Initial SPLA findings overstated licensable users by 20 to 40 percent
SPLA bills on a monthly meter, and an audit is that meter reconstructed by the counting party. Before the multi tenant boundary was defended, initial findings overstated licensable users by 20 to 40 percent, and back maintenance assumptions added 15 to 30 percent on top. The defense is your own monthly record.
Prepared by Redress Compliance · August 15, 2026 · Microsoft advisory. SPLA audit engagements for hosting and service providers, 2024 to 2026.
Executive summary
Initial findings overstated licensable users by 20 to 40 percent before the multi tenant boundary was defended. Internal admin accounts, cross tenant duplicates, and non hosted staff all count as customer users until the tenant map says otherwise.
Back maintenance and unfiled use assumptions added 15 to 30 percent to the first settlement number. The auditor projects the current finding backward across months, so every correction to the count also cuts the retroactive multiplier.
The first 10 days set the frame: acknowledge without volunteering data, agree scope and data requests in writing, freeze the monthly reporting workpapers, and assemble the tenant map before any count is discussed.
The metric question comes before the counting question. Confirm SAL or per core per product, because a workload measured on the wrong metric inflates the finding before a single user is miscounted.
The durable defense is boring: a clean monthly SAL report filed as part of the financial close. Twelve reconciled monthly reports turn an audit into a comparison of records; their absence leaves the meter to be reconstructed by the counting party.
The audit, element by element
| Element | What happens | Provider note |
|---|---|---|
| The notice | Scope, auditor, and data requests proposed | Everything in the notice is negotiable in writing, once |
| The metric | SAL or per core, per product | Wrong metric inflates the finding before any count does |
| The count | Directories and session data, auditor read | Without the boundary, every visible account is a customer user |
| The boundary | Your infrastructure versus each customer tenant | The tenant map is the single highest value document |
| The settlement | Current finding projected backward | Back maintenance assumptions added 15 to 30 percent |
| The renewal | The go forward terms after settlement | Trade commitment for settlement relief, and fix the reporting |
An SPLA audit is a reconstruction of a monthly meter that should never need reconstructing. The program bills on monthly usage reports the provider files; the audit exists because those reports and the deployed estate drifted apart. Whoever holds the better monthly record wins the reconstruction, and only one side can prepare that record in advance.
The defense, in order
- Use the first 10 days precisely: acknowledge, agree scope and data flow in writing, freeze the reporting workpapers, and start the tenant map. Volunteer nothing beyond the agreed scope.
- Confirm the metric per product before reconciling any count, SAL or per core, because the metric error is the cheapest correction and the most overlooked.
- Rebuild the monthly counts from authentication data per customer tenant, reconciled against the filed reports, so the conversation compares records rather than estimates.
- Defend the boundary with documentation: which users belong to which customer, which systems are shared management plane, which access is administrative. This is where the 20 to 40 percent lives.
- Correct the current count before discussing settlement, because the retroactive projection multiplies whatever number survives, in both directions.
The SPLA service provider licensing guide
The SPLA metrics per product, the monthly reporting discipline, the multi tenant boundary documentation, and the audit response sequence.
Get the guide →The meter is monthly, the audit is retroactive
SPLA's defining feature is that the provider reads its own meter. Every month, the provider counts its licensable use and files a report, and Microsoft bills what was filed. It is the most trust based licensing program Microsoft runs, and the audit is where the trust gets reconciled.
That structure explains both numbers in this brief. The 20 to 40 percent overstatement exists because the auditor, reconstructing the meter from directories and session logs, cannot see the multi tenant boundary from the data alone. An administrator who touches forty tenants looks like forty users. A shared management plane looks like a customer environment. Staff accounts look like hosted seats. The boundary is real, but it lives in documentation, and undocumented reality counts against the provider.
The 15 to 30 percent lives in time rather than space. A finding about today is projected backward across the unfiled or under filed months, on assumptions favorable to the party doing the projecting. This is the quiet arithmetic that makes SPLA settlements balloon: the count error and the time projection multiply each other, which is also why every correction to the count pays twice.
The strategic conclusion is that SPLA audit defense is not primarily an audit skill; it is a reporting discipline wearing audit clothes. A provider that files twelve reconciled monthly SAL reports a year, keeps the tenant map current, and confirms the metric per product has pre answered every question the audit can ask. The reconstruction becomes a comparison, the assumptions have nowhere to attach, and the settlement conversation starts near the truth instead of 35 to 70 percent above it.
The endgame mirrors every Microsoft compliance event: the settlement is a commercial negotiation, not a fine. Fix the go forward position in the same conversation, metrics, boundary documentation, reporting cadence, and trade the renewal commitment for relief on the settlement number, the same conversion that enterprise audit settlements reach 30 to 50 percent below cash demands with.
The wider position sits in the Microsoft practice.
Watch the briefing · 4:06Microsoft EA: Where the Leverage Really Is, and the Mistakes That Give It AwayLeverage lives in Microsoft's calendar and targets, and the mistakes that hand it back, the same mechanics that decide a settlement conversation.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
What the SPLA engagements showed, 2024 to 2026
Across the SPLA audit engagements we advised for hosting and service providers, the corrections concentrated in two places:
Overstated licensable users in initial findings, removed once the multi tenant boundary was documented and defended.
Added to first settlement numbers by back maintenance and unfiled use assumptions, cut as the current count was corrected.
Three patterns recurred. Providers who volunteered raw directory exports in week one and spent months walking them back. Tenant maps that existed in engineers' heads but not on paper, so the boundary could not be defended when it mattered. And monthly reports filed from estimates rather than reconciliations, which handed the auditor the drift the audit then priced.
The provider side move is to file the defense monthly, before any letter exists. The wider library sits in the Microsoft practice.
Your first five moves
- Commit to the monthly SAL report as part of the financial close, reconciled from authentication data per tenant, because twelve clean reports are the entire long game.
- Write the tenant map now: customers, shared infrastructure, administrative access, on paper and current.
- Confirm the metric per product across the estate, SAL or per core, before anyone else confirms it for you.
- On any notice, run the 10 day sequence: acknowledge, agree scope in writing, freeze workpapers, volunteer nothing beyond scope.
- Negotiate settlement as commerce: correct the count first, then trade the go forward commitment for relief. The Microsoft practice runs the defense with you.
Frequently asked questions
What should you do in the first 10 days of an SPLA audit notice?
Acknowledge without volunteering data, agree the scope and the auditor's data requests in writing, freeze your monthly SAL reporting workpapers, and assemble the tenant map that defines the multi tenant boundary. The first 10 days set whether the audit runs on your records or on the auditor's assumptions.
How do you reconcile SPLA SAL counts under audit?
Rebuild the monthly counts from authentication and access data per customer tenant, and reconcile them against the monthly usage reports you filed. Confirm the correct metric per product, SAL or per core, because a workload measured on the wrong metric inflates the finding before any counting question arises.
Why do initial SPLA findings overstate users?
Because auditors count from directories and session data without the multi tenant boundary applied. In our engagements, initial findings overstated licensable users by 20 to 40 percent before the boundary was defended: internal admin accounts, cross tenant duplicates, and non hosted staff all counted as if they were customer users.
What is the multi tenant boundary defense in an SPLA audit?
The documented line between your hosting infrastructure and each customer tenant: which users belong to which customer, which systems are shared management plane, and which access is administrative rather than consuming. Without that map, every account the auditor can see becomes a licensable user.
How does SPLA settlement math get inflated?
Back maintenance and unfiled use assumptions added 15 to 30 percent to the first settlement number in our engagements. The auditor projects the finding backward across months with assumed usage, so every correction to the current count also cuts the retroactive multiplier.
What is the best long term SPLA audit defense?
A clean monthly SAL report, filed as part of the financial close. SPLA bills on a monthly meter, and a provider that can produce twelve reconciled monthly reports turns the audit into a comparison of records; a provider that cannot leaves the meter to be reconstructed by the auditor.
Can an SPLA settlement be recovered at renewal?
Partially, yes. A settlement conversation that also fixes the go forward position, the correct metrics per product, the boundary documentation, and the reporting cadence, converts a one time payment into a corrected cost base, and the renewal is the natural moment to trade commitment for relief on the settlement number.
Negotiating Microsoft E5, E7, and Copilot Cowork: The Two-Layer Bill
E7 at $99 vs $117 in components, and the truth proposals omit: $99 is the governance floor. Agent execution bills separately through Copilot Credits with no rollover, Security Copilot overages at $6 per unit, and Cowork priced as license plus meter.