Skip to content

How virtualisation and usage monitoring affect a software audit

Virtualisation changed how software is licensed, not just how it is deployed. Add usage-based metrics and indirect access, and the gap between what you run and what you owe gets very expensive.

Virtualisation is mature, universal and almost invisible as a decision now. It is also one of the most reliable sources of audit exposure in enterprise software, because the licensing rules never settled down at the same rate the technology did.

The core problem is straightforward to state and difficult to manage: unless you understand how each publisher treats virtual environments, and can show your position at any moment, you can end up paying more in additional licences and settlement costs than virtualisation ever saved you.

What is the licensing risk?

Virtualisation divides physical resources into multiple execution environments. That broke the assumption most licensing metrics were built on — one installation, one machine, one countable thing — and publishers have been rewriting metrics to protect revenue ever since.

Every publisher’s rules differ between physical and virtual deployment. Terminology, metrics and definitions vary by publisher and by virtualisation technology, and publishers amend their own rules over time. You need to understand what your agreements actually say and how each set of rules applies to the specific platforms you run. Where the wording is ambiguous, it is worth getting more than one expert reading of it before you rely on your own.

The changes that most often move a licence position:

  • Hardware changes. Adding servers or CPUs to a cluster can change what is licensable well beyond the workload you added.
  • Server mobility. DRS and vMotion, once enabled, can multiply licensing requirements dramatically — because the rule is often about where a workload could run, not where it does.
  • Physical-to-virtual conversion. Converting changes the licensing basis. Model it before you migrate, not after.
  • Maintenance conditions. Some publishers attach conditions to server applications deployed in farms. Microsoft, for instance, requires active maintenance for certain server products in that configuration.

None of this can be assessed without knowing the relationship between each virtual machine and the physical host underneath it — which means your tooling needs connectors to every hypervisor and partitioning technology you run, not just the one that hosts most of the workloads.

CerteroX ITAM connects to VMware, Microsoft Hyper-V, Citrix XenServer, IBM HMC, Oracle VM, Red Hat oVirt and Nutanix, and the host-to-guest relationship it captures is what the licence engines in CerteroX SAM compute against. That matters most on the platforms where the maths is punishing: Oracle processor types and core factors, licence pools with hosting rights and geographic rules, cover-down logic for Enterprise Edition, and uncapped quantity handling for unlimited agreements. Microsoft server licensing is handled with the same cluster and virtualisation awareness across SQL Server and Windows Server core and processor metrics.

Monitoring usage

Depending on your licence terms, measuring usage may be essential — both to determine what you owe and to prove you stayed inside a limit.

SAP and Oracle both charge on business-specific metrics in places. A car manufacturer’s metric might be vehicles produced. Whatever the unit, you need a verifiable and repeatable way to measure it, for two reasons: working out what to pay, and demonstrating compliance with a preset ceiling.

Usage monitoring earns its keep in the other direction too. It finds non-use, which is where downgrade and reclamation opportunities live. On most software portfolios that is a larger number than the compliance exposure.

Tooling varies enormously here, and the difference is worth understanding. Some products require you to nominate individual applications for measurement, with limits on how many can be measured at once — which turns “measure our software usage” into a project that runs for months across thousands of titles.

CerteroX SAM measures all software usage continuously by default. AppsMonitor performs file-based metering with first-used and last-used tracking, and produces a percentage-used utilisation metric over a rolling 90-day window. Terminal Server and RDS remote usage is tracked per device, so streamed and published applications are not a blind spot. Access Control rules cover the RDS, Citrix and VDI cases where the licensing basis depends on who can reach an application rather than where it is installed.

Data centre publishers deserve specialist treatment rather than a generic count, and CerteroX SAM ships dedicated engines for six of them — Microsoft, Oracle, IBM, SAP, Adobe and Salesforce. For IBM that includes PVU and Virtual Processor Core metrics, an ILMT connector with compliance gap analysis, Component Resolution to match deployed components to products, and enforcement of the 30-minute inventory cycle that sub-capacity licensing actually requires. Miss that cycle and IBM is entitled to licence you at full capacity, which on a large cluster is the difference that ends the conversation.

Indirect access

On top of already-complicated agreements sits indirect usage — also called indirect access or multiplexing — and it produces some of the largest single audit findings in the industry.

Indirect access occurs when software is reached indirectly by parties the publisher has not been paid for, whether people or machines. The classic example: you build an expense system that every employee can use, and it writes to a second system through a single named service account. Every user of the expense system is an indirect user of the second one, and under a Named User metric each of them needs licensing.

Because SAP and Oracle both use Named User licensing, the exposure scales with your headcount rather than your architecture.

Classifying users correctly as direct or indirect is the whole game, and automated monitoring is what makes it tractable. Certain patterns are diagnostic: an account accessing a system continuously without a break, or processing a volume of transactions in a window no human could manage. Those are integrations wearing a person’s credentials.

CerteroX SAM approaches the SAP side with a non-invasive ABAP connector that reads named users de-duplicated across systems, along with roles, role groups, engines and authorisation definitions — without touching production. Priority-ordered analysis rules then propose the licence type each user should hold, so you can compare your current position, the suggested position and the optimal one side by side. That comparison is what an SAP negotiation actually needs.

On Oracle, one mitigation is to move to processor-based licensing rather than Named User, which decouples cost from the number of indirect consumers. SAP offers no direct equivalent, so there you are left with getting the user classification right and defending it.

Where this leaves you

Virtualisation, usage measurement and indirect access are three different problems, but they fail the same way: the position is knowable, nobody is computing it continuously, and the first accurate calculation happens under audit conditions with a deadline attached.

Tooling built for audit defence closes that gap by understanding the virtual environment, measuring usage without being asked, and surfacing the access patterns that indicate indirect use. CerteroX SAM does all three, and it computes the effective licence position continuously — purchased, used, available, required, variance and exposure — rather than reconstructing it the week the letter arrives.

The goal is unremarkable and very hard to achieve by hand: walk into the audit already holding the answer.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.