Software Licence Compliance: Surviving a Microsoft True-Up

Software licence compliance means you hold a valid, paid licence for every copy of every program your business runs. A vendor “true-up” or audit is when Microsoft, Adobe, Autodesk or another publisher checks whether what you’ve deployed matches what you’ve bought. Get it wrong and the bill arrives at list price.

What a true-up and an audit actually are

The two terms get used interchangeably, but they’re not the same thing. A true-up is the reconciliation built into a volume licensing agreement. If you signed a Microsoft Enterprise Agreement or similar, you committed to a baseline number of licences and agreed to “true up” annually for anything extra you deployed during the year. It’s routine accounting: you report the additional seats, you pay for them, the agreement rolls on. Where it bites is when nobody has tracked the additions and the annual reconciliation surfaces twelve months of unlicensed growth at once.

An audit is the adversarial version. The vendor, or a third party acting for them, exercises the audit clause in your licensing contract and asks you to prove compliance. They’ll count installs against entitlements and present you with a “compliance gap”. A right to audit is written into almost every software agreement you’ve ever clicked through. Microsoft, Adobe and Autodesk all do it, and so do Oracle, SAP and IBM, who are notoriously aggressive about it.

Why vendors audit

Because it pays. Software is one of the few products where the customer self-reports how much they’re using, and self-reporting drifts. In any business of reasonable size, deployment creeps past entitlement as staff are added, machines are reimaged and VMs are spun up. An audit converts that drift into revenue, usually at full list price with no discount.

The triggers are predictable: a sharp drop in renewal spend, a merger or acquisition, switching away from a vendor’s product, a jump in headcount, or simply the random rotation a publisher runs through its mid-market customers. Subscription licensing has made it easier still: when your software phones home, the vendor already knows who’s using what before they send a letter.

How SMEs end up non-compliant

Almost no one sets out to pirate software. Non-compliance is nearly always sloppiness, not theft, and it accumulates quietly. These are the patterns we see most across Melbourne SMEs.

  • Over-deployment. You bought 40 Microsoft 365 licences, you’ve grown to 52 staff, and the extra dozen are using the platform on borrowed credentials or seats that were never purchased. The headcount moved; the licence count didn’t.
  • Wrong licence type for the use. Running software licensed for development on a live production server, or using education and not-for-profit pricing in a commercial entity that no longer qualifies.
  • Mixing Business and Enterprise plans. Microsoft 365 Business plans (Basic, Standard, Premium) are capped at 300 seats. Plenty of growing firms blow past 300 users still stacking Business licences, when they should have moved to Enterprise (E3/E5) plans.
  • Client Access Licences (CALs). On-premises Windows Server and SQL Server still need a CAL for every user or device that connects. CALs are the most commonly under-counted licence in Australian SMEs, because the server “just works” whether or not the paperwork exists.
  • Unlicensed virtual machines. Spinning up a new VM from a template often clones a Windows Server or SQL install without anyone buying the licence to cover it.
  • Shared accounts. Three people on reception sharing one Adobe Acrobat or Microsoft 365 login. Named-user subscriptions are licensed per person, not per desk, and sharing breaches the terms even though it feels economical.

The real cost of getting it wrong

When a true-up or audit finds a gap, you don’t buy the shortfall at the keen price your reseller would normally quote. You typically pay back-charges for the period you were under-licensed, the licences at full list price, and in audit scenarios potentially penalties or the vendor’s audit costs on top. There’s no negotiating leverage, because you’ve been caught short and the clock is running.

The other cost is the rushed purchase. Faced with a deadline, businesses buy whatever the vendor puts in front of them, at list, often more than they need. A manufacturer in Dandenong we work with discovered during a routine Autodesk reconciliation that several engineering machines were running design software well beyond the seats they’d paid for. The catch-up purchase, under time pressure and at list, cost several times what an orderly renewal would have. The licences were genuinely needed; the panic premium wasn’t.

How to stay compliant

Compliance isn’t a once-a-year scramble. It’s an ongoing discipline, and most of it is unglamorous record-keeping that pays for itself the first time a letter lands.

Maintain a licence register

The foundation is knowing what you own. A licence register is a single, maintained record of every software product you’ve bought: publisher, product and edition, licence type (subscription or perpetual), quantity, purchase date and proof of purchase, and any agreement number. Most SMEs don’t have one, which is exactly why audits hurt. When you can produce entitlement evidence on demand, an audit becomes an afternoon’s work instead of a crisis. This sits inside broader IT asset management, the same discipline that tracks your hardware, warranties and end-of-life dates.

Reconcile assigned versus purchased seats

For Microsoft 365, the Microsoft 365 admin centre tells you exactly how many licences you’ve purchased against how many are assigned. Under Billing > Licences, you see each product, the seats you’re paying for and the seats in use. Reconciling this regularly catches both problems at once: seats assigned beyond what you’ve bought (a compliance gap) and seats you’re paying for that nobody uses (wasted spend). Do it monthly and neither surprise builds up.

Right-size unused licences

This is where compliance work actually saves money. The same register that protects you in an audit usually reveals seats you’re paying for and not using: the staff member who left three months ago whose Microsoft 365 and Adobe licences are still billing, the premium plan assigned to someone who needs the basic one, the perpetual product everyone forgot they retired. Reclaiming those licences, or cancelling them at renewal, frequently funds the cost of the housekeeping. Compliance and cost control are the same job done properly.

Understand subscription versus perpetual

The two licensing models carry different risks, and most environments are now a mix of both.

SubscriptionPerpetual
What you’re paying forThe right to use the software for a set term (monthly/annual)The right to use a specific version indefinitely, bought once
ExamplesMicrosoft 365, Adobe Creative Cloud, Autodesk subscriptionsOlder Office perpetual, on-prem Windows/SQL Server, legacy Acrobat
Compliance riskOver-assigning seats; the vendor can see live usageRunning more installs or versions than the licence allows; CALs untracked
If you stop payingThe software stops workingYou keep using the version you own, but get no updates or support

Autodesk and Adobe have moved almost entirely to subscription. Microsoft offers both, and a typical Melbourne SME runs Microsoft 365 subscriptions alongside perpetual on-premises Windows Server and its CALs. Knowing which model each product sits under tells you where your audit exposure actually lies.

SaaS sprawl makes this harder

Licence compliance used to mean counting installs on machines you owned. Now most software is bought as a subscription, often on a corporate card by whoever needed it, and the result is SaaS sprawl: dozens of overlapping tools, nobody sure who’s paying for what, and licences quietly renewing for people who left. A law firm in Hawthorn we onboarded was running three separate PDF and e-signature subscriptions across different teams, none fully used. You can’t licence-manage software you don’t know you have. The fix is the same register and the same reconciliation, applied to every subscription.

What to do if you receive an audit or true-up notice

Don’t panic, and don’t ignore it. The worst outcomes come from businesses that either go quiet, hoping it’ll pass, or that rush to admit a gap before they’ve established whether one exists.

  1. Read the agreement first. Find the audit or verification clause being relied on, and check what it actually entitles the vendor to: notice periods, scope and how data is gathered.
  2. Reconcile your own position before you respond. Run the numbers internally, deployments against entitlements, so you walk in knowing where you stand rather than learning it from the vendor. Your licence register is your evidence; don’t volunteer deployment data you haven’t verified.
  3. Bring in your licensing partner. Your reseller or MSP has dealt with these before and can challenge an over-stated gap, identify licences you already hold that the vendor missed, and negotiate the commercial close rather than accepting the first number.
  4. Treat the deadline as real but not immovable. Reasonable engagement buys time. A measured response almost always lands better than a fire-sale purchase.

Where the MSP and CSP partner fit

Most SMEs don’t buy Microsoft licences direct; they buy through a Cloud Solution Provider (CSP), and that’s usually their MSP. A good CSP partner does more than process the order. They right-size your seats at every renewal, flag when you’ve crossed a threshold like the 300-seat Business cap, keep the licence register current, and stand beside you if an audit ever lands. As a Melbourne MSP founded in 2014 with 13 Australian-employed engineers, TechAssist runs licence reconciliation as part of ongoing Microsoft 365 management, not as a billable scramble when the renewal looms. If you’ve never been sure your setup is right-sized, our Microsoft 365 support covers exactly this housekeeping.

Frequently asked questions

How often do software vendors actually audit small businesses?

Less often than large enterprises, but it does happen, and subscription products are effectively audited continuously because usage data flows back to the vendor automatically. For Microsoft 365 and similar SaaS, the bigger risk isn’t a formal audit but the annual true-up or renewal where over-assigned seats get reconciled at once. Perpetual on-premises software (Windows Server, SQL Server, older Office and Adobe) is where traditional formal audits are still most likely.

What’s the difference between a true-up and a fine?

A true-up is the routine process of paying for extra licences you deployed during the year under a volume agreement, no penalty, just the cost of the seats. A fine or penalty comes from an audit that finds you running software with no valid licence at all, where you may pay back-charges, list-price licences and potentially the vendor’s costs. The first is housekeeping; the second is what good housekeeping prevents.

Do we still need CALs if we’re moving to the cloud?

If you still run any on-premises Windows Server or SQL Server, yes, those CALs remain a live obligation regardless of how much else has moved to the cloud. Once a workload is fully migrated to a cloud service like Microsoft 365 or Azure, the CAL requirement for that service usually falls away, because the licensing is built into the subscription. The trap is a hybrid setup where the old server still runs and everyone assumes the cloud move dealt with the licensing. It didn’t.

Getting ahead of it

Software licence compliance is far cheaper to maintain than to fix under audit pressure. A current licence register, a monthly reconciliation in the Microsoft 365 admin centre, and a CSP partner who right-sizes at renewal will keep you compliant and usually trim your spend. If you’re not confident what you own versus what you’re running, that’s worth sorting before a true-up letter forces the issue. Get in touch with our team and we’ll audit your licensing before a vendor does.

SaaS sprawl is the uncontrolled spread of software-as-a-service subscriptions across a business — the dozens of cloud apps staff sign up for that nobody centrally tracks, approves or pays for through one channel. Most Melbourne SMEs we audit are running 30 to 60 of them, and the finance team can account for fewer than half.

The problem is rarely one big bill. It is a hundred small ones, plus a security exposure nobody is watching. This post explains how sprawl happens, what it actually costs you, and how to run a proper audit — using the tools you already own in Microsoft 365 — so you can see every app, kill the duplicates and put a gate on the front door.

What SaaS sprawl is and how it happens

SaaS sprawl is what you get when buying software becomes frictionless. A decade ago, new software meant a purchase order, an install and an IT ticket. Now any staff member with a corporate card and an email address can have a new tool running before lunch. That convenience is genuinely useful — and it is exactly why the count gets out of hand.

It accumulates through a few predictable channels:

  • Departments self-provisioning. Marketing signs up for Canva, a scheduling tool and three analytics platforms. Sales buys its own CRM add-ons. Each decision is reasonable in isolation; nobody sees the total.
  • Individuals on cards. One person expenses a $15-a-month transcription app, another a PDF editor, another a project board. They are small enough to slip through expense approval without a second look.
  • Free trials that convert. A trial gets set up for a one-off task, the card is entered to “unlock the export”, and twelve months later it is still billing because nobody cancelled it.
  • Duplicate tools. Three teams solve the same problem three different ways — you end up paying for two file-sharing platforms, two e-signature tools and a video conferencing app you already get free with Microsoft 365.

None of this is anyone behaving badly. It is the natural drift of a business where buying software is easier than asking permission.

What it actually costs you

The wasted subscription spend is the obvious cost, and it is real — paying twice for the same capability, paying for seats that left with departed staff, paying for trials that quietly converted. But the spend is usually the smallest part of the bill.

Security risk from unmanaged apps

Every app a staff member connects to your data is a door into it. When someone signs in to a third-party tool “with Microsoft” or “with Google”, they often grant that app standing permission to read mail, files or contacts — an OAuth grant that persists long after they have forgotten the app exists. You cannot defend what you cannot see, and an unmanaged app sitting on a live token to your SharePoint is exactly the kind of thing the Australian Cyber Security Centre (ACSC) warns about in its cloud guidance.

Orphaned accounts and offboarding gaps

This is the one that bites hardest. When a staff member leaves, you disable their Microsoft 365 account — but if they signed up directly to a dozen other tools with their work email and a separate password, those accounts keep working. A former employee can still log in to the marketing platform, the file-sharing app or the customer database weeks after their last day, because that login never touched your central identity. Offboarding is only as complete as your app inventory, and most inventories do not exist.

Data scattered everywhere

Sprawl means your business data ends up spread across systems you do not control and cannot search. Customer details in a trial CRM, contracts in a personal e-signature account, project files in someone’s individual cloud drive. When you need to respond to a privacy request, prove what data you hold, or recover after an incident, you cannot — because you do not know where it all is. Under the Notifiable Data Breaches scheme, “we did not know that app held customer data” is not a defence the Office of the Australian Information Commissioner (OAIC) will accept.

How to run a SaaS audit

You do not need a fancy SaaS-management platform to start. Four sources, cross-referenced, will surface almost everything.

1. Expense and card review

Pull twelve months of card statements and accounts-payable records and flag every recurring software charge. Look specifically for small monthly amounts, USD billing, and anything from a name you do not recognise. Twelve months matters because annual subscriptions only show up once. This is the fastest way to find spend nobody approved.

2. Entra ID enterprise apps and OAuth grants

This is the technical heart of the audit and the bit most businesses skip. In the Microsoft Entra admin centre, the Enterprise applications blade lists every third-party app that has been granted access to your tenant — every “sign in with Microsoft” connection your staff have ever made. Each one shows the permissions it holds and who consented. You will almost certainly find apps nobody can name, with read access to mail or files, that should have been revoked long ago. If you want the wider context on how this identity layer works, we have written a full piece on Microsoft 365 support in Melbourne.

3. Browser and SSO sign-in logs

Entra ID sign-in logs show which applications staff are authenticating to and how often. Cross-reference that against your enterprise apps list. If your business uses a single sign-on portal, its activity log is gold — it tells you what people actually use versus what they signed up for and abandoned. Low or zero usage is your cancellation shortlist.

4. Build a simple inventory

Put it all in one spreadsheet: app name, owner, what data it touches, monthly cost, billing channel, who has access, and whether it uses SSO. That single document is more than most SMEs have ever had, and it becomes the working register for everything that follows.

Rationalising what you find

An audit that produces a list and no decisions is just paperwork. The point is to cut. A construction firm in Box Hill we work with came out of this exercise running 41 SaaS tools; we got them to 23, and roughly $1,900 a month in spend disappeared along the way — before counting the risk we closed off.

Three moves do most of the work:

  • Consolidate onto Microsoft 365 where it already does the job. If you pay for Microsoft 365, you are already paying for video meetings (Teams), file sharing (SharePoint and OneDrive), forms, basic e-signature, task boards and a great deal more. A surprising share of the third-party tools we find are duplicating capability the business already owns. Killing those is free money.
  • Kill the duplicates. Where two tools do the same thing, pick one, migrate, and cancel the other. Two e-signature platforms is one too many.
  • Enforce SSO on what survives. Every retained app that can sit behind Entra ID single sign-on should. That gives you one place to grant access, one place to cut it when someone leaves, and one set of credentials staff are not reinventing weakly across a dozen logins.

Ongoing governance and a procurement gate

Sprawl regrows the moment you stop watching. The fix is not a one-off purge but a light, durable process.

Put a procurement gate on new software: any new SaaS tool gets a quick sign-off that checks whether the business already owns something equivalent, what data the tool will touch, and whether it supports SSO. This does not need to be bureaucratic — a two-minute conversation and a line in the inventory is enough. The aim is simply that no app enters the business completely unseen.

Then review the inventory quarterly: what is unused, what is duplicated, what is up for renewal, and which OAuth grants in Entra ID can be revoked. This is the sort of standing discipline a virtual CIO brings to a business that has no internal IT leadership — turning a chaotic app estate into a managed one.

The security angle: OAuth consent and Conditional Access

Two Microsoft 365 controls do most of the heavy lifting on the security side of sprawl.

App consent settings. By default, many tenants let any user grant a third-party app access to their own data. Tightening this so that risky permissions require admin approval stops the next unvetted app from quietly attaching itself to your tenant. It is a single configuration change with a large payoff, and it is one of the first things we set on a managed tenant.

Conditional Access. Policies that require a managed device or block legacy authentication shrink the ways a leaked credential or rogue app can be abused. Identity is the perimeter now, and Conditional Access is where you enforce it — we cover the detail in our guide to Conditional Access policies in Microsoft 365. Together with tightened app consent, these controls mean sprawl stops being a free-for-all and starts being something you govern.

TechAssist is a Melbourne-based MSP, founded in 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma. SaaS rationalisation and Entra ID hardening are standard work for our managed clients — and because we bill per user at a fixed monthly rate, this kind of clean-up is in scope rather than a surprise project invoice.

Frequently asked questions

How many SaaS apps does a typical small business actually use?

More than they think. Across Melbourne SMEs we audit, 30 to 60 distinct cloud applications is common, and the finance team can usually account for fewer than half because so many are bought on individual cards and through free trials that converted.

Can I find shadow apps without buying special software?

Yes. The Entra ID enterprise applications list and sign-in logs, cross-referenced against twelve months of card and accounts-payable records, will surface the overwhelming majority. Dedicated SaaS-management platforms add automation and continuous discovery, but you can run a thorough first audit with the tools you already own.

What is the single biggest risk from SaaS sprawl?

Offboarding gaps. When staff sign up to tools directly with a separate password, disabling their Microsoft 365 account does not close those accounts. A departed employee retaining access to a customer database or file-sharing app weeks after leaving is the exposure we see most, and it is invisible without an inventory.

How do I stop sprawl coming back after an audit?

A procurement gate plus a quarterly review. New tools get a quick sign-off that checks for existing capability and SSO support; every quarter you re-check the inventory for unused, duplicated and renewing apps and revoke stale OAuth grants in Entra ID. The process is light, but it has to be standing.

Talk to us about your app estate

If you have no idea how many SaaS tools your business is running — or what they can see — that is the normal starting point, not an embarrassing one. Our managed IT services team can run the audit, rationalise the estate onto Microsoft 365 where it makes sense, and put governance around what is left. Get in touch and we will tell you plainly what we find.

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon — just a clear-eyed look at where you stand and what's possible.