Licence sprawl builds up slowly. Someone is provisioned a top-tier plan for one feature they used once, a leaver's account stays enabled at full cost for months, and nobody revisits the original assignment because it was never wrong enough to trigger a review.

The useful audit window is 60 to 90 days before renewal, so findings can change what gets committed rather than arriving too late to matter. Start with seats nobody holds, accounts provisioned for a role that no longer exists, or a project that finished. That category typically accounts for a small but real slice of a licence bill. It sounds minor until it is multiplied by every renewal you have not checked.

On one tenant, a group of users still held E5 because a compliance project had needed it two years earlier. The project had ended and the group had not. A sign-in and feature-usage report showed none of them used an E5-only feature, and with the renewal still some way off there was time to move them down and reclaim the difference.

Next, check for licensed users with no sign-in activity in 90-plus days who are still fully enabled, a common gap when offboarding removes access but leaves the licence assignment untouched. Then look for duplicate or overlapping SKUs: users holding a bundle that already contains a feature they are separately licensed for on its own.

The audit is also the moment to check licence tier against actual usage, not assumed need. A user provisioned for a premium tier at onboarding two years ago may only be using the features in the base tier today, or the reverse: someone on a base licence has been requesting workarounds for functionality a higher tier already includes.

The audit isn't a one-off spreadsheet. Usage drifts as roles change, so the audit is only valuable if it becomes a recurring check rather than a pre-renewal scramble. Give the audit an owner and a calendar, whether that is an internal team or a managed engineering arrangement.

Reviewing your Microsoft 365 licences? Microsoft 365 licensing

All resources