HomeTraining AcademyMicrosoft Agreements and CopilotSession 33
Microsoft Agreements and Copilot · Module 7 ยท Compliance, governance, and FinOps · Session 33 of 40 · 18:30

Shelfware and mid term management

The gap ledger for Microsoft: assigned licences against active users, per tier, per quarter. Three knowledge checks along the way, and 1 clip from a senior cloud advisor.

The presenter in this session is an AI generated avatar. The curriculum and guidance are real, produced by Redress Compliance analysts from our consulting engagements and market network.

What you will be able to do after this session

  • 1The size of it. Reclaimable idle seats ran 8 to 18 percent of the paid count per estate, with accounts dormant past 90 days making up the bulk of safe recoveries.
  • 2And the tier layer on top. Over tiered users on E5 who genuinely fit E3 added another 5 to 10 percent, which is a different problem with a different remedy.
  • 3The four signals. No sign in for 90 days, departed staff, role change, and never activated. Four queries, and between them they find almost everything.
  • 4The false positives. Staff on leave and seasonal workers look identical to leavers in a usage report, which is why validation comes before action, every time.
  • 5The safe sequence. Identify, suspend, reassign the mailbox, then remove. Four stages, each reversible until the last, which is what makes reclaim safe to do at scale.

How the session works

This is a taught session, not a talking head. The instructor works through analyst grade slides, and three times the video stops on a question with four options on screen. Pause, commit to an answer, and the next slide explains which option is right and why each of the others is wrong. Once in the session the frame splits and a senior cloud advisor gives the view from inside real Oracle negotiations, and the instructor picks the clip apart when the slides return.

Homework before the next session, about an hour

  • 1Build the two columns. Per tier: assigned against active. Then split the gap into idle and over tiered, because they are different problems.
  • 2Run the never activated query. Paid seats that have never been signed into. Safest to act on and usually surprising in size.
  • 3Set up the HR join. Agree the route to leave and employment status data now, while nothing is contentious and nobody is waiting on it.
  • 4Pick twenty names. Send them to the relevant manager and ask whether each is genuinely idle. Five minutes of their time, and it calibrates your whole dataset.
  • 5Diary the quarter. Next run, named owner, timed to land before your true up date rather than after it.

Session transcript

The full narration of this session, section by section, for reading and reference. Guest analyst clips are marked.

Welcome and objectives 0:02

Welcome back, session thirty three of forty. Last session built the three way join and found the gap between what you pay for and what gets used. Today is what you do with that gap on an ongoing basis, and the reason it needs its own session is a property that surprises people. Shelfware regenerates. Every reclaim you run gets undone by the next twelve months of joiners, leavers, and role changes, because those three processes never stop and none of them has a licensing step at the end of it. So an organisation that runs a big cleanup, recovers a large number, and then declares the problem solved will find the same gap waiting three years later, usually at the renewal, usually at the worst moment. What prevents that is not a bigger cleanup. It is a ledger somebody keeps, quarterly, and that is a much smaller thing than most people expect.

Five takeaways. One, the size of it: reclaimable idle seats ran eight to eighteen percent of the paid count per estate, with accounts dormant past ninety days making up the bulk of safe recoveries. Two, the tier layer on top: over tiered users on E5 who genuinely fit E3 added another five to ten percent, which is a different problem with a different remedy. Three, the four signals: no sign in for ninety days, departed staff, role change, and never activated, which between them find almost everything. Four, the false positives: staff on leave and seasonal workers look identical to leavers in a usage report, which is why validation comes before action every single time. Five, the safe sequence: identify, suspend, reassign the mailbox, then remove, four stages each reversible until the last, which is what makes reclaim safe to do at scale.

What a gap ledger is 2:06

What a gap ledger is, three properties, and none of them are sophisticated. Assigned against active, per tier: not a total, but a row per plan tier showing what you pay for and what is used, so that a gap on E5 and a gap on a frontline plan are visible as different problems worth very different amounts of money. Per quarter rather than per renewal: shelfware accumulates continuously and gets addressed once every three years, which is exactly why it is always large when somebody finally looks, and a quarterly ledger turns a triennial shock into a routine correction. And owned by a person: the ledger exists or it does not, and what decides that is whether one named individual is responsible for producing it. Every other control in this session depends on that one being true, and I would rather you left with that than with any of the numbers.

The four dormancy signals 3:00

The four dormancy signals, what each finds and how safe it is to act on. No sign in for ninety days: the primary dormancy signal for a paid seat, safe after validation, and the bulk of recoveries. Departed staff: accounts left active after somebody leaves, which is the safest of the four once HR data is joined in. Role change: somebody who moved to a role needing a lower tier, and that one is a re tier rather than a reclaim, which is a genuinely different remedy. Never activated: a seat assigned at onboarding and never used, very safe and the cleanest single query in this session. And a fifth worth adding, shared and service accounts, which may need no paid seat at all, so check the alternatives before assuming they do. That third row deserves separating out, because a role change produces somebody over tiered rather than idle, and reclaiming their licence entirely would break their work.

Knowledge check 1 3:59

First check. Your dormancy report flags six hundred accounts with no sign in for ninety days. What do you do first? A, remove the licences, ninety days is a clear signal. B, cross check against HR records and manager confirmation first, because staff on leave and seasonal workers look identical to leavers in a usage report. C, email all six hundred users and ask if they need the licence. D, extend the window to one hundred and eighty days to be safe. Pause it, and as you think, ask yourself which people in your organisation would legitimately not sign in for three months.

The answer is B. Maternity and paternity leave, long term sickness, sabbaticals, and seasonal staff all produce exactly the pattern a leaver produces. And reclaiming a licence from somebody on parental leave is the kind of mistake that ends a reclaim programme permanently, regardless of how much the other five hundred and ninety nine accounts were worth, because it becomes the story everybody remembers. C sounds consultative and fails in a specific and slightly funny way: a dormant account belongs to somebody who is not reading email, so the people who reply are the active ones and the silence tells you nothing at all. D trades a large amount of genuine saving for a small amount of extra certainty and does not actually solve the problem, because somebody on a twelve month sabbatical is still dormant at one hundred and eighty days. Join against HR, ask managers, take the week.

Avoiding false positives 8:20

Avoiding false positives, five checks before anything is removed. Is the person still employed: the directory answers this, and the directory is sometimes wrong, which is why HR data is a second source rather than the only one. Are they on leave: the single most damaging false positive, and HR holds it while licensing systems never do. Is the work seasonal: populations that work three months in twelve are dormant nine months a year by design, and they are a re tiering question rather than a reclaim. Is it a shared or service account, because some accounts need no paid seat at all and some need a different kind, and both are cheaper than what they currently hold. And does the manager recognise the name, which is the cheapest validation in the whole process, since a list of twenty names takes a manager five minutes and catches what the data cannot. Budget a week for validation on a first reclaim.

Guest analyst: the reclaim that went wrong, and the one that did not 6:44

Guest analyst  I am going to describe two reclaims, because the contrast is the lesson. The first one was at a media company, and the analysis was excellent. Clean dormancy report, ninety day window, about eleven hundred accounts, and somebody with authority approved removing the licences in a single batch on a Friday. Among those eleven hundred were nine people on maternity or long term sick leave. On the Monday one of them tried to log in from home, could not, and rang her manager. And that is the entire story of that programme, because by the end of that week the reclaim had been reversed wholesale, the head of IT had apologised in writing, and the phrase licence reclamation became politically radioactive in that organisation for about two years. They lost a genuine seven figure annual saving over nine accounts. The second one was at a bank, same analysis, similar size, and the licence manager did three things differently. She ran the dormancy list against HR employment and leave status first, which removed about forty names. She sent each divisional manager the twenty or thirty names in their area and asked one question, is this person genuinely inactive. And then she suspended rather than removed, kept the licences assigned for thirty days, and told everybody that was what she was doing. Two people were challenged and re enabled within an hour each. Nobody was upset, the reclaim completed, and it has run every quarter since. Same data. Completely different outcome.

Avoiding false positives 8:20

A seven figure saving lost over nine accounts, and the same analysis succeeding elsewhere on the strength of one week of validation. Second check.

Knowledge check 2 8:31

Check two. A user has signed in every week but only ever uses email, on an E5 licence. Is that shelfware? A, yes, remove the licence, the value is not being realised. B, not shelfware, over tiering: the person is active and the licence is wrong, so the remedy is a downgrade rather than a reclaim, worth another five to ten percent on top of idle seats. C, no, an active user is correctly licensed by definition. D, yes, and it should be counted in the dormancy total. Pause it. Two different problems produce two different remedies, so the question is which of the two this actually is.

The answer is B. This person needs a licence, so removing it breaks their work, which is why A is wrong and why conflating these two problems is dangerous rather than merely imprecise. They need a smaller licence, which is a downgrade, and over tiered users on E5 who fit E3 added another five to ten percent of savings beyond the idle seat reclaim. C is the position that leaves that entire five to ten percent sitting on the table, because active gets treated as a synonym for correctly sized, and sessions eleven through fifteen exist precisely because it is not. D produces a number that mixes two populations with opposite remedies, which makes the total useless for planning, since you cannot tell how much of it is safe to reclaim and how much needs a tier change and a conversation with somebody. Keep two columns in the ledger, always, because the actions differ and so do the risks attached to them.

The safe harvest sequence 10:16

The safe harvest sequence, four stages, and the reversibility is the entire point. Identify, then suspend: flag the dormant and leaver seats with no change to the user at all, then block sign in while keeping the licence assigned, and that second stage is fully reversible, so a challenge is answered by re enabling rather than by re purchasing. Reassign the mailbox: convert to a shared mailbox where the data needs to remain accessible, which preserves access to what the person produced, and that is usually the real objection when somebody resists reclaiming a leaver's seat. Then remove: strip the paid licence and the seat returns to the pool, and only at that point does anything become hard to undo, by which stage three reversible steps have already tested the decision. And the sequence changes the politics as much as the risk, because a programme that can demonstrate a reversible middle stage gets approved far more easily.

The quarterly cycle 11:21

The quarterly cycle: reconcile, reclaim, re tier, carry forward. Reconcile, by re running the three way join from session thirty two, which updates the ledger. Reclaim, harvesting idle seats through the safe sequence, putting seats back in the pool before the true up. Re tier, downgrading the over tiered and upgrading the under served, which keeps the session fifteen mix model current rather than letting it decay. Carry forward, taking the current state into the next negotiation, whether that is a true up, an audit, or a renewal. And repeat, same queries and same definitions next quarter, producing a trend that is worth considerably more than any snapshot. Notice what the reclaim stage is timed against, because it matters: seats recovered before the true up are seats you do not pay for, and seats recovered after it are seats you have already bought. The anniversary discipline from session seven decides what this cycle is worth.

Knowledge check 3 12:23

Last check. You ran a reclaim last year and the gap is back. What went wrong? A, the reclaim was done incorrectly the first time. B, nothing was wrong with the reclaim, but shelfware regenerates from joiners, leavers, and role changes, so a one off exercise decays unless a quarterly cycle keeps score. C, the business grew, which explains it. D, the tooling is inadequate and needs replacing. Pause it, and ask yourself what happened inside your organisation over those twelve months that would rebuild the gap on its own.

The answer is B. Every month your organisation hires people, loses people, and moves people between roles, and each of those three generates exactly the patterns this session is about. A one off reclaim addresses the accumulated stock and does nothing at all about the flow, so the gap rebuilds at whatever rate your organisation changes. A goes looking for a failure in work that was probably done well, which is both unfair and unhelpful, because it sends people hunting for a fault when what was missing was a cadence. C is partially true and insufficient, since growth adds licences that are used while shelfware is licences that are not, and those are different populations. D is the most expensive wrong answer, because a tool does not create the cadence or the ownership, and an estate that will not run four exports quarterly will not run a tool quarterly either. The fix is a date, an owner, and a ledger.

The gap ledger method 14:09

The gap ledger method, three things to stand up once, after which it is a recurring hour rather than a project. One, the ledger itself: one table, per tier, assigned against active, with an idle column and an over tiered column kept separate because the remedies differ, dated, and stored somewhere a colleague could find it without asking you. Two, the validation route: an agreed path to HR data and a standing arrangement with managers for name checks, set up before the first reclaim rather than during it, because that is when it is entirely uncontroversial and takes ten minutes. Three, the quarterly slot: a recurring hour with the owner named, timed so the reclaim lands before the true up rather than after it, and that timing is worth more than the analysis it contains. Expect the first run to find eight to eighteen percent idle and another five to ten percent over tiered, and expect the second run to find much less.

Recap 15:07

Session thirty three, three sentences. One: reclaimable idle seats ran eight to eighteen percent of the paid count with dormancy past ninety days making up the bulk of safe recoveries, and over tiered users on E5 who fit E3 added another five to ten percent as a separate problem with a separate remedy. Two: validate before you act, because staff on leave and seasonal workers look identical to leavers in a usage report, and one bad reclaim costs the organisational permission that the whole programme depends on. Three: harvest in stages, identify, suspend, reassign, remove, and run the cycle quarterly timed before the true up, because shelfware regenerates from joiners, leavers, and role changes no matter what you did last year. Next session takes this ledger and the consumption lines from module four and puts them on one dashboard.

Homework 16:08

Homework, about an hour, and this week you start the ledger. One, build the two columns: per tier, assigned against active, then split the gap into idle and over tiered, because they are genuinely different problems with different remedies. Two, run the never activated query: paid seats that have never been signed into, which is the safest thing to act on and usually surprising in size. Three, set up the HR join: agree the route to leave and employment status data now, while nothing is contentious and nobody is waiting on it, because doing it under time pressure is how the media company in that story ended up where it did. Four, pick twenty names and send them to the relevant manager asking whether each is genuinely inactive, because five minutes of their time calibrates your entire dataset. Five, diary the quarter: next run, named owner, timed to land before your true up date.

Further reading 17:16

Five reads before next session, all free on redress compliance dot com. First, the Microsoft 365 licence reclamation guide, which carries the signals, the false positives, and the safe harvest sequence in full detail. Second, Microsoft 365 licence optimisation, on turning a reclaim into a recurring cycle rather than an event that decays. Third, Microsoft SAM and licence optimisation, for where the quarterly cycle sits inside the wider practice. Fourth, auditing your Microsoft licence usage, which contains the queries behind the four dormancy signals if you want to build them yourself. And fifth, Microsoft 365 add ons and duplicate cost, because the add on layer of this same ledger is the session thirteen reconciliation and belongs in the same quarterly hour. Next session is FinOps for the Microsoft estate: one dashboard across EA, CSP, Azure, and Copilot consumption, chargeback that changes behaviour, and the forecast. See you there.

Learning the playbook and want it applied to your numbers? We work on contingency: 25% of what we save you. Nothing saved, nothing paid.
Review my deal