Skip to content

The Top 5 Power-Plays to Optimise Your Microsoft Licensing

Five places Microsoft spend leaks — Microsoft 365 subscriptions, Windows Server Datacenter cores, Azure Hybrid Benefit, SQL Server editions and over-estimated Enterprise Agreements — and what it takes to close each one.

Your annual spend with Microsoft has probably been climbing for years, and shows no sign of levelling out. The question worth asking is not whether the number went up. It is whether the business value you get from Azure, Microsoft 365 and your Enterprise Agreement went up at the same rate.

Most of the time it has not, because Microsoft licensing rewards precision and punishes approximation. Below are five places the money leaks, ordered roughly from quickest win to biggest strategic gain.

1. Microsoft 365 subscriptions

If you only act on one item here, make it this one. It is the fastest to execute and usually the largest single recovery.

Subscription licensing changes the management problem. A traditional volume agreement covering Office was a periodic true-up exercise. Microsoft 365 is a per-user, per-month obligation against a workforce that changes every week — joiners, leavers, role changes, contractors, project teams that stood up in March and quietly stopped meeting in June. Nothing about that is self-correcting. Seats stay assigned until somebody removes them.

The waste is substantial. 46% of SaaS licences go unused — the average organisation actually uses 54% of what it pays for. Microsoft 365 is rarely an exception, and because it is usually the largest single SaaS line, it is where the percentage costs the most.

CerteroX SaaS Management handles this directly. It detects licences with 30 or more days of zero usage, distinguishes cost per licensed user from cost per active user, and gives you the actions to resolve it — reclaim, reassign, downgrade the tier, archive or remind. Renewals surface with days-to-renewal alongside the utilisation rate, so you go into the conversation knowing what you actually consume rather than what you bought last time.

Two things matter more than the headline saving. The first is that discovery converges from three independent signals — your identity provider, the vendor APIs and a browser extension — so the picture does not depend on any single source being complete. The second is offboarding. A leaver’s Microsoft 365 licence usually gets removed on day one because it is the visible one. The Figma, Notion and Linear seats often do not, and neither does the OAuth grant that still has read access to a shared drive. The offboarding checklist tracks every licence a user held, the revocation status behind each, and the monthly cost of whatever is still open.

2. Windows Server Datacenter cores

The shift to core-based licensing on Windows Server caused a great deal of confusion, and the confusion mostly ran in one direction: organisations acting in good faith and ending up over-licensed in the data centre.

The arithmetic is not intuitive. Core licensing interacts with physical processor counts, minimum core requirements per processor and per server, virtualisation rights and cluster behaviour. Get any of those assumptions wrong across a large environment and the error multiplies quietly.

CerteroX SAM models Windows Server and SQL Server core and processor licensing with cluster and virtualisation awareness, which is the part generic tools skip. The hard part of Microsoft licensing has always been the server room, not the desktop.

One related point worth acting on separately: we still see a great deal of Microsoft data centre software running past end of support. That is a security exposure independent of any licensing question. End-of-life and end-of-support lifecycle tracking is part of the same product, and the Software Recognition Service carries release date, end-of-support and extended-support dates against recognised titles — so this is visible without a separate exercise.

3. Bring Your Own Licence and Azure Hybrid Benefit

Almost every organisation running Microsoft products in Azure ran Microsoft products on-premises first. Depending on the agreement type and whether Software Assurance is active, some of those existing licences can cover cloud consumption through Azure Hybrid Benefit. Some cannot.

Getting this right reduces Azure cost. Getting it wrong creates compliance exposure in the one environment where consumption is metered and logged in detail. Both outcomes come from the same gap: you cannot make a confident decision about applying an on-premises licence to a cloud workload unless you can see both sides of that equation in one place, with the entitlement position and the deployment position reconciled against each other.

Microsoft Exchange is the example that comes up most often — usage rights during a transition from on-premises to cloud are where the meaningful savings and the meaningful risks both live.

There is a second, less-discussed version of the same problem. Organisations routinely fail to exercise licensing rights they already hold, running older versions when they are fully entitled to current ones. Downgrade rights and second-use entitlement handling are part of the licence engine precisely because these rights are worth money and are almost never tracked manually.

4. SQL Server

SQL licensing goes wrong for a specific and fixable reason: the inventory underneath it cannot reliably distinguish between versions and editions.

If your discovery tool reports “SQL Server” without resolving edition, you end up over-licensed on Standard and dangerously under-licensed on Enterprise at the same time. Neither is a good outcome, and the second one is the expensive one. Clustering compounds it further, because failover and high-availability configurations have their own licensing treatment that a flat install count cannot represent.

This is a recognition problem before it is a licensing problem. CerteroX SAM resolves it against the Software Recognition Database — 3.5 million+ normalised publisher, product and version titles — with publisher normalisation and version recognition, so the licence engine is reasoning about the actual editions deployed rather than a generic product name.

Once you can see the editions accurately, a second question usually follows: is the right type of SQL deployed for the use case? In our experience it frequently is not, and that is a cost conversation as much as a compliance one.

5. Over-estimating your Enterprise Agreement

This one is a classic and it has not gone away. Customers treat an Enterprise Agreement as unlimited, and fulfil software requests without checking what the agreement actually covers.

The standard example is Visio. The EA covers Visio, so the service desk fulfils a request with Visio Professional — which is not covered. The moment that happens you are non-compliant, and it stays that way until somebody notices. At true-up, they notice.

Two things follow from this. Having an EA does not exempt you from a Microsoft audit. And mis-managed software assets always catch up with you, because the evidence of the mis-management is sitting on the endpoints the whole time.

The controls that prevent it are unglamorous and effective: application blacklisting and prohibition rules, governance policies for unauthorised software, and an audit trail across agreements, transactions and exclusions so the position is defensible when it is questioned.

Where this leaves you

Broadly, organisations fall into two groups. Those who want to optimise software costs but do not have the time, skills or people to do it. And those who want to build an internal capability and run it themselves. Both are legitimate. They need different things.

If you have an in-house SAM team

Software asset management needs three components working together: knowledgeable people, mature processes and automated technology. CerteroX SAM covers the technology side for Microsoft licensing at enterprise scale:

Complete discovery and inventory. Ten discovery methods — agent, command-line, agentless, standalone, Active Directory, network scan, third-party import, cloud connector, browser monitoring and file metering — landing in one schema. There is no reconciliation project because there is nothing to reconcile.

Automated software recognition. The Software Recognition Database identifies what your discovered software actually is, with publisher normalisation, version recognition and SWID tag support.

Licence reconciliation. Microsoft licensing rules and rights are built into the engine, so your Effective Licence Position — purchased, used, available, required, variance, exposure — is computed continuously rather than reconstructed the week an audit letter arrives. Microsoft Licence Statement import brings your entitlement in cleanly.

Software usage metering. AppsMonitor tracks first-used and last-used per title, with a percentage-used metric over a rolling 90-day window. That is the evidence you need to safely reharvest licences into a pool rather than guessing at it.

Reporting you control. One platform, one data source, a read-only API and a documented Power BI data source. The philosophy is that all your data has value, so you should be able to ask your own questions rather than choose from someone else’s report list.

Cloud and multi-cloud. CerteroX Cloud Management extends the same visibility to IaaS and PaaS across twelve cloud and data platforms, with twenty-six named optimisation checks and pool-based showback and chargeback. It is a FinOps Certified Platform.

Even well-staffed teams often bring in outside expertise for the high-cost, high-risk publishers — Oracle, IBM and SAP — or for the long tail of tier 2 and 3 vendors, which carry less commercial risk but still need understanding and supporting.

If you have little or no internal SAM capability

A managed service is the sensible route, but it has traditionally carried one significant drawback: you never really own the intelligence you are paying for. You receive a position, you cannot interrogate it, and if you lack the capability to act on it, nothing changes.

The model we run inverts that. You own your own IT asset intelligence, and the service works as an extension of your team to drive the changes rather than only reporting the position.

NHS South West London ICB describes the outcome this way:

Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.

— Reece Emson, ITAM Asset/PSL Manager

Their published outcomes were £100k of Microsoft compliance risk mitigated and three to four years of SAM maturity accelerated.

If you have already had notice of intent to audit, that is a different and more urgent engagement — act on it as soon as the letter arrives, because the early decisions shape the whole process.


Whichever route fits, the five items above are where the money is. To see each of the five worked through in the product, book a demo.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.