Licensing
The Licensing pages give you a read-only, daily-refreshed view of the software licences your organisation owns: what you pay for, who is using it, and where licences are going to waste. Nothing is ever changed in your vendor tenant — the feature only reads.
Microsoft 365 is the provider available today. The pages are provider-neutral: connected providers appear here as they are added, and the figures below describe the Microsoft 365 licence estate.
Where to find it
Licensing appears in the sidebar under Tracking once the feature is enabled for your tenant. From there, Overview (/<tenant>/licensing) and Users (/<tenant>/licensing/users) are two tabs of the same page.
If you do not see it, ask your Cloud Ctrl account manager to enable licensing for your tenant — the whole surface (pages, connection card and recommendations) is gated on a per-tenant feature.
What you get
| View | Answers |
|---|---|
| Overview | How many licences do we own, how many are unused, and what is the waste worth? |
| Users | Who holds which licences, and which accounts have gone quiet? |
Both views refresh once per day. The ingest runs at 17:00 UTC — early morning AEST — and the page shows an as of … chip so you always know how old the figures are. Because the schedule is a fixed UTC time, it lands an hour later in local time during daylight-saving months.
Licence costs are indicative (see Indicative costs), and they appear only on these pages — they are deliberately not mixed into your cloud spend, budgets or Cost Explorer views.
Connecting Microsoft 365
Navigation: Settings → Cloud Connections → Microsoft 365 → Connect Licensing
A licensing connection is an Azure Entra App registration — the same credential type you use for Azure. You either pick an existing Azure Entra App credential already configured in Cloud Ctrl, or create a new one; connecting provisions a licensing cloud account linked to that credential.
- In the Azure portal go to Microsoft Entra ID → App registrations and create (or locate) an app registration in your own tenant.
- Add a client secret (Certificates & secrets) and copy it — it is only shown once.
- Under API permissions, add Microsoft Graph → Application permissions:
| Permission | Needed for | Required? |
|---|---|---|
Directory.Read.All | SKU inventory, per-user assignments, subscription lifecycle dates | Required |
User.Read.All | User names, types and licence states | Required |
AuditLog.Read.All | Sign-in activity — powers the inactivity and reclaim bands. Also requires an Entra ID P1 or P2 licence on your tenant. | Optional |
UserAuthenticationMethod.Read.All | The MFA column on the Users tab | Optional |
- Click Grant admin consent for the permissions you added.
- In Cloud Ctrl, either select the existing Azure Entra App credential or enter the Tenant ID, Application (client) ID and client secret to create one, then click Connect.
Verified before it is saved
Connecting proves the credentials against the live directory first — the tenant, application and secret are confirmed by acquiring a token, and the directory's display name is shown as verified. A mistyped tenant ID, an unconsented app registration, or a directory that already has a licensing connection is rejected at connect time rather than discovered days later. Re-enter a secret at any time with Change Credential on the connection.
After connecting, the dialog reports a capability readback: which datasets are ready now and which will stay empty until the missing consent (or Entra P1/P2 licence) is in place. Anything missing is picked up by the next daily ingest — grant the consent in Entra ID and use Re-check now on the Licensing page to apply it within minutes.
Multiple directories
Each licensing connection covers one Entra directory, and a Cloud Ctrl tenant can hold several — for example one per customer directory whose licences you manage. Connecting another directory is the same flow: use Connect Licensing again on the Microsoft 365 connections page.
With more than one directory connected, the Licensing pages show a Cloud Account selector in the top-right corner. Its options are the names of the licensing cloud accounts (the same names as the connection cards under Settings → Cloud Connections → Microsoft 365), and the selection scopes every figure on the page to that directory. The choice is kept in the URL (?directory=) so a refresh or a shared link reopens the same view. Rename the connection card to give the selector a friendlier label; until then, connections provisioned as "Microsoft 365" are disambiguated with a short directory identifier.
Disconnecting
Deleting the licensing connection (the connection card under Settings → Cloud Connections → Microsoft 365) stops the daily ingest and deletes that directory's licensing data — SKU inventory, users, assignments, subscriptions and history. The linked Azure credential itself is untouched and remains available for Azure. You can reconnect at any time.
Overview
Summary tiles
| Tile | Meaning |
|---|---|
| Total SKUs | Distinct licence products in the directory, split into paid and trial, with an Active chip when every SKU is in a healthy state. |
| Licensed Users | Directory accounts holding at least one licence, against your total prepaid seats (products with effectively unlimited seats are excluded from that total). |
| Unlicensed Users | Directory accounts with no licence — the assign-candidate list. Shows the enabled-member count (accounts that could legitimately take a seat) and the guest count separately. |
| Unassigned Seats | Paid seats with nobody assigned. Flagged as Waste Risk when greater than zero, with the largest SKUs named underneath. |
| Indicative Cost | Estimated monthly cost of the licences you own, from the price map, in your display currency — with the reclaimable portion shown beneath it. |
Optimization recommendation
When you have unassigned seats and enabled users without a licence, a banner suggests assigning the seats you already pay for before buying more. If you have unlicensed users but no free seats, it says so plainly — assigning would mean purchasing — and if you have free seats and nobody to give them to, it tells you that too. The banner links straight to the Users tab filtered for unlicensed accounts.
SKU Inventory & Wastage Overview
One row per licence product, expandable for detail:
| Column | Meaning |
|---|---|
| Product / SKU | Display name with the SKU part number underneath. Unlimited products (for example some Entra add-ons) show consumed / unlimited rather than a seat pool. |
| Seats (consumed / prepaid) | Assigned seats against the seats you pay for, with the unassigned remainder called out. |
| Utilisation | Percentage of prepaid seats in use. Unused prepaid seats are the problem, so the bar runs red at the low end through amber to green at full utilisation. |
| Status | The licence's lifecycle state reported by the vendor (for example Enabled, Warning, Suspended), plus a trial chip where the entitlement is a trial rather than a purchase. |
| Inactivity breakdown | Four counters for the seats assigned to quiet accounts: inactive 30–60 days, 60–90 days, more than 90 days, and never signed in. Hover a counter to see which band it is; a non-zero Never count is highlighted. Rows with no assigned seats read No active assignments. |
| Reclaimable waste | The indicative monthly cost of the seats worth reclaiming in that SKU, or an unpriced chip when the SKU has no price in the map. |
| Subscriptions | How many subscriptions make up that SKU, the next lifecycle date, and a note when the purchase came via a partner. Reads no data when subscription facts cannot be read for any connected directory. |
| Monthly cost | Indicative monthly cost of the SKU, or an unpriced chip. |
Expanding a row adds the licence counts (enabled, consumed, available of prepaid), the Δ 7d available drift — how the number of available seats has changed over the last seven days, taken from daily snapshots — the indicative unit price with its basis and as-of date, the full subscription detail, and the reclaim candidate count including how many are disabled accounts.
The card footer states the basis of the figures: costs follow your configured price map, and lifecycle dates reflect the next state if the subscription is not renewed — not a guaranteed renewal date. It also totals the Total Reclaimable Opportunity across the estate.
Wastage bands
A seat is treated as a reclaim candidate when the account behind it is:
| Band | Meaning |
|---|---|
| Disabled | The account is disabled but still holds a licence — an immediate candidate. |
| Inactive 30–60 / 60–90 / 90+ days | The account's last sign-in was that long ago. |
| Never signed in | The account is older than 14 days with no sign-in recorded. |
Sign-in bands need AuditLog.Read.All and an Entra ID P1/P2 licence on your tenant. The last sign-in recorded is the last sign-in attempt, not only successful ones, which keeps the bands conservative — an account that is being used but failing to authenticate is not flagged as idle.
Where sign-in activity cannot be read, the bands cannot be evaluated at all. Seats and unassigned licences still render in full, but every assigned account falls into the Never signed in band — and a banner tells you so (see When data is unavailable). Treat the inactivity bands as meaningful only when that banner is absent. Licence-waste recommendations are stricter: without sign-in data they count only disabled accounts as waste, so an unreadable band never inflates a savings figure.
Users
Navigation: Licensing → Users
A paged matrix (250 accounts per page) of every directory user, licensed and unlicensed:
- Search by name or user principal name; filters for SKU, type (member or guest), licence state (licensed or unlicensed), account state (enabled or disabled) and MFA registration.
- User shows the name and UPN. Unlicensed accounts are muted and show no products, which makes the list a convenient assign-candidate review.
- Type distinguishes members from guests. A guest without a licence holds no paid seat, so guests are listed for access hygiene rather than cost.
- Products shows how many products the account holds; expand the row to list them by name.
- Account shows the directory account state; MFA shows registration status, or no data when the consent is not granted.
- Last sign-in shows the last successful sign-in date, or no data when sign-in activity cannot be read. This differs from the inactivity bands on the Overview, which use the last sign-in attempt — so an account repeatedly failing to authenticate can look recently signed in here while still counting as idle there.
Indicative costs
Every cost figure on these pages is indicative, and labelled as such:
- Figures come from a maintained price map of vendor list prices, each row carrying the source and an as-of date. The unit price and its basis are shown in the expanded SKU row.
- Prices are held in US dollars and converted server-side to your tenant's display currency.
- List price is not what you pay: negotiated, partner and discounted rates are not reflected. Treat the figures as a guide to the size of waste, not as an invoice.
- A SKU with no price in the map is shown with an unpriced chip and no savings figure — never an invented $0.
- Per-tenant price overrides are supported through Cloud Ctrl support; there is no self-service price editor.
Recommendations
Licence waste appears in the standard Recommendations engine, so it sits alongside your cloud savings and can be ticketed and tracked like any other finding. Each entry covers one SKU, for example:
12 licenses reclaimable (3 disabled, 6 inactive >90d, 3 never signed in) ≈ USD 7,128/mo indicative
- An entry is emitted only when the waste is worth at least two licences or at least US$50 per month in indicative cost.
- SKUs with no price in the map still appear, with no savings figure attached.
- Entries are re-evaluated daily; once the waste is cleared the entry disappears within about 30 hours.
- Nothing is ever revoked for you. The recommendation is a review aid — you make the change in your own tenant.
When data is unavailable
The pages state plainly what is missing rather than showing misleading zeros. The states you may see:
| State | Meaning | What to do |
|---|---|---|
| Not connected | No licensing connection is configured. | Connect Microsoft 365 from Settings → Cloud Connections. |
| Connection problem | The connection failed to authenticate on the last run — the client secret expired or was revoked, or the credential was deleted. | Rotate the secret in Entra ID, update the credential, then reconnect or use Change Credential. |
| Sign-in data unavailable — Entra ID licence required | The tenant has no active Entra ID P1/P2 entitlement, which Microsoft Graph requires for sign-in activity. | Assign an Entra ID P1 or P2 licence (trials count). Nothing to change in Cloud Ctrl. |
| Sign-in data unavailable — consent missing | The named Graph permission (usually AuditLog.Read.All) has not been admin-consented. | Grant consent on the app registration in Entra ID, then choose Re-check now. |
| Sign-in data unavailable | The cause is not yet known — typically a run that has not completed. | The next daily ingest resolves it; Re-check now re-runs it immediately. |
| MFA shows no data | UserAuthenticationMethod.Read.All has not been admin-consented. | Grant consent, then choose Re-check now. |
| Stale as of … chip | The last ingest ran a while ago. | The daily run refreshes it; Re-check now forces one now. |
Re-check now queues an immediate ingest so a freshly granted consent or licence is reflected within minutes instead of waiting for the next daily run. It appears in the sign-in banner itself, and queues a run for every connected directory, not only the one in view.
Where the cause is a missing Entra ID licence, the banner links out to the Entra Admin Center; where the cause is missing consent, it links to your connection settings.
Frequently asked questions
Are these the amounts we actually pay?
No. They are vendor list prices from the price map, each with an as-of date, converted to your display currency. Negotiated, partner and discounted pricing is not reflected. Per-tenant overrides can be applied through support.
Can Cloud Ctrl assign or revoke licences?
No. Licensing is deliberately read-only — Cloud Ctrl reads your licence estate and reports on it, and every change is made by you in your own tenant.
Why is a user marked "never signed in" when they signed in yesterday?
Sign-in activity requires AuditLog.Read.All and an Entra ID P1/P2 licence. Without both, no sign-in dates can be read at all, and every assigned account therefore falls into the Never signed in band — check for the sign-in banner on the page, then grant the consent or licence and choose Re-check now. Newly created accounts are also exempt from the band for their first 14 days, so a genuinely new account is not flagged on the day it is created.
Why does a SKU show "unpriced"?
That licence product is not in the price map, so Cloud Ctrl cannot estimate its cost. The seat counts remain accurate; only the cost and any resulting savings are withheld. Ask support to add the SKU to your price map.
Do licence costs appear in my cloud spend, budgets or Cost Explorer?
Not in this release. Indicative licence costs are shown on the Licensing pages only, so they never inflate or distort your metered cloud spend. Budgets, Custom Views and Cost Explorer continue to reflect billed cloud usage.
How much history is kept?
Daily per-SKU snapshots are retained for 180 days. That history powers the Δ 7d drift column and is the basis for any future alerting.