Skip to content

Licence entitlement: matching licences to your installed software

Counting installs is the easy part. Turning an inventory into a defensible licence position means normalising the data, understanding how the software is actually used, and applying the entitlement you hold against it.

Once you have an accurate inventory of your software, the next job is to work out what you are entitled to run. That comparison — entitlement against deployment — is the whole of software asset management in one sentence.

It is also the point where most programmes stall. Matching licences to installed software sounds like a lookup. It is not. There are three stages, and each one is harder than it looks: normalising the inventory, understanding how the software is actually used, and applying the entitlement you hold to the requirement you have.

Stage one: normalising the software inventory

Raw inventory is not usable for licensing. A large organisation will collect tens of thousands of distinct software records, and the same product will appear under a dozen spellings, several versions and a handful of publisher names that all belong to the same company after an acquisition.

Normalisation turns that into a list you can act on: publisher, title, version, edition — and, critically, a decision about whether the thing requires a licence at all. A great deal of what discovery returns is a runtime, a driver, a browser plug-in or a component that ships as part of something else. Counting those as licensable is the fastest way to produce a compliance position that is wrong in your own disfavour.

Done by hand, this needs someone who knows each publisher’s product line well enough to make those calls, and it has to be redone every time the inventory changes.

CerteroX SAM does it against the Software Recognition Database, which holds more than 3.5 million normalised titles with centrally maintained categorisation. Publisher normalisation and version recognition are applied automatically, software identification (SWID) tags are read where they exist and classified against UNSPSC, and the Software Recognition Service adds each title’s release date, end-of-support date and extended support date. That last part matters more than it sounds: knowing a version is out of support is a licensing and a security fact at the same time.

Stage two: understanding how the software is used

It is not enough to count how many times a product has been deployed. You need to know whether the installs are being used, how often, and under what conditions — because the conditions change the number of licences you owe.

The questions worth asking are always the same:

  • Does it matter whether the software runs on a physical or a virtual server?
  • Is it licensed per device, per install, per processor, per core or per user — what are you actually counting?
  • How do clustering and dynamic virtualisation affect the entitlement?
  • Is it being delivered from Citrix, a Terminal Server or an application virtualisation environment?

In 2016 these were open questions you took to a consultant. They are answered in the product now.

Usage is measured rather than assumed. AppsMonitor meters software at file level with first-used and last-used tracking, and the % Used metric reports utilisation over a rolling 90-day window, so an install nobody has opened since March is visible as exactly that. Terminal Server and RDS remote usage is tracked per device, which is what makes shared-delivery environments countable at all.

The counting unit is handled per publisher, by an engine that knows that publisher’s rules. Microsoft server licensing is modelled with device CALs, user CALs, named users and external connectors alongside SQL Server and Windows Server core and processor licensing, with cluster and virtualisation awareness. Oracle carries processor types and core factors, options and packs with evidence and override, licence pools with hosting rights and geographic rules, and cover-down logic for Enterprise Edition. IBM sub-capacity is measured on PVU and Virtual Processor Core metrics, with the 30-minute inventory cycle sub-capacity licensing actually requires — not a daily snapshot that IBM will not accept.

Citrix, RDS and VDI streamed applications are handled through Access Control rules, so a published application is licensed against the people entitled to launch it rather than every device that can see the icon.

Stage three: matching entitlement to the normalised inventory

With deployment normalised and usage understood, you have a requirement. Now you apply what you own to it.

This is where the entitlement detail earns its keep. Downgrade and down-edition rights let a licence for a newer or higher edition cover an older or lower one. Second-use rights cover the same person running the same software on a second machine. And a meaningful share of what discovery finds should not be counted at all — developer machines under MSDN, training rigs, test environments and second-use devices are all legitimately excluded, but only if the exclusion is recorded and evidenced rather than applied by someone’s memory.

CerteroX SAM computes this as an Effective Licence Position: purchased, used, available, required, variance and exposure, per product. It calculates both directions of error, because there are two — additional licences required where you are short, and overspend where you are not. Downgrade rights and second-use entitlement are applied by the engine, and the Exclude From Licensing workflow records MSDN, development, training and second-use devices as deliberate, auditable decisions.

The important difference from the manual method is that the position is continuous rather than point-in-time. Deployment changes daily. A compliance position calculated in a spreadsheet is accurate on the day it was built and decaying from the next morning.

The same problem, now off the device

This article was written when “installed software” covered nearly everything you had to license. It no longer does.

A growing share of your software is never installed anywhere. It is reached in a browser, bought on a card, and entitled per named user in a vendor’s own console. The three stages have not changed, but the data source has: entitlement comes from the vendor’s API rather than a purchase order, and deployment is a seat assignment rather than an install record.

CerteroX SaaS Management works the same way against that data. Forty-seven connectors shipping today pull the authoritative user and licence list straight from each vendor, so purchased and assigned counts come from the system of record rather than a reconciliation. Unused licence detection flags seats with 30 or more days of zero usage — the SaaS equivalent of an install nobody opens — and reclamation, reassignment and tier downgrade are actions you take from the same screen.

The principle holds either way. You cannot match entitlement to deployment until you trust both sides of the comparison.

To see an effective licence position calculated rather than estimated, book a demo.

Related reading

Other posts covering the same ground.

  • Why good IT asset discovery is essential for SAM

    Most SAM programmes are built on Active Directory and an agent deployment, which means they are built on a list that is already wrong. Discovery is not a preliminary step to software asset management — it is the foundation the rest of it stands on.

    • ITAM
    • SAM
    5 min
  • Getting More From Your Microsoft SCCM Investment

    SCCM is good at what it was built for and was never built for software asset management. You do not have to throw it away to close the gap — but you do have to know precisely where the gap is.

    • ITAM
    • SAM
    7 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.