Skip to content

Microsoft Licensing Update — The Secure Productive Enterprise Offer

Microsoft bundled Office 365, Windows 10 Enterprise and Enterprise Mobility + Security into a single SKU in late 2016. The bundle has been renamed twice since, and the licensing problem it created has not changed at all.

Microsoft announced a new enterprise licensing option in late 2016 that pulled several previously separate purchases into one SKU: Secure Productive Enterprise. It combined productivity, device operating system, identity and security into a single line, and it was pitched squarely at organisations worried about the security implications of moving to the cloud.

The offer was itself a renaming and repositioning of the Enterprise Cloud Suite, which had bundled the same broad categories with a lighter security story.

What was in Secure Productive Enterprise?

SPE came in E3 and E5 editions, and each was a bundle of three things:

  • Office 365 — the productivity applications and services, at the matching E3 or E5 level
  • Windows 10 Enterprise — the desktop operating system, at E3 or E5
  • Enterprise Mobility + Security (EMS) — identity, device management and information protection, at E3 or E5

The E5 tier was where the security argument lived. Alongside the E3 contents, it brought in capabilities Microsoft was then selling separately:

  • Windows Defender Advanced Threat Protection, for detecting breaches at the endpoint rather than only preventing them at the perimeter
  • Microsoft Cloud App Security, for finding and controlling the SaaS applications employees were already using
  • Azure Information Protection, for classifying and protecting documents so that controls travel with the file
  • Office 365 Advanced Security Management, for visibility and control over activity inside the tenant

Taken together, this was Microsoft’s answer to a specific objection: that moving to cloud productivity meant giving up control. The bundle put detection, classification and shadow IT discovery in the same purchase as the thing being protected.

Editor’s note, July 2026. Almost every proper noun above has since changed, and the SKU itself no longer exists under this name. Secure Productive Enterprise was announced as the successor to the Enterprise Cloud Suite in October 2016; Microsoft renamed it again to Microsoft 365 Enterprise during 2017, which is what E3 and E5 mean today. The components were renamed too: Windows Defender ATP is now Microsoft Defender for Endpoint, Microsoft Cloud App Security is now Microsoft Defender for Cloud Apps, Azure Information Protection now sits under Microsoft Purview Information Protection, and Office 365 Advanced Security Management was folded into the Cloud App Security product. The post is kept because the licensing question it raises outlived every one of those names.

The licensing question a bundle creates

Bundles are attractive for a reason. One negotiation, one renewal date, one line on the invoice, and a materially better rate than buying the parts separately. For most organisations that is the right commercial decision.

It also creates a specific and durable problem: bundles conceal utilisation.

When identity, device management, threat detection and information protection are all separate purchases, nobody buys them without a reason. When they arrive inside one SKU, they arrive whether anyone deploys them or not. Three things follow, and they were as true of SPE in 2016 as they are of Microsoft 365 E5 today.

Entitlement you own and do not use. An organisation on the higher tier is entitled to the advanced security components. Whether they were ever configured is a separate question, and one that frequently goes unasked for years. That is not a compliance exposure — it is the opposite. It is capability you have already paid for sitting idle, often while a separate budget line buys a third-party product that does the same job.

Users on the wrong tier. Bundle tiers are assigned per user, and assignment tends to be done in bulk at the start and rarely revisited. Populations change, roles change, people leave. The tier does not follow them.

Assessment becomes harder, not easier. With separate SKUs, reconciling entitlement against deployment is tedious but direct. With a bundle, the question becomes which components each licensed user is entitled to, which are actually deployed to them, and which they use — three different numbers that a purchase record cannot answer on its own.

What to do about it

This is precisely the work software asset management exists to do, and it is the part the original post left implicit.

Establish the position from the publisher’s own record. CerteroX SAM imports the Microsoft Licence Statement, and holds volume licence, retail, OEM and FPP transactions alongside agreements, maintenance and subscription expiry dates. The Effective Licence Position is computed continuously — purchased, used, available, required, variance, exposure — rather than assembled the week an audit letter arrives.

Measure use, not just installation. AppsMonitor meters usage from the file level up, with first-used and last-used tracking and a % Used utilisation figure over a rolling 90-day window. That is the number that distinguishes a licence somebody needs from a licence somebody has.

Watch the subscription seats specifically. CerteroX SaaS Management pulls authoritative user and licence lists directly from Microsoft 365 through the vendor connector, cross-references identity provider data from Entra ID, and flags licences with 30 or more days of zero usage. Available actions are explicit — reclaim, reassign, downgrade tier, archive, remind or dismiss — and run through a workflow engine rather than a spreadsheet and a series of emails.

Close the leavers gap. The offboarding checklist tracks every licence a departing user held and the revocation status of each, with the monthly cost of whatever is still open. In practice this is where a lot of bundle spend quietly goes: the identity is disabled on day one and the seats are not.

Do not forget the server room. Microsoft licensing complexity does not stop at the desktop bundle. CerteroX SAM handles device and user CALs, named user and external connector licensing, and SQL Server and Windows Server core and processor licensing with cluster and virtualisation awareness. That is usually where the larger exposure actually is.

The bundle is a good deal when you use what is in it. Knowing whether you do is not a procurement question, and it is not answerable from the agreement.

If the Microsoft position is the one you would argue with, book a demo — the session is built around that publisher.

Related reading

Other posts covering the same ground.

  • 5 Ways Software Asset Management Improves Your Business

    SAM is usually sold as audit insurance. It is also a security control, a cost-reduction programme, due diligence for an acquisition, and the only reliable basis for rationalising your applications.

    • SAM
    • Governance
    • Security
    7 min
  • Software Vendor Audits – 8 Things you need to know

    What an audit actually is, how it differs from a SAM review, what triggers one, and what you can do about it once the letter has arrived — including whether a completed audit can still be challenged.

    • SAM
    • Governance
    • Security
    9 min
  • The Rise in Oracle Java Audits: How to gain clarity

    Oracle asks to see your Java deployments before it will sell you more subscriptions. Why Java is the hardest thing in your environment to count, what the employee-based subscription changed, and how to build a deployment record you can actually defend.

    • SAM
    • Governance
    • Security
    6 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.