We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Software asset management audit
Software asset management audit, UAE

You cannot be compliant with a licence agreement for software you did not know was installed.

A software asset management audit establishes what is actually installed across the estate, what you are entitled to run, where those two lists disagree, and which of the differences would matter if a publisher asked. Most organisations discover the disagreement is larger in both directions.

Book a software asset auditSee what we examine
Software asset management audit for UAE organisations
  • Both directionsOver-deployed and over-purchased
  • Every publisherNot only the one that wrote to you
  • UnsupportedVersions past end of support, found
  • DiscoveredNot collected from a spreadsheet
What we examine

Eight questions a software asset audit has to answer.

CIS Control 2 is Inventory and Control of Software Assets and it sits at number two for the same reason Control 1 sits at number one. Almost every other control assumes you know what is running, and in most estates that assumption is not supported by evidence.

What is actually installed, discovered rather than declared

A discovered inventory across every managed device, correlated with server and datacentre software. Intune discovered apps acts as a software inventory for the tenant and reports application name, platform, version, device count and publisher, exportable to CSV. That is a starting point, and the audit establishes what it does not cover.

How current the inventory data actually is

This matters more than teams expect. Intune discovered apps in general refreshes every seven days for each device from its enrolment date, and that refresh is not performed weekly for the whole tenant. The exception is Win32 application information collected by the Intune Management Extension every 24 hours. An inventory read on a Monday is not a snapshot of Monday.

What the inventory cannot see

Every discovery method has blind spots and they must be stated rather than assumed away. On personal devices Intune never collects information on unmanaged applications. AOSP enrolments do not display discovered apps at all. Windows co-managed devices with the client apps workload still in Configuration Manager do not collect app inventory through the Intune Management Extension.

What you are entitled to run

Entitlement assembled from purchase records, agreements, volume licensing portals and subscription tenants, which is usually the harder half of the exercise. Entitlement lives across finance systems, procurement records and reseller portals, and the organisation frequently owns more than it can evidence at short notice.

Where deployment and entitlement disagree

In both directions, because both cost money. Over-deployment is a liability if a publisher asks. Over-purchase is expenditure with no corresponding use, and it is at least as common. Reconciliation that only looks for shortfall is doing half the work and reporting the uncomfortable half.

Unauthorised and unmanaged software

Software installed outside any procurement process: free tier tools with commercial restrictions, personal licences used for business, remote access utilities, and applications installed by a departed employee that nobody has looked at since. Each is a licence question and a security question at the same time.

Versions past end of support

Discovery finds versions, and versions have published lifecycle dates. Software still installed after its support end date receives no security updates, which makes CIS Control 7 Continuous Vulnerability Management unenforceable for that application permanently. It is one of the most valuable outputs and rarely the one people commission the audit for.

Whether anybody is using it

Installed is not the same as used. A licence assigned to somebody who left, or an application installed estate-wide and opened by a fraction of the recipients, is spend that reconciles cleanly and delivers nothing. Usage evidence is what turns a compliance exercise into one that also reduces cost.

The detail that changes the answer

Your software inventory is older than you think, and it has documented blind spots.

Microsoft states the refresh behaviour for Intune discovered apps plainly, and reading it changes how much weight the report can carry in an audit.

  • The report in general refreshes every seven days for each device starting from its enrolment date, and that refresh is not performed weekly for the entire tenant. Devices refresh on their own cycles, so a report pulled today contains data collected across the previous week.
  • The only exception to that cycle is application information that the Intune Management Extension for Win32 Apps collects every 24 hours. Software inventory on Windows also has an initial delay of up to seven days for Win32 applications on new devices with no Microsoft Entra ID user signed in.
  • Coverage varies by platform and ownership. For personal devices Intune never collects information on unmanaged applications, while on corporate devices any app whether managed or not is collected. AOSP enrolments do not display discovered apps. Co-managed Windows devices with the client apps workload in Configuration Manager do not collect through the Intune Management Extension.
  • Microsoft also notes the number of discovered apps might not match the app install status count, for reasons including different collection intervals and overlapping targeting. Treating the two numbers as one figure produces a reconciliation that cannot be defended.
  • Enhanced App inventory is described as the intended long-term replacement for Discovered apps, collecting data multiple times per day with additional properties such as install location, app size and uninstall commands. Where it is available it materially improves the quality of the underlying data.
Ask us to test your inventory coverage
How we approach it

Four things that make this audit worth commissioning.

A reconciliation that reports a shortfall and stops has given you a bill. The engagement is worth doing when it also finds the surplus, the unsupported versions and the software nobody authorised.

We state what the inventory cannot see

Every discovery method has documented blind spots and pretending otherwise produces a confident wrong answer. Intune never collects unmanaged application data on personal devices, AOSP enrolments display no discovered apps, and co-managed devices with the client apps workload in Configuration Manager do not collect through the Intune Management Extension. Those facts belong in the report.

We account for how the data was collected

Discovered apps in general refreshes every seven days per device from its enrolment date, not weekly across the tenant, with Win32 information collected every 24 hours by the Intune Management Extension. A reconciliation that treats the export as a single point in time snapshot is measuring something other than what it claims.

We reconcile in both directions

Shortfall creates liability and surplus creates waste, and the second is at least as common as the first. Reporting only the shortfall makes the audit an expense rather than an investment, and it is also incomplete, since the same reconciliation produces both numbers from the same work.

We treat unsupported versions as a finding

Discovery finds versions and versions have published end dates. Software running past support receives no security updates, which permanently disables vulnerability management for that application. It is frequently the most valuable output of the engagement and almost never the reason the engagement was commissioned.

How the audit runs

Four phases across roughly four to six weeks.

Entitlement gathering is the phase that determines the timeline. Discovery is largely automated. Establishing what the organisation actually bought, from whom and under what terms, is not.
  1. 01
    Week 1

    Discovery, and honest statement of coverage

    Software inventory pulled from every available source and correlated. Equally important, the coverage gaps are documented: which devices are unmanaged, which platforms report nothing, and how stale the data is given a refresh cycle that runs per device rather than per tenant.

    • Discovered software inventory across managed estate
    • Coverage and refresh limitations documented explicitly
    • Devices and platforms outside inventory identified
    • Server and datacentre software captured separately
  2. 02
    Weeks 2 to 3

    Entitlement assembly

    Purchase records, agreements, volume licensing portals, reseller statements and subscription tenants gathered into a single entitlement position per publisher. This is the phase that takes longest, because entitlement is scattered across finance, procurement and IT and nobody currently owns the whole picture.

    • Entitlement position per publisher
    • Agreements and their terms located
    • Subscription assignments extracted from tenants
    • Entitlement that cannot be evidenced flagged
  3. 03
    Week 4

    Reconciliation in both directions

    Deployment against entitlement per publisher and per product, reporting shortfall and surplus with equal prominence. Alongside it, unauthorised software, unsupported versions and licences assigned to people who have left, since all three surface from the same data.

    • Shortfall and surplus quantified per publisher
    • Unauthorised software identified
    • Versions past end of support listed with dates
    • Assigned but unused licences identified
  4. 04
    Weeks 5 to 6

    Report, remediate and put a process in place

    Findings with a remediation plan, and more usefully a proposal for how the position stays accurate afterwards. A point in time reconciliation decays within a quarter. The organisations that stay compliant are the ones that made someone responsible and connected procurement to inventory.

    • Reconciliation report per publisher
    • Remediation actions prioritised by exposure
    • Cost reduction opportunities from surplus and non-use
    • An ongoing process with a named owner
Where this applies

Six situations where a software asset audit is the right first step.

The most common trigger is a letter from a publisher, which is the worst time to start. The other five are all better moments to do the same work.

An organisation that has received a publisher enquiry

The immediate instinct is to respond quickly, and the better move is to establish your own position first. Knowing what you are actually running and what you can evidence entitlement for, before responding, changes the conversation from a disclosure exercise to a negotiation with facts on both sides.

A business approaching a large agreement renewal

Renewals are negotiated on quantities, and quantities based on last renewal plus growth are usually wrong in both directions. An audit before renewal produces a position based on deployment and usage, which is the only basis for reducing counts without creating a compliance gap.

A company that has acquired another

Licence liability transfers with the acquisition and it is frequently not diligenced properly, because software entitlement is scattered and hard to value quickly. Establishing the combined position early determines whether consolidation reduces cost or exposes a shortfall that was previously nobody in particular problem.

An operator with engineering and specialist software

Specialist and engineering applications carry the most complex terms, are frequently node locked or seat limited, and are usually managed by the engineering function rather than IT. That combination produces the largest single findings in most audits of industrial and construction organisations.

A provider where unsupported software is a clinical risk

Clinical and diagnostic applications frequently run on versions certified years ago, and the certification is what keeps them there. Establishing which are past support, and what the vendor position on upgrading is, converts an unmanaged risk into a decision that can be recorded and owned.

An organisation that has grown headcount quickly

Rapid growth adds licences quickly and reclaims them slowly. Assignments follow joiners reliably and leavers unreliably, and after two years of growth the gap between assigned and used is usually large enough to fund the audit several times over from reclamation alone.

Three positions

How UAE organisations manage software assets.

The right column is the most common and it is not unusual. Software asset management is one of the few disciplines where doing nothing produces no visible symptom until a publisher writes to you.
Discovered software inventory
Audited with a maintained positionYes, with stated coverage
Spreadsheet updated occasionallyPartial
Position unknownNo
Inventory limitations understood
Audited with a maintained positionDocumented
Spreadsheet updated occasionallyNo
Position unknownNo
Entitlement position per publisher
Audited with a maintained positionMaintained
Spreadsheet updated occasionallyFor the main one
Position unknownNo
Reconciliation in both directions
Audited with a maintained positionYes
Spreadsheet updated occasionallyShortfall only
Position unknownNo
Unauthorised software visible
Audited with a maintained positionYes
Spreadsheet updated occasionallyRarely
Position unknownNo
Unsupported versions tracked
Audited with a maintained positionWith dates
Spreadsheet updated occasionallyNo
Position unknownNo
Unused licences reclaimed
Audited with a maintained positionRoutinely
Spreadsheet updated occasionallyOccasionally
Position unknownNever
Leaver licence reclamation
Audited with a maintained positionAutomated
Spreadsheet updated occasionallyManual
Position unknownMissed
Publisher enquiry readiness
Audited with a maintained positionPrepared
Spreadsheet updated occasionallyReactive
Position unknownExposed
Procurement linked to inventory
Audited with a maintained positionYes
Spreadsheet updated occasionallyNo
Position unknownNo
Feature
Audited with a maintained position
Spreadsheet updated occasionally
Position unknown
Discovered software inventory
Yes, with stated coveragePartialNo
Inventory limitations understood
DocumentedNoNo
Entitlement position per publisher
MaintainedFor the main oneNo
Reconciliation in both directions
YesShortfall onlyNo
Unauthorised software visible
YesRarelyNo
Unsupported versions tracked
With datesNoNo
Unused licences reclaimed
RoutinelyOccasionallyNever
Leaver licence reclamation
AutomatedManualMissed
Publisher enquiry readiness
PreparedReactiveExposed
Procurement linked to inventory
YesNoNo
Where the gaps are

Ten places software hides from a software inventory.

A discovery tool reports what it can reach. The audit value is in establishing what it cannot, because that is where the unlicensed and unsupported software accumulates.
Where it hidesWhy the inventory misses it
Unmanaged personal devicesIntune never collects unmanaged application data on personal devices
AOSP enrolled Android devicesAOSP enrolments do not display discovered apps
Co-managed Windows devicesClient apps workload still in Configuration Manager, so no IME collection
Newly enrolled Windows devicesUp to seven day delay for Win32 apps with no Entra ID user signed in
Servers outside the endpoint estateFrequently managed separately or not at all
Software as a service subscriptionsNothing is installed, so nothing is discovered
Departmental purchases on expensesNo procurement record to reconcile against
Virtual machines and lab environmentsOften excluded from management, rarely excluded from licence terms
Contractor and third party devicesOutside management, inside the network
Embedded and appliance softwareRuns on hardware nobody treats as a software asset
How an engagement runs

Five steps, and the second one is where the time goes.

Discovery is quick. Assembling what the organisation actually bought, from whom, under what terms, is the phase that sets the schedule.
  1. 1

    Agree scope and publishers in focus

    Whole estate or specific publishers, which entities, and whether servers, virtual environments and specialist applications are included. Where an enquiry has already been received, scope follows the enquiry first and widens afterwards, since the immediate exposure is the priority.

  2. 2

    Discover, and document the coverage honestly

    Software inventory pulled from every available source and correlated, with the limitations recorded rather than glossed over. Refresh behaviour, platform coverage, unmanaged devices and delays on newly enrolled devices all affect how much weight the numbers can carry.

  3. 3

    Assemble the entitlement position

    Purchase records, agreements, volume licensing portals, reseller statements and subscription tenants, gathered per publisher. Entitlement that exists but cannot be evidenced is flagged separately, because in a publisher discussion it is functionally the same as entitlement you do not have.

  4. 4

    Reconcile and quantify exposure

    Deployment against entitlement per product, in both directions, with unauthorised software, unsupported versions and unused assignments reported alongside. Findings prioritised by exposure rather than by count, since a small number of high value licences usually dominates the position.

  5. 5

    Remediate and make it continuous

    A remediation plan for the shortfall, a reclamation plan for the surplus, and a process that keeps the position current. A single reconciliation decays within a quarter. The organisations that stay compliant connected procurement to inventory and gave one person the responsibility.

Straight answers

What organisations ask about software asset audits.

It is a genuinely useful starting point and it is not a complete inventory. It reports application name, platform, version, device count and publisher, and exports to CSV. What it does not do is cover unmanaged personal device applications, AOSP enrolments, or co-managed Windows devices whose client apps workload is still in Configuration Manager.

Less current than most people assume. In general the report refreshes every seven days for each device starting from its enrolment date, and that refresh is not performed weekly across the whole tenant. The exception is Win32 application information collected by the Intune Management Extension every 24 hours.

Microsoft states directly that the number of discovered apps might not match the app install status count. Reasons include changing the targeting of an installed managed app, targeting multiple instances of the same app producing overlapping counts, and the two datasets being collected at different intervals. Reconciling them as one number is not defensible.

Microsoft describes it as the intended long-term replacement for Discovered apps for Windows devices needing faster refresh cycles and richer metadata. It collects data multiple times per day and adds properties such as install location, app size and uninstall commands. Where available it improves the quality of everything downstream of the inventory.

No, and an audit that does is doing half the work. Surplus is at least as common as shortfall: licences assigned to people who left, applications deployed estate-wide and opened by a fraction of recipients, and subscriptions renewed on last year quantity. Both numbers come out of the same reconciliation.

Establish your own position before responding in detail. Responding quickly with incomplete data tends to fix a narrative that is difficult to correct later. Knowing what you run and what entitlement you can evidence turns the exercise from disclosure into a discussion where you also know things.

Typically four to six weeks. Discovery is quick and largely automated. Entitlement assembly is what sets the schedule, because agreements, purchase records and portal access are scattered across finance, procurement and IT, and locating them is genuinely slower than most organisations expect.

Yes, and it needs a different method because nothing is installed to discover. The position comes from tenant assignment data, expense records and network evidence of use, and the finding is usually the same in every engagement: several subscriptions bought by a department that IT has no record of.

Reported with dates, and it is frequently the most valuable output. Software past its support end date receives no security updates, which makes continuous vulnerability management impossible for that application regardless of what any policy says. CIS Control 7 cannot operate on software the vendor no longer patches.

A significant part of it. Applications installed with no procurement record, free tier tools whose terms exclude commercial use, personal licences used for business, and remote access utilities installed for a reason nobody remembers. Each is simultaneously a licence question and a security question.

Flagged separately from entitlement we can. The distinction matters because in a publisher discussion, entitlement you believe you own but cannot produce documentation for behaves the same as entitlement you do not own. Identifying it early leaves time to retrieve records from resellers before it becomes urgent.

It covers Microsoft as one publisher among several. Where Microsoft licensing is the specific concern, the dedicated review goes considerably deeper into service plans, assignment models and the interactions between suites that this estate-wide audit necessarily treats at a higher level.

By connecting procurement to inventory and giving one person the responsibility. A reconciliation is accurate on the day it completes and drifts within a quarter as people join, leave and install things. The audit is worth far more when it ends with a process rather than a document.

Yes, from the beginning. Entitlement evidence lives in purchase records and agreements that IT frequently cannot access, and departmental purchases on expenses are invisible without finance participation. Audits run entirely from IT consistently understate both what the organisation owns and what it bought.

We scope by estate size, number of publishers in focus and how accessible entitlement records are. A useful free first step: ask for a licence position for your largest publisher within two working days. What arrives, and how quickly, predicts the shape of the whole engagement fairly reliably.
Before you engage anyone

Fifteen questions to ask your own team.

If more than four of these take longer than a day to answer, the audit will find things. That is not a criticism of the team, it is the normal state of an estate that grew through projects and purchases.

Inventory

  • What proportion of devices report a software inventory?
    Coverage needs a denominator.
  • How old is the newest data in that report?
    Seven day per-device refresh, not per tenant.
  • Which platforms report nothing at all?
    AOSP enrolments show no discovered apps.
  • Are co-managed devices collecting through IME?
    Check the client apps workload.
  • Are servers included in the same inventory?
    Usually not.

Entitlement

  • Can we produce a licence position per publisher?
    Within two working days.
  • Where are the agreements physically kept?
    And who has access.
  • Who owns entitlement records?
    Finance, procurement or IT.
  • Do we know what departments bought on expenses?
    Almost always no.
  • Are subscription assignments reviewed at leavers?
    Check five recent leavers.

Exposure

  • What software runs past its support end date?
    With dates, not impressions.
  • What is installed with no procurement record?
    Free tier tools count.
  • Are personal licences used for business work?
    Common and frequently a breach.
  • Have we had a publisher enquiry before?
    They tend to repeat.
  • Who would coordinate a publisher audit response?
    Decide before, not during.
Related reading

The pages around this one.

Microsoft licence audit

The Microsoft entitlement question in considerably more depth.

Learn more

IT infrastructure audit

The hardware and platform estate, dated against vendor lifecycles.

Learn more

IT audit services

The parent audit practice and the other audit types within it.

Learn more
Next step

Ask for a licence position for your largest publisher, by Friday.

Deployment count, entitlement count, and the evidence for the second. If that takes longer than two days to produce, you have your answer about where the audit will find things.

Book a software asset auditCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Microsoft Licence Audit

Assigned, used and entitled, compared properly

Learn more

IT Infrastructure Audit

What you run, how much is supported, what fails

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

Win32 App Packaging

Packaging, detection rules and deployment that works

Learn more

IT Risk Assessment

A short register with an owner against every risk

Learn more

M365 Licensing

Optimize your Microsoft 365 licensing costs

Learn more

IT Due Diligence

What the target runs, what it costs, what integration costs

Learn more

CIS Controls Assessment

Eighteen controls, assessed and re-assessed

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy