A license audit isn't a one-off mega-project — it's a routine you can repeat every few weeks. The goal is a solid answer to three questions: What are we paying for? What are we using? What can we cut? This guide walks you through a clean, repeatable process.
Preparation: Access and roles
For a complete audit, you need read access to three areas of data:
- Users & accounts (directory) – who exists, who's active, who's blocked.
- Licenses & subscriptions – what's been bought, what's assigned, what's free.
- Usage reports – activity per service (Exchange, Teams, SharePoint, OneDrive).
One thing to keep in mind: an audit is pure read-only work. It requires no rights to change accounts or licenses. In its overview of admin roles, Microsoft explicitly recommends granting the least-privileged role for the job — for an audit, read-only roles like Reports Reader or Global Reader are enough.
Step 1 – Take inventory
Start with the hard truth: how many seats of each product have been purchased, how many are assigned, and how many are free? The gap between purchased and assigned is already dead capital — buffer you pay for in full but never use. Microsoft covers the basics in Understanding subscriptions and licenses.
Step 2 – Overlay activity
Now comes the decisive link: for every assignment, overlay the user's activity signal from the Admin Center usage reports. A seat with no sign-in and no service usage for months is a candidate. Be sure to account for multiple workloads — someone might avoid Outlook but work heavily in Teams.
Step 3 – Build categories
Sort every assignment into one of four categories:
| Category | Meaning | Action |
|---|---|---|
| Active | Usage matches the plan | Keep |
| Over-provisioned | Active, but the plan is too large | Consider a downgrade |
| Inactive | No signal above the threshold | Consider removal |
| Redundant | Add-on duplicates the plan | Cut |
This categorization makes the result manageable — instead of a 2,000-row spreadsheet, you have four clear piles.
Over-provisioned seats are often E5 licenses without E5 usage; you spot inactive ones through the combined activity signals.
Step 4 – Clean up exceptions
Check the inactive candidates for the usual special cases: service accounts, shared mailboxes, employees on leave, freshly created accounts. These drop off the cancellation list. → Details in Finding unused licenses.
Step 5 – Decide and document
Hand the cleaned-up candidate list to the people responsible (IT leadership, department heads). Every decision — keep, downgrade, remove — should have an owner and a date. That way the audit stays traceable the next time around, too.
Step 6 – Make it repeatable
The biggest value comes from repetition. An audit once a year leaves too much on the table, because costs grow continuously. A sensible cadence follows every onboarding/offboarding cycle — ideally monthly.
How long does it take?
Done manually, the duration depends on tenant size: up to ~100 seats, an audit is doable in an hour or two. With several hundred users, merging the data sources (directory + multiple usage reports) quickly turns into a full-day project — and then has to be repeated every single time.
This is exactly the process License Lens compresses into seconds: connect your tenant in read-only mode, and you immediately get the categories from Step 3 along with the total savings — no Excel tinkering, no stored employee data. From there, you decide license by license.
Conclusion
A good audit isn't detective work — it's a fixed sequence: inventory → activity → categories → exceptions → decision → repetition. Establish this routine, and you keep the Microsoft 365 bill lean for good, instead of getting a scare once a year.