Microsoft 365 licence audit work is the least glamorous item on any IT improvement plan and, reliably, the one with the fastest payback. Nobody gets promoted for it. It produces no new capability, no launch email, no slide anybody wants to present. It simply stops money leaving the building every month for things nobody uses, and in most UK businesses that figure is far larger than anyone expects before they look.
The reason is structural rather than careless. Licences get bought in a hurry during a project, assigned to people who later leave, layered with add-ons that duplicate features already included in the base plan, and renewed automatically on a date nobody has in their diary. Every individual decision was defensible at the time. The accumulated result is a subscription bill that has drifted thousands of pounds a year away from what the business actually consumes, which is exactly the gap a Microsoft 365 licence audit exists to close.
This guide sets out how to do the work properly: what to count, where the waste consistently hides, which admin centre reports tell the truth, how to right-size plans without quietly stripping out security controls, and how to make the savings survive past the first quarter. If you are still choosing between plan tiers rather than trimming what you already own, our guide to Microsoft 365 licence tiers compared covers that ground instead.
One warning before you start. An audit that chases only the lowest possible number is a security incident with a spreadsheet attached. Several of the licences that look most redundant are the ones carrying multi-factor authentication policy, device compliance or retention. The goal is to pay for what you use, not to discover in nine months that you removed the control that would have stopped an intrusion.
Table of contents
- What a Microsoft 365 licence audit actually is
- Where a Microsoft 365 licence audit finds the waste
- How to run a Microsoft 365 licence audit step by step
- Reading the reports a Microsoft 365 licence audit depends on
- Right-sizing plans without losing capability
- The overlap trap: paying twice for the same capability
- What a Microsoft 365 licence audit typically saves
- Renewal timing and term commitments
- Making a Microsoft 365 licence audit stick
- Mistakes that ruin a Microsoft 365 licence audit
- Questions to ask before a Microsoft 365 licence audit
What a Microsoft 365 licence audit actually is
The phrase gets used loosely, so it is worth being precise. A Microsoft 365 licence audit is a structured reconciliation of three things that drift apart over time: what you are billed for, what is assigned inside the tenant, and what is genuinely being used. Waste lives in the gaps between those three numbers, and you cannot see any gap by looking at one number alone.
Billed versus assigned
Your invoice shows purchased quantity. The admin centre shows assigned quantity. When a person leaves and their account is deleted without the subscription being reduced, the licence returns to your available pool and you keep paying for it indefinitely. A pool of unassigned but purchased seats is the single easiest finding in any Microsoft 365 licence audit, and often the largest.
Assigned versus used
An assigned licence proves somebody has permission to use a service, not that they do. A user with a Business Premium seat who only ever opens Outlook on a phone is consuming a fraction of what you bought for them. This gap is slower to close because it requires judgement rather than arithmetic, but it is usually where the bigger long-term number sits, and a Microsoft 365 licence audit that skips it leaves most of the value on the table.
Entitled versus separately purchased
The third gap is the expensive one. Businesses routinely pay a third party for something their existing plan already includes — a backup product, a signature manager, a basic MDM tool, a conferencing service. A Microsoft 365 licence audit that stops at the Microsoft bill misses this entirely, because the duplicate spend appears on a different supplier’s invoice altogether.
Where a Microsoft 365 licence audit finds the waste
After enough of these exercises the same findings appear in nearly every tenant. Knowing them in advance turns a two-week investigation into a two-day one, because you are confirming a short list of suspicions rather than exploring a large surface with no map.
Leavers who never fully left
The classic finding. An employee departs, HR closes their file, IT blocks sign-in, and the licence stays assigned because blocking access and releasing a subscription are separate actions in separate places. Six leavers over a year at Business Premium rates is roughly £1,500 annually for accounts nobody can even sign into.
Shared and resource mailboxes given full seats
Shared mailboxes up to fifty gigabytes need no licence at all. So do room and equipment mailboxes. Yet they are frequently created by assigning a full user licence, because that is the path the setup wizard makes obvious. Every one of these found in a Microsoft 365 licence audit is a clean, zero-risk saving with no capability trade-off whatsoever.
Dormant accounts kept “just in case”
Contractor accounts, seasonal staff, the account created for a project that ended, the second account somebody uses for testing. These are usually defensible individually and indefensible collectively. Set a rule — no sign-in for ninety days means the licence comes off, the mailbox converts to shared, and the account is disabled rather than deleted.
Add-ons bought to solve a problem the plan already solved
Audio Conferencing purchased when Teams dial-in was already included at that tier. Extra storage bought while tens of terabytes sit unused. An archiving product bought alongside a plan that ships archiving. Effective IT asset management catches this at purchase; a licence audit catches it afterwards, at a cost of however many months have passed.
Everyone on the same plan because it was simpler
Standardising the whole business on one high tier is administratively tidy and financially blunt. Warehouse staff, part-time reception cover and field engineers rarely need what a finance director or systems administrator needs. Uniform licensing is comfort, and it is usually the most expensive comfort in the tenant.
How to run a Microsoft 365 licence audit step by step
The process below takes a competent administrator two to four days for a business under two hundred users, most of it waiting for reports rather than working. Follow the steps in order — a Microsoft 365 licence audit that starts by changing assignments instead of recording them loses its own baseline in the first hour.
Step one: export the subscription position
Start in Billing, then Your products. Record every subscription, quantity purchased, quantity assigned, unit price, billing frequency and renewal date. Do this before touching anything else, because it is the baseline every saving will later be measured against and it changes the moment you begin editing assignments.
Step two: export active users and last activity
The Reports section gives you per-user activity across Exchange, SharePoint, OneDrive and Teams. Microsoft documents these in the admin centre activity reports, and the export is the backbone of the whole exercise. Set the window to 180 days rather than 30 — a quarterly user looks dormant on a monthly view.
Step three: reconcile against a real people list
Pull the current employee list from HR or payroll, not from the tenant. Comparing the tenant against itself only tells you what the tenant already believes. Every account that does not map to a current person, a shared function or a documented service purpose becomes a candidate. This reconciliation is the part of a Microsoft 365 licence audit that people skip, and it is the part that finds leavers.
Step four: classify every account
Sort accounts into five buckets: active human, dormant human, leaver, shared or resource mailbox, and service or application account. Each bucket has a standard treatment. Only the dormant-human bucket needs a conversation with a manager; the other four are decisions you can make on the evidence alone.
Step five: identify duplicate tooling
List every software subscription the business pays for and mark anything whose function appears inside your Microsoft plans. Backup, MDM, conferencing, e-signature, basic DLP, password management and simple ticketing are the usual overlaps. Treat this as a vendor management exercise rather than a technical one, because the decision is commercial.
Step six: model the change before making it
Build the target state on paper first: who moves to which plan, which seats are released, which add-ons are cancelled, and what the monthly figure becomes. Modelling first is what separates a Microsoft 365 licence audit from a series of ad-hoc deletions that nobody can reverse or explain.
Reading the reports a Microsoft 365 licence audit depends on
The data is available to every administrator, which is precisely why it gets misread. Three cautions matter more than the rest, and each of them has caused a Microsoft 365 licence audit somewhere to remove access from someone who needed it.
Last activity date is not last sign-in
Activity reports measure service interaction, not authentication. A user can sign in daily to a line-of-business application through Entra ID and register almost no Exchange or SharePoint activity. Cross-check anything you intend to remove against sign-in logs before acting on it, or you will disable somebody’s working day.
Anonymised reports make reconciliation impossible
Many tenants have the privacy setting enabled that replaces usernames with anonymous identifiers in reports. It is a sensible default and it makes per-user analysis useless. Turn it off for the duration of the exercise, note that you have done so, and turn it back on afterwards.
Mobile-only users look inactive and are not
Someone who works entirely from Outlook and Teams on a phone generates a thin activity profile compared with a desktop user, because much of what desktop reporting counts never happens. Judge these users on the number of services they touch rather than the volume of activity within them.
Right-sizing plans without losing capability
This is where a Microsoft 365 licence audit earns its keep and where it most often goes wrong. Downgrades are not symmetrical with upgrades: moving down a tier can silently remove a control you depend on.
Map the controls, not just the apps
Before changing anyone’s plan, write down which security and compliance features you actively use — Conditional Access policy, Intune compliance, Defender for Office, retention labels, data loss prevention — and check which tier provides each. Apps are easy to compare. Controls are what actually break, and they break quietly.
Mix tiers deliberately
There is no requirement to license everybody identically. A frontline or deskless plan for staff who need email and Teams on a phone, a mid tier for most office users, and a premium tier for administrators and executives handling sensitive data is both cheaper and better aligned to risk than a single uniform tier.
Check the seat caps before you commit
Business plans cap at three hundred seats. A growing business that standardises on a Business tier at two hundred and eighty users is buying a migration for itself within a year or two. Right-sizing means sizing for the business you will be at renewal, not only the one you are today.
Do not strip the administrators
The accounts with the most access should keep the strongest protection available to you. Saving forty pounds a month by downgrading privileged accounts is the worst trade in this entire exercise. If anything, a Microsoft 365 licence audit should end with administrators better licensed than they started, funded by savings elsewhere. Our Microsoft 365 security audit checklist covers what those accounts should have in place.
The overlap trap: paying twice for the same capability
Duplicate spend is harder to find than unused seats because it hides on other suppliers’ invoices, and it is frequently the larger number of the two. A Microsoft 365 licence audit that never leaves the Microsoft admin centre will never see any of it.
Backup is the commonest duplicate
Microsoft provides retention and recovery features, and separately there is a genuine case for third-party backup — the two are not the same thing and the distinction matters commercially. What you should not do is pay for a third-party product whose only function duplicates retention you already own. Decide deliberately which risk each product covers.
Device management bought twice
Businesses on a plan that includes Intune often still pay for a separate endpoint management agent through their IT provider. Sometimes that is the right answer and sometimes it is inertia. Reviewing your device management position as part of the audit forces the question into the open rather than leaving it on a renewal.
Conferencing, signatures and storage
Standalone video conferencing alongside Teams. An e-signature subscription where the included capability would cover the actual volume. Cloud storage bought per-user while OneDrive allocations sit at ten per cent utilisation. None of these is dramatic on its own. Together they routinely exceed the unused-seat saving.
What a Microsoft 365 licence audit typically saves
Ranges are more useful than promises, and the figures below reflect what a first-time exercise usually produces in a UK business that has never done one.
Typical percentage reduction
A first Microsoft 365 licence audit generally removes between twelve and thirty per cent of the Microsoft subscription bill. Tenants that have grown quickly, been through a merger, or had high staff turnover sit at the upper end. Tenants with disciplined joiner and leaver processes sit at the lower end and still find something.
What that means in money
For a fifty-user business paying roughly £1,000 a month, a twenty per cent reduction is £2,400 a year, recurring, for a few days of work. At two hundred users the same percentage is close to £10,000 annually. Add duplicate third-party tooling and the total frequently doubles. Set against typical managed IT pricing models, the exercise pays for itself several times over in year one.
The second audit always finds less
Expect the first pass to be the big one. A repeat exercise twelve months later typically recovers three to eight per cent, which is precisely why it should become routine rather than heroic. Ongoing cost optimisation is a habit, and habits are cheaper than rescues.
Renewal timing and term commitments
When you act matters nearly as much as what you find, because most subscriptions cannot be reduced whenever you like. Timing is the difference between a Microsoft 365 licence audit that saves money this quarter and one that produces an excellent document nobody can act on for another ten months.
Annual terms lock your seat count
An annual commitment fixes quantity for the term. You can add seats mid-term but generally cannot remove them until renewal. A Microsoft 365 licence audit completed the week after an auto-renewal therefore banks nothing for eleven months — the findings are still valid, the savings simply queue.
Work backwards from the renewal date
Start sixty to ninety days before renewal. That gives time to model, agree changes with managers, adjust quantities and let the reduction take effect at the term boundary. Put the renewal date in a shared calendar the moment you find it, because the auto-renewal is what quietly funds the waste.
Monthly billing costs more and is worth it sometimes
Month-to-month pricing carries a premium of roughly twenty per cent over annual commitment. For a stable headcount, annual is correct. For a business hiring or contracting unpredictably, the flexibility to shed seats monthly can outweigh the premium — model both rather than assuming annual always wins.
Making a Microsoft 365 licence audit stick
Savings decay. Without a process, the same waste rebuilds itself within a year and the next Microsoft 365 licence audit finds an almost identical list, which is demoralising for whoever ran the first one.
Fix the leaver process first
The single highest-value control is a leaver checklist that includes releasing the licence, not merely blocking access. Convert the mailbox to shared, remove the licence, disable the account, and record the date. If nothing else from this article gets implemented, implement this.
Use group-based licensing
Assigning licences to security groups rather than individuals makes entitlement a consequence of role membership. Microsoft documents the approach for group-based licensing in Entra ID, and it turns most manual assignment errors into structural impossibilities.
Review quarterly, audit annually
A fifteen-minute quarterly check of assigned versus purchased seats catches drift early. A full Microsoft 365 licence audit once a year, timed to renewal, catches everything else. Businesses working with a managed IT services partner should expect this in the service, not as a chargeable project.
Mistakes that ruin a Microsoft 365 licence audit
Most failed exercises fail the same handful of ways, and none of them is exotic enough to excuse. Read this list before starting rather than afterwards.
Deleting accounts instead of converting them
Deleting a departed user’s account starts a thirty-day clock on their mailbox data. Convert to a shared mailbox first, then remove the licence. The data stays available, costs nothing, and you avoid the call from Legal eight months later asking for correspondence that no longer exists.
Acting on thirty days of data
A thirty-day window misclassifies anyone on holiday, on parental leave, on secondment or working a quarterly cycle. Use one hundred and eighty days. The extra patience costs one month of licence fees and prevents the reputational damage of removing access from someone who was simply away.
Treating it as a pure finance exercise
A Microsoft 365 licence audit run entirely from a spreadsheet by someone who cannot see the security implications will find real savings and create real exposure. The finding is financial; the decision is technical. Both perspectives need to sign off before anything is cancelled.
Never telling anyone what changed
Silent downgrades generate support tickets, and support tickets cost more than the licence saved. Tell affected users what is changing, when, and what they should do if something they need stops working. A short email prevents most of the friction a Microsoft 365 licence audit otherwise creates.
Questions to ask before a Microsoft 365 licence audit
If a provider runs this for you, these questions separate a genuine exercise from a report generated in ten minutes by an automated tool nobody read.
Ask what data window they used
If the answer is thirty days, the analysis is unreliable. If they cannot say, it was automated and unreviewed. A credible Microsoft 365 licence audit states its window, its date, and its assumptions explicitly on the front page.
Ask what they checked beyond the Microsoft bill
An exercise that never looks at third-party subscriptions has examined half the problem. Duplicate tooling is where much of the money is, and finding it requires looking at invoices your IT provider may not normally see.
Ask what happens to the savings
Reduced spend can go back to the business or fund something the estate genuinely needs — better protection for privileged accounts, proper backup, device refresh. Deciding that in advance turns a cost exercise into a planning one. Businesses in the North West can talk this through with our IT support team in Chester.
The work is not complicated. It is simply nobody’s job by default, which is exactly why it is worth making somebody’s job once a year.