SaaS Management

Microsoft 365 License Optimization: Where the Spend Actually Leaks, and How to Find It

Chinmay Panda
Lead Product Manager, Zluri
Last Updated
May 5, 2025
8 MIn read

Ready to secure your identity surface?

About the author

Chinmay, an IIM Bangalore alum, leads Product Management at Zluri. Before Zluri, Chinmay has worked in the product team of Media.net, and in engineering roles in Bharat Heavey Electricals Limited & Tata Consultancy Services. He is a technology enthusiast.

Somewhere in your Microsoft 365 tenant, a percentage of E5 seats are paying for Power BI Pro, Advanced eDiscovery, and Defender for Office 365 P2 that nobody on those accounts has ever opened. Nobody assigned them that way on purpose. It happened gradually, through onboarding defaults, role changes, and departures nobody circled back on, and it's costing real money every renewal cycle.

Microsoft 365 is close to unavoidable in most organizations: email, documents, meetings, and collaboration all running through one subscription. That ubiquity is exactly why it's also one of the easiest places to overspend without noticing. Licenses get assigned by default at onboarding, upgraded during a project and never downgraded after, and left active for months after someone leaves, because nobody owns the job of checking.

None of this is a Microsoft pricing problem. It's a visibility and process problem, and it's fixable with a structured approach rather than a one-time audit that goes stale the moment it's finished.

Where Microsoft 365 Spend Actually Leaks

Five patterns account for most of the waste in a typical tenant, and they compound quietly over time.

Inactive and dormant licenses. Accounts that were provisioned and never fully adopted, or were active once and have since gone quiet: no logins, no email activity, no file access for an extended stretch. Every one of these is a full license fee for zero usage.

Orphaned licenses from offboarding gaps. When an employee leaves, license reclamation often isn't part of the offboarding checklist, or it's a manual step that gets missed under time pressure. The license (and often a mailbox, OneDrive storage, and Teams access) stays live and billed.

Over-tiered assignments. E5 licenses assigned by default to users who only need E3 or Business Standard functionality. Features like Power BI Pro, Advanced eDiscovery, Customer Lockbox, Viva Insights, and Defender for Office 365 Plan 2 sit in the seat unused while the organization pays the premium price for every one of those licenses, whether or not anyone ever opens them.

Duplicate functionality. Teams already covers video conferencing and chat; a separate, still-paid Zoom or Slack license alongside it is redundant spend, adopted before Microsoft 365 covered the same use case, or adopted by a different department unaware Microsoft 365 already provides it.

Silent auto-renewals. Subscription tiers or add-on licenses that renew automatically at full volume every cycle, with nobody re-evaluating whether the count still matches headcount and usage before the renewal date passes.

A Practical Optimization Checklist

Five checks worth running against any Microsoft 365 tenant, covering the leak points above as a repeatable process rather than a one-time project.

Duplicate apps. Identify tools running alongside Microsoft 365 that duplicate functionality already included in the suite, and consolidate onto one where it makes sense.

Unused licenses. Find accounts with no or minimal activity over a defined window (commonly 30, 60, or 90 days) and downgrade, reassign, or reclaim them.

Autorenewal of subscriptions. Build a calendar of every Microsoft 365 SKU's renewal date, and require an active usage review before each one processes rather than letting it renew by default.

Abandoned apps. Look specifically for departments or teams that adopted a Microsoft 365 add-on for a project that's since ended, and never released the licenses afterward.

Suitable licenses. Match each user's actual usage pattern against the tier they're assigned, and right-size: not everyone needs E5, and some power users genuinely do.

Run through this checklist as a recurring quarterly exercise rather than an annual one, since license drift accumulates continuously, not on a yearly schedule.

Why Unused Licenses Are Also a Security Question, Not Just a Cost One

It's worth pausing on why an unused Microsoft 365 license matters beyond the invoice line.

An inactive license is very often attached to an active account: a departed employee's credentials still valid, a service account nobody remembers creating, a dormant identity that authenticates cleanly if anyone ever tries. The same dormancy that shows up as wasted spend on a finance report shows up as unreviewed, unmonitored access on a security report, and it's frequently the exact same account driving both numbers.

This is why license optimization and access governance are related disciplines rather than separate projects. A license reclaimed for cost reasons is very often an account that should have been deprovisioned for security reasons, and an organization that only tracks the finance side of that overlap is solving half the problem discovered by the other half's data.

How Zluri Approaches Microsoft 365 Optimization

Zluri is an identity security platform for autonomous enterprises, built as four products on one platform: Identity Visibility & Intelligence (IVIP), Identity Governance & Administration (IGA) with its four modules (Access Management, Access Requests, Access Reviews, and SoD), Identity Security Posture Management (ISPM), and SaaS Management (SMP).

SMP handles the cost side of this checklist directly: license usage tracked across every Microsoft 365 tier, inactive and dormant accounts surfaced automatically rather than requiring a manual export, duplicate and overlapping tools flagged against what Microsoft 365 already covers, and renewal dates tracked with usage data attached so a renewal decision is never made blind.

Because SMP runs on the same underlying identity data as IVIP and IGA, the license optimization work connects to the governance side without a second project. An inactive Microsoft 365 license surfaced for cost reasons is visible to the same platform that can deprovision the account for security reasons, and lifecycle automation through IGA means departing employees lose their license the same day they lose everything else, closing the offboarding gap that creates orphaned licenses in the first place.

Optimization Is a Process, Not a Project

The organizations that keep Microsoft 365 costs under control aren't the ones that ran a great audit once. They're the ones that turned a checklist like this into a recurring habit: checked before every renewal, applied continuously to new hires and departures, and treated as one input into the same system that governs access more broadly. Spend waste and access risk tend to point at the same accounts. Finding them once fixes a quarter. Finding them continuously fixes the pattern.

Frequently Asked Questions

How do I find unused Microsoft 365 licenses?

Track login and activity data across Outlook, Teams, SharePoint, and OneDrive for each licensed account over a defined window, commonly 30 to 90 days. Accounts with no meaningful activity in that window are candidates for downgrade or reclamation. Doing this manually through the Microsoft 365 admin center is possible for small tenants; larger environments typically need a SaaS management tool to surface it automatically and repeatedly.

How often should we review Microsoft 365 license usage?

Quarterly is a practical minimum for most organizations, with an additional review triggered before each subscription's renewal date rather than letting it auto-renew unreviewed. Waste accumulates continuously through onboarding defaults, role changes, and offboarding gaps, so an annual review alone tends to let months of drift build up between checks.

Are unused Microsoft 365 licenses a security risk as well as a cost issue?

Often, yes. An inactive license is frequently attached to an account that should have been deprovisioned, whether from a departed employee, a completed contractor engagement, or an abandoned service account. That account remains a valid, unmonitored credential for as long as it stays active, which makes license cleanup and access governance overlapping concerns rather than separate ones.

What's the difference between right-sizing licenses and reclaiming licenses?

Right-sizing means matching a user's Microsoft 365 tier to their actual usage, for example moving a user with basic email and document needs from E5 down to E3 or Business Standard, without removing their access entirely. Reclaiming means removing a license altogether, typically because the account is inactive, orphaned, or belongs to someone who has left the organization.

Ready to secure your identity surface?