Microsoft 365 licence optimisation – cut costs without losing functionality and security

Microsoft 365 licence optimisation – cut costs without losing functionality and security

Paying for Microsoft 365 licences you do not need? How to work with usage data, licence profiles, security dependencies and ongoing licence optimisation.

Summary: Microsoft 365 licences should not simply be renewed year after year. Organisations change, employees change roles and new features are added. A structured licence review can find unused licences and unnecessary add-ons – but also ensure that cost savings do not remove important security or management features at the same time.

Microsoft 365 is rarely a static environment. An organisation may have started with 40 users. A few years later there are 120 users, several licence types, extra Project and Visio licences, Power BI, Copilot or other add-ons. In the meantime, people have:

  • changed roles
  • left
  • joined
  • moved to working as consultants
  • been given temporary licences that were never removed

It is therefore not particularly surprising if the licence picture becomes hard to oversee over time.

Licence optimisation is not just about buying cheaper

The simplest way to reduce cost is, of course, to remove or downgrade licences. But that can also be a poor decision. A licence may contain features used for, among other things:

  • identity protection
  • Conditional Access
  • device management
  • information protection
  • logging
  • security features

If the organisation only looks at which Office apps the user opens, the analysis can be misleading. Licence optimisation needs to balance three perspectives:

  • What does the user need?
  • What is actually used?
  • Which features does the organisation need for security and governance?

Only then does the decision become relevant.

Start with facts

The Microsoft 365 admin center contains reports on assigned licences and usage, among other things. Microsoft explicitly describes that the usage reports can show who uses a service to the fullest extent and who barely uses it and might not need a Microsoft 365 licence. Reports are normally available for periods of 7, 30, 90 and 180 days, and there are also reports for active users and use of the Microsoft 365 apps.

That is a good start. But the report should not make the decision automatically.

A user can look inactive for perfectly good reasons

Consider, for example:

  • parental leave
  • long-term sick leave
  • seasonal work
  • project employment
  • leave of absence
  • service accounts
  • resource accounts
  • on-call roles

A licence that looks unused may still serve a purpose. That is why the analysis needs to involve HR, line managers, IT and the business.

Start with user types

An effective approach is to define a small number of standard profiles, for example:

  • office user
  • mobile user
  • manager or executive
  • technical administrator
  • consultant
  • frontline user with limited needs
  • resource or functional account

Then define which features each profile actually needs. That makes onboarding simpler. It also makes changes simpler when someone moves to a new role.

Joiner, mover, leaver is a licensing question

Licence costs often reveal problems in the identity lifecycle.

  • When a person joins: who orders the licence?
  • When a person changes role: who checks whether the licence is still right?
  • When a person leaves: when is the licence removed? What happens to the mailbox and OneDrive? Are there extra products left behind?

A well-functioning onboarding and offboarding process can therefore deliver both lower cost and better security.

Do not forget the add-on licences

The large licence bundles get most of the attention. But costs can also sit in:

  • Project
  • Visio
  • Power BI
  • Copilot
  • telephony
  • security products
  • other Microsoft add-ons

Microsoft’s usage data includes information on activation, licence assignment and product usage that can support decisions on both adoption and licensing. That lets the organisation ask more concrete questions: does the user have the licence because it is genuinely needed, or because they needed it for a project two years ago?

Be careful with the security features

It is tempting to say: this user only opens Outlook and Teams, so we can downgrade. But the user’s visible product usage is not the whole picture. The current licence may also be a prerequisite for certain security or management features that the organisation uses centrally.

Every change should therefore be verified against Microsoft’s current licensing terms and feature tables before it is made. Product packaging also changes over time. That makes licence optimisation an ongoing management task, not a one-off exercise.

A practical licence review

We usually see an approach in roughly the following steps:

  1. Inventory. Which licences and add-ons exist? How many are assigned? How many are unassigned?
  2. Analyse usage. Which services are used? Which licences appear underused?
  3. Link the user to the role. Which tasks and security requirements apply?
  4. Check technical dependencies. Which identity, security, device-management and compliance features depend on the licence?
  5. Identify changes. Remove, move, standardise or adjust where reasonable.
  6. Build a management process. Decide who follows up on licences going forward, and how often.

Standardisation often has more effect than hunting individual licences

If every user has a unique combination, licence management becomes expensive to maintain. A few clear standard profiles make it easier to:

  • order
  • troubleshoot
  • budget
  • follow up
  • change roles
  • close accounts

It also gives better control over which security features the organisation actually relies on.

How Kristensson i Skåne can help

Kristensson i Skåne works with Microsoft 365 from a technical, financial and security perspective. We can help with, for example:

  • licence inventory
  • usage analysis
  • licence profiles
  • onboarding and offboarding
  • Entra ID
  • Conditional Access
  • Intune
  • Microsoft 365 security
  • ongoing management

If you want to start with a consolidated review of the environment, our Microsoft 365 Health Check is a natural starting point. You may also want to read our article on secure Microsoft 365, which goes deeper into the security perspective.

Frequently asked questions

Can Microsoft show which licences are not being used?

Microsoft reports provide usage and licence data that is a good basis, but the business still needs to decide whether a licence should be removed. A seemingly inactive user may have perfectly good reasons.

How often should licences be reviewed?

It depends on how quickly the organisation changes. A recurring review, combined with checks at role and employment changes, is normally better than one large exercise every three years.

Is the cheapest licence always best?

No. Security, device management, compliance and other features must be weighed in. A downgrade can remove features the organisation relies on centrally.

Can licence optimisation also improve security?

Yes. The work often uncovers old accounts, unnecessary permissions and gaps in onboarding and offboarding.

Are you paying for licences you do not need, or unsure which features you actually rely on? Read more about our Microsoft 365 services for businesses or contact us for an informal conversation.

Sources: Microsoft Learn, Microsoft 365 admin center usage reports overview and Microsoft 365 Apps active users report (verified 8 September 2026).

This text is general information. Microsoft’s licensing terms and product packaging change over time; always check the current terms before making a licence change.