First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Blog/How to Run a Microsoft 365 License Audit (and Wh…

How to Run a Microsoft 365 License Audit (and What to Look For)

2026-06-16·IT PartnerNewMicrosoft 365LicensingCost OptimizationSecurity

Microsoft 365 overspend usually builds in small layers: premium suites assigned by default, disabled accounts still licensed, standalone add-ons duplicated by bundles, unmanaged licensing groups, and annual subscriptions renewed before anyone reviews usage. A useful audit ties billing, identity, workload activity, security requirements, and renewal dates to specific license actions.

1. Start with subscriptions and renewal constraints

Begin with what the organization is paying for, not with the user list. Export active subscriptions from the Microsoft 365 admin center or Partner Center: product name, SKU, purchased quantity, assigned quantity, available quantity, renewal date, billing term, commitment term, and whether the subscription is monthly or annual under the New Commerce Experience (NCE).

Build a baseline by SKU. Example: 500 Microsoft 365 E3 licenses purchased, 463 assigned, 37 available, renewal in 18 days. Those 37 licenses are waste, but the action depends on the term. If the subscription is annual and outside the cancellation or seat-reduction window, document the reduction target, stop additional purchases, and reduce seats before renewal.

Separate suites from add-ons. Review Microsoft 365 E3/E5, Office 365 E1/E3/E5 where still used, Microsoft 365 Business Basic/Standard/Premium, Microsoft 365 F3, Exchange Online, Microsoft Entra ID, Microsoft Intune, Microsoft Defender, Microsoft Purview, Visio, Project, Power BI Pro, Teams Phone, Audio Conferencing, and Microsoft 365 Copilot. Savings usually come from the SKU mix, not from one product.

2. Build a clean identity and license inventory

Export users from Microsoft Entra ID and include user type, account enabled status, department, job title, manager, last interactive sign-in, last non-interactive sign-in where available, assigned licenses, direct versus group-based assignment, mailbox type, mailbox size, archive status, OneDrive activity, Teams activity, and device enrollment status.

Classify accounts before changing licenses. Use practical categories: active employee, frontline worker, contractor, guest, shared mailbox, room/resource mailbox, service account, emergency access account, leaver, and unknown. A disabled former employee on litigation hold is different from an inactive contractor. A service account may show no Teams or OneDrive activity but still support an application.

Target obvious hygiene first: disabled users with paid licenses, test accounts with premium suites, stale contractors, and shared mailboxes with unnecessary licenses. Shared mailboxes normally do not need a license unless they require features such as an archive mailbox, litigation hold, Microsoft Purview retention or eDiscovery requirements, a mailbox size above the unlicensed limit, or direct sign-in.

3. Define inactivity with workload evidence

Do not remove licenses based on sign-in alone. A user may have low interactive sign-in activity but still use mail through a client, mobile app, delegated access, or a service workflow. The reverse is also common: a user authenticates regularly but does not use the premium workloads in the assigned license.

Use a 30/60/90-day review model. At 30 days, flag accounts for review. At 60 days, validate with the manager or application owner. At 90 days, remove or downgrade the license unless there is a documented exception. Check Exchange mailbox activity, Teams chat and meeting activity, OneDrive and SharePoint file activity, Microsoft 365 Apps activation, Power BI activity, Defender device onboarding, Intune enrollment, and Entra sign-ins.

For example, a user with Microsoft 365 E5 who signed in last week is not inactive. But if that user has no Microsoft Defender for Endpoint Plan 2 dependency, no Microsoft Entra ID P2 requirement, no Purview advanced compliance use, no eDiscovery (Premium) involvement, no Teams Phone requirement, and no Power BI Pro usage, E5 may still be excessive. Audit for mismatched entitlement, not only unused accounts.

4. Find over-licensing and duplicate coverage

Map licenses to roles. Executives, finance, legal, security, IT administrators, and regulated users may justify E5. Standard information workers may fit E3. Eligible small and midsize business users may fit Microsoft 365 Business Premium. Frontline users may fit Microsoft 365 F3 or another frontline plan, depending on mailbox, app, and device needs.

Use list pricing only for directional modeling because pricing varies by region, agreement, term, promotions, and channel. In the US, common reference points are Microsoft 365 Business Premium at about $22 user/month, Microsoft 365 E3 at about $36 user/month, and Microsoft 365 E5 at about $57 user/month. Moving 100 users from E5 to E3 can represent about $2,100 per month before discounts, taxes, add-ons, and term restrictions.

Check duplicate entitlements. Microsoft 365 Business Premium includes Microsoft Entra ID P1, Microsoft Intune Plan 1, Defender for Business, and Microsoft 365 Apps for business. Users with Business Premium usually should not also have separate Entra ID P1, Intune Plan 1, or overlapping small-business security add-ons. Microsoft 365 E5 can overlap with standalone identity, security, compliance, analytics, and voice add-ons depending on the exact subscription mix.

Do not downgrade until dependencies are checked. Before moving from E5 to E3, validate Microsoft Defender for Endpoint Plan 2, Microsoft Entra ID P2, Microsoft Purview advanced compliance, Audit (Premium), eDiscovery (Premium), Insider Risk Management, Information Protection, Power BI Pro, Teams Phone, and audio conferencing requirements. Before moving from E3 to Business Premium, check the 300-user limit, Exchange mailbox and archive requirements, device management design, security baseline requirements, app deployment, and VDI/RDS activation needs.

5. Validate group-based licensing and assignment logic

Many tenants drift because licensing is assigned through old Microsoft Entra groups with unclear ownership. A user joins a department group and receives E3, moves roles and receives E5, then gets a project add-on through another group. The admin center shows the assigned products, but the business rule is often buried in group membership.

Export assignment paths for each paid SKU. Identify direct assignments, group-based assignments, dynamic group rules, nested group assumptions, HR provisioning mappings, and onboarding workflows. Direct assignments are often exceptions that were never removed. Group-based licensing is cleaner only when group ownership and membership rules are governed.

Use role-based licensing groups with named owners and documented criteria. Examples: M365-E3-Standard-Users, M365-E5-Security-Users, M365-F3-Frontline, PowerBI-Pro-Approved, TeamsPhone-Enabled, Copilot-Approved. Avoid vague groups such as All Staff Premium or Test Licensing Group.

6. Convert findings into a controlled reduction plan

Split findings into four action buckets: remove now, downgrade after validation, keep with documented justification, and review at renewal. This separates real savings from savings that are blocked by contract terms, feature dependencies, or business risk.

For removals, start with disabled users, confirmed leavers, duplicate add-ons, available licenses that can be reduced, and inactive accounts approved by the business owner. For downgrades, pilot with a small group and confirm access to Exchange, Microsoft 365 Apps, Teams, Conditional Access-protected resources, Defender, Intune, Power BI, Teams Phone, and Purview workflows.

Set a renewal review 45 to 60 days before each subscription anniversary. For NCE annual commitments, seat reductions generally need to be planned at renewal or during the allowed cancellation/reduction window. Track target quantity, current quantity, forecast hiring, approved exceptions, and the person accountable for the change.

Add controls after cleanup. Require approval for E5, Microsoft 365 Copilot, Power BI Pro, Project, Visio, Teams Phone, and other premium add-ons. Tie leaver workflows to license removal. Review direct assignments monthly. Keep emergency access accounts licensed only where required by your identity and security design.

Audit step What to pull What to look for Action
1. Export subscriptions Product/SKU, purchased quantity, assigned quantity, available quantity, renewal date, term, billing frequency Available seats, annual commitments, NCE reduction constraints Mark what can be reduced now versus at renewal
2. Export user/license data Entra users, assigned licenses, direct/group assignment source, account status Disabled users, test accounts, stale contractors, unmanaged direct assignments Remove licenses or route to owner validation
3. Check activity Sign-ins, Exchange, Teams, OneDrive, SharePoint, Microsoft 365 Apps activation, Power BI, device activity Licensed users with no workload activity for 30/60/90 days Review at 30, validate at 60, remove or downgrade at 90
4. Classify account types Employees, frontline workers, contractors, guests, service accounts, shared mailboxes, rooms, leavers Shared mailboxes with full suites, service accounts with premium licenses Reassign, remove, or document the exception
5. Compare SKU to role Job role, department, workload usage, security/compliance requirements E5 users without E5-only dependencies; E3 users eligible for Business Premium or F3 Downgrade in pilot batches after dependency checks
6. Find duplicate entitlements Suite licenses plus standalone add-ons Business Premium plus separate Entra ID P1/Intune/security; E5 plus overlapping add-ons Remove standalone add-ons when suite coverage is sufficient
7. Review premium add-ons Power BI Pro, Project, Visio, Teams Phone, Audio Conferencing, Microsoft 365 Copilot Assigned licenses with no usage or no business owner Reclaim licenses and require approval for reassignment
8. Validate group-based licensing Licensing groups, dynamic rules, assignment paths, direct assignments Old groups, unclear owners, overlapping membership, stale exceptions Standardize role-based groups and remove manual exceptions
9. Check downgrade blockers Mailbox size, archive, litigation hold, retention, Conditional Access, Defender, Intune, Purview, Teams Phone Users who would lose required features after license reduction Keep, redesign, or migrate before downgrading
10. Build the renewal plan Contract dates, target quantities, hiring forecast, exception list Savings blocked by missed renewal or reduction windows Schedule review 45–60 days before renewal

Key takeaways

  • The biggest license savings usually come from mismatched SKUs, duplicate add-ons, disabled users, and unmanaged licensing groups.
  • Do not define unused by sign-in alone; validate workload activity, role, and business ownership before removing or downgrading.
  • E5, Microsoft 365 Copilot, Power BI Pro, Teams Phone, Project, and Visio need recurring review because small assignment drift becomes recurring spend.
  • A license audit must account for NCE commitment terms and renewal dates; otherwise savings may be valid but not immediately actionable.
  • The target state is role-based licensing with named owners, approval controls, documented exceptions, and a recurring review cycle.

If you want a second set of eyes on license waste, security gaps, and tenant configuration risk, IT Partner offers a free Microsoft 365 Tenant Health Check. It is a practical review of your current tenant, not a generic licensing presentation.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.