Skip to content

Understanding Your Software Use Rights

Buying a licence does not make you the owner of the software. It grants you a right to use it under conditions — and those conditions are where both your compliance risk and your unclaimed value are hiding.

When you buy a software licence, you do not own the software the way you own almost anything else you purchase. What you have bought is a right to use it, subject to restrictions.

Those restrictions are set out in the End User Licence Agreement, and they are your software use rights. They are legally binding, and they typically cover things like:

  • Where you can use the software — country or region
  • What you can run it on — desktop, laptop, mobile, tablet, server, virtual machine
  • How long you can use it for — perpetual, or time-limited

The part that gets overlooked is that use rights run in both directions. Most people read them as constraints, which they are. They are also entitlements. A close reading tells you the rules you must follow to stay compliant, and it tells you every way you might extract more value from a contract you have already paid for.

Organisations routinely buy licences they already own the right to use. That is not a licensing failure. It is a reading failure.

The most common software use rights

The terminology varies between publishers, but a handful of mechanisms recur often enough to be worth knowing by name.

Software upgrade

Allows you to move to the latest version at no additional cost, within a defined period. This right usually comes with a subscription agreement, or with some form of maintenance purchased on top of perpetual licences.

Example — active Microsoft Software Assurance can enable an upgrade to a newer version, provided it is the same edition. Version and edition are not interchangeable words in a licence agreement, and the difference between them is frequently where the finding comes from.

Software downgrade

The opposite right: permission to run an older version than the one you have licensed. Publishers want you on the latest release, so downgrade rights are granted rather than assumed.

You would typically use this where you maintain a standard desktop image and have just renegotiated an agreement under which the version you actually deploy is no longer available to buy.

Example — your standard build is Windows 10, but the licences you can now purchase are Windows 11. Downgrade rights let you buy what is available and run what your hardware and applications are currently certified for, until you are ready to move.

Check this one carefully. Some subscription services remove downgrade rights altogether, so what was true of your last perpetual agreement may not be true of the subscription that replaced it.

Virtualisation rights

These allow you to run multiple installations across virtual machines while paying for a reduced volume of licences — or, depending on the publisher, they define exactly how many licences a virtualised deployment consumes.

This is a minefield and a major source of compliance exposure. Server virtualisation and dynamic provisioning save money on hardware, and those savings can be wiped out several times over by licensing, because you are effectively multiplying licensable instances every time a workload moves.

The specific traps differ by publisher. Oracle cares about processor type, core factor and whether a licence pool covers a host down through the cluster. IBM cares about whether you can evidence sub-capacity at all. Microsoft cares about cores, clusters and which edition you licensed the host with.

This is one of the few places where the answer genuinely does depend on tooling, because the underlying facts change faster than anyone can record them manually. CerteroX SAM handles the publisher-specific mathematics directly: Oracle processor types and core factors, licence pools with hosting rights and geographic rules, cover-down logic for Enterprise Edition; IBM PVU and Virtual Processor Core metrics with an ILMT connector; Microsoft SQL Server and Windows Server core and processor licensing with cluster and virtualisation awareness. Underneath it, CerteroX ITAM connects to VMware, Hyper-V, Citrix XenServer, Nutanix, Oracle VM, Red Hat oVirt and IBM HMC, so the host-to-guest relationships the licence calculation depends on are actually known rather than inferred.

Secondary use

Allows you to install the software on both a desktop and a laptop, for the same user, and count it as a single licence.

Straightforward in principle. Frequently missed in practice, because inventory counts installations and nobody has told it which two installations belong to the same person.

Disaster recovery use

Typically allows a copy of the software on both your production and your standby or disaster recovery servers, while consuming one licence.

The conditions attached vary considerably: how long the standby may run, whether it may be powered on at all, whether periodic failover testing counts as production use. Read them before you build the architecture, not after.

Multiple installations

Allows the same application to be installed on one device several times — usually different versions — while counting as a single licence.

Where use rights are actually applied

Knowing your rights is one thing. Making sure the licence position reflects them is another, and this is where most of the value leaks away. A calculation that ignores your entitlements will overstate what you need to buy, every quarter, quietly.

In practice that means three things have to happen inside the licence calculation rather than in a spreadsheet next to it.

The entitlements have to be modelled. Downgrade rights and second-use entitlement are handled as part of the effective licence position in CerteroX SAM, so a device covered by an existing right is not counted as a shortfall.

The exceptions have to be recorded. Installations that should not consume a licence — MSDN and developer machines, training environments, second-use devices — go through an Exclude From Licensing workflow, so the exclusion is explicit, attributable and defensible when an auditor asks why a machine was not counted.

Access has to be reflected. Where applications are streamed or published through RDS, Citrix or VDI, who can actually launch the application matters more than which image it appears in. Access Control rules apply the licensing consequence of that, rather than assuming that every user of a shared desktop needs a licence for everything installed on it.

The point of doing this properly is not tidiness. It is that every one of these rights represents licences you would otherwise buy again.

Subscription and SaaS terms

The article above was written about installed software, and the mechanisms it describes are mostly artefacts of the perpetual licensing world. Subscriptions behave differently, and the difference is not always in your favour.

Downgrade rights are commonly removed. Secondary use is often replaced with a device limit per user, which is a similar idea with a harder edge. Disaster recovery provisions may not exist in any recognisable form, because the service is the provider’s to run.

What replaces them is a different set of questions: how many named users are provisioned versus how many are active, what happens to access when someone leaves, what a mid-term reduction in seats costs you, and what the renewal terms say about reducing quantity at all. Those are use rights too. They are just enforced by the contract and the provisioning system rather than by a licence key.

Read the agreement

Understanding your use rights is essential to staying in control, and to getting the full benefit of agreements you have already signed. It is not easy, and it is not a one-off exercise — the rights change with each renegotiation.

If you would like help, get in touch.

Related reading

Other posts covering the same ground.

  • Certero Insider Newsletter – July 2025

    The licensing changes that mattered in June and July 2025 — Microsoft Product Terms, the return of the SAMOSA Act, the end of the Microsoft 365 nonprofit grant, Adobe's AI credit cuts, a Dutch ruling against Broadcom, and rising Oracle Java audit activity.

    • ITAM
    • SAM
    • SaaS
    • Governance
    10 min
  • Software Asset Management Plan

    A six-step plan for building a SAM programme that covers on-premises, SaaS and cloud as one problem rather than two — scope, maturity, people and technology, accountability, and what to do first.

    • ITAM
    • SAM
    • SaaS
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.