The license audit: the security budget you already have

The cheapest security budget increase available to a small organization is the money it's already wasting. Before you ask leadership for a dollar, run this audit. It rarely comes back empty — and what it finds often funds the next thing you were going to ask for.

There's a reason this works so reliably: subscription spend is invisible work's financial twin. Nobody decided to waste it; it accumulated one reasonable purchase at a time, and nothing in the monthly routine ever makes it visible again. You can't cut what you can't see. The audit below is just the act of making it visible.

Step 1: Ghost licenses (and ghost accounts)

Pull a list of all licensed users and compare it against your HR roster. At most organizations that have never done this, somewhere between 5% and 15% of paid licenses belong to people who left. That's the money problem.

The bigger problem: many of those accounts are still enabled. A departed employee's active account is a standing credential waiting to be phished, with nobody watching the mailbox for alerts. This single check is simultaneously a cost recovery and a security control — which makes it the perfect first finding to show leadership, because it pays for the time it took.

Fix the process, not just the snapshot: the audit found symptoms; the disease is an offboarding process that doesn't include "disable account, reclaim license, transfer data" as same-day steps. Write that checklist now.

Step 2: Duplicate capability

Small organizations accumulate tools the way kitchens accumulate gadgets — each purchase made sense at the time. If you're on Microsoft 365 Business Premium or E5, check whether you're separately paying for:

  • Third-party antivirus/EDR while licensed for Defender for Business / Defender for Endpoint
  • Third-party MDM while licensed for Intune
  • Third-party email filtering while licensed for Defender for Office 365
  • Standalone password/identity tools overlapping Entra ID features you already hold

Sometimes the third-party tool is genuinely better and worth keeping — that's a fine outcome, but make it a decision, not an accident of purchase history. List every duplicate, pick one of each, and write down why.

Step 3: Tier mismatch

The two classic M365 mistakes run in opposite directions:

  • Under-buying: running standard Business or E3 licenses, then bolting on third-party security tools that Business Premium would have included for a few dollars more per user. For organizations under 300 seats, Business Premium is usually the best security-per-dollar SKU Microsoft sells.
  • Over-buying: putting E5 on every seat because the security features sounded good in the demo. Licensing is per-user — mix tiers. Frontline staff who use email and one app don't need what your finance team needs.

Run the math per role, not per company. (Prices change often enough that I won't print them here — check current pricing, and check it again at renewal. Your reseller's quote is a starting position, not a price.)

Step 4: Shelfware — the features you own but never enabled

This is the audit's best finding, because the remediation is free. It's common to find tenants paying for security features that have never been switched on: Conditional Access policies sitting unused, Intune licensed but no devices enrolled, Defender for Office running on default policies, audit retention never configured.

Reframe for leadership: "We are paying for security capability we don't use. My next project costs nothing but my time." That sentence has worked in more budget conversations than anything else I've tried — and the follow-up work is mapped out in the M365 baseline.

One caution before the shopping reflex kicks back in: money spent away from the constraint just buys a feeling of progress. At most small organizations the thing actually limiting security isn't the absence of another tool — it's identity hygiene, untested backups, and unowned alerts. A new dashboard added on top of those is an improvement everywhere except where it matters.

Make it boring and recurring

A one-time audit decays in about two quarters. Put a one-hour license review on the calendar quarterly: licensed users vs. roster, sign-ins on inactive accounts, new duplicate subscriptions, renewal dates coming in the next 180 days. Tie it to your joiner/leaver process so the gap never reopens.

And keep the running total of what you've recovered. That number is your credibility in every future budget conversation: you're the person who funds security by eliminating waste first and asking for money second. There aren't many of those, and leadership remembers them.