Software License Management: How to Stop Paying for Seats Nobody Is Using

Software License Management

# Software License Management: An Operational Guide for Finance and IT Leaders

In our experience working with mid-market and enterprise organizations, companies are paying for 25-35% more software licenses than they actually use. This isn’t a procurement failure—it’s a management failure. And more specifically, it’s an execution failure. Most organizations understand *what* they should do about license waste. Few have built the operational machinery to actually do it.

Software license management sits at the intersection of legal compliance, cost optimization, and operational efficiency. Yet most organizations still treat it as a reactive, spreadsheet-driven exercise rather than the strategic function it needs to be. This guide provides the execution-level detail required to move from aspiration to implementation.

The Real Cost of Poor License Management

License waste manifests in ways that rarely appear on a single line item. The obvious cost—paying for unused seats—represents only part of the total financial impact. The rest hides in compliance penalties, operational inefficiency, and missed optimization opportunities.

Software audits have become a profit center for major vendors. Microsoft, Oracle, SAP, and IBM actively conduct software audits, with settlement costs ranging from hundreds of thousands of dollars for mid-market companies to millions for enterprises. Oracle audit settlements frequently reach seven figures, with some large enterprises paying significantly more. Finance and IT leaders consistently report that vendor audits have increased in frequency and aggressiveness over the past several years.

The operational costs are equally significant but harder to quantify. IT teams spend substantial time manually tracking licenses across fragmented systems. Finance teams waste cycles reconciling vendor invoices against actual deployment. Procurement lacks visibility into existing entitlements, leading to redundant purchases. Organizations that have implemented robust license management consistently find that a significant portion of new software purchases duplicate capabilities already licensed but deployed elsewhere in the organization.

The compliance risk extends beyond audit settlements. Under-licensing can trigger immediate true-up requirements that blow quarterly budgets. Over-licensing represents dead capital that could fund strategic initiatives. And the gray zone between them—where your deployment technically violates licensing terms but hasn’t been caught—creates material financial risk that should appear on your enterprise risk register.

License Models: Understanding What You’re Actually Buying

Modern software licensing has evolved far beyond simple per-seat models, and misunderstanding your license terms is the fastest path to compliance exposure. Each model carries distinct financial and operational implications that affect total cost of ownership.

| License Model | Cost Structure | Optimization Lever | Audit Risk | Common Pitfalls |
|—————|—————-|——————-|————|—————–|
| Named User | Per individual | User lifecycle management | Medium | Orphaned accounts, shared credentials |
| Concurrent User | Peak simultaneous usage | Usage scheduling, pooling | Low | Over-provisioning for peak demand |
| Device/Node | Per installation | Consolidation, virtualization | High | VM sprawl, container deployment |
| Processor/Core | CPU capacity | Hardware right-sizing | Very High | Virtualization licensing gaps, cloud migration |
| Consumption/Usage | Actual utilization | Demand management, efficiency | Low | Unpredictable costs, runaway usage |
| Enterprise/Unlimited | Flat fee, full estate | Maximizing deployment | Low | Paying for unused scope, renewal leverage loss |

Processor-based licensing deserves particular attention because it’s where the largest audit exposures occur. Oracle’s licensing policies for virtualized and cloud environments remain notoriously complex. Running Oracle Database on VMware may require licensing every physical core in the entire VMware cluster—not just the cores allocated to your Oracle VMs. A single misconfigured deployment can generate millions in compliance exposure overnight.

Microsoft’s licensing has grown equally complex with hybrid cloud deployments. Azure Hybrid Benefit, License Mobility through Software Assurance, and the distinction between Server + CAL versus Per Core licensing create a matrix of options that most organizations navigate poorly.

SaaS subscriptions add another layer of complexity. Many organizations assume subscription models eliminate license compliance concerns, but most SaaS agreements include usage restrictions, data residency requirements, and fair-use clauses that create audit exposure.

Building a License Management Program: A Five-Phase Framework

Effective license management requires a structured approach that moves beyond reactive compliance checking toward proactive optimization. The following framework provides a maturity model for building sustainable license governance.

Phase 1: Discovery and Inventory (Months 1-3)

You cannot manage what you cannot see. Discovery establishes your baseline by answering three questions: What software is deployed? Where is it deployed? Who authorized the deployment?

Start with your identity provider. Every licensed seat in a modern organization is tied to an identity. Your first step is pulling the complete user list from Azure AD, Okta, or Google Workspace—whichever serves as your primary IdP. Export all users, including their status (active, suspended, deleted), last login date, and group memberships. This becomes your authoritative roster against which all license assignments will be validated.

Cross-reference this user list against active logins. Most identity providers track last sign-in timestamps. Any user who hasn’t authenticated in 90+ days is immediately a candidate for license reclamation across their entire application portfolio.

SSO login data is your most reliable usage signal. For any application connected through your SSO infrastructure, you have visibility into exactly when each user last accessed that tool. Pull SSO logs for the past 90-180 days and aggregate by application and user. This data tells you not just *who* has access, but *who is actually using* what they have access to.

Equally important: catalog which applications are *not* SSO-connected. If a SaaS tool bypasses your identity infrastructure entirely, that’s both a security risk and a visibility gap. These applications require alternative discovery methods and should be prioritized for SSO integration or retirement.

For tools without SSO, use financial forensics. Credit card statement analysis and accounts payable records catch the subscriptions that bypass IT entirely. Pull the past 12 months of corporate card transactions and AP records. Search for recurring charges to known SaaS vendors. Look for payments to unfamiliar companies and investigate—shadow IT often hides behind generic vendor names.

Common patterns we see: department heads putting tools on personal cards for reimbursement, marketing teams subscribing to design tools outside procurement, sales teams paying for prospecting tools from expense budgets. Each of these represents license spend invisible to central IT.

Browser extension tools can surface shadow IT at scale. Solutions like Torii, Zylo, and Productiv offer browser-level monitoring that detects SaaS application usage regardless of SSO status. These tools see what employees actually access in their browsers and can identify applications that never touch your corporate systems otherwise.

However, deploying browser monitoring requires careful handling. Work with Legal and HR to update your acceptable use policy before deployment. Employees need to understand what’s being monitored and why. In many jurisdictions, explicit consent is required. Privacy policy review isn’t optional—it’s a prerequisite. Organizations that skip this step create employee relations problems that undermine the entire program.

Normalize discovered software against a standardized catalog. Raw discovery data contains thousands of variations of the same application name. Without normalization, you cannot match deployments to entitlements. Tools like Flexera, Snow, and ServiceNow provide pre-built normalization libraries, but expect to spend 2-4 weeks refining them for your environment.

In our experience working with mid-market organizations, discovery typically reveals 30-40% more applications than IT formally tracks—this shadow IT represents both cost and compliance exposure.

Phase 2: Entitlement Reconciliation (Months 3-5)

Gather all license entitlements—purchase orders, contracts, enterprise license agreements, volume licensing statements, cloud subscriptions, and maintenance records. Centralize this data in a single repository. Most organizations find their entitlement records distributed across procurement systems, email archives, SharePoint sites, and individual employees’ filing cabinets.

Map entitlements to discovered deployments. This effective license position (ELP) calculation is the core of license management. For each software title, calculate:

Licenses Owned – Licenses Consumed = License Position

Negative numbers indicate compliance exposure. Large positive numbers indicate optimization opportunity.

Expect this phase to reveal significant discrepancies. Organizations that have implemented this approach typically find substantial under-licensing *and* over-licensing across the software estate—the imbalances often reveal both compliance risk and immediate savings opportunities.

Phase 3: Optimization and Remediation (Months 5-8)

Address compliance gaps before vendors identify them. For under-licensed software, evaluate options: purchase additional licenses, reduce deployment, or negotiate true-up terms proactively. Finance and IT leaders consistently report that proactive disclosure results in significantly lower settlement costs compared to vendor-initiated audit findings.

License Reclamation Workflow

Harvesting unused licenses requires a systematic workflow that balances cost savings against operational disruption. Here’s the step-by-step process we’ve seen work effectively:

Step 1: Flag reclamation candidates. Any user showing no login activity for 90+ days across a specific application becomes a reclamation candidate. This threshold balances identifying true waste against catching legitimate but infrequent users. For specialized tools with known seasonal usage patterns (tax software, annual audit tools), adjust thresholds accordingly.

Step 2: Send a 2-week notification before deprovisioning. Never surprise a VP by cutting their access to a tool they use once per quarter for board reporting. The notification email should explain: what’s happening, why, the effective date, and how to contest the reclamation if they still need access. Most reclamation candidates won’t respond—because they genuinely don’t use the tool. But the notification process protects you from the political fallout of the exceptions.

Step 3: Deprovision in your IdP, not just in the vendor portal. This is a common execution gap. Teams remove the license in the SaaS admin console but leave the user provisioned in Okta or Azure AD. The user remains in the application’s identity sync, creating confusion and sometimes re-provisioning the license automatically. Both systems must be updated: remove the license assignment *and* remove the user from the application’s access group in your IdP.

Step 4: Document reclaimed seats for renewal negotiation. This step transforms cost savings into negotiating leverage. Track every reclamation in a centralized log: user, application, date, license type. When renewal approaches, you walk into negotiation with data: “We reduced from 500 to 380 active users over the past year. We need to right-size this contract.” That’s leverage, not just a cost saving.

Step 5: Hold reclaimed licenses in a pool for 30 days before cancelling. Reactivations happen. New hires need licenses. Reclaimed users suddenly remember they need access. Maintaining a 30-day buffer of reclaimed-but-not-cancelled licenses gives you flexibility without requiring new procurement. After 30 days with no reactivation requests, move the license to formal cancellation or reduction at the next contractual opportunity.

Standardize and consolidate where possible. Most organizations maintain 2-4 applications for the same function across different departments. PDF editors, diagramming tools, and project management applications are common consolidation targets. Reducing application count simplifies management and improves negotiating leverage.

Where License Waste Actually Hides

In our experience, the first software license audit typically surfaces 20-35% unused or underused seats across a mid-market SaaS stack. But the waste isn’t evenly distributed.

The most common finding: collaboration and project management tools have the highest license waste. Slack, Microsoft Teams, Zoom, Jira, Asana, Monday.com—these applications get provisioned automatically at hire and almost never reviewed. They’re “default-on” in most onboarding workflows. The result is large populations of licensed users who either never activated their accounts or used the tool briefly during onboarding and never returned.

Security and compliance tools are the exception. Teams tend to keep those licenses provisioned even for inactive users as a risk buffer. An employee who hasn’t logged into your SIEM in 90 days may still need access for the next security incident. This is usually the right call—don’t apply aggressive reclamation policies to tools where the cost of being wrong is a security gap.

Phase 4: Process Integration (Months 8-12)

Embed license management into existing IT and procurement processes. Software requests should trigger entitlement checks before new purchases. Employee onboarding and offboarding should include automated license assignment and revocation. Change management should include license impact assessment for infrastructure changes.

Establish license governance with clear ownership. Define roles for license administrators, compliance reviewers, and executive sponsors. Create policies for acceptable use, shadow IT remediation, and audit response. Document procedures for vendor-specific programs like Microsoft’s License Statement review or SAP’s license measurement.

Phase 5: Continuous Optimization (Ongoing)

License management is not a project—it’s an ongoing program. Establish regular cadences: weekly usage reviews, monthly compliance checks, quarterly optimization assessments, annual contract reviews. Automate reporting to surface anomalies before they become audit findings.

Benchmark your performance against industry standards. Organizations with mature license management programs typically achieve high license utilization rates, minimal compliance gaps, and controlled annual software cost growth. Immature programs often show significantly lower utilization, persistent compliance exposure, and double-digit annual cost growth.

Vendor Negotiation: Using Your Data as Leverage

The discovery and reclamation work described above isn’t just about cost reduction—it’s about building the data foundation for effective vendor negotiation. Every contract renewal should be approached with current utilization data in hand.

Utilization-Based Negotiation Strategies

Usage rate below 60%: Demand seat reduction or price adjustment. If you’re paying for 500 seats and only 300 show meaningful activity, you have two negotiation paths. First, request a contract amendment reducing seats to match actual usage plus reasonable growth buffer (typically 10-15%). Second, if the vendor resists seat reduction, negotiate a price-per-seat reduction that reflects your actual value received. “We’re paying $50/seat but only getting value from 60% of them—effectively $83/seat for productive users. We need the rate to reflect reality.”

Usage rate below 40%: Question whether the tool survives rationalization. At this utilization level, you’re paying for a tool that most licensed users don’t use. Before negotiating renewal, ask the harder question: should this application exist in your portfolio at all? Can its function be absorbed by another tool with higher utilization? Is the low usage a training problem, an adoption problem, or a signal that the tool doesn’t solve a real need? Negotiate from the position that you’re evaluating alternatives—because you should be.

Multi-year deals: Negotiate price-per-seat, not just total contract value. Vendors approaching multi-year renewals will often offer discounts on total contract value while holding the per-seat rate constant. This locks you into paying the same rate for any future seats while reducing your flexibility. Instead, use your seat reduction data to negotiate the per-seat rate downward: “We’ve demonstrated we can operate effectively with 380 seats instead of 500. We’ll commit to a three-year term, but at a per-seat rate that reflects our optimized footprint.” This protects you if utilization drops further and creates savings on any seats you do add.

Data Points That Matter in Negotiation

Walk into renewal conversations with:

Current utilization rate (active users / licensed seats)
Trend data showing utilization over past 12 months
Reclamation log documenting seats you’ve recovered
Competitive alternatives you’ve evaluated (vendors respond to credible switching threats)
Contract end date and auto-renewal terms (never negotiate under time pressure)

The most powerful position in any software negotiation is genuine willingness to walk away. If your utilization data shows a tool isn’t delivering value, and you’ve identified alternatives, you negotiate from strength. If you need the tool and have no alternatives, vendors know it—and price accordingly.

Selecting License Management Tools: An Honest Assessment

The software asset management (SAM) tool market has consolidated around several major platforms, but no single tool solves every license management challenge. Understanding their strengths and limitations is essential for appropriate investment.

Flexera One offers the broadest and deepest capabilities, particularly strong for complex on-premises environments and traditional enterprise software. Its normalization library covers hundreds of thousands of applications with licensing rules for thousands of publishers. However, Flexera’s complexity requires significant implementation investment—expect 6-12 months for enterprise deployments. Pricing typically runs in the range of $15-25 per managed device annually, making it expensive for organizations with large device counts but limited software complexity.

Snow Software provides similar enterprise capabilities with a reputation for faster implementation. Snow’s cloud management capabilities have improved significantly, and its SaaS management module addresses a gap that Flexera still fills through third-party integrations. However, Snow’s Oracle and SAP license calculations sometimes require manual verification—organizations with significant Oracle estates should supplement with specialized tools.

ServiceNow SAM appeals to organizations already invested in the ServiceNow platform. Native integration with ITSM, ITOM, and procurement workflows is genuinely valuable. However, ServiceNow’s normalization capabilities lag behind Flexera and Snow, and its license calculation rules for complex products require more manual configuration. ServiceNow works best for organizations with moderate software complexity who prioritize workflow integration.

Microsoft-specific tools deserve mention because Microsoft represents a significant portion of most organizations’ software spend. Microsoft’s License Statement provides authoritative entitlement data directly from Microsoft. The Viva Insights and Microsoft 365 admin center provide usage data for Microsoft 365. For organizations where Microsoft dominates the software estate, these native tools may reduce the business case for third-party SAM platforms.

SaaS management platforms like Zylo, Productiv, and Torii have emerged to address the SaaS blind spot in traditional SAM tools. These platforms discover SaaS applications through SSO integration, expense data, and browser extensions. They excel at identifying shadow IT and tracking subscription utilization. However, they don’t replace SAM tools for on-premises and hybrid environments—most enterprises need both.

Audit Defense: Preparation Over Reaction

Software audits are not random events—they follow predictable patterns that enable proactive defense. Vendors audit most frequently during contract renewals, after significant M&A activity, when organizations reduce maintenance coverage, and when they detect unusual deployment patterns through telemetry.

Audit preparation should begin 12-18 months before anticipated exposure. Conduct internal audits using the same tools and methodologies vendors employ. Oracle’s LMS scripts, Microsoft’s MAP toolkit, and SAP’s LAW tool are publicly documented—run them yourself before vendors do.

When an audit notification arrives, respond professionally but protect your interests:

Review the contract carefully. Audit clauses vary significantly. Some require 30 days notice; others allow only annual audits. Some limit scope to specific products; others permit estate-wide review. Know your rights before engaging.
Control data access. Vendors often request broad access during audits. Provide only what the contract requires. Run discovery scripts yourself rather than granting vendors direct system access.
Engage specialized counsel. Software licensing attorneys understand vendor audit tactics and acceptable settlement ranges. Legal fees typically pay for themselves many times over in reduced settlement amounts.
Negotiate from data. Vendors’ initial audit findings often overstate exposure through aggressive interpretation of licensing terms. Counter with your own analysis and documentation.
Consider the commercial relationship. Audits often coincide with renewal cycles. Vendors may offer compliance amnesty in exchange for expanded commitments. Evaluate whether this trade-off serves your interests.

Frequently Asked Questions

How do I find software I don’t know about?

Start with what you can see: SSO logs show every application connected to your identity infrastructure. Then expand outward. Pull 12 months of corporate credit card statements and accounts payable records—search for recurring charges to any vendor you don’t recognize. Review expense reports for software-related reimbursements. For comprehensive discovery, deploy a SaaS management platform with browser-level visibility (Zylo, Torii, Productiv), but coordinate with Legal and HR first on privacy policy requirements.

What’s a reasonable utilization threshold before reclaiming a license?

90 days of inactivity is the standard threshold for most business applications. This balances identifying true waste against catching legitimate infrequent users. Adjust for known usage patterns: tax software might show no activity outside of quarterly close periods; that’s expected, not waste. For expensive per-seat licenses ($100+/month), you might apply a 60-day threshold. For low-cost collaboration tools, 120 days may be more appropriate to avoid administrative overhead exceeding savings.

How do I handle pushback from employees when reclaiming licenses?

The 2-week notification window handles most pushback—employees who genuinely need access will respond and retain their licenses. For contested reclamations, ask for evidence of planned usage: “What will you use this tool for in the next 90 days?” Often, the answer reveals the license was held “just in case” rather than for defined work. For executives and VPs, frame reclamation as temporary and reversible: “We’re consolidating unused licenses; if your needs change, we can reactivate within 24 hours.” The political cost of forcing the issue rarely justifies the savings on a single seat.

When should I use a SaaS management platform vs. doing this manually?

Manual management works for organizations with fewer than 50 SaaS applications and dedicated staff time for quarterly reviews. Above that threshold, the administrative burden exceeds tool cost. SaaS management platforms typically cost $3-8 per employee per month. If you’re spending more than 20 hours per quarter on manual SaaS tracking, or if you suspect significant shadow IT exists, the tool pays for itself. For organizations with 500+ employees and 100+ SaaS applications, manual management is no longer viable—you need automated discovery and continuous monitoring.

What is the difference between software license management and software asset management?

Software license management focuses specifically on ensuring proper license entitlement and compliance—matching what you own to what you’ve deployed. Software asset management (SAM) is broader, encompassing the entire software lifecycle from procurement through retirement, including inventory management, vendor relationships, and cost optimization. In practice, effective license management requires SAM capabilities, but SAM programs address concerns beyond pure licensing compliance.

How often should software license audits be conducted internally?

Organizations should conduct comprehensive internal license audits annually, with targeted reviews quarterly for high-risk vendors (Oracle, SAP, Microsoft, IBM). Continuous automated compliance monitoring should supplement periodic audits—the goal is identifying exposure when it occurs, not discovering it during annual reviews. Organizations facing imminent vendor audits should conduct deep internal audits 3-6 months in advance.

Software license management has evolved from a back-office compliance function into a strategic capability that directly affects IT cost efficiency, financial risk exposure, and operational agility. But strategy without execution is just aspiration.

The organizations that capture value from license management are those that build repeatable operational workflows: systematic discovery starting from identity providers, disciplined reclamation with proper notification protocols, and data-driven vendor negotiation. The investment in people, process, and tools pays dividends not just in avoided penalties, but in the operational clarity that comes from knowing exactly what you own, what you use, and what you need.

ty247

Ty Sutherland is the Chief Editor at Kost Kompass. With 25 years of experience in enterprise strategy and financial management, Ty Sutherland is the driving force behind kostkompass.com. Specializing in helping Finance and Technology Managers optimize costs in servers, cloud, and SaaS, Ty combines technical acumen with financial discipline to deliver actionable insights for cost-effective solutions.

Recent Posts