Two questions, and most organisations can answer neither: what are you paying for that nobody uses, and what are you using that you may not be entitled to.
A licence audit compares assignment against usage against entitlement. The first gap is commercial and recoverable. The second is a compliance exposure that only surfaces when somebody asks, and by then it is expensive. Both are established from data you already hold.

- AssignedWhat is allocated, per user and per workload
- UsedWhat activity data actually shows
- EntitledWhat the agreement permits
- Three shapesPer user, per resource, and consumption
Seven areas, and the feature-level questions are where the exposure sits.
Assigned against active, per user
Licences assigned to accounts that are disabled, unused, belong to leavers, or duplicate another assignment. This is the recoverable half of the audit and the least contentious, because nobody defends paying for a licence attached to somebody who left eighteen months ago. It is also the finding most organisations could produce themselves and have not.
Assigned against actually used, per workload
A licence bundle assigned to a user who uses two of its eight workloads is not necessarily wrong, and it is a question worth answering deliberately. Usage data per service, over a representative period, distinguishes the population that genuinely needs the bundle from the population that was given it because everybody was.
Features in use that carry their own entitlement
This is where the compliance exposure sits. Conditional Access requires an Entra ID P1 licence for the tenant. Access reviews and entitlement management require Entra ID Governance or Entra Suite, with only some capabilities operating on Entra ID P2. Where a feature is configured and the underlying entitlement was assumed rather than checked, the gap is silent until somebody looks.
Licences that are not per user at all
Defender for Servers is enabled per subscription with Plan 1 also enableable per resource, and Plan 2 disableable but not enableable per resource. Microsoft 365 Backup is a pay-as-you-go offering charged on consumption rather than through traditional user-based licences. Neither appears in a user licence report, and both cost real money.
Administrative accounts and the licence they may or may not need
A specific and frequently misunderstood case. Microsoft states that from June 2021 Intune began supporting unlicensed administrators, so accounts created after that change can administer Intune without an assigned licence, while accounts created before it, and administrator accounts in a nested security group assigned to a role, still require one. Both over-licensing and under-licensing occur here.
Group-based assignment and what it silently grants
Where licences are assigned through group membership, the licence follows the group rather than a decision about the individual. Nested groups, dynamic membership rules written for another purpose, and groups that have grown since the assignment was made all produce licensing that nobody consciously chose and that changes without a change record.
Whether you are entitled to what you have configured
The most valuable output and the least comfortable. Where the audit finds a capability in use whose entitlement cannot be evidenced from the agreement, that is a position to correct deliberately, before it is found by somebody with a commercial interest in finding it. Correcting it voluntarily is materially cheaper than any other route.
Feature-level entitlement is where the silent gaps are, and the platform does not always stop you.
A capability that is configured, working and reported as healthy does not always mean the entitlement behind it has ever been checked.
- Microsoft states that to use Conditional Access, your tenant needs a Microsoft Entra ID P1 licence. Where policies exist and P1 coverage across the affected population has never been verified, the configuration works and the entitlement question is open.
- Access reviews and entitlement management require Microsoft Entra ID Governance or Microsoft Entra Suite subscriptions, with Microsoft noting only that some capabilities within those features may operate with a Microsoft Entra ID P2 subscription. Building a governance programme on P2 alone is a common and understandable error.
- Newer capabilities add their own shapes. Assigning agents to access packages requires either Microsoft 365 E7, which includes Agent 365 and Microsoft Entra Suite, or a Microsoft Agent 365 licence paired with at least Microsoft Entra P1 or Microsoft 365 E3.
- None of these appear in a user licence count. They surface when somebody compares what is configured against what the agreement supports, which is the entire point of doing the audit before anybody else does it for you.
Four things a licence audit should do and most do not.
We check feature entitlement, not only licence counts
Whether the capabilities configured in the tenant are supported by the licences held. Conditional Access requires Entra ID P1. Access reviews and entitlement management require Entra ID Governance or Entra Suite, with only some capabilities operating on P2. Configuration working is not evidence of entitlement, and the platform does not always prevent the gap.
We audit all three licensing shapes
Per user, per protected resource and consumption. Defender for Servers is enabled at subscription scope with different resource-level behaviour between Plan 1 and Plan 2. Microsoft 365 Backup charges on consumption rather than through user licences. Neither appears in a user licence report and both are real expenditure.
We measure usage per workload rather than per bundle
A bundle assigned to a user who uses two of its workloads may be entirely correct, and it should be a decision rather than an inheritance. Usage per service over a representative period distinguishes the population that genuinely needs the higher tier from the population that received it because a previous project standardised everybody.
We fix the process, not only the position
Who assigns licences and on what approval, whether removal is part of leaver processing rather than only directory disablement, how group-based assignment grants silently, and who reviews consumption services. Without those four, the position corrected today drifts back within a renewal cycle and the next audit repeats itself.
Six UAE situations where a licence audit earns its cost quickly.
An organisation approaching an agreement renewal
The renewal conversation is far better informed by usage data than by last year count plus growth. Establishing what is assigned, what is used per workload and what is entitled, before the negotiation rather than during it, changes the shape of that discussion in a way that no amount of preparation on price alone achieves.
A business that has enabled features nobody licensed deliberately
The most common pattern. A project configured Conditional Access, access reviews or entitlement management because the capability was visible in the portal, and the entitlement question was never asked. Correcting that voluntarily is materially cheaper than any other route, and it is entirely fixable once it is known.
A regulated firm that must evidence licence compliance
Where an obligation or an internal audit function requires evidence that software in use is properly licensed, the answer needs to cover feature entitlement rather than seat counts. A documented audit across all three licensing shapes is that evidence, and it is considerably easier to produce proactively than under a deadline.
A group that has grown by acquisition
Acquisitions bring their own agreements, their own tenants and their own assumptions. Consolidation frequently produces duplicate entitlement, licences assigned in two places for the same people, and capabilities configured in one entity that the group agreement does not cover. All three are found by comparing configuration against entitlement across the group.
An operator with large numbers of shared or frontline workers
Frontline and shared-device populations are where bundle choice matters most commercially, because the difference between tiers multiplied by a large headcount is substantial. Usage data per workload for that population is the evidence that determines whether the current assignment is right, generous or insufficient.
An organisation that has adopted consumption-based services
Services charged on consumption rather than per user behave differently from everything else in the estate. Microsoft 365 Backup, for example, is described as a pay-as-you-go offering charged on consumption unlike traditional user-based licences. Reviewing them monthly rather than annually is the discipline, and few organisations have it yet.
How UAE organisations manage Microsoft licensing.
| Feature | Audited across all three shapes | Counted before renewal | Renewed on last year numbers |
|---|---|---|---|
Assignment against active accounts | Yes | Yes | No |
Usage per workload measured | Yes | Rarely | No |
Feature entitlement verified | Yes | No | No |
Per-resource plans reviewed | Yes | No | No |
Consumption services reviewed | Yes | No | No |
Administrative account exceptions checked | Yes | No | No |
Group-based assignment understood | Yes | Partly | No |
Position defensible if questioned | Yes | Partly | No |
Findings actioned before renewal | Yes | Sometimes | No |
Surprise at the next true-up | Unlikely | Possible | Likely |
What is licensed how, and why it matters to the audit.
| Shape | Examples confirmed in Microsoft documentation | How the audit checks it | |
|---|---|---|---|
| Per user | Conditional Access requires Entra ID P1 for the tenant; access reviews and entitlement management require Entra ID Governance or Entra Suite | Assignment against active accounts, and against the population using the feature | |
| Per protected resource | Defender for Servers, enabled at subscription level with Plan 1 also enableable per resource and Plan 2 disableable per resource | Enabled scope against the actual resource count, including resources excluded | |
| Consumption | Microsoft 365 Backup, a pay-as-you-go offering charged on consumption rather than user-based licences | Protected volume against what was expected when the service was enabled | |
| Administrative exception | Intune administrators, where accounts created after June 2021 can administer without a licence and older accounts still require one | Administrator accounts checked individually against creation date and group nesting | |
| Capability-tiered | Agent assignment in entitlement management requiring Microsoft 365 E7, or Agent 365 with at least Entra P1 or Microsoft 365 E3 | Configured capability against the specific entitlement the documentation names |
Five steps, and it is a short engagement with a long tail of value.
- 1
Establish what is assigned
Licences per user, per group where assignment is group-based, and per service plan within each bundle. Then reconciled against account state, so licences attached to disabled accounts, never-signed-in accounts and duplicates are separated immediately as the recoverable and uncontentious half of the finding.
- 2
Establish what is actually used
Activity per workload over a representative period, so bundle assignment can be assessed against real usage rather than against assumption. This is also where the population that needs a higher tier and the population that inherited one become distinguishable, which is the substance of any right-sizing conversation.
- 3
Establish what is configured, and what it requires
The compliance half. Which capabilities are in use in the tenant, and what entitlement each requires according to the published documentation. Conditional Access, identity governance features, per-resource security plans and consumption services all get checked individually, because none of them appears in a user licence report.
- 4
Reconcile against the agreement
What the agreement actually entitles you to, compared against what is assigned and what is configured. Where entitlement for a configured capability cannot be evidenced, that is stated plainly as a position to correct rather than softened, because the value of the audit is entirely in knowing before somebody else does.
- 5
Fix the process, then set the review rhythm
Assignment approval, licence removal as part of leaver processing rather than only directory disablement, group-based assignment reviewed and documented, and a monthly look at consumption services. Then an annual audit timed to precede the renewal rather than follow it.
What organisations ask about Microsoft licence audits.
Fifteen questions the audit answers.
Commercial
- How many licences are assigned to disabled accounts?Usually more than expected.
- How many to accounts that have never signed in?Provisioned and forgotten.
- Which workloads in each bundle are used?Per service, over a real period.
- Are there duplicate or overlapping assignments?Common after a bundle change.
- What are you paying on consumption?It does not appear in a licence count.
Compliance
- Does everyone under Conditional Access hold P1?It is a stated requirement.
- Do you have Governance or Entra Suite?Required for reviews and entitlement management.
- Which capabilities were assumed rather than checked?That is the audit question.
- Are per-resource plans scoped as intended?Plan 1 and Plan 2 behave differently.
- Can you evidence entitlement from the agreement?Rather than from configuration.
Process
- Who assigns licences, and on what approval?Frequently nobody in particular.
- Are licences removed at leaver processing?Directory disable is not the same.
- Is group-based assignment understood?Nested groups grant silently.
- Who reviews consumption services monthly?They vary with usage.
- When does the agreement renew?The audit should precede it.
Count the licences attached to accounts that have never signed in.
It is a single report and it takes minutes. It is also the smaller half of the finding, because the question that follows it, whether every capability you have configured is entitled, is the one nobody has asked.
Related Services
Explore more solutions that work great with this service
Software Asset Management Audit
What is installed against what you own
M365 Licensing
Optimize your Microsoft 365 licensing costs
Microsoft CSP
Microsoft Cloud Solution Provider for UAE businesses
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
M365 Administration
Expert Microsoft 365 tenant management
Entra ID P1 vs P2
What P2 genuinely adds, and what quietly moved
IT General Controls
What your external auditor tests, and the evidence they sample
Access Rights Review
Certification that removes access, not one that gets approved