Microsoft announced a new enterprise licensing option in late 2016 that pulled
several previously separate purchases into one SKU: Secure Productive
Enterprise. It combined productivity, device operating system, identity and
security into a single line, and it was pitched squarely at organisations
worried about the security implications of moving to the cloud.
The offer was itself a renaming and repositioning of the Enterprise Cloud Suite,
which had bundled the same broad categories with a lighter security story.
What was in Secure Productive Enterprise?
SPE came in E3 and E5 editions, and each was a bundle of three things:
- Office 365 — the productivity applications and services, at the matching
E3 or E5 level
- Windows 10 Enterprise — the desktop operating system, at E3 or E5
- Enterprise Mobility + Security (EMS) — identity, device management and
information protection, at E3 or E5
The E5 tier was where the security argument lived. Alongside the E3 contents, it
brought in capabilities Microsoft was then selling separately:
- Windows Defender Advanced Threat Protection, for detecting breaches at the
endpoint rather than only preventing them at the perimeter
- Microsoft Cloud App Security, for finding and controlling the SaaS
applications employees were already using
- Azure Information Protection, for classifying and protecting documents so
that controls travel with the file
- Office 365 Advanced Security Management, for visibility and control over
activity inside the tenant
Taken together, this was Microsoft’s answer to a specific objection: that moving
to cloud productivity meant giving up control. The bundle put detection,
classification and shadow IT discovery in the same purchase as the thing being
protected.
Editor’s note, July 2026. Almost every proper noun above has since
changed, and the SKU itself no longer exists under this name. Secure
Productive Enterprise was announced as the successor to the Enterprise Cloud
Suite in October 2016; Microsoft renamed it again to Microsoft 365
Enterprise during 2017, which is what E3 and E5 mean today. The components
were renamed too: Windows Defender ATP is now Microsoft Defender for Endpoint,
Microsoft Cloud App Security is now Microsoft Defender for Cloud Apps, Azure
Information Protection now sits under Microsoft Purview Information
Protection, and Office 365 Advanced Security Management was folded into the
Cloud App Security product. The post is kept because the licensing question it
raises outlived every one of those names.
The licensing question a bundle creates
Bundles are attractive for a reason. One negotiation, one renewal date, one
line on the invoice, and a materially better rate than buying the parts
separately. For most organisations that is the right commercial decision.
It also creates a specific and durable problem: bundles conceal utilisation.
When identity, device management, threat detection and information protection
are all separate purchases, nobody buys them without a reason. When they arrive
inside one SKU, they arrive whether anyone deploys them or not. Three things
follow, and they were as true of SPE in 2016 as they are of Microsoft 365 E5
today.
Entitlement you own and do not use. An organisation on the higher tier is
entitled to the advanced security components. Whether they were ever configured
is a separate question, and one that frequently goes unasked for years. That is
not a compliance exposure — it is the opposite. It is capability you have
already paid for sitting idle, often while a separate budget line buys a
third-party product that does the same job.
Users on the wrong tier. Bundle tiers are assigned per user, and assignment
tends to be done in bulk at the start and rarely revisited. Populations change,
roles change, people leave. The tier does not follow them.
Assessment becomes harder, not easier. With separate SKUs, reconciling
entitlement against deployment is tedious but direct. With a bundle, the
question becomes which components each licensed user is entitled to, which are
actually deployed to them, and which they use — three different numbers that a
purchase record cannot answer on its own.
What to do about it
This is precisely the work software asset management exists to do, and it is the
part the original post left implicit.
Establish the position from the publisher’s own record. CerteroX SAM imports
the Microsoft Licence Statement, and holds volume licence, retail, OEM and FPP
transactions alongside agreements, maintenance and subscription expiry dates.
The Effective Licence Position is computed continuously — purchased, used,
available, required, variance, exposure — rather than assembled the week an
audit letter arrives.
Measure use, not just installation. AppsMonitor meters usage from the file
level up, with first-used and last-used tracking and a % Used utilisation figure
over a rolling 90-day window. That is the number that distinguishes a licence
somebody needs from a licence somebody has.
Watch the subscription seats specifically. CerteroX SaaS Management pulls
authoritative user and licence lists directly from Microsoft 365 through the
vendor connector, cross-references identity provider data from Entra ID, and
flags licences with 30 or more days of zero usage. Available actions are
explicit — reclaim, reassign, downgrade tier, archive, remind or dismiss — and
run through a workflow engine rather than a spreadsheet and a series of emails.
Close the leavers gap. The offboarding checklist tracks every licence a
departing user held and the revocation status of each, with the monthly cost of
whatever is still open. In practice this is where a lot of bundle spend quietly
goes: the identity is disabled on day one and the seats are not.
Do not forget the server room. Microsoft licensing complexity does not stop
at the desktop bundle. CerteroX SAM handles device and user CALs, named user and
external connector licensing, and SQL Server and Windows Server core and
processor licensing with cluster and virtualisation awareness. That is usually
where the larger exposure actually is.
The bundle is a good deal when you use what is in it. Knowing whether you do is
not a procurement question, and it is not answerable from the agreement.
If the Microsoft position is the one you would argue with, book a
demo — the session is built around that publisher.