Skip to content

By vendor exposure
Cores, CALs and the MLS

The hard part of Microsoft licensing
is the server room.

Device CALs, user CALs, named user and external connectors, alongside SQL Server and Windows Server core and processor licensing with cluster and virtualisation awareness, all reconciled against the Microsoft Licence Statement as Microsoft itself issues it.

Answered on one platform. One data model across ITAM, SAM, SaaS, Cloud and AI.

Microsoft position

Illustrative

By product · reconciled against MLS

Cluster and virtualisation aware

Windows Server 2022 Datacenter per core, cluster-wide
512 required
SQL Server Enterprise per core, passive failover applied
variance −24
Windows Server CAL (device) devices accessing the servers
4,180 / 4,000
RDS CAL (user) access control rules applied
900 / 1,200
Microsoft 365 E5 no activity in 30+ days
318 idle

Entitlement source

Microsoft Licence Statement, imported

The problem

Desktop licensing is a counting problem. Server licensing is a modelling problem.

The CAL count and the cluster count both have to be computed from topology and access rules that no purchase order records.

  1. 01 who reaches the server

    A CAL exists only as a right of access.

    It is derived from which devices or users touch which servers. No inventory agent will ever find one, which is why CAL positions are so often a guess with a purchase order attached.

    Assignment types: per device, per processor, per core SAM

  2. 02 cores, clusters, movement

    You licence every host a VM could move to.

    Core licensing in a virtualised cluster depends on topology and mobility rights. Model it wrong in either direction and you are either exposed or paying for hosts that never run the workload.

    SQL Server and Windows Server core and processor licensing with cluster and virtualisation awareness SAM

  3. 03 the purchase record

    The MLS stops at what you bought.

    Reconciling it by hand against what you deployed, across agreements, downgrade rights and second use, is where Microsoft true-ups quietly become negotiations you lose.

    Microsoft Licence Statement (MLS) import SAM

  4. 04 the seats nobody opened

    Several hundred E5 licences have not been used in a month.

    Subscription is the easiest Microsoft money to recover and the least often recovered, because seat assignment lives in a different console from everything else you licence.

    Unused licence detection at 30+ days of zero usage SaaS Management

  5. Microsoft exposure concentrates in four places that need a model: cores, clusters, CALs and subscriptions.

Customer

“Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.”

NHS South West London ICB Reece Emson, ITAM Asset/PSL Manager Healthcare
Microsoft compliance risk mitigated
£100k
of SAM maturity accelerated
3–4 yrs
Read the case study

Recognition

The only vendor named Customers’ Choice in the 2024 Gartner® Peer Insights™ Voice of the Customer for Software Asset Management Tools.

Customers’ Choice in the category: 2019, 2020, 2021, 2024

Read the announcement

GARTNER is a registered trademark and service mark, and PEER INSIGHTS is a trademark and service mark, of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates.

How it is actually done

How the Microsoft position is built.

Inventory feeds the model, the MLS feeds the entitlement, and access rules decide the CALs.

  1. Take the inventory from the systems you already run

    SCCM, Intune, WSUS and Active Directory all feed the same model.

    • SCCM interface — import and drive SCCM applications, packages and jobs ITAM
    • Active Directory import of users, groups, computers, sites and subnets ITAM
    • Native inventory agent for Windows, macOS, Linux, AIX, HP-UX and Solaris ITAM
    • Non-persistent VDI inventory support ITAM
  2. Model the server room

    Cores, clusters and access rights are the three things a count cannot give you.

    • SQL Server and Windows Server core and processor licensing with cluster and virtualisation awareness SAM
    • Assignment types: per device, per processor, per core SAM
    • Access Control rules for RDS, Citrix and VDI streamed-application licensing SAM
    • Terminal Server and RDS remote-usage tracking per device SAM
  3. Reconcile against the statement

    The MLS imported, then matched line by line against what is deployed.

    • Microsoft Licence Statement (MLS) import SAM
    • Volume licence, retail, OEM and FPP transaction capture SAM
    • Downgrade rights and second-use entitlement handling SAM
    • Exclude From Licensing workflow for MSDN, dev, training and second-use devices SAM
  4. Recover the subscription waste

    The fastest money on this page, and the part that sits outside SAM in most organisations.

    • Connector sync pulling authoritative user and licence lists from the vendor SaaS Management
    • Unused licence detection at 30+ days of zero usage SaaS Management
    • Actions: reclaim, reassign, downgrade tier, archive, remind, dismiss SaaS Management
    • Offboarding checklist per user with per-licence revocation status SaaS Management

Ask to see any one of these running in the product itself, on the screen where it happens.

The licence model

The Microsoft licence model, term by term.

The desktop is where the volume is. These are the places where the money is.

Device and user CALs

How the publisher counts A CAL is a right of access, derived from who or what reaches a server, and no agent can inventory one.

What the engine does Device CALs, user CALs, named user and external connectors modelled as assignment types.

Core and processor licensing

How the publisher counts Windows Server and SQL Server are licensed by core, with minimums and per-host rules.

What the engine does Core and processor licensing computed from inventoried host topology.

Clusters and virtualisation

How the publisher counts Mobility means a workload can require entitlement on hosts it is not currently running on.

What the engine does Cluster and virtualisation awareness across VMware, Hyper-V, Citrix XenServer and Nutanix.

Microsoft Licence Statement

How the publisher counts The MLS is Microsoft’s record of what you purchased, in Microsoft’s vocabulary.

What the engine does MLS import, reconciled against deployment so the statement becomes a position.

Downgrade rights and second use

How the publisher counts Entitlement often covers older versions and a second device, and organisations routinely fail to claim it.

What the engine does Downgrade rights and second-use entitlement handling applied before exposure is reported.

RDS, Citrix and VDI

How the publisher counts Streamed and remote applications are licensed by who can access them, which is why RDS, Citrix and VDI sessions need access rules of their own.

What the engine does Access Control rules for RDS, Citrix and VDI streamed-application licensing, with per-device remote usage.

Microsoft 365 subscriptions

How the publisher counts Seats are assigned in a different console from everything else and renew whether used or not.

What the engine does Connector sync for authoritative seat lists, plus unused licence detection at 30+ days of zero usage.

Every capability in the right-hand column ships across CerteroX SAM and CerteroX SaaS Management.

The end state

What good looks like.

Microsoft is the publisher most organisations think they have covered. These are the five tests.

  1. 01

    The CAL position is derived from access.

    Device CALs, user CALs and external connectors modelled from who and what actually accesses the servers, including remote and streamed access.

  2. 02

    Cluster licensing matches the cluster.

    Core and processor entitlement computed against inventoried topology, with mobility rights modelled host by host across VMware, Hyper-V, Citrix XenServer and Nutanix.

  3. 03

    The MLS becomes a position.

    Imported, matched to deployment, and combined with volume, retail, OEM and FPP transactions so the entitlement picture is complete.

  4. 04

    You claim the rights you already paid for.

    Downgrade rights, second use, and MSDN or lab exclusions applied with evidence. These are the adjustments that most often turn an exposure into a surplus.

  5. 05

    M365 seats are managed like licences.

    Authoritative seat lists from the vendor, idle-seat detection at thirty days, and reclamation that runs to completion inside the same platform that holds the server position.

Microsoft, specifically

Questions worth asking us.

Not the one you came with? Ask it directly and we will answer it in writing.

We have SCCM. Does that not already tell us our Microsoft position?

SCCM tells you what is deployed on the devices it manages, which is one of the four inputs. It does not hold entitlement, it does not model core licensing across a cluster, and it cannot derive a CAL requirement. CerteroX imports from SCCM and drives SCCM applications, packages and jobs, then does the licensing work on top.

How do you calculate CALs when nothing installs a CAL?

From access: which devices and which users reach which servers, including remote and streamed sessions through RDS, Citrix and VDI, with Access Control rules deciding how streamed applications are licensed. That is why per-device remote usage tracking matters: it is the evidence behind the number.

Can you import our Microsoft Licence Statement?

Yes, MLS import is a first-class capability. It is reconciled against deployment alongside volume, retail, OEM and FPP transactions, so the statement becomes an entitlement position you compute against during a true-up, with downgrade rights and second use already applied.

Does this cover Microsoft 365 as well as on-premises?

Both, on one platform. CerteroX SaaS Management holds the connector for authoritative seat lists, idle-seat detection and reclamation, while CerteroX SAM holds the perpetual and server-side position. Same asset model, so an M365 seat and a Windows Server core appear in the same inventory.

Our developer and lab machines distort everything. Can they be separated?

That is exactly what the Exclude From Licensing workflow is for. MSDN, development, training and second-use devices are excluded with a recorded reason and an entitlement behind them, so the production position is clean and the exclusion is defensible.

Microsoft, specifically

See the statement reconciled
and the server room modelled.

An MLS import reconciled against the agreements, core and CAL licensing modelled across a cluster, and the idle Microsoft 365 seats on the same asset record. Say whether servers, CALs or subscription hurts most and the session leads with it.

Come with the true-up you are dreading. That is the conversation worth having.