Microsoft enacted a cloud licensing change in 2019 that was going to cost some
customers a lot of money. It is worth understanding, because the reasoning behind
it has shaped every outsourcing rule Microsoft has written since.
As of 1 October 2019, Windows licences acquired without Software Assurance and
Licence Mobility rights could no longer be deployed on services offered by
“Listed Providers” — the named set of large public cloud providers, which
included Amazon Web Services, Google and Alibaba, as well as Microsoft itself.
According to Microsoft:
The emergence of dedicated hosted cloud services has blurred the line between
traditional outsourcing and cloud services and has led to the use of
on-premises licenses on cloud services. Dedicated hosted cloud services by
major public cloud providers typically offer global elastic scale, on-demand
provisioning and a pay-as-you-go model, similar to multi-tenant cloud services.
Why did Microsoft do this? The cynical reading at the time was that with Azure
growth under pressure, Microsoft was looking to promote benefits such as Azure
Hybrid Use Rights to regain a competitive edge over Amazon, Google and Alibaba.
Whatever the motive, the effect was unambiguous: the licence you already owned
stopped being portable to a competitor’s dedicated hardware.
Who was affected?
The change hit organisations with a dedicated hosting arrangement at one of the
Listed Providers, running a BYOL — Bring Your Own Licence — model without active
Software Assurance.
The impact was not immediate. Existing deployments could continue. But any new
instance, and any version upgrade, required the purchase of new licences with
active Software Assurance. That is the detail that catches people out: nothing
breaks on day one, so nothing gets escalated, and the exposure accumulates
quietly until the first upgrade cycle.
Which products were affected?
The products most likely to be affected are Windows Server, SQL Server, and any
applications required alongside them. The definitive list is the one published in
Microsoft’s Product Terms — historically the Product Use Rights document — rather
than any summary of it, including this one.
What did it cost?
The cost impact depends on several factors: whether you are running legacy
licences in the dedicated hosting environment, which agreement types you hold
(transactional, Enterprise Agreement), and the price level you are entitled to.
The mechanism matters more than the arithmetic. If your deployments are not fully
covered by active Software Assurance, the cost lands the moment you upgrade or
buy new — because Software Assurance cannot be added retrospectively to licences
you already own. There is no catching up after the fact. You either had it, or
you buy the licence again.
Where this stands now
Treat everything above as a description of a specific change on a specific date,
not as the current rule. Microsoft has revised its outsourcing terms more than
once since 2019 — most substantially in October 2022, which introduced the
Flexible Virtualisation Benefit for customers with Software Assurance or
subscription licences deploying with Authorised Outsourcers. Listed Providers
remained carved out of that benefit.
The principle the 2019 change established has not moved: your rights on someone
else’s dedicated hardware depend on the currency of your Software Assurance and
on who is running the hardware. Before you act, read the current edition of the
Microsoft Product Terms. Do not act on a licensing blog post from any year,
including this one.
What you actually need to do
Further changes to Microsoft licensing will keep making an already complicated
management problem harder. The defence is unglamorous and it does not change: you
need to know what you have deployed with hosted and cloud providers, and what
licensing you hold to cover it. If you have Software Assurance and can prove it
covers the deployments, you are already in control.
If you cannot prove it — or you want to upgrade or deploy new instances in a
dedicated environment — you have a compliance and Software Asset Management gap
that needs closing before someone else finds it.
Closing it means two things being true at once, which is where most tooling
falls down.
You have to see the deployments. CerteroX ITAM inventories
across ten discovery methods and six operating system families, with connectors
for AWS, Microsoft Azure, VMware, Hyper-V and Citrix XenServer, so hosted and
virtualised workloads land in the same schema as everything on your own floor.
There is no separate cloud inventory to reconcile against the on-premises one,
because there is only one.
You have to hold the entitlement against them.
CerteroX SAM covers Windows Server and SQL Server core and
processor licensing with cluster and virtualisation awareness, device and user
CALs, and external connectors — with Microsoft Licence Statement import to bring
in what you have actually bought. Subscription flags with expiry tracking are
what turn “we think we have Software Assurance” into a date you can check, and
the Effective Licence Position is computed continuously rather than assembled the
week the question is asked.
If you are not certain what Microsoft software you have deployed or how it is
licensed, that uncertainty is the finding. Talk to us before an
upgrade forces the answer.