Skip to content

Data Centre Software Asset Management – Six Tips for Success

The data centre is where licensing gets expensive and where generic tools stop being useful. Six practical rules for managing Oracle, IBM, SAP and Microsoft licensing before an audit notice arrives.

Originally published October 2017, revised November 2019 and again on migration.

The data centre is where software licensing gets expensive. It is also where it gets hard: vendor programmes carry different metrics with different stipulations around installation, usage, edition and virtualisation, and the rules interact. The result is a class of software where you can be non-compliant and over-licensed at the same time, on the same product, and not know either.

Six rules for getting it under control.

Get on the front foot and take control

Do not sit back and wait until the annual submission is due, and certainly do not wait until a vendor arrives with a compulsory audit notice. By then it is usually too late to do anything but pay.

Take control of data centre licensing before any of the large publishers come knocking. Maintaining the compliance position through the year is what makes the next audit ordinary rather than an emergency, and it is what removes the nasty surprises — the option someone enabled, the cluster someone extended, the environment someone stood up for a migration and never tore down.

That requires tooling. Which brings us to the rest of the list.

Do not rely on the licensing tools the vendors give you

The tools supplied by publishers — Oracle’s LMS tooling, SAP’s SLAW and USMM, IBM’s ILMT, TAD4D and BigFix — are built to capture installation and usage data. They are point-in-time, they do not support refinement, and some of them exist primarily to produce a number the vendor can act on rather than one you can optimise against.

They are not SAM tools, and they will not help you improve a position.

That is not the same as ignoring them. IBM sub-capacity licensing is contingent on ILMT, so the sensible approach is to consume it rather than compete with it: CerteroX SAM carries an ILMT connector with compliance gap analysis, applies PVU and Virtual Processor Core metrics, and enforces the 30-minute inventory cycle that sub-capacity licensing actually requires. Component Resolution matches deployed components to products with a scored suggestion you can apply in bulk, which is the part that otherwise consumes weeks.

The distinction to hold onto is this: vendor tools measure. A SAM platform has to measure, then apply the entitlement, then tell you what to do.

Be careful with SAM consultancies and licensing specialists

Specialist licensing consultancies can be extremely costly, and they usually address a point-in-time requirement. They also tend to rely heavily on manual process, which by definition is error-prone and varies in quality with the experience of whoever is assigned.

What you need is a dynamic compliance view that tells you the moment you are non-compliant, so that the business decisions that follow are informed ones. Expertise is worth buying. Expertise that has to be re-bought every time you want to know where you stand is not.

SAM tools are available, but choose carefully

Plenty of vendors will tell you their tool is a silver bullet. Test the claim rather than the demo.

The specific things worth testing in a data centre context:

  • Does it model the publisher, or just count installs? A generic tool will tell you that you have 400 installs of Oracle Database. It will not tell you which options are enabled, which cores are licensable under which core factor, or which hosts are covered down by an Enterprise Edition pool. That gap is where the audit finding lives.
  • Does it survive the data volume? Data centre inventory is large and it does not get smaller. Ask what happens at your scale, not at the demo’s scale.
  • Is there one view, or several? Separate tools for Oracle, IBM, SAP and Microsoft means separate data, separate reconciliation and separate arguments about which one is right.
  • Is it automated end to end? Anything that requires a consultant to re-run it is a report, not a position.

The original version of this article recommended finding specialist tools designed for each environment. That was the right advice when the alternative was a generic inventory tool with a licence field bolted on. It is no longer necessary. CerteroX SAM carries dedicated licence engines for six publishers — Microsoft, Oracle, IBM, SAP, Adobe and Salesforce — on one platform and one data model, with the same inventory feeding all of them.

The depth is real rather than nominal. Oracle brings options and packs with per-detection evidence and override, processor types and core factors, licence pools with hosting rights and geographic rules, cover-down logic for Enterprise Edition, uncapped quantity for unlimited agreements and E-Business Suite responsibilities. SAP is read through a non-invasive ABAP connector that de-duplicates named users across systems and proposes the licence type each user should hold, so current, suggested and optimal positions sit side by side. Microsoft covers device and user CALs, named user and external connectors, and SQL Server and Windows Server core and processor licensing with cluster and virtualisation awareness — because the hard part of Microsoft licensing is the server room, not the desktop.

On Oracle there is also an external check worth knowing about. Certero is a verified third-party tool vendor: Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools.

Remember: an ELP is only the start

Establishing an Effective Licence Position gives you visibility and a foundation. It is not the destination. The destination is an Optimised Licence Position, and getting there means acting on what the ELP shows — harvesting what nobody uses, applying downgrade rights and second-use entitlement, and excluding the devices that should never have been counted in the first place.

Both positions then have to be maintained, or the benefit decays. This is the part that has genuinely changed since this article was first written. The compliance position is now computed continuously rather than reconciled periodically, and the ELP itself is a set of fields you can act on — purchased, used, available, required, variance and exposure — with the overspend and additional-licences-required calculation alongside it. Exclude From Licensing handles MSDN, development, training and second-use devices as a workflow rather than as a footnote in a spreadsheet, and Access Control rules deal with RDS, Citrix and VDI streamed-application licensing.

Maintaining an ELP used to be a recurring project. It should now be a property of the system.

Find a trusted partner

Optimising data centre licensing takes effective technology and process — services delivered by internal or external people who know the publishers.

Ideally you want a partner capable of both, and that is harder to find than it sounds. Tool vendors tend to fall short on services and lean on partners whose agenda is not aligned with yours. Service providers may offer the right process but run it on the wrong technology, so the outcome is neither quick nor cheap.

Look for highly automated technology and services that conform to industry best practice, executed by consultants who are expert at applying tools-based SAM. What that combination compresses is time. As Reece Emson, ITAM Asset/PSL Manager at NHS South West London ICB, put it: “Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.”

That is the measure worth applying to any partner conversation — not what they promise to find, but how quickly they can get you to a position you can defend.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.