of users, agreements and system configuration, with a continuous trail across agreements, transactions and exclusions.