HomeTraining AcademyMicrosoft Agreements and CopilotSession 32
Microsoft Agreements and Copilot · Module 7 ยท Compliance, governance, and FinOps · Session 32 of 40 · 18:33

What Microsoft can see

Admin centre telemetry, assigned versus active licences, and building your own evidence before anyone asks for it. Three knowledge checks along the way, and 1 clip from a senior cloud advisor.

The presenter in this session is an AI generated avatar. The curriculum and guidance are real, produced by Redress Compliance analysts from our consulting engagements and market network.

What you will be able to do after this session

  • 1The visibility is mutual. Cloud licensing runs in a tenant the vendor operates, so assignment data is not something you disclose. The question is only who reads it first.
  • 2Assigned is not active. The single most important distinction in this module. A licence can be assigned, paid for, and never opened, and only one of those three is visible on an invoice.
  • 3The three way join. Entitlements, assignments, and usage, per user. Visibility is the precondition for everything in modules 3 through 8, and most estates have never built it.
  • 4What it is worth commercially. The renewal outcome gap between estates negotiating from reconciled telemetry and estates negotiating from the vendor's pitch ran 8 to 15 percent.
  • 5It is faster than expected. Buyers expecting a governance programme found a cash programme, because the waste was not subtle: leavers licensed for years, duplicate assignments, E5 blankets over frontline populations.

How the session works

This is a taught session, not a talking head. The instructor works through analyst grade slides, and three times the video stops on a question with four options on screen. Pause, commit to an answer, and the next slide explains which option is right and why each of the others is wrong. Once in the session the frame splits and a senior cloud advisor gives the view from inside real Oracle negotiations, and the instructor picks the clip apart when the slides return.

Homework before the next session, about an hour

  • 1Pull the four exports. Entitlements, assignments, 90 day usage, and directory identity. If any one of them takes more than a week to obtain, that is the finding.
  • 2Count licences against people. Total assigned seats against current headcount. Note the difference before you explain it.
  • 3Find the never activated. Accounts assigned a paid seat that have never signed in. The cleanest single query in this session.
  • 4Classify a sample. Take 200 accounts and put each in one of the five states. You will learn more from that than from any total.
  • 5Book the next run. Same exports, same definitions, next quarter. A snapshot becomes a trend only if the second one happens.

Session transcript

The full narration of this session, section by section, for reading and reference. Guest analyst clips are marked.

Welcome and objectives 0:02

Welcome back, session thirty two of forty. Last session ended on a rule: your own reconciliation before any data moves. Today is what that reconciliation is made of, and I want to start by correcting an instinct that costs organisations a great deal of money. There is a belief, and it is usually unspoken, that not running usage reports is a form of protection. That if nobody has looked at the data, the data cannot be used against you. In an on premises world that instinct has some basis, because discovery genuinely takes effort and the information really is asymmetric until you share it. In a cloud estate it is simply false. The telemetry is generated by a platform the vendor operates. It exists whether or not anybody on your side reads it. So declining to look does not protect you, it just makes you the less informed party in every conversation that follows.

Five takeaways. One, the visibility is mutual: cloud licensing runs in a tenant the vendor operates, so assignment data is not something you disclose, and the only question is who reads it first. Two, assigned is not active, which is the single most important distinction in this module, because a licence can be assigned, paid for, and never opened, and only one of those three shows on an invoice. Three, the three way join: entitlements, assignments, and usage, per user, which is the precondition for everything in modules three through eight and which most estates have never built. Four, what it is worth commercially: the renewal outcome gap between estates negotiating from reconciled telemetry and estates negotiating from the vendor's pitch ran eight to fifteen percent. Five, it is faster than expected: buyers expecting a governance programme found a cash programme, because the waste is not subtle.

Who can see what 1:59

Who can see what, three facts about a cloud estate. Assignment data is not private: licences assigned in a tenant the vendor operates are visible to the vendor by construction, so there is no version of this where you protect information by not looking at it, and that is worth stating plainly because the instinct genuinely exists in a lot of organisations. Usage data is the same data: sign in activity, workload usage, and service consumption are all produced by the platform, so the reports you would run and the reports an account team can reference come from the same underlying source. And only the reading is asymmetric: what differs between organisations is whether anybody internally has looked, which is the entire asymmetry and it is entirely within your control to close. The on premises estate from session twenty two is genuinely different, and the mistake is carrying that instinct across to the cloud where it costs you and protects nothing.

The three way join 3:02

The three way join, what it is made of and where each part lives. Entitlements, from contract and order documents, answering what you are permitted to use and how much. Assignments, from the admin centre, per user, answering what each person currently holds. Usage, from activity and sign in telemetry over ninety days, answering what each person actually does. Identity, from directory and HR data, answering whether that person still works here and in what role, and that fourth input is the one people forget. And then the join itself, all four matched per user, which answers every finding in modules three to eight. Build the join first, because visibility is the whole precondition. Without it every recommendation in this course is an opinion. With it, the same recommendations become statements about named accounts, and that is the difference between a proposal and a report.

Knowledge check 1 4:03

First check. Somebody suggests not running usage reports, so there is no evidence of over licensing. Is that sound? A, yes, unexamined data cannot be used against you. B, no, because the telemetry exists in a tenant the vendor operates whether or not you read it, so declining to look forfeits your own evidence while protecting nothing. C, yes, provided the reports are never exported. D, it depends on your contract's audit clause. Pause it, and as you think, ask yourself what actually changes on the vendor's side at the moment you choose not to run a report.

The answer is B, and the answer to that prompt is nothing. Nothing changes on the vendor's side when you decline to run a report. The data is generated by the platform they operate, and your choice affects only whether your own organisation knows what it says. A is that on premises instinct carried into the wrong context, where discovery does take effort and information genuinely is asymmetric until shared, so it is a reasonable instinct in the wrong place rather than a foolish one. C confuses running a report with disclosing one, and there is no disclosure implied in reading your own tenant. D is worth understanding for the on premises estate and does not change the cloud position at all. And the practical consequence runs entirely the other way: because the vendor can already see it, your only available advantage is to see it first and to have acted on it, which turns a potential finding into a completed correction.

Assigned is not active 8:27

Assigned is not active, and here are the five states a licence can be in. Purchased and unassigned: bought and sitting in the pool attached to nobody, invisible to usage reports because there is no user to report on, and fully billed. Assigned and never activated: given to somebody at onboarding who never signed in, which looks perfectly healthy in every assignment count and has produced no value whatsoever. Assigned and dormant: used once and abandoned, or belonging to somebody who left, with no sign in for ninety days as the primary dormancy signal. Assigned and partially used: the person uses email and nothing else on a plan carrying far more, which is tier misallocation rather than dormancy and is the session fifteen problem. And assigned and fully used, which is the state everybody assumes is universal when they read a seat count off an invoice. Only usage data separates states two, three, four, and five.

Guest analyst: the export nobody had run 6:48

Guest analyst  The fastest finding I have ever produced took about forty minutes and I have thought about why ever since. A professional services firm, around six thousand people, and they had engaged us for a renewal that was still eight months out, which is exactly the right timing. First meeting, and I asked for four things: the entitlement schedule, the licence assignment export, ninety days of sign in activity, and a current directory extract. The assignment export and the directory extract arrived that afternoon. And when we joined those two alone, before we even got to usage, there were about seven hundred and forty accounts holding paid licences that did not appear in the current directory at all. Leavers. Some of them years old. Now the thing that stayed with me was not the number, it was the reaction, because the licence manager was genuinely embarrassed and I do not think she had any reason to be. Nobody had ever asked her to run that comparison. Her job was provisioning, and provisioning worked flawlessly. There was a joiners process, there was a movers process, and the leavers process ended at disabling the account rather than reclaiming the licence, because the licence cost was not visible to anybody in that workflow. Two exports, one join, forty minutes, and a number in the high six figures annually. What I always say now when somebody tells me a licence review would be a big project is that the first hour is not a project. The first hour is two files and a lookup.

Assigned is not active 8:27

Two exports, one join, forty minutes. The first hour is not a project. Second check.

Knowledge check 2 8:38

Check two. Your assignment report shows nine thousand four hundred licensed users and your headcount is eight thousand nine hundred. What is the likely explanation? A, a reporting error, since you cannot have more licences than people. B, leavers never deprovisioned, duplicate assignments, and service or shared accounts holding paid seats, which is the fastest reclaim available. C, contractors, who are legitimately licensed. D, growth that HR has not yet recorded. Pause it. All four of those are genuinely possible, so the question to ask is which one is usually the largest.

The answer is B. Seat reclaim is the fastest Microsoft licensing win available: leavers never deprovisioned, duplicate assignments across tenants or domains, and parked service account seats, all recoverable with directory data joined to usage and a true up calendar. It returned ten to twenty percent of Microsoft 365 spend inside a quarter across the optimisation engagements reviewed. A assumes a control that mostly does not exist, because joiners processes are always built and leavers processes frequently are not, which is exactly the story you just heard. C and D are both real and both usually smaller, and the useful move is to quantify them rather than accept them as an explanation. A contractor population you can count is a legitimate line on the ledger. A contractor population invoked to explain a gap nobody has measured is a way of closing the question without answering it. Join the lists, name the accounts, and the four explanations separate themselves.

Building your own evidence 10:21

Building your own evidence, three properties of a base that holds, and the goal is a record you can put in front of finance, security, and a vendor without changing it for any of them. Per user rather than per total: totals cannot be acted on and cannot be defended, whereas a per user record lets you say which four hundred accounts, and that is what turns an assertion into a correction and what made the counter quote answerable in session twenty eight. Dated and repeatable: same query, same definitions, run on a schedule, because a one off extract is a snapshot and a series is a trend, and only a trend answers whether adoption is rising or decaying. And held internally first, which is the session thirty one rule, because the same export that supports your renewal position supports somebody else's finding if it leaves unreconciled. One practical warning: validate before you act, because staff on leave and seasonal workers are real.

What clean data is worth 11:28

What clean data is worth, the measured returns in order of speed. Idle and duplicate seat reclaim: ten to twenty percent of Microsoft 365 spend, within one quarter. Role based right sizing: a further twelve to twenty two percent, at the following renewal. Negotiating from clean data: an eight to fifteen percent better renewal outcome, at the renewal itself. Audit exposure removed: findings become corrections, per session thirty one, continuously once the cycle runs. And the cycle itself: reconcile, reclaim, re tier, carry forward, quarterly and indefinitely. Note the timeframe on that first row, because it is the surprising one. Buyers expecting a governance programme discovered a cash programme, since the waste is not subtle at all: leavers licensed for years, duplicate tenant assignments, and E5 blankets over frontline populations are all visible in the very first join anybody runs, which is why the first quarter pays for the exercise.

Knowledge check 3 12:36

Last check. You have three months to your renewal and no usage baseline. What is the highest value thing you can do? A, benchmark your rates against comparable deals. B, build the three way join and run the idle seat reclaim, because it returns ten to twenty percent within a quarter and produces the evidence the negotiation needs. C, get a competitive quote from another route. D, model the EA against MCA comparison. Pause it, and notice as you think that three of those four options depend on already knowing what you actually use.

The answer is B. C and D are both genuinely valuable, and both need a basket to price, which means both depend on the join. Getting a competitive quote for a seat count you have not corrected simply prices the wrong estate, and comparing EA against MCA on inflated quantities compares two versions of the same error at some expense. A can be done without the join and tells you where your rate sits without telling you whether your quantities are right, which is the smaller half of the question and the half most people do first. B fits inside the three months, returns ten to twenty percent by itself, and produces exactly the evidence that makes the other three worth doing at all. If your timeline only permits one thing, it is this one, and the estates that ran it consistently found the reclaim had paid for the whole analysis several times before the renewal even opened.

The visibility method 14:17

The visibility method, three steps, and the first is a data request rather than an analysis. One, pull the four exports: entitlements from the contract, assignments from the admin centre, usage over ninety days, and identity from the directory. Four files, one join key, which is the user. No tool purchase required. Two, classify every account into the five states: unassigned, never activated, dormant, partially used, fully used, where every account lands in exactly one and the four that are not fully used each carry a different remedy. Three, validate and then act: cross check the dormant list against HR and manager confirmation before touching anything, because staff on leave and seasonal workers are the false positives that turn a reclaim into an incident and cost you the trust you need. Then make it a series rather than an event, quarterly, carried into whichever negotiation arrives next.

Recap 15:21

Session thirty two, three sentences. One: cloud licensing telemetry lives in a tenant the vendor operates, so declining to run reports forfeits your own evidence while protecting nothing, and the only asymmetry available to you is who reads it first. Two: assigned is not active, and a licence can be unassigned, never activated, dormant, partially used, or fully used, with four of those five carrying different remedies that only usage data can separate. Three: build the three way join of entitlements, assignments, and usage per user, because idle and duplicate seat reclaim returned ten to twenty percent of Microsoft 365 spend within a quarter, and negotiating from clean data was worth a further eight to fifteen percent at renewal. Next session turns that join into a standing ledger, and gives the gap between assigned and active a permanent home.

Homework 16:24

Homework, about an hour, and this week you run the join. One, pull the four exports: entitlements, assignments, ninety day usage, and directory identity, and if any one of them takes more than a week to obtain then that difficulty is itself the finding and worth reporting. Two, count licences against people: total assigned seats against current headcount, and write the difference down before you start explaining it, because the explaining is where the number usually shrinks without evidence. Three, find the never activated: accounts assigned a paid seat that have never signed in, which is the cleanest single query in this session. Four, classify a sample: take two hundred accounts and put each into one of the five states, and you will learn more from that than from any total. Five, book the next run: same exports, same definitions, next quarter, because a snapshot only becomes a trend if the second one happens.

Further reading 17:29

Five reads before next session, all free on redress compliance dot com. First, Microsoft SAM and licence optimisation, which carries the three way join, the quarterly cycle, and what each stage returned. Second, auditing your Microsoft licence usage, which is essentially the step by step version of this session's homework. Third, the Microsoft 365 licence reclamation guide, on dormancy signals, false positives, and the safe harvest sequence, and that one sets up next session directly. Fourth, Microsoft 365 audit logs explained, for what the platform actually records and how to read it. And fifth, Microsoft 365 licence optimisation, on turning the join into a recurring saving rather than a one off exercise that decays. Next session is shelfware and mid term management: the gap ledger for Microsoft, assigned licences against active users, per tier, per quarter. See you there.

Learning the playbook and want it applied to your numbers? We work on contingency: 25% of what we save you. Nothing saved, nothing paid.
Review my deal