Microsoft 365 license optimization

10-30% of your paid seats belong to nobody. Here is the list.

In a typical Microsoft 365 tenant, one seat in five is assigned to an account that has not signed in for months, sits on a guest, or belongs to a paid app nobody opens - and none of that shows in an assignment-only view. 1Security joins every SKU to real sign-in and activity history, shows purchased vs assigned vs actually used, and reclaims the idle seats behind a 72-hour review window.

  • 10-30%
    of paid seats on dormant accounts in a typical tenant
  • 3 numbers
    per SKU - purchased, assigned and available - plus who is actually using it
  • 10 min
    for the renewal-prep pass that usually changes the quote

The problem

Assignment says who holds a seat. Usage says who needs it.

Assignment data tells you who a seat belongs to. The question that saves money is whether that person signed in this year.

People leave and their E3 stays. Projects end and the Visio and Project Plan seats stay. A trial converts and 50 Copilot seats bill on for a team that stopped using it in week two. Because assignment and usage live in different places - the license list and the sign-in logs - joining them is a spreadsheet exercise that happens once a year at best. In most tenants that gap is 10-30% of the bill.

Guests are the second leak. External identities holding paid seats are common, usually accidental - a license group with a broad membership rule, a seat assigned to unblock one feature - and almost never reviewed, because the guest review and the license review are run by different people at different times.

Unassigned units are the third: seats already purchased and sitting idle in the tenant while somebody is about to buy more. It is common to find hundreds of them.

What you get

One row per SKU, with the usage next to the assignment.

The Licenses screen turns the license list into a reclaim list - the same columns an admin builds by hand before every renewal, kept live.

  • The unit math per SKU

    Purchased, assigned and available units side by side for every subscription plan. Sort by available units and the savings shortlist sorts itself.

  • Guests holding paid seats

    External users are broken out on every SKU row, so "why do 14 guests hold E3?" is a filter, not a discovery.

  • Dormant holders

    License holders crossed with sign-in and activity history from the Users screen. An account with a paid seat and no sign-in for 90 days or a year is one click away.

  • Subscription status

    Active, in warning or suspended per subscription, read next to utilization - so the renewal conversation starts from real numbers, not the vendor's proposal.

  • User vs device licensing

    The applies-to column keeps user SKUs and device SKUs apart, which matters the moment a tenant has any device-based plans in the mix.

  • Reclaim as an automation

    Select licenses or dormant holders and stage a reclaim. Proposals wait behind a 72-hour review window, and every executed reclaim lands in Actions with who approved it.

How deep it goes

The ten-minute renewal prep.

One pass that consistently pays for itself before the meeting starts.

Open Licenses and sort by available units descending. Those are seats already bought and sitting idle - in most tenants the number is larger than anyone in the room expects, often in the hundreds. Then read each SKU's external users column: that is where accidental guest licensing shows up.

The third move is the one that changes the number: cross the holders against dormancy. Open Users, filter to no sign-in for a year with a license attached, and the list is typically 10-30% of paid seats. Each of those accounts is a cost line and an unwatched login at once - a paid seat that still reaches thousands of files through its groups.

Do that, and the renewal starts from measured utilization per SKU rather than from a proposal. It is a materially different negotiation, and preparing it takes about ten minutes.

In practice

From annual true-up to a process that runs itself.

The reclaim is worth automating because the drift never stops.

  1. 01

    Measure the gap

    Purchased against assigned against actually used, per SKU. The distance between the second and third number is the recoverable part - and it is usually enough to change the renewal quote.

  2. 02

    Handle the guests

    Filter to external holders on paid SKUs. Almost always accidental, almost always safe to reclaim after a quick confirmation with the seat owner.

  3. 03

    Tie it to offboarding

    Put the reclaim in the same automation that disables the leaver, revokes their links and removes their guests - so it stops depending on someone remembering.

  4. 04

    Let it run behind a review window

    Enable the "reclaim licenses on dormant accounts" suggestion. It shows its live match count first; enabled, it stages one proposal per account with 72 hours to object before anything moves.

Beyond assignment

The joins behind the reclaim list.

Assignment is the starting point. Everything below is a join on top of it, made for you and kept live.

  • License holders crossed with last sign-in and real activity, not just the assignment date
  • Guests and external identities holding paid seats, counted on every SKU row
  • Available units ranked descending - the seats you already bought and are about to buy again
  • Subscription status next to utilization instead of in a separate view
  • Dormant licensed accounts shown as both a cost line and an unwatched login with reach
  • Device licensing kept distinct from user licensing
  • Reclaim as a staged automation with a 72-hour review window rather than a manual sweep
  • Every reclaim recorded in Actions with the approver and the timestamp

Scale

Small percentages of a large recurring number.

License waste is rarely dramatic per seat. It is 10-30% of a bill that renews every year, which is exactly the kind of cost that survives for years because no single seat is worth anyone's afternoon. Read on the same live inventory as everything else, no billing access needed, on standard licenses with the read-only connection.

  • 3
    numbers per SKU - purchased, assigned, available
  • 90 days / 1 year
    the dormancy horizons the reclaim filters use
  • 72 h
    default review window before a reclaim executes

Related

Where this fits.

License findings come from user activity and end in an automation. This page sits between two others that do most of the work.

  • User access review

    The dormancy signal that makes a seat reclaimable in the first place - and what that account can still reach.

    See users
  • Activity analytics

    Unused users, apps and agents ranked by how long they have been idle - 30-50 paid apps with no users is a normal first result.

    See activities
  • Remediation automation

    Where the reclaim actually happens, with the review window in front of it.

    See automations

FAQ

Common questions.

Does this connect to my Microsoft billing?

No. It reads the subscription and assignment data from your tenant over the read-only connection, which is where the unit counts and statuses live. It does not need billing access to tell you that four hundred purchased seats are unassigned.

How do you decide a seat is reclaimable?

The platform does not decide - it presents the join. A license with no sign-in for a year is a candidate; whether it is reclaimable depends on things only you know, like a contractor returning in March. That is exactly why the reclaim automation waits in a review window and can route to the account's manager.

Why do guests end up with paid licenses?

Usually because a license group had a broad membership rule, or because someone assigned one to unblock a specific feature and never revisited it. Neither is malicious and both are easy to miss, which is why the external count sits on the SKU row.

Can the reclaim be automatic?

Yes, and it is one of the better first automations to enable: high value, low controversy, and the 72-hour grace period means every proposal is visible before it executes. Write access is opt-in and separate from the read-only consent.

Does it help with renewals specifically?

That is the most common use. Walking into a renewal with measured utilization per SKU, including the unassigned units you already paid for and the 10-30% of seats on dormant accounts, changes the starting position of the conversation.

Find the seats you pay for and nobody uses.

Connect read-only and the unit math and the dormancy join are on screen the same day. The available units column is usually the surprise.

Or renew the same number of seats as last year.