Contents
Key takeawaysWhat a SAM engagement isSAM versus auditWho controls the dataWhere gaps appearWhat we have seenKeeping controlWhat to do nextFAQA Microsoft SAM engagement is offered as a helpful licensing review, usually by a partner. It uses the same data and produces the same Effective License Position as an audit, so prepare your own position before any discovery runs.
- Same data as an audit. A SAM engagement and a formal audit collect the same data and produce the same compliance position.
- Partner delivered. The engagement is usually run by a Microsoft partner, funded by Microsoft, on your systems and tenant.
- The ELP drives the bill. The Effective License Position is the document behind any true up demand.
- You hold more control than you think. You decide how the inventory data is collected and cleaned, what is in scope and how long the review runs.
- Reconcile first. Checking your own entitlements before the partner does removes most surprises.
- Reuse the baseline. A clean position from SAM strengthens your hand at the next renewal as well as in the review itself.
What is a Microsoft SAM engagement?
A Microsoft SAM engagement is a structured review of the Microsoft software you have deployed against the licenses you own. Microsoft often funds it and a partner delivers it. The output is your compliance position, written up as an Effective License Position.
Microsoft publishes its Microsoft compliance documentation on Microsoft Learn, and the wider asset management practice follows the ISO 19770 standard for IT asset management. Whatever the invitation letter calls it, every engagement runs through the same three stages.
- Discovery. Tools inventory the Microsoft software running on your servers, desktops, virtual machines and cloud tenants.
- Entitlement review. Contracts, enrollments and purchase records are gathered into one entitlement record.
- Reconciliation. Deployment is netted against entitlement, product by product, to show a gap or a surplus.
Who runs the engagement?
Usually an authorized partner working under a Microsoft program, not Microsoft directly. Microsoft pays the partner for the work, so the partner's incentives are not automatically aligned with yours. The same partner is often in a position to sell you the licenses that close any gap it finds.
What is the deliverable?
The Effective License Position, or ELP. For each product it states your deployed quantity, your entitled quantity and the difference between them. Any true up demand is built on that difference, so the ELP is the one document in the process you should check line by line before you accept it.
The Microsoft EA Preparation Playbook: The Work That Wins the Renewal
How is a SAM engagement different from a Microsoft audit?
The tone differs and the data does not. A SAM engagement is voluntary and presented as help, while an audit is a contractual right Microsoft exercises. Both end in an ELP that can turn into an invoice.
| Dimension | SAM engagement | Formal audit |
|---|---|---|
| Framing | Optimization and help | Contractual compliance check |
| Trigger | Partner or Microsoft outreach | Audit clause in the agreement |
| Who runs it | Microsoft funded partner | Microsoft or an appointed auditor |
| Output | Effective License Position | Effective License Position |
| Your control | High, if you manage it | Lower, but your contract rights still apply |
The audit right itself lives in your agreement. Read the current Microsoft Product Terms and licensing terms next to your signed contract so you know what you agreed to. The Microsoft Customer Agreement, for example, sets out these verification terms:
- Notice. Microsoft may verify compliance at any time on 30 days' notice, at its own expense.
- Auditor. It may use an independent auditor bound by a nondisclosure obligation.
- Consequences. If unlicensed use is 5 percent or more of your total use of all products, you reimburse Microsoft's verification costs and buy the missing licenses at 125 percent of the current price.
Enterprise Agreements carry their own verification wording, so check the exact text in your enrollment. Our note on bounding the Microsoft audit clause covers what can be negotiated.
Is a SAM engagement mandatory?
No. Participation is voluntary, unlike an audit, and that gives you room to set scope and timing. Declining outright is rarely wise, because Microsoft keeps the option of a formal verification under the audit clause. Shaping the engagement is fair, and a competent partner will expect it.
The Microsoft EA renewal guide
What to do with a cleaned license position once the renewal starts, worked through the full EA cycle.
Get the white paper →What data does Microsoft see, and who controls it?
Microsoft sees what leaves your environment, and you decide what that is. The inventory comes from your systems, so you choose which tools run, what they collect and how the results are checked before anything is shared.
- Inventory source. Agent based or script based discovery on your own systems.
- Validation. Raw discovery is noisy and should be cleaned before handover.
- Entitlement evidence. Your purchase records, which you assemble and verify.
- Final position. Your own reconciled numbers, prepared before you look at the partner's.
Microsoft lists its licensing programs and buying routes on the Microsoft how to buy page. Use it as a cross check when a partner claims a product was bought through the wrong program, or that a right you rely on does not apply to your agreement type.
How do you check your own position before the partner does?
Most of the evidence already sits in Microsoft's consoles and your own management tools. Pull it first, so you have your own numbers to set beside the partner's discovery output.
- Entitlements. The volume licensing pages in the Microsoft 365 admin center hold your agreements, license summary and product keys. Microsoft retired the Volume Licensing Service Center in April 2024, so exports saved from the old portal may be incomplete.
- Cloud subscriptions. The Licenses page in the Microsoft 365 admin center shows purchased and assigned counts, and Microsoft Entra sign in logs show which licensed accounts have gone unused for months.
- Devices and installs. Microsoft Intune and Configuration Manager inventories list installed software per device, with last contact dates that expose stale records.
- SQL Server. Run SELECT SERVERPROPERTY('Edition') on each instance to confirm the edition, then record the physical or virtual cores behind it. Azure Arc can collect the same details centrally for the servers you connect to it.
- Virtualization hosts. Export host and cluster membership from your hypervisor management console, since Windows Server and SQL Server licensing often depends on where a virtual machine can run.
Why fast, full cooperation usually costs more
The usual advice is to cooperate fully and quickly, because the review is free and goodwill should earn leniency. We disagree. In the engagements we supported, fast cooperation without any control over the data produced inflated deployment counts and a larger gap than the buyer had.
Treat the review as data discovery that you run, and release data only after you have checked it. In those engagements goodwill did not lower a true up. A position backed by purchase records, decommission tickets and edition queries did.
Where do Microsoft SAM reviews usually find license gaps?
Mostly in on premises and hybrid server products. Cloud subscriptions such as Microsoft 365 are provisioned in your tenant against what you ordered, so the tenant already tracks the count. Server licensing depends on cores, editions, virtualization and access rights, and each of those can be miscounted in either direction.
| Area | What the partner counts | What to check before you accept it |
|---|---|---|
| Windows Server | Physical cores on every host running Windows Server | The minimum is 16 core licenses per server and 8 per processor. Standard edition with every core licensed covers two virtual machines, and each additional pair of virtual machines needs every core licensed again. |
| SQL Server | Cores behind every instance, by edition | At least 4 core licenses per physical processor or per virtual machine. Exclude Express, and Developer edition where it runs only for development and testing. |
| SQL Server failover | Secondary replicas as separate installs | Passive failover rights apply only while Software Assurance or a subscription is active. |
| Client Access Licenses | Users or devices reaching your servers | Each user or device needs a Windows Server CAL, and Remote Desktop Services needs additional CALs. |
| Desktop applications | Visio, Project and older Office installs | Machines retired or reimaged since the last inventory, and installs that were never used. |
For product detail, our guides to SQL Server licensing and common Microsoft audit findings go further on each line.
A worked example: cleaning a SQL Server gap
Say the partner's discovery lists 40 virtual machines running SQL Server Enterprise, each with 8 virtual cores. That is 320 core licenses of demand against 200 owned, so the draft ELP shows a gap of 120 core licenses.
| Step | VMs counted | Core licenses needed | Gap |
|---|---|---|---|
| Partner's raw discovery | 40 | 320 | 120 |
| Remove 3 VMs decommissioned but still in inventory | 37 | 296 | 96 |
| Remove 2 VMs running Developer edition for testing | 35 | 280 | 80 |
| Remove 1 duplicate record from a renamed host | 34 | 272 | 72 |
The gap falls from 120 to 72 core licenses, a 40 percent reduction, before any discussion of license rights. Each step rests on evidence you already hold, such as decommission tickets, edition queries and host records.
What have we seen in Microsoft SAM engagements in 2024 and 2025?
Preparation decided the outcome. Across roughly 25 to 35 Microsoft SAM and audit engagements I supported in 2024 and 2025, the buyers who built their own position before the partner started finished with far smaller claims.
- Self prepared ELPs cut the claim. A position built in house before discovery reduced the partner's initial gap claim by 20 to 45 percent.
- Unmanaged handover inflated counts. Where raw discovery went to the partner unchecked, stale and duplicate records pushed deployment numbers up.
- Framing changed the result. Engagements set up as cost optimization, with compliance as one output among several, returned savings rather than a true up.
One document was constant across all of them. Whatever the engagement was called, a single ELP decided the bill, which is why the rest of this guide is about controlling how that document is built.
How do you keep a Microsoft SAM engagement under your control?
Prepare before the partner does and fix the order of work. If the partner's numbers arrive first, every later conversation starts from their figure.
- Prepare first. Build your own Effective License Position before discovery starts.
- Clean the data. Remove stale, duplicate and decommissioned records.
- Set scope. Agree what is in and out before any tool runs.
- Reconcile claims. Challenge every gap line against your entitlement evidence.
What should you agree in writing before discovery starts?
- Scope by product and entity. Name the products, affiliates and environments in scope, so the review cannot widen halfway through.
- Tools and fields collected. List each discovery tool, where it runs and what it collects, and exclude personal data the review does not need.
- Who receives the results. Agree whether raw data, the draft ELP or only a summary goes to Microsoft.
- A review period on the draft ELP. Reserve time to challenge each line with evidence before anything is marked final.
- Confidentiality and deletion. Sign a nondisclosure agreement with the partner that covers how long it keeps your data and when it deletes it.
What will the partner say, and how should you answer?
- "This is an optimization review, not an audit." Agree, and ask for that in writing along with what happens to the data if a gap appears.
- "We need to run our tool across the whole network." Offer your own inventory exports first, and allow tooling only inside the agreed scope.
- "Every install counts, whether or not the server is live." Ask for the license term that says so, and remove records you can show were decommissioned before the review.
- "The gap can be closed through a new agreement." Settle the count first, and discuss purchases only once the ELP matches your evidence.
Discovery tools count what they find. Only you hold the records that prove a server was retired or a copy never ran in production.
How long should the engagement take?
Long enough to prepare, and no longer than the agreed scope needs. Your own position should be finished before the discovery window opens. An engagement with no fixed end date tends to widen, so put a completion date in the scope letter next to the review period for the draft ELP.
How does the approach change with company size?
A 1,000 seat company with a few dozen servers can often build its own ELP with a small internal team, working from admin center exports and a server list. A 20,000 seat group with several affiliates, mixed agreement types and thousands of virtual machines needs an entity map and firm scope limits, because each affiliate brings its own purchase trail.
How does SAM connect to the renewal?
A clean position is a negotiation asset. Bring it to the renewal table with independent Microsoft licensing experts, so the discount is set against the cleaned count instead of an inflated gap. If the review lands close to your anniversary date, our EA true up guide and SAM audit preparation checklist cover the sequencing.
What to do next
- Read the clause. Locate the audit and verification clauses in your current Microsoft agreement.
- Gather entitlements. Assemble entitlement evidence from purchase and contract records, starting with the volume licensing pages in the Microsoft 365 admin center.
- Clean the inventory. Run your own discovery and remove stale and duplicate records.
- Build your ELP. Prepare your own Effective License Position before the partner starts.
- Fix the scope. Agree scope, tools and timeline in writing before any tooling runs in your environment.
- Challenge each line. Reconcile every claimed gap against your evidence before accepting it.
- Carry it into the renewal. Bring the cleaned position to the renewal with independent licensing experts.
Frequently asked questions
What is a Microsoft SAM engagement?
It is a licensing review, usually delivered by a Microsoft partner and funded by Microsoft, that compares the Microsoft software you run with the licenses you own. It typically starts with an invitation from your account team or a partner and ends with an Effective License Position.
Is a Microsoft SAM engagement the same as an audit?
Not in framing, but yes in data. SAM is voluntary and offered as help, while an audit is a contractual right. The penalty terms differ too: the cost reimbursement and 125 percent pricing in a verification clause belong to a formal audit, while a SAM gap is usually settled as an ordinary purchase.
What is an Effective License Position?
The ELP, or Effective License Position, is a product by product table of deployed quantity, entitled quantity and the difference, which is the basis for any compliance demand. Check the entitlement column as hard as the deployment column, because missing purchase records create false gaps as often as over counted installs do.
Do I have to participate in a SAM engagement?
No. Participation is voluntary, unlike a contractual audit, and you can shape the scope, the timing and the data you share from your own environment. If you decline, reply politely and in writing, since Microsoft can still use the verification clause in your agreement.
Who actually runs a Microsoft SAM engagement?
Usually an authorized partner funded by Microsoft rather than Microsoft itself. Ask the partner at the outset who pays for the work, what it reports back to Microsoft and whether it will also quote for any licenses the review finds missing.
How do I reduce the gap a SAM engagement finds?
Build your own position first, clean the discovery data before handover and challenge each claimed gap with evidence. Check license rights as well: Software Assurance benefits, Developer edition use and License Mobility often cover deployments a partner has counted as unlicensed.
Can SAM data be used against me later?
Yes. The position you accept becomes the reference point for true up, renewal and any later audit. Agree in writing how long the partner keeps your data and who receives it, and make sure the baseline you sign off is one you can support with records.
How does SAM affect my Microsoft renewal?
A clean position strengthens your hand. It allows you to negotiate the renewal discount against your real count, and it removes the risk of a compliance claim appearing in the final weeks of the negotiation, when you have the least time to challenge it.