The security, compliance, identity, and voice delta, valued component by component against what you already own elsewhere. Three knowledge checks along the way, and 1 clip from a senior cloud advisor.
This is a taught session, not a talking head. The instructor works through analyst grade slides, and three times the video stops on a question with four options on screen. Pause, commit to an answer, and the next slide explains which option is right and why each of the others is wrong. Once in the session the frame splits and a senior cloud advisor gives the view from inside real Oracle negotiations, and the instructor picks the clip apart when the slides return.
The full narration of this session, section by section, for reading and reference. Guest analyst clips are marked.
Welcome back, session twelve of forty. Last session we drew the map and established that the plan mix moves more money than the discount does. Today we take the single biggest decision on that map and price it properly, which is E3 against E5. I should say at the start that this is the most argued about question in Microsoft licensing, and the argument is usually conducted badly, because the two sides are answering different questions. Security is answering, would we be better protected. Finance is answering, would we spend less. Both answers can be yes, both can be no, and the two are only connected through a specific mechanism that most business cases assume rather than demonstrate. That mechanism is retirement: whether you actually switch something off. By the end of this session you will be able to price the delta component by component, apply a retirement test that most cases fail, and produce a break even number per persona rather than an opinion per estate.
Five takeaways. One, what the delta is: the productivity core is identical, so everything you pay the step up for sits in security, compliance, analytics, and voice, and that fact changes who owns the decision. Two, component values: valuing each element against what it would cost standalone and against what you already license from somebody else. Three, the retirement test: E5 pays when you decommission the tools it replaces, and where tools were kept running alongside E5 total cost rose by fifteen to twenty five percent. Four, the mixed estate: E5 on thirty to fifty percent of seats beat a blanket upgrade in the reviews behind this course, so mixed is usually the right answer rather than the diplomatic one. Five, the break even: a per seat calculation you can run this week, and the condition to attach to any E5 purchase so the business case survives contact with the term.
Start with what does not change, because it removes most of the noise. The productivity core is identical: Office applications, mailbox, Teams, SharePoint, OneDrive, the same in E3 and E5. So if an E5 business case mentions collaboration benefits or productivity gains, it is describing capability the estate already holds and that section can be struck out before you read further. It happens more than you would expect. What is added, first: security and identity. Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Defender for Identity, and the advanced identity protection layer. That is the largest part of the delta by value and the part most likely to duplicate something you already run. Second: compliance, analytics, and voice. The advanced Purview capabilities for eDiscovery, insider risk, and information protection, plus Power BI Pro and advanced calling. Three separate value pools that different parts of the business care about, which is exactly why the case gets argued badly in a single meeting.
Valuing the delta component by component. Defender for Endpoint Plan two can replace a third party EDR platform, and you value it at the per seat cost of the incumbent, counted only if the incumbent is decommissioned. Defender for Office 365 Plan two can replace an email security gateway, same rule. Defender for Identity replaces identity threat detection tooling, usually with partial overlap, so value only the portion genuinely replaced rather than the whole product. Purview advanced replaces an eDiscovery or DLP product, and there you count the licence plus the internal effort that tool consumes, because those tools are labour intensive and that labour is real money. Power BI Pro replaces standalone Power BI Pro seats, which is the honest one on this list because it is a clean substitution with a published standalone price. And Teams Phone replaces a telephony platform, but only where the migration is actually planned and resourced. The Defender rows are where business cases inflate, because replacement gets assumed at the point of purchase and decided, if at all, considerably later.
First check. An E5 business case values the full security stack at the incumbent tools' cost, but no decommission dates exist anywhere in the document. What is the case worth? A, the full stated value, the capability is delivered on day one. B, very little, because value from replacement only exists when the incumbent contract stops being paid, so without dates the case is an assumption rather than a saving. C, half, as a reasonable planning allowance. D, the full value minus the migration effort. Pause it. Ask yourself what actually stops cash going out of the door, and when.
The answer is B, and this is the central mistake in the whole E5 debate so it is worth stating plainly. Capability arrives when the licence is assigned. Savings arrive when somebody cancels a contract. Those are two different dates, frequently years apart, and sometimes they never converge at all. Across roughly forty to fifty Microsoft 365 plan reviews, the E5 business case lived or died on tool retirement. It paid where two to four point tools were genuinely decommissioned. Where the tools were kept running alongside E5, total cost rose by fifteen to twenty five percent. A is the version presented in most proposals. D is closer to serious because it at least accounts for migration effort, but it still assumes a retirement with no owner and no date attached. C is a planning allowance dressed as analysis, and a fifty percent haircut on a number nobody verified is still a number nobody verified. Value only the components with a named owner, a contract end date, and a decommission plan. Carry everything else at zero until it has one.
The retirement test, five conditions before a replacement counts. A named owner: a person, not a team, accountable for switching the incumbent off. Retirements without an owner do not happen, and everybody involved already knows that. A contract end date: when the incumbent can actually be cancelled without penalty, because an auto renewing tool with eighteen months to run releases no cash next year regardless of what you deploy. A deployment date that comes first: the Microsoft capability has to be live and trusted before the incumbent goes, and sequencing failures here are what turn a consolidation into a period of paying twice. Acceptance from the people who rely on it, in writing, because a licensing led swap the operators do not accept gets quietly reversed. And a line in the budget: the saving removed from next year's forecast for the incumbent tool, because a saving that stays inside somebody's budget was never realised, it was only announced. Apply those five and the case shrinks, sometimes dramatically. That is the point of them.
Guest analyst The case I use when people ask me why I am difficult about decommission dates involves a professional services firm that moved about eleven thousand seats from E3 to E5. The business case was well written. Genuinely, it was one of the better ones I have read. It valued the endpoint tool, the email gateway, and a compliance product, and it showed a net saving over three years that any board would approve. It got approved. Eighteen months later they asked us to look at their Microsoft spend because it had grown more than expected, and the first thing we did was check the three tools in the business case. All three were still running. All three were still being paid for. Nobody had acted in bad faith. The endpoint tool had a renewal that fell three months after the E5 deployment started and it auto renewed for two years because the person who would have cancelled it was mid project and it was not on anybody's list. The email gateway had a security owner who wanted a parallel run, and the parallel run was still going eighteen months later because nobody had defined what the end of it looked like. The compliance product was embedded in a regulatory process and the legal team had never been asked. So they had bought the bundle and kept the parts. The cost of that, on their numbers, was about seven hundred thousand a year of duplication, on a decision that had been approved as a saving. What we changed was not the licensing. It was that the retirement schedule became a condition of the next order, with names and dates on it.
Bought the bundle, kept the parts, and nobody acted in bad faith at any point. Names and dates, or the number is zero. Second check.
Check two. Security wants E5 estate wide. Finance wants the cheapest option available. Your own data says three thousand of nine thousand seats actually use the delta. What do you propose? A, E5 estate wide, security concerns take precedence. B, E3 estate wide, finance sets the budget. C, a mixed estate with E5 on the roles that use the delta and targeted add ons elsewhere, which is what beat the blanket upgrade in most of the reviews we ran. D, defer the decision to the next renewal. Pause it, and as you think, notice that both stated positions are answers to a question your data has already reframed.
The answer is C, and I want to be clear that the mixed estate is not a compromise between two stakeholders, it is the technically correct answer. A mixed model with E5 on roughly thirty to fifty percent of seats beat a blanket upgrade in the reviews behind this course, and the reason is structural: risk is not evenly distributed across an estate, so a uniform control level is either too much for most people or too little for some. Segment by risk, put E5 on the roles that justify the delta, attach standalone components where one specific control is needed without the whole suite. A buys advanced protection for thousands of people who will never trigger it. B ignores a genuine risk concentration to hit a budget line, which is the kind of saving that becomes extremely expensive exactly once. D is the worst of the four, because deferring inside a three year agreement means committing to the current mix for the term, so the decision you postponed gets made by default and in the vendor's favour. One caution on the mixed route: check it against the Microsoft Product Terms, because some E5 features carry prerequisites a partial deployment can miss.
Three rules that keep a mixed model working, because mixed estates fail through drift and administration rather than through licensing logic. One, segment by risk and write the rule down: which roles hold E5 and why, in one paragraph, agreed with the security owner. Without a written rule the tier becomes a request queue, and every request gets approved, because refusing one is harder than paying for it. That is how a mixed estate becomes a standardised one over four years without any decision ever being taken. Two, attach add ons rather than upgrading: where one control is needed and the suite is not, buy the component. That is the whole of next session, and the arithmetic shifts with the number of components, because past three or four the suite usually wins. Three, re run the allocation every year, because people change roles and the risk map moves with them, and an annual pass at true up keeps E5 attached to the work rather than to the person who once did it. On nine thousand seats that reallocation is a few days of work against a saving in the hundreds of thousands.
The break even, worked, one seat at a time. Step one, the uplift: your net E5 rate minus your net E3 rate, per user per month, at your rate rather than at list. That is the number to beat. Step two, tools retired: sum the per seat cost of the tools that have a date and an owner, so for example the EDR platform plus the email gateway plus a standalone Power BI Pro seat. Step three, partial credits: where a tool is only partly replaced, count only the part, and resist the temptation to round it upward. Step four, compare: if the retired total exceeds the uplift, E5 pays for that persona. If it does not, E5 is an addition and should be described that way in the paper. Step five, attach the condition: make the purchase conditional on the decommission plan, with the retirement schedule signed as a condition of the order. Run this per persona rather than per estate and the answer comes back mixed, which is the previous slide. That last step is the one that changes behaviour, because conditionality converts an intention into a commitment on both sides.
Last check. You are told that E5 is cheaper than buying its parts, so the whole estate should upgrade. Is that true? A, yes, bundles are always cheaper than components. B, only for the seats that would genuinely buy those parts, because the bundle is cheaper than its parts only when you actually stop paying for the parts, and elsewhere it is an addition rather than a consolidation. C, no, bundles are always more expensive. D, it depends on the discount level offered. Pause it. The claim is true as arithmetic and false as a conclusion, so work out where those two separate.
The answer is B. The claim is arithmetically true and directionally misleading, which is precisely what makes it effective. E5 does cost less than assembling its components separately, for a user who would have assembled them. For a user who would have bought none of them, the comparison is not bundle against parts, it is bundle against nothing, and against nothing a bundle is pure addition. In roughly twenty eight of forty reviews, the customer bought E5 and never retired the point tools it replaced, so total cost rose rather than fell. A generalises a true statement past its conditions, which is the most common way accurate information is used to reach an inaccurate conclusion. C is the opposite prejudice and is equally unhelpful, because bundles genuinely are right for the roles that use them. D matters at the margin and does not change the structure: a deeper discount on capability nobody uses is still spending. The buyer side move is to make the upgrade conditional on a signed decommission plan, seat by seat, so that the consolidation story has to become true in order to get paid for.
The E5 decision method, three steps and about a fortnight of work, producing one page that finance, security, and IT can all sign. One, build the usage evidence: which accounts have used which E5 capability in ninety days, from your own admin centre. That produces the population genuinely using the delta, and it settles most of the argument before the argument starts, because it is your data rather than anybody's opinion. Two, price the delta per persona: uplift against retired tool cost, counting only components with an owner and a date. Expect a mixed answer, with a clear E5 group, a clear E3 group, and a middle band where add ons win. Three, attach the condition and the date: buy E5 for the population the evidence supports, with a signed decommission schedule attached, and diary the reallocation for the next true up, because without that diary entry the mix drifts back within two years. And sequence it properly: schedule the decommission before the renewal, not after. A retirement plan signed while you still hold a purchasing decision is a very different document.
Session twelve, three sentences. One: the productivity core is identical, so the entire E5 step up is a security, compliance, analytics, and voice purchase, and the business case belongs to the people who own those risks rather than to licensing. Two: the step up pays only where tools are genuinely decommissioned, and where they were kept running alongside E5 total cost rose by fifteen to twenty five percent, so value only the components that have an owner, a date, and a budget line. Three: the answer is almost always mixed, with E5 on roughly thirty to fifty percent of seats, priced per persona and bought conditional on a signed decommission plan. If you take one habit from this session, take the conditionality. It costs nothing to ask for and it changes what happens after signature.
Homework, about an hour, and this week you price your own delta. One, get the uplift: your net E5 rate minus your net E3 rate per user per month, from the price sheet you rebuilt in session ten, your rate and not list. Two, list the incumbents: every security, compliance, and analytics tool that E5 could replace, with its annual cost and its contract end date, and that second column is usually the harder one to fill in. Three, mark the retirable: for each one, is there an owner, a date, and acceptance from the team that uses it. Only those count, and everything else goes in at zero. Four, run the usage query: which accounts used an E5 only capability in the last ninety days, and compare that count against your E5 seat count. Five, write the one page: uplift, retirable value, usage population, recommended mix. Take it to the security owner before you take it anywhere near the account team.
Five reads before next session, all free on redress compliance dot com. First, the E3 to E5 decision framework, which carries the delta, the break even test, and the staged path in full. Second, maximising security and compliance with E5 add ons, which is the add on route for estates where the full suite is not justified, and it sets up next session directly. Third, Microsoft 365 add ons and duplicate cost, on where the delta duplicates tools you are already paying for. Fourth, E3, E5, and F3 per persona, which is the allocation arithmetic that produced the mixed estate answer. And fifth, auditing your Microsoft licence usage, a step by step guide to producing the usage evidence this whole session depends on. Next session is step ups, add ons, and buying E5 piecemeal: when the components beat the bundle, when they stop beating it, and the arithmetic that decides where that line sits for your estate. See you there.