SaaS Portfolio and Renewal Optimization Review
A fixed-price, two-week review of every software subscription your organization pays for — not only the Microsoft ones. We build one inventory from three independent sources: Microsoft Entra enterprise applications and their sign-in activity, a Cloud Discovery snapshot from your firewall and proxy logs where you are licensed for one, and your finance and accounts-payable exports. For every application we record the business owner, the seats you pay for against the people who actually sign in, the annual cost, the contract term, the renewal date and — the date that actually matters — the notice deadline after which the renewal happens whether you meant it or not. We then map the whole portfolio against what your existing Microsoft 365 plans already include, grade each consolidation candidate with a migration path and an honest effort estimate, build a twelve-month renewal calendar ordered by decision date, prepare the usage evidence for the renewals you intend to keep, and hand you an action plan with a named owner on every line. $2,950 fixed for organizations up to 500 users; larger estates are quoted per estate in writing before we start. We publish no savings percentage: the number comes out of your own contracts and your own usage data, and you see every line of the arithmetic behind it. We do not negotiate with your vendors, and we resell none of the software we assess.
What this engagement is
SaaS sprawl is rarely a decision. It accumulates. A department buys a tool on a card to solve this quarter's problem; a project needs a tracker; an acquisition arrives with a full stack of its own; a trial converts quietly into an annual contract nobody diarized. Two years later the organization cannot answer three basic questions: what are we paying for, who is actually using it, and when can we get out of it. IT knows the applications it federated to Microsoft Entra ID. Finance knows the invoices. Neither list is complete, and the gap between the two lists is where the money sits. This review builds the missing single list, and it uses three sources because no single source is enough. Microsoft Entra enterprise applications show which apps are integrated for single sign-on, and sign-in activity shows who has actually used them inside the retention window. A Cloud Discovery snapshot report, built from firewall and proxy logs you upload, finds the web applications that never touched Entra at all — the underlying Cloud App Discovery capability comes at no additional cost with Microsoft Entra ID P1, Enterprise Mobility + Security E3 and Microsoft 365 E3, and it scores what it finds against Microsoft's catalog of more than 31,000 cloud apps; the full Microsoft Defender for Cloud Apps adds continuous, endpoint-based discovery when you also hold Defender for Endpoint Plan 2. Finally, accounts-payable and corporate-card exports find the subscriptions that have an invoice but no login trail, which is usually where the expensive surprises live. We reconcile the three into one register and then chase the differences between them, because the differences are the finding. Then comes the part most spend reviews skip: mapping the portfolio against entitlements you have already bought. Microsoft 365 plans include a great deal that organizations pay for a second time elsewhere — Teams against Zoom, Slack or Webex; SharePoint and OneDrive against Box or Dropbox; Planner against Asana, Trello or Monday; Bookings against standalone scheduling tools; Forms, Loop and Whiteboard against their standalone equivalents; Teams Phone against RingCentral, 8x8 or Zoom Phone; Power Automate against Zapier; Microsoft Entra ID P1 or P2 against a separate single sign-on and MFA product; Intune against a third-party MDM; Exchange Online Protection and Defender for Office 365 against a third-party mail gateway; Microsoft Purview against a separate archiving or eDiscovery subscription. Overlap is not a verdict. For each candidate we state the feature gap plainly, the migration path and effort, the switching risks — integrations, compliance obligations, data extraction, retraining — and whether we think the incumbent should stay. Sometimes it should, and a report that never says so is not worth reading. The renewal work is what turns findings into decisions. Most SaaS contracts renew automatically, and the date you need in the calendar is not the renewal date — it is the notice deadline, minus the time your own approval process actually takes. We read the paperwork you hold and record term length, notice window, auto-renewal clause, uplift language, and any minimum-commitment or true-up mechanics, then build a twelve-month calendar sorted in that order, with a named owner and an internal decision date on every line. For each renewal you intend to keep, you get a preparation pack: seats bought against active users, credible alternatives with their real costs, and the term and volume options worth asking for. You run the conversation. We do not negotiate with your vendors, we take no share of what you save, and our fee is the same whatever you decide. The discipline here is FinOps applied to software rather than infrastructure — the FinOps Foundation's 2025 Framework revision made SaaS a scope in its own right alongside public cloud, which is exactly the shape of this work. We stay tooling-neutral: SaaS management platforms exist, they earn their keep at the top of the size range, and we sell none of them and take no referral fee for naming one. Related but deliberately separate engagements: the Microsoft 365 License Audit and Optimization goes deep on the Microsoft licences themselves at service-plan level, the Shadow IT Assessment Workshop examines unsanctioned apps through a security lens, Microsoft Defender for Cloud Apps Implementation builds the continuous discovery and control that this review only borrows a snapshot from, and the Azure performance and cost optimization assessment covers cloud consumption, which is a different discipline with different tooling.
Success criteria
What you receive
How the work unfolds
We agree the scope in writing — headcount, entities in scope, whether recently acquired companies are included — and you grant read-only access: Global Reader and Reports Reader in Microsoft Entra ID are sufficient for the enterprise-application and sign-in data. In parallel we issue the document request: twelve months of accounts-payable and corporate-card detail at vendor level, whatever contracts and order forms you hold, and a list of the applications you already know about. Nothing in this engagement writes to your tenant.
We extract enterprise applications and sign-in activity from Microsoft Entra ID; where you are licensed for Cloud App Discovery or Microsoft Defender for Cloud Apps, your team uploads firewall or proxy logs and we work from the resulting Cloud Discovery snapshot report; and we parse the finance exports for anything that looks like a software subscription. The three lists are reconciled into one register, and every disagreement between them is written down rather than smoothed over.
For each application we establish what you are actually paying for against who is actually using it: licensed seats from the invoice or the vendor admin console, active users from sign-in or discovery evidence. Short interviews with the named business owners fill in what no log can tell us — why the tool was bought, which team depends on it, what would break if it disappeared, and which contract file lives in whose mailbox.
Your current Microsoft 365 subscriptions are decomposed to the capabilities they actually grant, and every third-party application is tested against them: collaboration and meetings, file sharing, work management, scheduling, forms and whiteboarding, telephony, workflow automation, identity, device management, mail security, archiving and eDiscovery. Each overlap gets an honest feature-gap statement rather than a checkmark.
Contract terms are summarized — term length, notice window, auto-renewal, uplift, minimum commitment — and turned into a twelve-month calendar ordered by notice deadline. Consolidation candidates are ranked by net effect and effort, each with its migration path, the Microsoft-side changes it would require, and the switching risks that argue against it.
Findings become a twelve-month plan with an owner, a date and a dependency on every line, plus the negotiation packs for the renewals in the next two quarters and the intake process recommendation. We walk your finance and IT leads through all of it, defend each finding against challenge, and leave the working files with you whether or not you ever engage us again.
Prerequisites
Who does what
IT Partner
- Collect Microsoft Entra enterprise-application and sign-in evidence through read-only access only.
- Reconcile discovery, identity and finance data into a single register, and document every discrepancy between the three sources.
- Assess each application against the capabilities your current Microsoft 365 subscriptions already include, and name the feature gaps honestly — including where the third-party product is the better tool.
- Summarize the contract terms you supply into a renewal calendar ordered by notice deadline.
- Build the consolidation shortlist, the negotiation preparation packs and the twelve-month action plan.
- Present the findings, defend them under challenge, and hand over the working files.
- Treat commercial and usage data as confidential, use it only for this engagement, and delete it on request once you have accepted delivery.
Your team
- Grant the read-only Microsoft Entra access and, where applicable, produce the Cloud Discovery snapshot report or the logs it is built from.
- Provide the finance exports, contracts and vendor admin data — the quality of the register follows directly from the quality of these inputs.
- Make the named application owners available for short interviews.
- Decide what to act on. Nothing is cancelled, downgraded, migrated or renegotiated during this engagement; every change stays your decision and your action.
- Verify any notice deadline against your own executed contract before relying on it commercially.
What's not included
Limitations & technical notes
Frequently asked questions
How is this different from the Microsoft 365 License Audit and Optimization?
Different estate, different question. The license audit goes deep inside your Microsoft tenant — every subscription at service-plan level, per-user usage evidence, duplicate add-ons, a right-sized mix across Business Premium, E3 and E5. This review goes wide across everything else you pay for: the whole SaaS portfolio, its contracts, its renewal dates and its overlap with the Microsoft entitlements you already hold. Most organizations eventually want both; if you can only do one first, do the license audit when your Microsoft bill is the anomaly, and do this one when nobody can list what the company subscribes to.
Do we need Microsoft Defender for Cloud Apps to get value from this?
No, though it helps. Cloud App Discovery — the discovery subset — comes at no additional cost with Microsoft Entra ID P1, Enterprise Mobility + Security E3 and Microsoft 365 E3, and a snapshot report built from your firewall or proxy logs is enough to surface the web applications your identity data never sees. The full Defender for Cloud Apps adds continuous reporting and, with Defender for Endpoint Plan 2, endpoint-based discovery that follows users off the corporate network. If you hold neither, we build the register from Microsoft Entra enterprise applications and your finance data, tell you plainly what that will miss, and get on with it.
What if we cannot produce firewall or proxy logs?
It happens more often than vendors admit — the estate is fully remote, the gateway does not retain logs, or the security team cannot release them in the window. The review proceeds on identity and finance evidence, which between them catch the overwhelming majority of paid subscriptions, because paid software leaves an invoice even when it leaves no packet. The report then states the blind spot explicitly rather than quietly presenting a partial list as a complete one.
Will you just tell us to cancel everything and use Microsoft 365 for it all?
No, and you should be suspicious of anyone who would. Some third-party tools are genuinely better for the team that chose them, some carry integrations that would cost more to rebuild than the subscription costs to keep, and some are contractually locked for another two years. Every overlap we find is written up with the feature gap, the migration effort and the switching risk, and a recommendation that is often 'keep it, and revisit at the 2027 renewal'. We are not paid more if you consolidate.
Do you resell any of the software you assess, or take a referral fee?
No. We resell no SaaS applications and no SaaS management platform, we take no referral fee for naming one, and nobody at IT Partner is paid a commission of any kind — the people who handle sales are salaried. We do sell Microsoft subscriptions, and we sell them at Microsoft's published list prices, so even a recommendation that moves spend toward Microsoft does not move our margin. It is worth asking every advisor in this category the same question before you hire them.
Will you negotiate with our vendors for us?
No. We prepare the case — seats bought against active users, the alternatives with their real costs, comparable term and volume structures, and the questions worth asking — and your people carry it into the conversation. Two reasons. Your leverage is yours, not ours; and a fixed fee keeps our advice clean, whereas a share of savings would quietly bias every recommendation toward whatever is easiest to cut.
How much will we save?
We do not know yet, and we will not put a percentage on this page or in the proposal. What we commit to is the method: every application inventoried from three sources, every seat count tested against usage evidence, every overlap named with the Microsoft capability that covers it, and every line of the plan carrying its own annual figure so you can total it yourself and check our arithmetic. The savings, if there are any, are in your contracts already — the review just makes them visible in time to act.
What is a notice window, and why do you keep calling it the important date?
Most SaaS agreements renew automatically unless you give notice a set period before the renewal date — commonly 30, 60 or 90 days. Miss that deadline and the decision is made for you for another full term, however clear the business case was. So the calendar we build is sorted by notice deadline, not renewal date, and each line is backed off further by however long your own approval process takes. A renewal 'we will look at in the autumn' is frequently already decided by the summer.
Is the review read-only? What data do you actually touch?
Read-only throughout. Nothing is written to your tenant, no application is cancelled or modified, and no mailbox, file or document content is ever read — the work runs on enterprise-application metadata, sign-in activity, discovery reports, invoices and contracts. Global Reader and Reports Reader are sufficient in Microsoft Entra ID. Commercial data is treated as confidential, used only for this engagement, and deleted on request once you have accepted delivery. You can revoke the access the moment the walkthrough ends.
How do you find applications nobody told us about?
Three ways that catch different things. Identity data catches anything federated for single sign-on — including apps that were integrated once and forgotten. Discovery data catches web applications people reach in a browser without ever involving IT. Finance data catches everything with an invoice or a recurring card charge, including the ones with a single user and a renewal next month. The apps that appear in only one of the three are usually the interesting part of the report.
What if consolidating means buying a bigger Microsoft 365 plan?
Then we cost it that way. If replacing a telephony vendor needs Teams Phone licences, or replacing a separate SSO product needs Microsoft Entra ID P1, the plan shows the Microsoft-side increase against the third-party saving as a net figure, per year, on the same line. Those Microsoft licences are yours to buy — at Microsoft's published list prices, whether you buy them from us or anyone else — and any metered or consumption charges attached to them stay on your bill, not ours.
We are mid-term on most of our contracts. Is it too early for this?
No — mid-term is the right time, and the week before a renewal is the wrong one. Cancellation decisions need lead time: the notice has to be served, a replacement has to be chosen, data has to be extracted and people have to be moved and trained. A review that lands three or six months before your largest notice deadline gives you options. One that lands two weeks before it gives you a report about what you should have done.
What exactly do we receive, and in what format?
Working files you keep, not a slide deck: the SaaS application register as a workbook, the evidence appendix behind it, the Microsoft 365 overlap map, the consolidation shortlist, the contract summary sheet, the twelve-month renewal calendar, the negotiation preparation packs for the next two quarters, the action plan and the intake-process recommendation — plus the walkthrough call with the consultant who did the analysis. Everything is yours to reuse, including with another provider.
How long does the register stay accurate, and can you keep it current?
Assume a useful life of six to twelve months in a stable organization, and considerably less after an acquisition or a reorganization — which is why the intake-process recommendation is part of the deliverable rather than an afterthought. If you want the portfolio actively maintained, that is a retainer rather than a project: the Virtual CIO advisory retainer carries it as part of a wider IT roadmap, and the Microsoft 365 License Optimization Subscription keeps the Microsoft side of it under continuous review.
Does this cover our Azure spend, or our Microsoft 365 licences?
Azure and other cloud consumption, no — that is metered infrastructure spend with entirely different tooling, and it has its own Azure performance and cost optimization assessment. Microsoft 365 licences appear here only as entitlements: what your current plans already include, so we can tell which third-party tools duplicate them. The audit of the Microsoft licences themselves — assignment against usage, service-plan overlaps, plan-tier right-sizing — is the license audit, and the two engagements are deliberately priced and scoped apart.
Who does the work, and what happens after the walkthrough?
A licensing and commercial consultant, working to a written scope with read-only access, supported by an engineer for the Microsoft entitlement mapping. After the walkthrough you decide: most clients execute the plan themselves, because the hard part was knowing what to do and by when. If you want help with a specific migration or with moving Microsoft billing, that is quoted separately, fixed-price and in writing. There is no obligation in either direction, and no lock-in — you paid for a review and you own the output.