
License Sprawl: What Unmanaged M365 or Workspace Licensing Actually Costs
Somebody leaves the company, IT deactivates their laptop, and their Microsoft 365 or Google Workspace license quietly keeps billing every month because nobody owns the step of actually removing it. Multiply that by every departure, every seasonal contractor, and every "let's try this tier for a project" upgrade that never got downgraded, and most growing companies are paying full price for a meaningful slice of software nobody is using. It rarely shows up as a single bad decision. It shows up as a line item that grows a little every quarter until someone finally looks at it.
What License Sprawl Actually Looks Like
License sprawl is not one mistake. It is the accumulation of small, individually reasonable decisions that nobody ever circles back to clean up.
Offboarding gaps. An employee leaves, their account gets disabled for security reasons, and the license attached to that account keeps renewing because deactivation and license removal are treated as two separate steps, and only the first one has a clear owner.
Over-provisioned tiers. A handful of employees get upgraded to a premium tier for a project, a compliance requirement, or because "we might as well," and the upgrade outlives the reason for it by months or years.
Contractor and seasonal accounts. Temporary staff get full licenses provisioned quickly to get them working, and removing access at the end of the engagement falls lower on the priority list than granting it did.
Duplicate tools covering the same function. A team adopts a point solution for e-signature, file storage, or video conferencing that a Microsoft 365 or Google Workspace tier already includes, and both get paid for indefinitely because nobody audits for overlap.
Departmental purchasing with no central visibility. A manager adds licenses for a new hire or a new tool without IT ever seeing the transaction, so the person tracking the software budget is not the person who can see the full software inventory.
None of these individually look like a problem. Together, they are the reason most companies are paying for meaningfully more seats and more capability than anyone is actually using.
What the Data Says This Actually Costs
The numbers on this are consistent enough across independent research that they are worth taking seriously rather than treating as a rounding error.
Zylo's 2025 SaaS Management Index, which tracks spend and usage data across its customer base, found that 52.7% of purchased SaaS licenses go unused at any given time, and that mid-market companies in the 50 to 500 employee range manage an average of 291 separate SaaS applications while spending 4 to 8% of annual revenue on software. Gartner's research puts the broader estimate at roughly 30% of SaaS budgets going to unused licenses, duplicate tools, and shadow purchases that nobody centrally tracks.
To make that concrete: Microsoft 365 Business Premium currently lists at $22 per user per month on an annual commitment. For a 100-person company where 25% of licenses are unused or unnecessarily over-provisioned at any given time, that works out to roughly 25 seats paid for and never used, or about $6,600 a year, on a single platform. Add a duplicate e-signature tool, an unused project management seat tier, and a handful of premium add-ons nobody remembers approving, and the real number for a company that size is usually two to three times that before anyone has looked closely.
That figure does not include the harder-to-quantify cost: a growing SaaS footprint that nobody has a complete inventory of is also a growing attack surface, since every unused-but-still-active account is a credential that does not need to exist and could be compromised.
Where the Waste Actually Comes From
Most license sprawl traces back to a small number of structural gaps rather than individual carelessness, which is good news, because structural gaps are fixable with a process rather than a personality change.
| Root Cause | How It Shows Up | Fix |
|---|---|---|
| No offboarding checklist tied to licensing | Ex-employee accounts still billing months later | License removal as a required, tracked offboarding step |
| No quarterly usage review | Nobody notices seats sitting idle | Scheduled audit against actual login and activity data |
| Decentralized purchasing | IT doesn't know what departments have bought | Single system of record for all software spend |
| Default over-provisioning | Everyone gets the premium tier "to be safe" | Role-based tier assignment reviewed at hire and at renewal |
| No overlap check before buying new tools | Duplicate tools covering one function | Require an existing-stack check before approving new software |
The pattern across all five rows is the same: nobody owns the ongoing accuracy of the license inventory. Provisioning has a clear owner. Deprovisioning and right-sizing usually do not.
A Practical License Audit Framework
None of this requires specialized tooling to start fixing. It requires a defined process run on a fixed schedule rather than an occasional cleanup when someone notices the bill looks high.
- Pull a complete license inventory. Export every active license across Microsoft 365 or Google Workspace admin consoles, plus any other SaaS tools with per-seat billing. Most companies discover the first surprise here, since the actual list is usually longer than the list anyone was carrying around mentally.
- Cross-reference against active employees. Match every licensed account against current headcount. Any license attached to someone no longer with the company gets flagged for immediate removal, not scheduled for "next cleanup."
- Check actual usage, not just active status. The Microsoft 365 admin center's Active Users report shows last sign-in date and per-service activity, including whether a licensed user has actually opened Exchange, Teams, or SharePoint recently. Google Workspace's Admin console reports the equivalent through its Apps usage and Account activity views. Either platform can produce this data in a few minutes; the step most companies skip is actually pulling it and cross-referencing it against the license list, rather than assuming an active account means an active user. An account can be technically active and still be a candidate for downgrade or removal if usage has been near zero for 60 to 90 days.
- Right-size tiers against actual need. Compare each user's assigned tier against what their role actually requires. A premium tier assigned during a project six months ago is worth questioning if that project ended.
- Look for functional overlap. List what each paid tool actually does and check it against what your core productivity suite already includes. Duplicate capability is one of the more expensive and most avoidable categories of waste.
- Assign an owner and a recurring date. A one-time audit finds the current backlog of waste. A named owner and a quarterly recurrence is what keeps the backlog from rebuilding six months later.
- Tie license removal to the offboarding checklist directly. The single highest-leverage fix on this list is making license deprovisioning a required, tracked step in the same process that disables an employee's account, not a separate task someone might get to.
Companies that run this audit for the first time typically find a meaningful percentage of their license spend recoverable immediately, concentrated in offboarding gaps and forgotten upgrades rather than anything more complicated.
Why This Keeps Happening Even at Well-Run Companies
License sprawl is not usually a sign of a poorly run IT function. It is a sign of an IT function stretched across help desk tickets, device management, and day-to-day support with no standing time carved out for the kind of recurring administrative review that catches this early. NIST's guidance on IT asset management treats a complete, current asset inventory as a foundational security control precisely because it tends to erode without deliberate maintenance, not because anyone is being negligent.
This is also where the model of support matters more than the size of the IT budget. A managed IT arrangement built around ticket response and patching does not automatically include a recurring review of license spend and usage, because that work is administrative and easy to defer when the phone is ringing with more urgent requests. It only gets done consistently when someone is explicitly accountable for it on a fixed schedule, separate from reactive support.
That is the specific gap Foundation IT is built to close. Alongside device management, proactive monitoring, and help desk support, Foundation IT includes a quarterly Technology Health Review where license and subscription spend gets checked against actual usage as a standing part of the conversation, not an occasional favor. It is the same principle behind Elevaire's broader positioning: an existing managed IT provider keeps the day-to-day running, and Elevaire makes sure someone is actually looking at where the technology budget is going and whether it lines up with what the business needs.
Frequently Asked Questions
How much should we expect to recover from a license audit?
It varies by how long it has been since the last review, but recovering 15 to 25% of current SaaS and Microsoft 365 or Google Workspace spend on the first pass is common based on the independent usage data cited above. The number is usually concentrated in a small number of categories: former employees, over-provisioned tiers, and duplicate tools, rather than spread evenly across every user.
Does a license audit require replacing our existing IT provider or MSP?
No. A license and subscription audit is administrative and complements whatever managed IT support is already in place. Elevaire's Foundation IT service is designed to run alongside an existing IT setup or as the managed layer itself, with the quarterly Technology Health Review adding the recurring oversight that day-to-day support does not typically include on its own.
How often should a license audit actually happen?
Quarterly is the practical minimum for a company with any regular hiring or turnover. A company with low headcount change and a small software footprint can sometimes stretch to twice a year, but waiting longer than that reliably lets waste rebuild to where it was before the last cleanup.
What's the difference between a license audit and just checking the monthly bill?
A monthly bill shows what you are being charged. It does not show who is actually using what you are being charged for. The audit requires cross-referencing licenses against current employees and actual usage data, which is a different exercise than reviewing a total spend figure and assuming it reflects real need.
How do we get started if we've never done this before?
Start with the inventory step: export every active license across your core platforms and list every other tool billed per seat. That single list, cross-referenced against current headcount, usually surfaces the most obvious waste within an hour. From there, a quarterly cadence and a named owner are what keep it from becoming a backlog again.
About Elevaire Systems
Elevaire Systems provides fractional Chief Information Officer (CIO), Chief Technology Officer (CTO), and Chief Information Security Officer (CISO) leadership, along with infrastructure modernization, intelligent automation, and compliance strategy for growing organizations.
Ready to Put This Into Practice?
Schedule a free consultation and let's talk through what this means for your organization specifically.
Schedule a Free Consultation