Server hardware in a rack with green and blue status lights
Microsoft SPLA

Microsoft SPLA licensing and reporting. Pick the meter that fits the access, then report what you made available.

How the Services Provider License Agreement works for hosters, SaaS operators and MSPs, from the monthly report to the SAL, core and edition choices auditors test.

Contact Us Microsoft Advisory
500+Enterprise clients
$2B+Under advisory
PublishedJune 26, 2024UpdatedSeptember 23, 2026
ContentsKey takeawaysWhat SPLA isMonthly reportingSAL and per coreStandard or DatacenterReseller boundariesWhat we have seenAudit triggersRenewalWhat to do nextFAQ

SPLA allows service providers to rent Microsoft software monthly and report what they made available. Profit depends on matching SAL or per core to real access, and on reports that count every authorized user.

Key takeaways
  • Third party use only. SPLA is a monthly rental program for providers that deliver software services to customers outside their own organization.
  • Two core meters. The Subscriber Access License counts each user or device authorized in the month, and the per core option counts cores with unlimited users.
  • The use rights decide. The Services Provider Use Rights in the Product Terms govern what you may and may not do, including License Mobility.
  • Reseller boundaries cause drift. The reseller processes your report, but the agreement holder owns its accuracy, and unclear roles are where most providers slip into noncompliance.
  • Audits follow patterns. Underreporting, shared tenancy, edition mismatches and License Mobility errors are what SPLA audits target.
  • Undercounts are common. In our reviews, leaving dormant and test tenants out of reports opened a 10 to 20 percent gap against real access.

What is Microsoft SPLA and who needs it?

SPLA is the Services Provider License Agreement. It allows a provider to rent Microsoft software by the month to deliver hosted services to customers outside its own organization, paying only for what it made available in the previous month.

Microsoft sets the program terms on its SPLA program page, and the usage rules sit in the Services Provider Use Rights inside the Microsoft Product Terms. Three kinds of business sign it:

  • Hosters. Providers running shared or dedicated infrastructure for clients.
  • Application service operators. SaaS builders whose product runs on Microsoft components such as SQL Server or Windows Server.
  • Managed service providers. Firms that operate customer workloads and supply the licenses in the fee.

What the agreement asks of you

The entry requirements are light, but each one is an obligation you will be held to later. Microsoft lists these conditions:

  • Partner enrollment. Membership of the Microsoft partner network at any level.
  • Two contracts. A signed Microsoft Business and Services Agreement plus the SPLA itself.
  • A designated SPLA reseller. The reseller helps you complete both contracts, then collects your report and your payment each month.
  • A three year term. You can end it early with 60 days prior written notice to Microsoft.
  • A spending floor. Six months after the start date, each monthly report must reach at least $100, or Microsoft may terminate the agreement.

When SPLA is the wrong fit

If you serve only your own employees, you do not need SPLA. Internal use stays under volume licensing, such as an Enterprise Agreement, and using SPLA for it breaches the agreement.

Most providers need both, with staff systems on the volume agreement and the customer platform on SPLA. Keep the two sets of servers and accounts apart, because an auditor who finds them mixed will ask you to prove which license covers which user.

Watch the briefingResearch briefing · 3:58

How does SPLA reporting work each month?

Each month you report, product by product, the licenses you made available to customers during the preceding calendar month. The report goes to your SPLA reseller, which submits it to Microsoft and invoices you for those licenses.

Reporting is 100 percent self declared. Microsoft does not meter your servers, so the report is only as accurate as the inventory behind it. The agreement allows Microsoft and its designees to review your records and facilities, including the data centers, to verify what you filed.

The reporting chain and its rules

  • A report every month. The agreement holder files a usage report or a zero use report. Missed months are the first thing a reviewer looks for.
  • Zero reports are limited. Consecutive zero use reports are allowed only in the first six months. After that, Microsoft accepts them on a non consecutive basis, and a pattern of them reads as a red flag that invites scrutiny.
  • Larger end customers are named. Where the licenses reported for one end customer generate more than $1,000 a month in revenue to Microsoft, the report must include that customer's name and address.
  • Exit has a deadline. When the agreement ends, the final usage or zero use report is due within 30 days.

How to check your own numbers before you file

Build the report from system data. The billing system only shows the customers you invoice, which is a subset of the users you have authorized. These sources show what you actually made available:

  • Directory groups. Export the membership of every Active Directory or Entra ID group that grants access to a licensed product, including service, admin and test accounts.
  • Hypervisor inventory. Pull host, processor and core counts from vCenter, or from Hyper-V with the Get-VMHost and Get-VM PowerShell cmdlets.
  • SQL Server instances. Query SERVERPROPERTY('Edition') and sys.dm_os_sys_info on each instance to confirm the edition installed and the cores it sees.
  • Remote desktop hosts. List the users allowed to sign in to each Remote Desktop Services session host, since each of them needs an RDS SAL.
  • Short lived servers. A VM made available for even a few days belongs in that month's report.
Free white paper

Microsoft EA renewal guide

Your own staff sit on volume licensing, not SPLA. This guide covers renewing that agreement.

Get the white paper →

How does the SPLA SAL and per core math work?

SPLA meters two ways. A Subscriber Access License is required for each unique individual user or device authorized to access or otherwise use the product in the month, whether or not they logged in. A core license covers the physical or virtual cores running the software and allows any number of users.

A SQL Server or Exchange SAL includes the right to run that product's server software, so you report no separate server license for it. The Windows Server underneath is licensed on its own. For the SAL itself, authorization sets the count, and low activity does not reduce it.

SPLA metering options
MeterCountsBest fitAudit risk
SALUnique users or devices authorized to accessKnown, named user baseUndercounted dormant users
Per coreCores on the host or in the VMAnonymous or large user baseUnderreported core changes
SAL for SAEnd customers with existing SA coverageHybrid environmentsEligibility errors

Choosing the meter

  • Few named users. SAL is usually cheaper, as long as the list of authorized accounts is kept tight.
  • Large or anonymous access. Per core caps the exposure, because the bill stops tracking the number of people who can reach the service.
  • Mixed workloads. Model both meters for each service line before committing, and repeat the model when a customer grows.

A worked example for SQL Server Standard

SPLA prices come from your reseller's price list, so this hypothetical uses a ratio instead of dollars. Say one SQL Server Standard core license costs the same as 8 SALs. SQL Server needs at least four core licenses per virtual machine, so a 4 core VM costs the same as 32 SALs.

Hypothetical service lines, cost shown in SAL equivalents
Service lineAuthorized usersActive usersSAL costPer core costCheaper meter
Hosted finance application, one 4 core VM25222532SAL
Customer portal, one 4 core VM1405514032Per core
Public web shop database, one 8 core VMAnonymousUnknownCannot be counted64Per core

The portal is the line that catches providers out. Counting the 55 active users makes SAL look cheaper than per core. Counting the 140 authorized accounts, as the SAL rule requires, makes SAL more than four times the cost of per core.

When does a hosting provider need Datacenter instead of Standard?

A host needs Datacenter, or several sets of Standard licenses, once it runs more than two Windows Server VMs. Microsoft's Windows Server rules give Standard two operating system environments for each time you license all of the host's physical cores, while Datacenter covers any number of them.

Both editions share the same core minimums: 8 core licenses per physical processor and 16 per server. Say a host has two processors with 16 cores each and runs 10 Windows Server VMs:

  • Standard. Every block of two VMs needs all 32 cores licensed again, so 10 VMs need 5 times 32, or 160 core licenses.
  • Datacenter. 32 core licenses cover all 10 VMs and any added next month.
  • Break even. At this density, Datacenter is cheaper whenever its core price is below 5 times the Standard core price.

Edition drift starts when a host is built on Standard for two VMs and then filled. The report keeps showing 32 Standard cores while the host needs five times that.

What changes for SQL Server

SQL Server licenses per core with at least four core licenses per physical processor, or four per virtual machine when you license by VM. Enterprise edition is available per core only, while Standard can be reported by SAL or per core.

Watch the version on new builds. SQL Server 2025 has no Web edition, although Microsoft notes that SQL Server 2022 Web edition may still be available under SPLA, so check before you price an upgrade.

License Mobility and what customers can bring

License Mobility through Software Assurance allows an end customer to run its own application server licenses on your shared hardware instead of renting them from you. The rules are narrower than many providers assume:

  • Application servers only. Exchange Server, SharePoint Server and SQL Server are among the eligible products listed in the Product Terms.
  • No Windows Server. Windows Server is not eligible, so the provider still supplies and reports it under SPLA.
  • Active Software Assurance. The customer's licenses need current SA coverage for as long as they run on your platform.
  • Paperwork in 10 days. The customer completes the License Verification Form within 10 days of deployment, and you must be an Authorized Mobility Partner with a current SPLA.

SAL for SA is a separate route for end customers whose licenses carry SA. Either way, file each customer's verification and SA expiry date, because eligibility is what the auditor tests.

Where do SPLA Reseller boundaries trip providers up?

They trip providers up when the reseller and the provider each assume the other owns the report. Every SPLA holder designates an authorized reseller, which collects the monthly report and the payment and passes the report to Microsoft. The reporting obligation still lands on whoever holds the agreement.

Smaller providers often skip their own agreement and resell the hosted service of a larger provider that holds one. That works only if the larger provider counts your customers in its own report, and gaps between the two surface in audit.

How the setup changes with provider size

  • A small MSP reselling a host's platform. Agree in writing who reports which users and cores, and ask for the report lines that cover your customers.
  • A mid sized hoster with its own SPLA. Reconcile the report internally before the reseller's deadline, since the reseller processes it without checking it.
  • A large operator with several data centers. Report by site and service line, so any spike or drop can be explained.

Where your hardware sits

Check who owns the data center. As of October 2025, Microsoft's SPLA guidance excludes Listed Providers, such as Amazon Web Services and Microsoft Azure, from acting as a data center provider or outsourcing company for SPLA partners. The exclusion also covers any provider that uses a Listed Provider to deliver that service.

What have we seen in SPLA reviews in 2024 and 2025?

Across roughly 18 to 24 SPLA hosting businesses we reviewed between 2024 and 2025, the reported user count understated true access by a meaningful margin in most cases. Three patterns came up repeatedly:

  • SAL undercount. Dormant and test tenants were left out of the report, a gap of 10 to 20 percent against actual access.
  • Edition drift. Standard editions ran workloads that required Datacenter, which exposed the provider to per core liability.
  • Mobility error. License Mobility was assumed where the Services Provider Use Rights did not grant it, a frequent audit finding.

Why we do not default to SAL

The standard guidance is that SAL is always the cheapest meter for a hosting business. We disagree. In the providers we reviewed, those with large anonymous or fluctuating user bases paid more under SAL once dormant and test access was counted in full, because every account authorized to touch the service became a reportable user.

Model per core against your real access pattern instead of the headline rate. For anonymous web facing workloads, per core often caps exposure and removes the monthly undercount risk that drives audit findings. Pick the meter that matches how people reach the service, whatever the aggregator quotes first.

Aisle between two rows of server racks in a data center
On a shared host, the Windows Server edition is set by the number of VMs on the hardware, so a host that fills up over the year can change the license it needs.
An honest SPLA report only costs too much when the meter behind it is wrong.

What triggers a Microsoft SPLA audit?

SPLA audits are common because reporting is self declared. The frequent triggers are flat or falling reports against a growing business, and shared tenancy that crosses license boundaries.

  1. Underreporting. Reported use that does not match observed growth in customers, revenue or infrastructure.
  2. Edition mismatch. Standard installed where the VM count required Datacenter.
  3. Mobility misuse. Customer licenses moved onto shared hardware in ways the Services Provider Use Rights do not allow.
  4. Zero reports. Months with no submission at all, or a string of zero use reports.

What the auditor will say, and how to answer

Typical audit statements and the evidence that answers them
What you will hearWhat to answer with
Every account in your directory needs a SAL.Only accounts authorized to use the licensed product count. Show the access groups that grant it and the accounts that sit outside them.
Your reports fell while your business grew.Show which customers left, which service lines moved to per core and which customers brought their own licenses under License Mobility.
These customers' SQL Server licenses were never verified.Produce each License Verification Form, Microsoft's confirmation and the customer's SA dates.
Standard is installed on hosts running more than two VMs.Give the VM count per host by month, and the extra Standard licenses or the Datacenter line you reported for each.

Defending an audit

Bring your own access records, your monthly reports and your tenancy map for every month under review, since the auditor tests past reports as well as the latest one. Industry bodies such as BSA shape how software audits run, so a clean evidence trail is your strongest position.

Read the verification clause in your signed agreement before the first auditor meeting. It sets who pays for the review and how unreported licenses are priced.

How should a provider approach a SPLA renewal?

Treat the end of the three year term as a chance to re baseline the meter, the editions and the report accuracy before Microsoft does it for you. The work falls into three parts:

  • Re baseline access. Reconcile the reports to the users and devices actually authorized.
  • Validate editions. Confirm Standard or Datacenter host by host against the VM counts.
  • Fix mobility. Align every customer license reassignment to the current Services Provider Use Rights.
SPLA renewal timeline
Before the term endsWhat to do
12 monthsReconcile the last 12 monthly reports against directory and hypervisor data.
6 monthsModel SAL against per core by service line and close edition gaps.
3 monthsCollect verification forms and SA dates, confirm your hosting partners are not Listed Providers, and agree with the reseller when the new agreement must be signed so reporting does not lapse.
1 monthAgree with the reseller how any past shortfall will be reported, and sign the new term on corrected data.

Questions to put to your SPLA reseller

  • Which day of the month is the report due to you, and what happens if it arrives late?
  • How do you handle a correction to a past month, and at which price list is it invoiced?
  • Who answers licensing questions on your side, and will they confirm the answer in writing?

For how a review runs step by step, see our guide to the Microsoft SPLA audit process, and for related topics the SPLA knowledge hub.

What to do next

  1. Reconcile the last year. Compare 12 months of reports against directory exports and access logs.
  2. Classify every workload. Confirm Standard or Datacenter on each host against its VM count.
  3. Model both meters. Cost SAL against per core for each service line using authorized users as the SAL count.
  4. Map License Mobility. Check each customer supplied license against the current Services Provider Use Rights.
  5. Explain zero reports. Close any zero report month with a documented reason.
  6. Draw the tenancy map. Build a diagram that shows where customer boundaries sit on shared hosts.
  7. Re baseline before renewal. Correct the data first, so you negotiate the new term from clean figures.
When to bring in help

Want a second opinion on your Microsoft licensing? Our Microsoft licensing consultants work only for buyers, with no reseller margin.

Frequently asked questions

What is Microsoft SPLA?

The Services Provider License Agreement is Microsoft's program for renting its software to third party customers through a hosted service. Providers sign a three year agreement, report actual monthly use through a SPLA reseller and pay in arrears, with no upfront license purchase.

What is a SAL in SPLA?

A Subscriber Access License is the per user or per device meter in SPLA. A user SAL covers that person on any device they use, and because the count is monthly, an account removed before the month starts drops off the next report.

When should I use per core instead of SAL?

Choose per core when the authorized user count is large, anonymous or changes month to month, as with a public web service. The bill then follows the hardware, so dormant accounts and seasonal spikes stop adding cost.

Can I use SPLA for my own employees?

No. Staff use, including internal systems on the same hardware as customer services, must be licensed through a volume agreement such as an Enterprise Agreement. Reporting it under SPLA breaches the third party requirement.

What triggers a SPLA audit?

Reports that stay flat while the business grows are the most common trigger. Microsoft also looks for Standard edition on crowded hosts, customer licenses moved without License Mobility rights, and gaps or zero use reports in the history.

What is SPLA Reseller?

A SPLA reseller is the authorized partner between the provider and Microsoft. It helps you sign the agreement, collects your monthly report and payment, and passes the report on. Responsibility for the report being right stays with you.

How often do I report under SPLA?

Monthly, covering what you made available in the previous calendar month, by a due date your reseller sets. A final report is due within 30 days after the agreement ends, and your reseller needs a correction process for any past month you get wrong.

How do I prepare for a SPLA renewal?

Start a year before the term ends. Reconcile past reports with directory and hypervisor data, fix edition and mobility gaps, and agree with your reseller how any shortfall will be reported, so you sign the next term on corrected figures.

Newsletter
Licensing news that changes what you pay

One email a week on vendor price moves, audit activity and what worked in recent renewals.

Subscribe
Vendor Shield
An advisor on call for every vendor conversation

Always on advisory for renewals, audits and contract questions across your software vendors.

Explore Vendor Shield
Advisory White Paper

Get the Microsoft EA renewal guide.

For the internal side of a provider's licensing: how the Enterprise Agreement that covers your own staff is priced, renewed and negotiated.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
We never share your details with vendors.

Microsoft licensing news, once a week.

Price changes, audit activity and what worked in recent renewals. No vendor spin.