First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Blog/Right-Sizing Microsoft 365: Match Licenses to Ac…

Right-Sizing Microsoft 365: Match Licenses to Actual Usage

2026-06-16·IT PartnerNewMicrosoft 365LicensingCost Optimization

Microsoft 365 overspend usually comes from accumulated exceptions: E5 assigned by default, inactive accounts left licensed, shared mailboxes carrying user SKUs, and add-ons that outlive the project that needed them. Renewal discounts help less than fixing the license mix. The durable answer is a usage-based licensing process that proves which users need which workloads.

The Real Problem: Paying for Entitlement Instead of Need

The Microsoft 365 admin center shows what users are entitled to use. It does not prove that they need those entitlements.

Common findings include:

  • Microsoft 365 E5 assigned to users with no use of E5 or add-on-dependent capabilities such as Microsoft Defender for Office 365 Plan 2, Microsoft Purview advanced compliance features, Microsoft Entra ID P2 features, Power BI Pro, or Teams Phone.
  • Microsoft 365 Business Premium assigned where users only need Exchange Online, Teams, and web apps.
  • Frontline or task workers licensed like full knowledge workers.
  • Departed employees retaining licenses after offboarding.
  • Service, scanner, application, room, and shared mailbox accounts consuming full user SKUs without a documented reason.
  • Project, Visio, Teams Phone, Power BI Pro, Microsoft 365 Copilot, Defender, or Purview add-ons attached to accounts with no recent workload activity.

Use list pricing only as a sizing guide, because Microsoft pricing varies by term, region, program, and billing model. As a simple example, if Microsoft 365 E3 is about $36 per user/month and Microsoft 365 E5 is about $57 per user/month, the E5 premium is about $252 per user/year. If 200 users have E5 and only 70 have a validated E5 requirement, the potential annual waste on the suite delta alone is about $32,760 before add-ons. The point is not to downgrade blindly; it is to keep premium licensing where it reduces risk or enables work, and remove it where it is parked.

Start With Evidence, Not SKU Names

Begin with tenant telemetry and business requirements. SKU names are packaging; usage data shows operational need.

Collect evidence from these areas:

  • Identity activity: last interactive sign-in, non-interactive sign-ins, disabled accounts, stale guests, privileged roles, and accounts with no recent activity.
  • Core Microsoft 365 usage: Exchange mailbox activity, Teams chat/meeting/calling activity, SharePoint and OneDrive file activity, Microsoft 365 Apps activation, Outlook activity, and mobile/web-only use.
  • Premium workload usage: Defender alerts and investigations, Defender XDR advanced hunting, Purview eDiscovery, Audit (Premium), retention, communication compliance, insider risk, DLP and endpoint DLP, sensitivity label publishing and auto-labeling, Power BI reports/workspaces, Teams Phone numbers/call queues/auto attendants, Project, Visio, and Copilot activity.
  • Security dependencies: Conditional Access, Intune device compliance, Microsoft Defender for Endpoint or Defender for Business coverage, privileged identity management, identity protection, access reviews, and risk-based policies.
  • Role requirements: executives, finance, legal, HR, IT admins, regulated teams, frontline workers, contractors, shared-device users, board members, seasonal staff, and non-human accounts.

Treat a user as an E5 user only when E5-included capabilities are used, required by policy, or intentionally assigned for risk control. Otherwise, evaluate E3, Business Premium, frontline plans, or targeted add-ons.

Segment Users by Workload Profile, Not Department

Department-based licensing is too blunt. Finance may include a CFO who needs elevated identity protection, analysts who need Power BI Pro, AP clerks who need standard productivity, and contractors who need time-bound access. One department can contain several licensing profiles.

Use workload profiles instead:

  1. Full productivity users: need desktop Microsoft 365 Apps, Exchange, Teams, OneDrive, SharePoint, and standard security controls. Depending on organization size and security requirements, these users may fit Microsoft 365 Business Standard, Business Premium, E3, or E5. Business plans are capped at 300 users per tenant.

  2. Security-sensitive users: executives, finance, HR, IT, and privileged users with elevated risk. These users may justify Business Premium, E3 plus security add-ons, Microsoft 365 E5 Security, or E5, depending on Entra ID, endpoint, email security, and investigation requirements.

  3. Compliance-heavy users: legal, records management, regulated teams, and users in eDiscovery, retention, DLP, audit, insider risk, or communication compliance workflows. E5 or Microsoft 365 E5 Compliance may be justified when those capabilities are deployed and assigned to the right users.

  4. Frontline or task workers: users who need Teams, email, mobile/web apps, or shared-device workflows but not full desktop apps. Microsoft 365 F-series plans can fit, but validate mailbox size, app access, device management, and compliance requirements first.

  5. Light or occasional users: board members, seasonal workers, contractors, vendors, and project-based staff. These accounts need expiration dates, access reviews, and license reviews.

  6. Non-human accounts: shared mailboxes, room and equipment mailboxes, scanner accounts, application accounts, service accounts, and emergency access accounts. Do not assign full user SKUs by habit. Document the exact reason when a license is required.

Know Where Downgrades Create Risk

Right-sizing is controlled change, not cost cutting by spreadsheet. Several capabilities are license-sensitive, and removing the wrong license can create security, compliance, or productivity gaps.

Check these dependencies before downgrading or removing a license:

  • Mailbox limits: Exchange Online Plan 1 and Plan 2 have different mailbox, archive, and compliance capabilities. Shared mailboxes can often be unlicensed, but a license is required for scenarios such as an archive mailbox, larger mailbox requirements, or certain compliance needs.
  • Desktop apps: Business Basic and many frontline plans do not include desktop Microsoft 365 Apps. Moving a desktop-app user to a web-only plan will create activation issues.
  • Identity: Conditional Access requires Microsoft Entra ID P1 for covered users. Identity Protection, Privileged Identity Management, and access reviews require Entra ID P2.
  • Device management and endpoint security: Intune, Defender for Business, and Defender for Endpoint licensing must still cover users/devices after the change.
  • Email and collaboration security: Defender for Office 365 Plan 1 and Plan 2 capabilities differ; do not remove Plan 2 where investigation, automation, or advanced protection workflows depend on it.
  • Compliance: eDiscovery (Premium), Audit (Premium), advanced retention, endpoint DLP, auto-labeling, communication compliance, and insider risk management may require E5 or compliance add-ons.
  • Voice and meetings: Teams Phone, Calling Plans, Operator Connect, Direct Routing, resource accounts, call queues, auto attendants, and audio conferencing should be checked before removing voice-related licenses.
  • Specialized apps: Power BI Pro, Project, Visio, and Microsoft 365 Copilot are separate entitlement checks. Confirm actual use and base-license eligibility before removal.

Savings are real only when the target license still supports the user’s work, security posture, and compliance obligations.

Run a 90-Day Right-Sizing Cycle

Microsoft 365 licensing drifts because onboarding templates, manager requests, projects, reorganizations, and security initiatives change faster than renewals. Make right-sizing a recurring operating process.

Use this 90-day cycle:

  • Week 1: Export assigned licenses, group-based licensing rules, direct assignments, add-ons, disabled users, inactive users, shared/resource mailboxes, privileged accounts, service accounts, and emergency access accounts.
  • Week 2: Pull 30/60/90-day usage signals. Use more than one time window because some workloads, such as eDiscovery, audit review, Project, Visio, and Power BI, may be periodic.
  • Week 3: Map users to workload profiles. Identify removals, downgrades, add-on cleanup, and exceptions requiring documentation.
  • Week 4: Review proposed changes with IT, security, compliance, finance/procurement, and business owners. Approve an exception list with owners and review dates.
  • Weeks 5-6: Pilot changes with a small group. Monitor help desk tickets, sign-in failures, Office activation, mailbox issues, Teams calling, Power BI access, compliance workflows, and Conditional Access impact.
  • Weeks 7-8: Apply approved changes in batches. Keep rollback instructions and record before/after license state.
  • Weeks 9-12: Update group-based licensing, onboarding templates, request forms, offboarding automation, access reviews, and procurement quantities so the same waste does not return.

A one-time cleanup reduces today’s bill. A governed cycle prevents the next renewal from rebuilding the same problem.

Use Assignment Rules to Prevent Drift

Manual license assignment creates a record of old decisions. Use governed assignment rules instead.

A practical model:

  • Baseline licenses by role and employment type.
  • Premium suites only for approved security, compliance, analytics, voice, or productivity requirements.
  • Add-ons assigned by workload owner approval and reviewed against usage.
  • Exceptions with expiration dates.
  • Disabled users reviewed automatically for license removal after offboarding and retention checks.
  • Direct license assignments minimized; group-based licensing used where groups are governed.

Group-based licensing is not governance by itself. An “All Employees - E5” group only automates overspend unless membership rules and exceptions are controlled.

Separate license cleanup from access cleanup. Removing a license is not the same as disabling access, and disabling access is not the same as preserving data. Offboarding should cover mailbox conversion, OneDrive ownership transfer, retention or legal hold requirements, group memberships, app permissions, privileged roles, guest access, and license removal in the correct order.

Decision area What to check Right-sizing action
Inactive users No interactive sign-in in 30/60/90 days, disabled accounts, no mailbox/Teams/SharePoint/OneDrive activity Remove licenses after confirming offboarding, retention, legal hold, mailbox ownership, and OneDrive transfer requirements
Microsoft 365 E5 assignments Use or requirement for E5-included security, compliance, identity, analytics, or voice capabilities Keep E5 where justified; move others to E3, Business Premium, frontline plans, or targeted add-ons where requirements are still met
Business Premium vs Business Basic/Standard Desktop app need, Intune, Defender for Business, Defender for Office 365 Plan 1, Conditional Access, device compliance Keep Business Premium where the security/device stack is deployed; downgrade only when security and app requirements remain covered
Frontline users Shared-device use, mobile/web-only workflows, mailbox size, Teams needs, desktop app requirement, compliance scope Consider F-series plans when mailbox, app, security, and compliance limits fit the role
Add-ons Power BI Pro, Project, Visio, Teams Phone, Calling Plans, Microsoft 365 Copilot, Defender, Purview, Entra ID P2 Remove, reassign, or time-limit unused add-ons; require owner approval and usage review before renewal
Shared and resource mailboxes User licenses assigned to shared, room, equipment, scanner, or application accounts Remove unnecessary licenses; document exceptions such as archive mailbox, mailbox size, compliance, or authentication requirements
Admin and privileged accounts Entra ID P2, PIM, Identity Protection, access reviews, Conditional Access, MFA, emergency access design Do not downgrade blindly; privileged access often justifies premium identity and security licensing
Teams Phone and meeting services Phone numbers, call queues, auto attendants, Operator Connect, Direct Routing, Calling Plans, audio conferencing Remove unused voice licenses only after validating number assignment, routing, and service dependencies
Renewal planning Assigned licenses, 90-day usage, approved projects, hiring plan, seasonal demand, exception list Buy to validated demand plus approved growth, not historical assignment counts

Key takeaways

  • The largest Microsoft 365 savings usually come from correcting the license mix, not negotiating a small discount on unused entitlements.
  • E5, Microsoft 365 Copilot, Teams Phone, Project, Visio, Power BI Pro, Defender, Purview, and Entra ID P2 should be tied to measured usage or documented risk requirements.
  • Every downgrade needs dependency checks across identity, security, compliance, mailbox, device, voice, and app workloads.
  • Right-sizing should run every 90 days with governed assignment rules, exception owners, and expiration dates.

If you want a second set of eyes before renewal, IT Partner’s free Microsoft 365 Tenant Health Check can help identify stale licenses, risky assignments, and practical optimization candidates without turning the review into a hard-sell licensing exercise.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.