You cannot be compliant with a licence agreement for software you did not know was installed.
A software asset management audit establishes what is actually installed across the estate, what you are entitled to run, where those two lists disagree, and which of the differences would matter if a publisher asked. Most organisations discover the disagreement is larger in both directions.

- Both directionsOver-deployed and over-purchased
- Every publisherNot only the one that wrote to you
- UnsupportedVersions past end of support, found
- DiscoveredNot collected from a spreadsheet
Eight questions a software asset audit has to answer.
What is actually installed, discovered rather than declared
A discovered inventory across every managed device, correlated with server and datacentre software. Intune discovered apps acts as a software inventory for the tenant and reports application name, platform, version, device count and publisher, exportable to CSV. That is a starting point, and the audit establishes what it does not cover.
How current the inventory data actually is
This matters more than teams expect. Intune discovered apps in general refreshes every seven days for each device from its enrolment date, and that refresh is not performed weekly for the whole tenant. The exception is Win32 application information collected by the Intune Management Extension every 24 hours. An inventory read on a Monday is not a snapshot of Monday.
What the inventory cannot see
Every discovery method has blind spots and they must be stated rather than assumed away. On personal devices Intune never collects information on unmanaged applications. AOSP enrolments do not display discovered apps at all. Windows co-managed devices with the client apps workload still in Configuration Manager do not collect app inventory through the Intune Management Extension.
What you are entitled to run
Entitlement assembled from purchase records, agreements, volume licensing portals and subscription tenants, which is usually the harder half of the exercise. Entitlement lives across finance systems, procurement records and reseller portals, and the organisation frequently owns more than it can evidence at short notice.
Where deployment and entitlement disagree
In both directions, because both cost money. Over-deployment is a liability if a publisher asks. Over-purchase is expenditure with no corresponding use, and it is at least as common. Reconciliation that only looks for shortfall is doing half the work and reporting the uncomfortable half.
Unauthorised and unmanaged software
Software installed outside any procurement process: free tier tools with commercial restrictions, personal licences used for business, remote access utilities, and applications installed by a departed employee that nobody has looked at since. Each is a licence question and a security question at the same time.
Versions past end of support
Discovery finds versions, and versions have published lifecycle dates. Software still installed after its support end date receives no security updates, which makes CIS Control 7 Continuous Vulnerability Management unenforceable for that application permanently. It is one of the most valuable outputs and rarely the one people commission the audit for.
Whether anybody is using it
Installed is not the same as used. A licence assigned to somebody who left, or an application installed estate-wide and opened by a fraction of the recipients, is spend that reconciles cleanly and delivers nothing. Usage evidence is what turns a compliance exercise into one that also reduces cost.
Your software inventory is older than you think, and it has documented blind spots.
Microsoft states the refresh behaviour for Intune discovered apps plainly, and reading it changes how much weight the report can carry in an audit.
- The report in general refreshes every seven days for each device starting from its enrolment date, and that refresh is not performed weekly for the entire tenant. Devices refresh on their own cycles, so a report pulled today contains data collected across the previous week.
- The only exception to that cycle is application information that the Intune Management Extension for Win32 Apps collects every 24 hours. Software inventory on Windows also has an initial delay of up to seven days for Win32 applications on new devices with no Microsoft Entra ID user signed in.
- Coverage varies by platform and ownership. For personal devices Intune never collects information on unmanaged applications, while on corporate devices any app whether managed or not is collected. AOSP enrolments do not display discovered apps. Co-managed Windows devices with the client apps workload in Configuration Manager do not collect through the Intune Management Extension.
- Microsoft also notes the number of discovered apps might not match the app install status count, for reasons including different collection intervals and overlapping targeting. Treating the two numbers as one figure produces a reconciliation that cannot be defended.
- Enhanced App inventory is described as the intended long-term replacement for Discovered apps, collecting data multiple times per day with additional properties such as install location, app size and uninstall commands. Where it is available it materially improves the quality of the underlying data.
Four things that make this audit worth commissioning.
We state what the inventory cannot see
Every discovery method has documented blind spots and pretending otherwise produces a confident wrong answer. Intune never collects unmanaged application data on personal devices, AOSP enrolments display no discovered apps, and co-managed devices with the client apps workload in Configuration Manager do not collect through the Intune Management Extension. Those facts belong in the report.
We account for how the data was collected
Discovered apps in general refreshes every seven days per device from its enrolment date, not weekly across the tenant, with Win32 information collected every 24 hours by the Intune Management Extension. A reconciliation that treats the export as a single point in time snapshot is measuring something other than what it claims.
We reconcile in both directions
Shortfall creates liability and surplus creates waste, and the second is at least as common as the first. Reporting only the shortfall makes the audit an expense rather than an investment, and it is also incomplete, since the same reconciliation produces both numbers from the same work.
We treat unsupported versions as a finding
Discovery finds versions and versions have published end dates. Software running past support receives no security updates, which permanently disables vulnerability management for that application. It is frequently the most valuable output of the engagement and almost never the reason the engagement was commissioned.
Four phases across roughly four to six weeks.
- 01Week 1
Discovery, and honest statement of coverage
Software inventory pulled from every available source and correlated. Equally important, the coverage gaps are documented: which devices are unmanaged, which platforms report nothing, and how stale the data is given a refresh cycle that runs per device rather than per tenant.
- Discovered software inventory across managed estate
- Coverage and refresh limitations documented explicitly
- Devices and platforms outside inventory identified
- Server and datacentre software captured separately
- 02Weeks 2 to 3
Entitlement assembly
Purchase records, agreements, volume licensing portals, reseller statements and subscription tenants gathered into a single entitlement position per publisher. This is the phase that takes longest, because entitlement is scattered across finance, procurement and IT and nobody currently owns the whole picture.
- Entitlement position per publisher
- Agreements and their terms located
- Subscription assignments extracted from tenants
- Entitlement that cannot be evidenced flagged
- 03Week 4
Reconciliation in both directions
Deployment against entitlement per publisher and per product, reporting shortfall and surplus with equal prominence. Alongside it, unauthorised software, unsupported versions and licences assigned to people who have left, since all three surface from the same data.
- Shortfall and surplus quantified per publisher
- Unauthorised software identified
- Versions past end of support listed with dates
- Assigned but unused licences identified
- 04Weeks 5 to 6
Report, remediate and put a process in place
Findings with a remediation plan, and more usefully a proposal for how the position stays accurate afterwards. A point in time reconciliation decays within a quarter. The organisations that stay compliant are the ones that made someone responsible and connected procurement to inventory.
- Reconciliation report per publisher
- Remediation actions prioritised by exposure
- Cost reduction opportunities from surplus and non-use
- An ongoing process with a named owner
Six situations where a software asset audit is the right first step.
An organisation that has received a publisher enquiry
The immediate instinct is to respond quickly, and the better move is to establish your own position first. Knowing what you are actually running and what you can evidence entitlement for, before responding, changes the conversation from a disclosure exercise to a negotiation with facts on both sides.
A business approaching a large agreement renewal
Renewals are negotiated on quantities, and quantities based on last renewal plus growth are usually wrong in both directions. An audit before renewal produces a position based on deployment and usage, which is the only basis for reducing counts without creating a compliance gap.
A company that has acquired another
Licence liability transfers with the acquisition and it is frequently not diligenced properly, because software entitlement is scattered and hard to value quickly. Establishing the combined position early determines whether consolidation reduces cost or exposes a shortfall that was previously nobody in particular problem.
An operator with engineering and specialist software
Specialist and engineering applications carry the most complex terms, are frequently node locked or seat limited, and are usually managed by the engineering function rather than IT. That combination produces the largest single findings in most audits of industrial and construction organisations.
A provider where unsupported software is a clinical risk
Clinical and diagnostic applications frequently run on versions certified years ago, and the certification is what keeps them there. Establishing which are past support, and what the vendor position on upgrading is, converts an unmanaged risk into a decision that can be recorded and owned.
An organisation that has grown headcount quickly
Rapid growth adds licences quickly and reclaims them slowly. Assignments follow joiners reliably and leavers unreliably, and after two years of growth the gap between assigned and used is usually large enough to fund the audit several times over from reclamation alone.
How UAE organisations manage software assets.
| Feature | Audited with a maintained position | Spreadsheet updated occasionally | Position unknown |
|---|---|---|---|
Discovered software inventory | Yes, with stated coverage | Partial | No |
Inventory limitations understood | Documented | No | No |
Entitlement position per publisher | Maintained | For the main one | No |
Reconciliation in both directions | Yes | Shortfall only | No |
Unauthorised software visible | Yes | Rarely | No |
Unsupported versions tracked | With dates | No | No |
Unused licences reclaimed | Routinely | Occasionally | Never |
Leaver licence reclamation | Automated | Manual | Missed |
Publisher enquiry readiness | Prepared | Reactive | Exposed |
Procurement linked to inventory | Yes | No | No |
Ten places software hides from a software inventory.
| Where it hides | Why the inventory misses it | |
|---|---|---|
| Unmanaged personal devices | Intune never collects unmanaged application data on personal devices | |
| AOSP enrolled Android devices | AOSP enrolments do not display discovered apps | |
| Co-managed Windows devices | Client apps workload still in Configuration Manager, so no IME collection | |
| Newly enrolled Windows devices | Up to seven day delay for Win32 apps with no Entra ID user signed in | |
| Servers outside the endpoint estate | Frequently managed separately or not at all | |
| Software as a service subscriptions | Nothing is installed, so nothing is discovered | |
| Departmental purchases on expenses | No procurement record to reconcile against | |
| Virtual machines and lab environments | Often excluded from management, rarely excluded from licence terms | |
| Contractor and third party devices | Outside management, inside the network | |
| Embedded and appliance software | Runs on hardware nobody treats as a software asset |
Five steps, and the second one is where the time goes.
- 1
Agree scope and publishers in focus
Whole estate or specific publishers, which entities, and whether servers, virtual environments and specialist applications are included. Where an enquiry has already been received, scope follows the enquiry first and widens afterwards, since the immediate exposure is the priority.
- 2
Discover, and document the coverage honestly
Software inventory pulled from every available source and correlated, with the limitations recorded rather than glossed over. Refresh behaviour, platform coverage, unmanaged devices and delays on newly enrolled devices all affect how much weight the numbers can carry.
- 3
Assemble the entitlement position
Purchase records, agreements, volume licensing portals, reseller statements and subscription tenants, gathered per publisher. Entitlement that exists but cannot be evidenced is flagged separately, because in a publisher discussion it is functionally the same as entitlement you do not have.
- 4
Reconcile and quantify exposure
Deployment against entitlement per product, in both directions, with unauthorised software, unsupported versions and unused assignments reported alongside. Findings prioritised by exposure rather than by count, since a small number of high value licences usually dominates the position.
- 5
Remediate and make it continuous
A remediation plan for the shortfall, a reclamation plan for the surplus, and a process that keeps the position current. A single reconciliation decays within a quarter. The organisations that stay compliant connected procurement to inventory and gave one person the responsibility.
What organisations ask about software asset audits.
Fifteen questions to ask your own team.
Inventory
- What proportion of devices report a software inventory?Coverage needs a denominator.
- How old is the newest data in that report?Seven day per-device refresh, not per tenant.
- Which platforms report nothing at all?AOSP enrolments show no discovered apps.
- Are co-managed devices collecting through IME?Check the client apps workload.
- Are servers included in the same inventory?Usually not.
Entitlement
- Can we produce a licence position per publisher?Within two working days.
- Where are the agreements physically kept?And who has access.
- Who owns entitlement records?Finance, procurement or IT.
- Do we know what departments bought on expenses?Almost always no.
- Are subscription assignments reviewed at leavers?Check five recent leavers.
Exposure
- What software runs past its support end date?With dates, not impressions.
- What is installed with no procurement record?Free tier tools count.
- Are personal licences used for business work?Common and frequently a breach.
- Have we had a publisher enquiry before?They tend to repeat.
- Who would coordinate a publisher audit response?Decide before, not during.
Ask for a licence position for your largest publisher, by Friday.
Deployment count, entitlement count, and the evidence for the second. If that takes longer than two days to produce, you have your answer about where the audit will find things.
Related Services
Explore more solutions that work great with this service
Microsoft Licence Audit
Assigned, used and entitled, compared properly
IT Infrastructure Audit
What you run, how much is supported, what fails
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
Win32 App Packaging
Packaging, detection rules and deployment that works
IT Risk Assessment
A short register with an owner against every risk
M365 Licensing
Optimize your Microsoft 365 licensing costs
IT Due Diligence
What the target runs, what it costs, what integration costs
CIS Controls Assessment
Eighteen controls, assessed and re-assessed