Platform · Microsoft 365 licensing

Cut your Microsoft 365 licensing bill, not the capability people use.

Microsoft 365 license waste is rarely dormant accounts. It's active people on E5 who never open Purview or Entra ID P2, add-ons duplicating rights the base SKU already grants, and frontline staff on knowledge-worker plans. Chronom reads sub-SKU feature usage, not sign-ins, for every identity in the tenant.

Read-only Access No Credit Card SOC 2 Compliant
microsoft 365 admin center
no issues reported
What the admin center reports
1,204
licensed
1,198
signed in / 30d
6
unassigned
What it can't see
E5 seats with no premium usage
212 seats · no Purview eDiscovery, Entra ID P2 or Power BI in 12 months
$55,968
E3 seats that never left the browser
84 seats · Outlook on the web, Office desktop never activated
$29,232
Knowledge-worker plans on frontline identities
140 shared-device accounts · F3 covers every workflow they use
$52,080
Add-ons the base SKU already grants
61 standalone Entra ID P2, Intune Plan 1 and Power BI Pro seats
$8,400
Licensed but sign-in blocked
38 leavers · mailbox kept, license never reclaimed
$9,960
Reclaimable / year
$0
1,204 seats analysed · 40+ license checks
0 alerts
5 decisions
Sound familiar

Nobody chose this. M365 license waste is the sum of defaults nobody revisited.

The Microsoft 365 admin center answers a different question than the one that saves money. It tells you who signed in, which apps opened and how many seats sit unassigned. It never tells you whether the premium half of an E5 license - Purview, Entra ID P2, Defender for Office 365 P2, Power BI Pro, Teams Phone - was ever exercised by the person holding it.

Checking properly means cross-referencing entitlements against feature-level usage for every identity in the company. Then re-learning the SKU matrix each quarter as Microsoft moves what's included in which plan. Nobody has a spare month for that, so the number gets discovered at renewal - when it's already billed, and already the floor for the next term.

15–30 %
of M365 license spend is recoverable
20–35 %
of enterprise seats qualify for a lower tier
48 hrs
to your own named-user figure
the default that stuck

E5 was bought for forty people

It arrived for a security programme covering one department, then quietly became the template for every new starter. Nobody decided that. It just never got revisited.

paid for twice

The add-on that predates the bundle

Standalone Entra ID P2 and Power BI Pro were bought before the E5 rollout. The upgrade granted the same rights, and both line items carried on billing side by side.

the wrong license family

Identities that were never knowledge workers

Shift workers on shared devices, kiosk accounts, room and equipment mailboxes, external collaborators and service accounts - all holding full E-series seats because nothing in the tenant stops them.

The short version

How Microsoft 365 license optimization actually works

Same tenant, same people, a smaller invoice. The work is matching every identity to the cheapest SKU that still covers what they do - and knowing which rights they already own.

You're buying capability tiers, not seats

A Microsoft 365 license is a bundle. E3 carries the Office apps, Exchange, SharePoint and Teams. E5 adds the premium half - Microsoft Purview compliance, Entra ID P2, Defender for Office 365 P2, Power BI Pro, Teams Phone - for roughly $21 more per user per month.

Nothing on the invoice distinguishes a person who uses that premium half from a person who has never opened any of it. Both rows read the same, every month, for years.

July 2026 list: E5 $60 · E3 $39 · Office 365 E1 $10 per user / month

Three patterns account for most of the waste

Over-tiered actives: busy people on E5 whose twelve-month usage never leaves E3 territory. Duplicate entitlements: standalone Entra ID P2, Intune or Power BI Pro billing a right the base SKU already grants. Wrong license family: frontline, shared-device, kiosk and service identities on knowledge-worker plans.

None of the three looks like waste in a seat count, because all of them are assigned to something real.

Why the reports don't get you there

Native usage reporting is built around sign-ins and app opens, and it arrives de-identified by default. Entitlement inheritance - which add-on rights come free inside which plan - appears in no portal view at all, and Microsoft revises it every quarter.

So the gap between what you bought and what gets used is discoverable, but only by someone treating it as a full-time job.

How to reduce a Microsoft licensing bill, in order
  1. 1

    Separate identities from people

    Shared mailboxes, room and equipment accounts, guests, service principals and automation accounts rarely need a paid seat. Start here because nothing is at risk.

  2. 2

    Read feature usage, not sign-ins

    Twelve months of per-feature activity per user. This is the step that distinguishes a genuine E5 from an E5 that behaves like an E3.

  3. 3

    Remove what you already own

    Standalone add-ons stacked on a base SKU that grants the same right. Fastest saving on the list: no user loses a capability.

  4. 4

    Re-tier by cohort, not by person

    Group the E5-to-E3, E3-to-E1 and E3-to-F3 populations, exclude anyone with compliance or legal custody, then price each cohort separately.

  5. 5

    Convert mailboxes before you release SKUs

    Removing an Exchange-bearing license first starts a 30-day soft-delete clock. Convert to shared, preserve OneDrive, then release.

  6. 6

    Time it to the agreement, then lock it in

    Microsoft doesn't prorate mid-term changes, so reclaims land on your anniversary. Group-based licensing keeps the tier from drifting back.

What we look for

Six places Microsoft 365 license spend hides

Examples rather than the catalogue - a sample of what the platform reads across your users, SKUs and add-ons, and why each one stays invisible until something is looking for it.

01 Microsoft 365 licensing

You buy capability tiers. Nobody bills you for the half you never touch.

The waste is almost never dormant accounts. It's active people sitting a tier too high, standalone add-ons duplicating rights their base SKU already grants, and whole categories of identity carrying knowledge-worker licenses they were never meant to have.

Users SKUs Add-ons Groups Mailboxes Guests Service accounts
15–30%
of M365 license spend
PAID TIER USAGE SAYS E5 4 overpaid E3 right-sized F / shared frontline base SKU add-on same right, billed twice
What the scan reads

Sub-SKU feature usage, per person

We read whether the premium half of the license is ever exercised: Purview eDiscovery and DLP, Entra ID P2 conditional access, Defender for Office 365 P2, Power BI Pro, Teams Phone, Intune enrolment. User by user, across twelve months - which is the only way to tell an E5 power user from an E5 that behaves like an E3.

$180–$300 per seat / yr

Admin-center reports show sign-ins and app opens, and usage data arrives de-identified by default.

Entitlements you're paying for twice

Standalone Entra ID P1 and P2, Intune Plan 1, Defender for Office 365 P1, Exchange Online Plan 2, Power BI Pro, Visio and Project, stacked on E3, E5 or Business Premium seats that already include the same right. Removing the duplicate changes nothing a user can see.

4–9% of license spend

Entitlement inheritance appears in no portal view. You have to know the SKU matrix, and it moves every quarter.

The E3-to-E1 population

Some people spend the entire day in Outlook on the web, Teams chat and shared documents. No Office desktop activation, no Teams Phone, no eDiscovery custody, no enrolled device - and Office 365 E1 covers all of it at $10 per user per month against $39.

$348 per seat / yr

Mailboxes have to be converted before the SKU is removed, or the 30-day soft-delete clock starts on mail nobody agreed to lose.

Frontline and shared-device eligibility

Microsoft 365 F1 and F3 are built for shop-floor, retail, field and clinical staff who share a device. Exchange Online Kiosk covers mailbox-only identities, and shared mailboxes never needed a paid seat at all.

up to 70% cheaper per identity

Frontline eligibility is contractual, not technical - nothing in the tenant warns you when you over-license.

Identities that shouldn't hold a paid seat

Sign-in-blocked leavers, unconverted leaver mailboxes, guest and B2B collaborators, service and automation accounts, room and equipment mailboxes. Plus the duplicate identities every tenant migration leaves behind.

$260–$660 per identity / yr

Offboarding closes the ticket. It very rarely reclaims the SKU, and nothing reconciles the two.

The plan boundaries your growth crossed

Microsoft 365 Business Premium and Business Standard stop at 300 seats. Grow past that line and you inherit a mixed estate: two plan families, two price points, and an E3 default nobody re-derived once the headcount changed.

the whole mix, re-derived

Nothing flags the moment the cheaper plan family stopped being an option, or stopped being necessary.

We handle

Every recommendation lands as a named user, a named SKU and an exact annual figure. Because Microsoft doesn't prorate mid-term changes, reclaims are sequenced against your renewal and anniversary dates, mailboxes are converted before anything is removed, and the result is locked in with group-based assignment so the estate can't quietly re-tier itself.

Ranges and figures on this page are aggregate patterns across audited tenants, shown for illustration. Your audit replaces every one of them with your own numbers, tied to named users, SKUs and add-ons.

No alerts. No open questions.

Not 'low usage detected'. A SKU, a cohort, and a dollar figure.

Chronom outputs conclusions rather than signals: which license, on which people, changes to what, why it's safe to do, and what it's worth over a year.

E5 × 212 E3 + Defender P1
sales, ops, field engineering
Why it's safe

Twelve months with no Purview eDiscovery, DLP, Entra ID P2 or Power BI Pro activity. Office desktop, Teams and calling continue untouched.

$56K
recovered spend
E3 × 84 Office 365 E1
web-only administrative staff
Why it's safe

Outlook on the web only, no Office desktop activation in a year, no Teams Phone, no enrolled device. Mailboxes stay in place at 50 GB.

$29K
recovered spend
E3 × 140 Microsoft 365 F3
shop floor & shared devices
Why it's safe

Shared-device sign-ins, no dedicated endpoint, no data custody. Frontline eligibility is confirmed against your agreement before the change is proposed.

$52K
recovered spend
61 add-ons Removed
Entra ID P2, Intune P1, Power BI Pro
Why it's safe

Each assignment sits on a base SKU that already grants the identical right. Removing the standalone changes nothing a user can see.

$8K
recovered spend
E3 × 38 Release
sign-in-blocked leavers
Why it's safe

Blocked at offboarding, license never reclaimed. Mailbox converted to shared and OneDrive content preserved before release.

$10K
recovered spend

What you won't be handed

Every line in a Chronom report is a decision with an owner, a SKU and a dollar figure. Nothing is left for you to go and find out.

  • “Low Teams usage detected” - a fact you now have to interpret

  • An alert queue that grows faster than you can triage it

  • A dashboard that hands the analysis back to you

Illustrative figures for a 1,204-seat tenant. Your report carries your real numbers, tied to named users and SKUs.
Continuous, not one-and-done

License waste rebuilds quietly. So the scanning doesn't stop.

A one-off clean-up decays. New starters inherit the default SKU, projects provision add-ons, someone re-enables an account. Chronom keeps reading the tenant so it never compounds back to where it started.

24/7

New drift, flagged in a day

Every scan compares the tenant against the baseline you approved. A new E5 assignment, a re-added Power BI Pro add-on or a re-licensed leaver surfaces within a day - not in a quarterly review.

pre-purchase

Buy nothing you already own

When a team asks for Intune, Entra ID P2 or Project seats, you can check whether the entitlement already exists inside someone's base SKU before the purchase order goes out.

renewal-safe

Fewer true-up surprises

Peak seat count is what gets reconciled at true-up, so catching a spike in week one instead of month twelve is what keeps the next reconciliation small.

always-on

Group-based assignment guardrails

Approved right-sizing is enforced through group-based licensing rather than a spreadsheet, so the tier a cohort belongs on is a rule in the tenant instead of a memory.

M365 licensing FAQ

The obvious questions.

It's matching every identity in your tenant to the cheapest license that still covers what that person actually does, then keeping it that way. In practice there are four moves: reclaim seats nobody uses, drop over-tiered users to a lower plan, remove standalone add-ons that duplicate a right the base SKU already grants, and move non-knowledge-workers onto frontline or kiosk plans. Done properly it reduces a Microsoft 365 licensing bill by 15–30% without changing anything an employee can see, because nothing anyone actually uses gets taken away.

The admin center answers a different question. It tells you who signed in and which apps opened - not whether the capability you're paying for was used. An E5 user who never opens Purview, Entra ID P2, Defender for Office 365 P2 or Power BI looks identical to a power user in every native report. Chronom reads feature-level usage per identity across twelve months, maps it against what each SKU and add-on actually entitles, and prices the gap against your own rates.

Not if the baseline is treated as untouchable, which is how we run it by default. Chronom operates in one of two modes. Savings-first shows you the largest defensible number and lets you carve out exclusions once you can see them priced. Security-first fences off premium licensing that exists because security, legal or compliance asked for it, and finds savings around it. Either way, anyone with eDiscovery, retention or litigation-hold custody - legal, HR, finance, executives, security operations - stays where they are regardless of what their usage looks like.

Usage tells us who behaves like a frontline worker: shared-device sign-ins, no dedicated endpoint, no Office desktop activation, no data custody. Eligibility, though, is contractual rather than technical - Microsoft's frontline terms are about the role and the device, not the telemetry. So every frontline recommendation is checked against the wording of your agreement before it reaches you, which is exactly the check nothing in the tenant performs for you.

It can, if the sequence is wrong. Removing an Exchange-bearing SKU before the replacement lands starts a soft-delete clock, and that's how organizations lose mail they can't recover. Chronom sequences it the other way: mailboxes are converted to shared where needed, OneDrive content is preserved, the replacement SKU is assigned, and only then is the old one released. Analysis itself is read-only, and execution never happens without your approval.

Yes, and the paper changes the timing rather than the findings. Microsoft doesn't prorate mid-term subscription changes, so on an EA or CSP term the reclaim is timed to your anniversary or renewal to capture the full annual value instead of paying for seats you've already stopped using. Chronom is vendor-agnostic and sells no licenses, so you keep whatever agreement and partner you have - we just hand you the usage evidence behind every line item.

Across audited tenants, 15–30% of M365 license spend, with around 32% of total tenant spend wasted once storage, Copilot and cloud are included. In structured audits, 20–35% of seats at mid-to-large enterprises qualify for a lower tier. Your assessment replaces those ranges with your own figure, tied to named users and SKUs, within 48 hours of connecting.

One Audit. Real Savings.
Zero Risk.

Get a comprehensive audit of your environment and see exactly how much you can save in under 15 minutes.

Read-only Access No Credit Card SOC 2 Compliant