Contents
Key takeawaysWhy SQL Server is auditedCore countingVirtualization rulesPassive failoverAzure Hybrid BenefitSA and license mobilityDev and testEdition mismatchServer plus CALWhat our reviews findCheck your positionAuditor lines and repliesWhat to do nextFAQMost SQL Server audit findings trace back to eight rules: core minimums, virtualization rights, passive failover, Azure Hybrid Benefit, license mobility, dev and test use, edition features and CALs. Most of them depend on active Software Assurance.
- Licensed per core. SQL Server is licensed per physical or virtual core with a four core minimum, and the CAL model is rare in new deployments.
- Unlimited virtualization needs Enterprise with SA. Without SA you license VM by VM only on SQL Server 2019 and earlier, because from SQL Server 2022 per VM licensing itself needs SA or subscription licenses.
- Failover rights end with SA. A passive secondary is free only while the primary has active SA.
- Switch on Azure Hybrid Benefit. Without it, bringing licenses to Azure means paying for SQL Server twice.
- Keep dev and test off production cores. Visual Studio subscriptions and the free Developer editions cover that use.
- Standard does not cover Enterprise features. Enterprise binaries or features on a Standard license trigger a true up.
- Mobility requires SA. Without it, moving a license more than once in 90 days is a relicensing event.
Why is SQL Server the Microsoft product auditors check most?
SQL Server draws more audit attention than any other Microsoft product because it combines high spend with rules that are easy to break by accident. The number of deployments rarely matches the entitlement record, and almost every review we run finds gaps once a company passes 50 cores.
For the audit process itself, read our Microsoft audit defense guide. For the commercial side, see the Microsoft vendor management toolkit, our Microsoft advisory practice and our notes on EA discount negotiation.
Three reasons SQL Server draws audit attention
- High value. In the Microsoft accounts we review, SQL Server makes up 18 to 26 percent of enterprise spend.
- A complex metric. Core counting, virtualization rights and passive failover each carry edge cases that produce findings.
- Constant change. Cloud migration, version upgrades and consolidation change what must be licensed, and the license record lags behind.
How do you count SQL Server cores correctly?
Count physical cores when you license the server and virtual cores when you license the VM. Licenses come in two core packs, with a minimum of four core licenses per physical processor or per virtual machine.
Most errors come from mixing those two bases. Counting hardware threads on physical servers wastes money, and counting small VMs below the minimum produces a finding.
Four core counting rules
- License all physical cores when licensing per physical processor. Standard Edition 2022 uses at most 24 cores (32 in SQL Server 2025), yet a 48 core host running Standard on physical hardware still needs 48 core licenses.
- Minimum four cores per VM. This applies even if the VM has fewer vCPUs assigned.
- Two core packs. Licenses are sold in even pairs only.
- Hyperthreading does not change the physical count. Inside a VM, each vCPU needs one core license whether it maps to a core or a thread.
A VM with three vCPUs needs four cores of SQL Server, bought as two two core packs. A VM with five vCPUs needs six cores, or three packs. Round every VM up to the next even number, and never below four.
How do SQL Server virtualization rules differ by edition and Software Assurance?
Only Enterprise Edition with Software Assurance (SA) or subscription licenses gets unlimited virtualization. Everything else is licensed VM by VM or capped by the host's core count. Virtualization is the largest single source of SQL Server audit findings.
SQL Server 2022 also tightened the per VM rule. Licensing an individual VM now needs active SA or subscription licenses. Perpetual licenses without SA can still be assigned per VM only for SQL Server 2019 and earlier.
| Configuration | Standard Edition | Enterprise Edition |
|---|---|---|
| License per VM, no SA | Each VM individually (SQL Server 2019 and earlier) | Each VM individually (SQL Server 2019 and earlier) |
| License per host, no SA | Not allowed | License all host cores, run as many VMs as core licenses assigned |
| License per host with SA or subscription | Each VM individually | Unlimited virtualization, all host cores licensed |
| License mobility | Yes with SA | Yes with SA |
Why clusters create the biggest findings
Without SA, a license can be reassigned to another server only once every 90 days. A SQL VM that migrates between hosts more often needs licenses on every host it can reach, which is why auditors ask you to license the whole VMware or Hyper-V cluster.
When is a passive SQL Server failover instance free?
A passive secondary is free only while the primary has active SA and the secondary does no production work. Many companies drop SA at a renewal and keep running the same secondaries, which from that date are licensable at the primary's edition.
Four passive failover rules
- The primary must hold active SA. The benefit ends the day SA expires.
- The passive instance must stay passive. No serving data, no reports, no read workloads. Consistency checks, full and log backups, and resource monitoring are permitted.
- Free secondaries are capped. SA covers one passive for high availability and one for disaster recovery on premises, plus one for disaster recovery in Azure, each with no more compute than the primary. Any further secondary is licensable.
- Running both as active is time limited. After a failover the roles swap and the old primary must become the passive. Both may run as active together only for brief disaster recovery tests, once every 90 days.
How does Azure Hybrid Benefit work for SQL Server licenses?
Azure Hybrid Benefit applies SQL Server licenses with SA, or subscription licenses, to Azure SQL so you pay the Azure rate without the license component. Without it you pay for SQL Server twice, once in the licenses you own and again in the Azure price, which doubles license cost in many configurations.
| Service | Hybrid Benefit applies | How licenses convert |
|---|---|---|
| SQL Server on Azure VM | Yes, Enterprise and Standard | One core license per vCPU, with SA or subscription on the cores assigned |
| Azure SQL Managed Instance | Yes, vCore provisioned compute | Enterprise: one core to four General Purpose vCores or one Business Critical vCore. Standard: one core to one General Purpose vCore, four cores to one Business Critical vCore. |
| Azure SQL Database | Yes, General Purpose and Business Critical provisioned tiers | Same ratios. Not on DTU pricing, serverless, or Hyperscale since December 2023. |
Where Hybrid Benefit goes wrong
Some teams never switch the benefit on, so Azure bills the license while owned licenses sit idle. Others switch it on for more cores than their SA covers, which is a finding of its own.
During a migration you get 180 days of dual use rights to cover the old server and the Azure workload. Our Azure Hybrid Benefit guide covers Windows Server too.
What happens when SQL Server Software Assurance lapses?
You keep the perpetual licenses but lose license mobility, the right to reassign them between servers without the 90 day rule. Buyers who drop SA to cut the renewal then trigger a relicensing event with every workload migration, and only permanent hardware failure is exempt.
When SA expiry triggers relicensing
- Server consolidation projects. Shifting SQL workloads between servers.
- Disaster recovery testing. Running workloads at the DR site.
- Cloud migration. Shifting SQL workloads to Azure, AWS or GCP.
- VM patching cycles. Migrating VMs between hosts during maintenance.
Why we do not recommend dropping SQL Server SA across the board
A common piece of renewal advice says SA on SQL Server can go because the perpetual licenses keep working. For most companies we disagree. SA also carries passive failover, per VM licensing on SQL Server 2022 and Azure Hybrid Benefit, so removing it changes what you must license the day it lapses.
Sort workloads before the renewal instead. Keep SA on anything clustered, replicated, bound for Azure or licensed per VM, and drop it only on stable physical servers with no failover partner or migration plan. Our Software Assurance guide lists the full set of benefits.
How should SQL Server development and test environments be licensed?
Dev and test environments are licensed separately from production, and production cores cannot be stretched to cover them. Visual Studio subscriptions include SQL Server for development by named users, and the free Developer editions cover dev and test servers.
Five rules for dev and test SQL Server
- Visual Studio subscriptions cover named developer use. One subscription for each person who uses the software.
- Load testing needs Visual Studio Enterprise. Its subscribers can run load tests with any number of virtual users, though a production server under test still needs production licenses.
- Free Developer editions exist. SQL Server 2025 ships Enterprise Developer and Standard Developer, both licensed for dev and test only.
- A license covers one server. Cores assigned to a production server do not also cover a separate test copy, and developer rights never cover production.
- Some pre production counts as production. An environment that connects to a production database, backs up or stands in for production, or serves end users beyond acceptance testing needs production licenses. User acceptance testing that uses no live production data can stay on dev rights.
Which SQL Server features require Enterprise Edition?
Online index operations, full Always On availability groups and compute beyond the Standard caps require Enterprise Edition. Several features older checklists still call Enterprise only moved to Standard years ago: data compression and table partitioning with SQL Server 2016 SP1, and transparent data encryption with SQL Server 2019.
The Standard engine refuses most Enterprise only operations, so the usual finding is about what is installed. Enterprise binaries reach a server licensed for Standard through a build template, an application installer or copied media. Once an Enterprise feature is in use there, the fix is a true up to Enterprise Edition.
- The edition each instance reports, including Developer or Evaluation editions doing production work.
- Online index create and rebuild, which Standard does not support.
- Availability groups beyond basic groups, which in Standard allow two replicas, one database and no readable secondary.
- Compute above the Standard limit of 24 cores in SQL Server 2022, or 32 in SQL Server 2025.
- Edition specific features persisted in each database, which decide whether an instance can drop back to Standard.
When does the SQL Server Server plus CAL model still apply?
Server plus CAL is still sold for Standard Edition only, and it mostly appears on legacy contracts. New deployments almost always use the per core model. Mixing the two metrics on one deployment is not allowed.
Three rules for the CAL model
- A server license plus a CAL per user or device. Count every user with access, including those who reach the database through an application or pooling layer.
- External users are licensable. Web facing access needs per core licensing or another metric.
- No mixing on one server. Per core or Server plus CAL, never both.
At Microsoft's open prices, a Standard server license costs $989 and a CAL $230. An eight core server licensed per core needs four packs at $3,945, or $15,780, so Server plus CAL wins below about 64 users. One CAL covers access to any number of licensed servers, which improves the CAL case across several servers.
What do our SQL Server compliance reviews usually find?
They usually find audit exposure of 8 to 24 percent of annual SQL spend on a typical enterprise SQL Server footprint. The eight pitfalls above account for about 90 percent of that risk, and fixing all eight keeps an audit result within a range most budgets can absorb.
Each review runs four to eight weeks. We pull the deployment inventory, entitlement record and configuration data, then build the effective license position, a value for the audit risk and a remediation plan before any Microsoft audit or renewal.
Many SQL Server findings come from rights that lapsed at a renewal while the servers kept running exactly as before.
A worked example at list price
Say a review of a hypothetical company finds three gaps, priced here at Microsoft's open list prices for SQL Server 2025. Your agreement and any settlement will change the final figure.
| Finding | Gap | Cost |
|---|---|---|
| 10 Standard VMs with 2 vCPUs, licensed at 2 cores each | 20 Standard cores: 10 packs × $3,945 | $39,450 |
| Secondary of a 16 core Enterprise primary after SA lapsed | 16 Enterprise cores: 8 packs × $15,123 | $120,984 |
| 8 vCPU VM running Enterprise on Standard licenses | 8 Enterprise cores: 4 packs × $15,123 | $60,492 |
| Total | $220,926 |
On $1.5 million of annual SQL spend, that is close to 15 percent. Renewing SA before it lapsed would have prevented the second line, because SA generally cannot be added back to existing licenses afterward. The Standard cores freed by the third fix can be reassigned elsewhere.
How can you check your own SQL Server licensing position?
Most of the evidence an auditor wants comes from tools you already run. Pull it per instance, then match it to your Volume Licensing entitlements, which now sit in the Microsoft 365 admin center.
| What to check | Where to look |
|---|---|
| Edition and version | SERVERPROPERTY('Edition') and SERVERPROPERTY('ProductVersion') |
| Cores seen by SQL Server | sys.dm_os_sys_info: cpu_count, socket_count, cores_per_socket |
| Host cores and VM placement | vCenter or Hyper-V inventory and cluster affinity rules |
| Enterprise features in use | sys.dm_db_persisted_sku_features in each database |
| Readable secondaries | sys.availability_replicas: secondary_role_allow_connections_desc |
| Hybrid Benefit in Azure | SQL VM license type in the Azure portal, or centrally managed Hybrid Benefit in Cost Management |
What will Microsoft's auditors say, and how should you answer?
Auditors work from the data you hand over and tend to apply the most expensive reading of the rules. These four lines come up most often.
- "Every host in the cluster must be licensed." That holds for per host licensing or VMs that break the 90 day rule. Show mandatory (must run) affinity rules, since preferred rules can be overridden, plus per VM licenses with SA, and limit the finding to hosts SQL VMs can reach.
- "Your secondary replica is active." Ask for evidence of client reads, since backups and consistency checks are permitted. If reads did happen, license that replica only.
- "Enterprise is installed, so these are Enterprise deployments." If sys.dm_db_persisted_sku_features shows no Enterprise features, ask to reinstall Standard within an agreed window. It is a request, not a right.
- "Buy the gap on the new agreement and we will close the audit." Get the final findings and release terms in writing first, and price the settlement apart from new spend.
Our SQL Server audit defense service takes on these conversations with Microsoft and its audit partners.
What to do next
Open this checklist 90 days before any Microsoft renewal or audit. Start six to twelve months out if you expect edition swaps or SA changes, because both need a change window or a budget cycle.
- Pull the SQL deployment inventory. By server, instance, edition and version.
- Map the core counts. Physical cores, vCPU assignments and the four core minimum.
- Audit Software Assurance status. Per license, per environment and per benefit.
- Inventory virtualization configurations. Per VM, per host and the license model for each cluster.
- Confirm passive failover compliance. Map each secondary to a primary with active SA.
- Score Azure Hybrid Benefit use. Every eligible Azure SQL workload should use it, within SA coverage.
- Separate dev and test from production. Visual Studio subscriptions or the free Developer editions.
- Validate edition use. Confirm Enterprise features run only on Enterprise Edition. For help, see our Software Spend Assessment, benchmarking, Benchmark Program, Renewal Program and Vendor Shield, read about us, meet the management team, find our locations or contact us.
Frequently asked questions
How are SQL Server cores counted on virtual machines?
One core license per vCPU, with a floor of four per VM. A VM with two vCPUs needs four cores and one with five vCPUs needs six, because licenses come in two core packs and counts round up to an even number. Hyperthreading does not lower the count.
Does unlimited virtualization apply to SQL Server Standard Edition?
No. It is an Enterprise Edition right that requires every physical core on the host to be licensed, with active Software Assurance or subscription licenses. Standard Edition VMs are always licensed one by one. Buy Enterprise with SA before you rely on unlimited virtualization.
Is passive failover free under all SQL Server licenses?
No, it is a Software Assurance benefit. Without SA on the primary, the secondary is licensable at the primary's edition. With SA, up to three passive replicas are covered: one for high availability, one for disaster recovery on premises and one for disaster recovery in Azure, provided none serves reads or reports.
How does Azure Hybrid Benefit work for SQL Server?
It applies licenses with SA, or subscription licenses, to Azure SQL. Enterprise cores convert four to one into General Purpose vCores, Standard cores one to one, and Azure VMs use licenses one to one. You can assign it per resource or centrally per subscription. Without SA it does not apply.
Can a developer use a production SQL Server license for personal development?
Not the same license. A core license assigned to a production server does not extend to a developer's machine. Use a Visual Studio subscription that includes SQL Server or the free Developer edition. Mixed production and non production use is one of the most frequent Microsoft review findings.
What is the most common SQL Server audit finding?
In our reviews it is Enterprise Edition running where only Standard is licensed, often after an application stack upgrade or server template installs Enterprise without the licensing team knowing. The fix is Enterprise licenses, or a Standard reinstall if no Enterprise features are in use.
Does SQL Server 2022 require Software Assurance to license by VM?
Yes. From SQL Server 2022, licensing an individual VM needs active SA or subscription licenses. Without them, the only way to run SQL Server in VMs is to license every physical core on the host with Enterprise Edition, which caps the number of VMs at the number of core licenses assigned.
Can SQL Server Developer edition be used in production?
No. The Developer editions are free but licensed for development and test only. Anything connected to a production database, standing in for production, or used by end users beyond acceptance testing needs paid licenses.