Hidden Duplication in Microsoft 365 Licenses (and How to Find It Fast)
Microsoft 365 overspend is often quiet: add-ons left assigned after an upgrade, users holding two products for the same workload, shared mailboxes that kept user licenses, and security bundles stacked on top of suites that already include the same service plans. In a 300-user tenant, a few legacy add-ons can turn into thousands of dollars per month in avoidable spend.
The duplication problem usually starts after a reasonable decision
License duplication usually starts with a valid fix that never gets retired.
Common pattern: an organization starts with Microsoft 365 Business Standard, adds Microsoft Intune Plan 1, Microsoft Entra ID P1, Microsoft Defender for Office 365 Plan 1, or Microsoft Defender for Business, then later moves users to Microsoft 365 Business Premium or Microsoft 365 E3. The old add-ons stay assigned because no one wants to break security policies, device management, or mail protection.
Another pattern: a team buys Visio, Project, Power BI Pro, Teams Phone, or Exchange Online Plan 2 for a temporary need. The project ends, the user changes roles, or the capability becomes covered by a higher suite, but the license assignment remains.
The cost is only part of the problem. Stacked licensing makes it harder to know which entitlement is enabling a feature, which users are actually covered, and which controls are configured versus merely purchased.
Start with license stacking, not utilization reports
The fastest first pass is license stacking: users with a base suite plus add-ons that overlap with that suite. Usage reports help later; stacking shows obvious candidates immediately.
Check these combinations first:
- Microsoft 365 Business Premium plus standalone Intune Plan 1, Entra ID P1, Defender for Business, or Defender for Office 365 Plan 1. Business Premium includes these capabilities for eligible users.
- Microsoft 365 E3 plus Enterprise Mobility + Security E3, Intune Plan 1, Entra ID P1, or Exchange Online Plan 2. Microsoft 365 E3 includes core identity, device management, Windows Enterprise, Microsoft 365 Apps, and Exchange Online Plan 2 service plans.
- Microsoft 365 E5 plus Microsoft 365 E5 Security or individual Entra ID P2, Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Defender for Identity, or Defender for Cloud Apps licenses. Full Microsoft 365 E5 already includes those security workloads.
- Microsoft 365 Apps for enterprise plus Microsoft 365 E3, Microsoft 365 E5, or Microsoft 365 Business Premium. If the suite includes desktop apps for that user, the standalone Apps license is usually unnecessary.
- Power BI Pro plus Microsoft 365 E5. Microsoft 365 E5 includes Power BI Pro; Microsoft 365 E3 and Business Premium do not.
- Exchange Online Plan 2 plus Microsoft 365 E3 or E5. For user mailboxes, E3 and E5 already include Exchange Online Plan 2 capabilities.
Use your actual agreement or CSP prices, not public list prices, for the business case. The model is simple: 120 redundant Entra ID P1 licenses at $6 each is $720 per month; 80 redundant Intune Plan 1 licenses at $8 each adds $640; 60 redundant Defender for Office 365 Plan 1 licenses at $2 each adds $120. That is $1,480 per month before reviewing Project, Visio, Power BI, Teams Phone, or E5 add-ons.
Map licenses to personas, not departments
Duplication is not always two overlapping products. Sometimes the wrong tier follows a user after a role change.
A finance analyst may need Power BI Pro. A warehouse supervisor may need Teams, mobile access, a mailbox, and managed identity, but not Microsoft 365 E3 plus Visio Plan 2. A former project manager may still hold Project Plan 3 after the active project ended.
Use personas as the licensing control point:
- Knowledge worker: Microsoft 365 Apps, mailbox, Teams, OneDrive, device management, and baseline security.
- Frontline worker: Teams, mobile/web productivity, limited mailbox needs, managed identity, and shared-device scenarios where applicable.
- Executive or privileged admin: stronger identity protection, privileged access controls, audit, and compliance coverage.
- Contractor or vendor: time-bound access, least privilege, limited data footprint, and enforced expiration.
- Shared or service account: no interactive sign-in by default; no user license unless there is a documented workload requirement.
A one-time cleanup removes today’s waste. Persona-based group licensing keeps the same waste from returning.
Do not ignore shared mailboxes, disabled users, and dormant accounts
Shared mailboxes usually do not need a paid Exchange license if they stay within the 50 GB shared mailbox limit and do not need licensed features. A license may be required for archive mailboxes, litigation hold, retention requirements that depend on licensed features, larger mailbox size, or direct user sign-in. Converted user mailboxes often keep Microsoft 365 Business Standard, Microsoft 365 E3, or Exchange Online Plan 2 licenses long after conversion.
Disabled users are another common leak. Blocking sign-in does not reclaim the license. Offboarding should include a retention/legal hold check, data handoff, group removal, and license removal.
Dormant licensed accounts are both cost and security risk. An account with no recent sign-in may still have a mailbox, OneDrive content, Teams memberships, app consents, and external sharing history. Review inactivity together with identity hygiene: validate the owner, preserve required data, remove access, and reclaim the license.
Check whether expensive add-ons are assigned but not operationalized
Some spend is not duplicated, but it is still wasted because the control is not deployed.
Examples:
- Entra ID P2 is assigned, but access reviews, Privileged Identity Management, and risk-based policies are not in use.
- Defender for Endpoint Plan 2 is licensed, but endpoints are not onboarded or show stale sensor health.
- Defender for Office 365 Plan 2 is licensed, but Safe Links, Safe Attachments, anti-phishing policies, and attack simulation training are not targeted to the right users.
- Microsoft Purview features are licensed, but retention labels, sensitivity labels, DLP policies, eDiscovery, or audit requirements were never implemented.
- Power BI Pro is assigned broadly, but only a small group publishes or consumes shared content that requires Pro licensing.
The answer is not always removal. Sometimes the right action is to finish the deployment. Make that explicit: either operationalize the control with owners and dates, or reduce the licensing scope.
Use a 30-minute triage before a full license redesign
You do not need a long licensing project to find the first savings wave.
Pull three views:
- Subscribed SKUs: products purchased, assigned, and available.
- User license detail: SKUs and service plans assigned to each user.
- Account and workload signals: disabled state, last sign-in where available, mailbox type, device onboarding, Teams Phone status, and workload usage.
Sort by cost and risk. Start with E5, E5 Security, Teams Phone, Calling Plans, Project, Visio, Power BI Pro, Defender, Entra, Intune, and Exchange Online Plan 2. Flag users with stacked products. Split findings into confirmed removals, configuration fixes, and decisions that need business validation.
Do not remove licenses blindly. License removal can affect archive mailboxes, holds, retention, advanced security, device management, Teams Phone, eDiscovery, audit, or compliance obligations. Remove confirmed overlap; validate anything tied to data retention, security controls, or telephony.
Fast Microsoft 365 License Duplication Checklist
| Check | What to look for | Likely action |
|---|---|---|
| Business Premium users with standalone Intune Plan 1, Entra ID P1, Defender for Business, or Defender for Office 365 Plan 1 | Add-ons bought before the Business Premium rollout | Remove duplicate add-ons after confirming policies, device enrollment, and service plan assignments |
| Microsoft 365 E3 users with EMS E3, Intune Plan 1, Entra ID P1, or Exchange Online Plan 2 | Legacy add-ons still assigned after E3 migration | Consolidate into E3 where feature coverage is equivalent |
| Microsoft 365 E5 users with E5 Security or individual Entra ID P2/Defender add-ons | Full E5 plus security bundle stacking | Remove redundant add-ons unless there is a specific licensing exception |
| Microsoft 365 E5 users with standalone Power BI Pro | Power BI Pro assigned separately even though E5 includes it | Remove standalone Power BI Pro after confirming the user keeps E5 |
| Users with Microsoft 365 Apps for enterprise plus E3, E5, or Business Premium | Standalone desktop apps license overlapping with a suite | Remove standalone Apps license if desktop app rights are already covered |
| Exchange Online Plan 2 plus Microsoft 365 E3 or E5 | Separate Exchange license assigned to users already covered by the suite | Remove standalone Exchange license unless there is a documented exception |
| Shared mailboxes with paid Microsoft 365 or Exchange licenses | Converted user mailboxes that kept licenses | Remove license unless archive, hold, mailbox size, retention, or sign-in requirements justify it |
| Disabled users with assigned licenses | Offboarding blocked sign-in but did not reclaim licenses | Complete retention/legal review, preserve required data, then remove licenses |
| No recent sign-in with paid licenses | Dormant users, stale contractors, abandoned accounts | Validate owner, remove access, preserve data if needed, reclaim license |
| Project, Visio, or Power BI Pro assigned through broad groups | Premium apps assigned by habit or old group membership | Confirm active use and reassign only to users who need the product |
| Teams Phone, Calling Plan, or operator voice add-ons with no number, routing, or call activity | Voice licenses assigned before rollout or after role changes | Remove or reassign after validating voice requirements |
| Entra ID P2, Defender, or Purview licensed but not configured | Paid security/compliance controls not operationalized | Implement the control with owners and dates, or reduce licensing scope |
| Manual one-off license assignment | Inconsistent admin-driven assignments | Move to group-based licensing tied to personas and exceptions |
| Purchased licenses consistently above assigned need | Overbuying before renewal | Reduce quantities at renewal or use monthly terms where flexibility is needed |
Key takeaways
- The largest Microsoft 365 duplication often comes from add-ons left behind after moving to Business Premium, E3, or E5.
- Start with stacked license assignments before utilization reports; it is the fastest way to find obvious overlap.
- Shared mailboxes, disabled users, dormant accounts, and stale contractors create both wasted spend and identity risk.
- Not every unused add-on should be removed immediately; some controls should be deployed instead.
- Persona-based group licensing prevents duplication from returning after cleanup.
If you want a second set of eyes on hidden overlap, stale assignments, and risky license gaps, IT Partner offers a free Microsoft 365 tenant review: Microsoft 365 Tenant Health Check. It is designed to surface practical cleanup opportunities without turning the exercise into a sales-heavy licensing project.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.