We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Microsoft licence audit
Microsoft licence and entitlement audit, UAE

Two questions, and most organisations can answer neither: what are you paying for that nobody uses, and what are you using that you may not be entitled to.

A licence audit compares assignment against usage against entitlement. The first gap is commercial and recoverable. The second is a compliance exposure that only surfaces when somebody asks, and by then it is expensive. Both are established from data you already hold.

Book a licence auditSee what the audit compares
Microsoft licence and entitlement audit for UAE organisations
  • AssignedWhat is allocated, per user and per workload
  • UsedWhat activity data actually shows
  • EntitledWhat the agreement permits
  • Three shapesPer user, per resource, and consumption
What the audit compares

Seven areas, and the feature-level questions are where the exposure sits.

Microsoft licensing is no longer one shape. Some capabilities are licensed per user, some per protected resource, and some on consumption. An audit that counts user licences and stops answers a fraction of the question, and it is the fraction least likely to contain a compliance problem.

Assigned against active, per user

Licences assigned to accounts that are disabled, unused, belong to leavers, or duplicate another assignment. This is the recoverable half of the audit and the least contentious, because nobody defends paying for a licence attached to somebody who left eighteen months ago. It is also the finding most organisations could produce themselves and have not.

Assigned against actually used, per workload

A licence bundle assigned to a user who uses two of its eight workloads is not necessarily wrong, and it is a question worth answering deliberately. Usage data per service, over a representative period, distinguishes the population that genuinely needs the bundle from the population that was given it because everybody was.

Features in use that carry their own entitlement

This is where the compliance exposure sits. Conditional Access requires an Entra ID P1 licence for the tenant. Access reviews and entitlement management require Entra ID Governance or Entra Suite, with only some capabilities operating on Entra ID P2. Where a feature is configured and the underlying entitlement was assumed rather than checked, the gap is silent until somebody looks.

Licences that are not per user at all

Defender for Servers is enabled per subscription with Plan 1 also enableable per resource, and Plan 2 disableable but not enableable per resource. Microsoft 365 Backup is a pay-as-you-go offering charged on consumption rather than through traditional user-based licences. Neither appears in a user licence report, and both cost real money.

Administrative accounts and the licence they may or may not need

A specific and frequently misunderstood case. Microsoft states that from June 2021 Intune began supporting unlicensed administrators, so accounts created after that change can administer Intune without an assigned licence, while accounts created before it, and administrator accounts in a nested security group assigned to a role, still require one. Both over-licensing and under-licensing occur here.

Group-based assignment and what it silently grants

Where licences are assigned through group membership, the licence follows the group rather than a decision about the individual. Nested groups, dynamic membership rules written for another purpose, and groups that have grown since the assignment was made all produce licensing that nobody consciously chose and that changes without a change record.

Whether you are entitled to what you have configured

The most valuable output and the least comfortable. Where the audit finds a capability in use whose entitlement cannot be evidenced from the agreement, that is a position to correct deliberately, before it is found by somebody with a commercial interest in finding it. Correcting it voluntarily is materially cheaper than any other route.

The exposure that is not about user counts

Feature-level entitlement is where the silent gaps are, and the platform does not always stop you.

A capability that is configured, working and reported as healthy does not always mean the entitlement behind it has ever been checked.

  • Microsoft states that to use Conditional Access, your tenant needs a Microsoft Entra ID P1 licence. Where policies exist and P1 coverage across the affected population has never been verified, the configuration works and the entitlement question is open.
  • Access reviews and entitlement management require Microsoft Entra ID Governance or Microsoft Entra Suite subscriptions, with Microsoft noting only that some capabilities within those features may operate with a Microsoft Entra ID P2 subscription. Building a governance programme on P2 alone is a common and understandable error.
  • Newer capabilities add their own shapes. Assigning agents to access packages requires either Microsoft 365 E7, which includes Agent 365 and Microsoft Entra Suite, or a Microsoft Agent 365 licence paired with at least Microsoft Entra P1 or Microsoft 365 E3.
  • None of these appear in a user licence count. They surface when somebody compares what is configured against what the agreement supports, which is the entire point of doing the audit before anybody else does it for you.
Ask us to check your feature entitlements
How we approach it

Four things a licence audit should do and most do not.

The commercial half of this work is well served by tooling and by the reseller relationship. The compliance half is where organisations are exposed, and it is the half nobody with a commercial interest in selling licences has an incentive to raise.

We check feature entitlement, not only licence counts

Whether the capabilities configured in the tenant are supported by the licences held. Conditional Access requires Entra ID P1. Access reviews and entitlement management require Entra ID Governance or Entra Suite, with only some capabilities operating on P2. Configuration working is not evidence of entitlement, and the platform does not always prevent the gap.

We audit all three licensing shapes

Per user, per protected resource and consumption. Defender for Servers is enabled at subscription scope with different resource-level behaviour between Plan 1 and Plan 2. Microsoft 365 Backup charges on consumption rather than through user licences. Neither appears in a user licence report and both are real expenditure.

We measure usage per workload rather than per bundle

A bundle assigned to a user who uses two of its workloads may be entirely correct, and it should be a decision rather than an inheritance. Usage per service over a representative period distinguishes the population that genuinely needs the higher tier from the population that received it because a previous project standardised everybody.

We fix the process, not only the position

Who assigns licences and on what approval, whether removal is part of leaver processing rather than only directory disablement, how group-based assignment grants silently, and who reviews consumption services. Without those four, the position corrected today drifts back within a renewal cycle and the next audit repeats itself.

Where this matters most

Six UAE situations where a licence audit earns its cost quickly.

The triggers are commercial and compliance in roughly equal measure, and the organisations that do it voluntarily are in a considerably better position than those that do it in response.

An organisation approaching an agreement renewal

The renewal conversation is far better informed by usage data than by last year count plus growth. Establishing what is assigned, what is used per workload and what is entitled, before the negotiation rather than during it, changes the shape of that discussion in a way that no amount of preparation on price alone achieves.

A business that has enabled features nobody licensed deliberately

The most common pattern. A project configured Conditional Access, access reviews or entitlement management because the capability was visible in the portal, and the entitlement question was never asked. Correcting that voluntarily is materially cheaper than any other route, and it is entirely fixable once it is known.

A regulated firm that must evidence licence compliance

Where an obligation or an internal audit function requires evidence that software in use is properly licensed, the answer needs to cover feature entitlement rather than seat counts. A documented audit across all three licensing shapes is that evidence, and it is considerably easier to produce proactively than under a deadline.

A group that has grown by acquisition

Acquisitions bring their own agreements, their own tenants and their own assumptions. Consolidation frequently produces duplicate entitlement, licences assigned in two places for the same people, and capabilities configured in one entity that the group agreement does not cover. All three are found by comparing configuration against entitlement across the group.

An operator with large numbers of shared or frontline workers

Frontline and shared-device populations are where bundle choice matters most commercially, because the difference between tiers multiplied by a large headcount is substantial. Usage data per workload for that population is the evidence that determines whether the current assignment is right, generous or insufficient.

An organisation that has adopted consumption-based services

Services charged on consumption rather than per user behave differently from everything else in the estate. Microsoft 365 Backup, for example, is described as a pay-as-you-go offering charged on consumption unlike traditional user-based licences. Reviewing them monthly rather than annually is the discipline, and few organisations have it yet.

Three positions

How UAE organisations manage Microsoft licensing.

The middle column is the common one. Somebody reviews the count before renewal, the number is reconciled, and no part of the exercise touches whether the features in use are actually entitled.
Assignment against active accounts
Audited across all three shapesYes
Counted before renewalYes
Renewed on last year numbersNo
Usage per workload measured
Audited across all three shapesYes
Counted before renewalRarely
Renewed on last year numbersNo
Feature entitlement verified
Audited across all three shapesYes
Counted before renewalNo
Renewed on last year numbersNo
Per-resource plans reviewed
Audited across all three shapesYes
Counted before renewalNo
Renewed on last year numbersNo
Consumption services reviewed
Audited across all three shapesYes
Counted before renewalNo
Renewed on last year numbersNo
Administrative account exceptions checked
Audited across all three shapesYes
Counted before renewalNo
Renewed on last year numbersNo
Group-based assignment understood
Audited across all three shapesYes
Counted before renewalPartly
Renewed on last year numbersNo
Position defensible if questioned
Audited across all three shapesYes
Counted before renewalPartly
Renewed on last year numbersNo
Findings actioned before renewal
Audited across all three shapesYes
Counted before renewalSometimes
Renewed on last year numbersNo
Surprise at the next true-up
Audited across all three shapesUnlikely
Counted before renewalPossible
Renewed on last year numbersLikely
Feature
Audited across all three shapes
Counted before renewal
Renewed on last year numbers
Assignment against active accounts
YesYesNo
Usage per workload measured
YesRarelyNo
Feature entitlement verified
YesNoNo
Per-resource plans reviewed
YesNoNo
Consumption services reviewed
YesNoNo
Administrative account exceptions checked
YesNoNo
Group-based assignment understood
YesPartlyNo
Position defensible if questioned
YesPartlyNo
Findings actioned before renewal
YesSometimesNo
Surprise at the next true-up
UnlikelyPossibleLikely
The three licensing shapes

What is licensed how, and why it matters to the audit.

Microsoft licensing now takes several forms and each requires a different audit method. An audit that only counts assigned user licences examines one of three.
ShapeExamples confirmed in Microsoft documentationHow the audit checks it
Per userConditional Access requires Entra ID P1 for the tenant; access reviews and entitlement management require Entra ID Governance or Entra SuiteAssignment against active accounts, and against the population using the feature
Per protected resourceDefender for Servers, enabled at subscription level with Plan 1 also enableable per resource and Plan 2 disableable per resourceEnabled scope against the actual resource count, including resources excluded
ConsumptionMicrosoft 365 Backup, a pay-as-you-go offering charged on consumption rather than user-based licencesProtected volume against what was expected when the service was enabled
Administrative exceptionIntune administrators, where accounts created after June 2021 can administer without a licence and older accounts still require oneAdministrator accounts checked individually against creation date and group nesting
Capability-tieredAgent assignment in entitlement management requiring Microsoft 365 E7, or Agent 365 with at least Entra P1 or Microsoft 365 E3Configured capability against the specific entitlement the documentation names
How an engagement runs

Five steps, and it is a short engagement with a long tail of value.

Typically two to four weeks. Most evidence is available from the tenant and the agreement. Reconciling configured capability against entitlement is where the analysis effort concentrates.
  1. 1

    Establish what is assigned

    Licences per user, per group where assignment is group-based, and per service plan within each bundle. Then reconciled against account state, so licences attached to disabled accounts, never-signed-in accounts and duplicates are separated immediately as the recoverable and uncontentious half of the finding.

  2. 2

    Establish what is actually used

    Activity per workload over a representative period, so bundle assignment can be assessed against real usage rather than against assumption. This is also where the population that needs a higher tier and the population that inherited one become distinguishable, which is the substance of any right-sizing conversation.

  3. 3

    Establish what is configured, and what it requires

    The compliance half. Which capabilities are in use in the tenant, and what entitlement each requires according to the published documentation. Conditional Access, identity governance features, per-resource security plans and consumption services all get checked individually, because none of them appears in a user licence report.

  4. 4

    Reconcile against the agreement

    What the agreement actually entitles you to, compared against what is assigned and what is configured. Where entitlement for a configured capability cannot be evidenced, that is stated plainly as a position to correct rather than softened, because the value of the audit is entirely in knowing before somebody else does.

  5. 5

    Fix the process, then set the review rhythm

    Assignment approval, licence removal as part of leaver processing rather than only directory disablement, group-based assignment reviewed and documented, and a monthly look at consumption services. Then an annual audit timed to precede the renewal rather than follow it.

Straight answers

What organisations ask about Microsoft licence audits.

Both, and they are separable. The commercial half is licences assigned to disabled accounts, never-used accounts, duplicates and bundles assigned to populations who use a fraction of them. The compliance half is capabilities configured in the tenant whose entitlement was assumed rather than verified. The second is the one nobody else is incentivised to raise with you.

A capability that is configured and working where the licence supporting it has not been verified. Microsoft states that Conditional Access requires an Entra ID P1 licence, and that access reviews and entitlement management require Entra ID Governance or Entra Suite with only some capabilities operating on P2. Configuration succeeding is not evidence that the entitlement exists.

Because it determines how the audit checks it. Per-user licensing is checked against accounts. Per-resource licensing, such as Defender for Servers where Plan 1 can be enabled per resource and Plan 2 can only be disabled per resource, is checked against resource counts and enablement scope. Consumption services, such as Microsoft 365 Backup which charges on consumption rather than user licences, are checked against protected volume.

It depends on when the account was created, and this catches people both ways. Microsoft states that from June 2021 Intune began supporting unlicensed administrators, so accounts created after that change can administer Intune without an assigned licence, while accounts created before that change, and administrator accounts in a nested security group assigned to a role, still require one.

They are in scope and they are frequently where unintended assignment originates. A licence attached to a group follows group membership rather than an individual decision, so nested groups, dynamic membership rules written for another purpose, and groups that have grown since the assignment produce licensing nobody consciously chose and that changes without any change record.

Activity per service over a representative period, rather than a snapshot. The period matters because monthly, quarterly and seasonal patterns exist, and a two-week sample makes a genuinely used workload look abandoned. The output is per workload rather than per bundle, since the question is which parts of a bundle the population actually needs.

No, and an audit that reflexively does is not doing the work. A bundle assigned to a user who uses two of its workloads may be entirely correct if one of those two is only available in that tier. The output is a decision framed with evidence, per population, rather than a blanket recommendation based on service usage counts alone.

Then you correct it deliberately, which is materially cheaper and less disruptive than any other route to the same discovery. We state such findings plainly rather than softening them, because the entire value of the audit is knowing before the question is asked by somebody whose interest is different from yours.

We work from Microsoft published documentation for what a feature requires, and we flag where a question turns on the specific terms of your agreement rather than answering it ourselves. Entitlement questions that depend on agreement wording get confirmed against the agreement, with your licensing partner or Microsoft where necessary, rather than asserted.

Before a renewal rather than during one, because the negotiation is far better informed by usage evidence than by last year count plus growth. Also worth doing after any significant change: an acquisition, a large project that enabled new capabilities, a tenant consolidation, or the adoption of a consumption-based service.

Two to four weeks for most organisations. Assignment and usage data are available from the tenant and analysis is quick. The variable is the entitlement reconciliation, which depends on how many capabilities are configured and how readily the agreement documentation can be located, and the second of those is frequently the slower half.

They will do the commercial half well and they have an obvious position on the compliance half. That is not a criticism, it is a structural point about incentives. An audit that identifies under-licensing is a sale for a reseller and a risk finding for you, and the two parties should not be the same one where that matters to you.

A broader software asset management audit covers the wider estate, and it is a different engagement with a different method because the evidence sources differ per vendor. This audit is Microsoft-specific because that is where most UAE organisations concentrate their spend and where the feature-level entitlement complexity is greatest.

Four process changes. Licence assignment through an approval rather than at request, licence removal as an explicit step in leaver processing rather than relying on directory disablement, group-based assignment documented and reviewed, and a monthly look at consumption-based services since those vary with usage rather than with headcount.

We scope by tenant size and by how many capabilities are configured, since the entitlement reconciliation is where the effort concentrates. It is one of the shorter audits we run. Where the commercial finding is significant the engagement frequently pays for itself within the first renewal cycle, though we would not lead with that as the reason to do it.

Yes, and frequently more than organisations expect. A reseller sells you what you ask for, and what you ask for is usually last year quantity adjusted for headcount. Neither party is checking whether the assignments match what people actually use, which is where both the compliance gap and the surplus accumulate.

In most tenants, less than intended. Assignment follows joiners reliably because somebody is waiting for access, and follows leavers unreliably because nobody is. After two years of turnover the gap between assigned and used is usually large enough to fund the review several times over from reclamation alone.
Before the audit

Fifteen questions the audit answers.

The first group is the commercial half, the second is the compliance half, and the third is the process half that determines whether the position holds after the audit.

Commercial

  • How many licences are assigned to disabled accounts?
    Usually more than expected.
  • How many to accounts that have never signed in?
    Provisioned and forgotten.
  • Which workloads in each bundle are used?
    Per service, over a real period.
  • Are there duplicate or overlapping assignments?
    Common after a bundle change.
  • What are you paying on consumption?
    It does not appear in a licence count.

Compliance

  • Does everyone under Conditional Access hold P1?
    It is a stated requirement.
  • Do you have Governance or Entra Suite?
    Required for reviews and entitlement management.
  • Which capabilities were assumed rather than checked?
    That is the audit question.
  • Are per-resource plans scoped as intended?
    Plan 1 and Plan 2 behave differently.
  • Can you evidence entitlement from the agreement?
    Rather than from configuration.

Process

  • Who assigns licences, and on what approval?
    Frequently nobody in particular.
  • Are licences removed at leaver processing?
    Directory disable is not the same.
  • Is group-based assignment understood?
    Nested groups grant silently.
  • Who reviews consumption services monthly?
    They vary with usage.
  • When does the agreement renew?
    The audit should precede it.
Related reading

The pages around this one.

Microsoft 365 licensing

The advisory view of which licence fits which population.

Learn more

Microsoft Cloud Solution Provider

The commercial relationship and how licences are procured.

Learn more

IT audit services

The wider audit practice and the other assessments available.

Learn more
Next step

Count the licences attached to accounts that have never signed in.

It is a single report and it takes minutes. It is also the smaller half of the finding, because the question that follows it, whether every capability you have configured is entitled, is the one nobody has asked.

Book a licence auditCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Software Asset Management Audit

What is installed against what you own

Learn more

M365 Licensing

Optimize your Microsoft 365 licensing costs

Learn more

Microsoft CSP

Microsoft Cloud Solution Provider for UAE businesses

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

M365 Administration

Expert Microsoft 365 tenant management

Learn more

Entra ID P1 vs P2

What P2 genuinely adds, and what quietly moved

Learn more

IT General Controls

What your external auditor tests, and the evidence they sample

Learn more

Access Rights Review

Certification that removes access, not one that gets approved

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy