A Disabled Account Keeps Its License Until Somebody Notices

Conversational FinOps license optimization in Microsoft 365, run and verified with Sia.

You provision the license the day someone joins. Business Premium, assigned, done.

Eight months later the role changes, or the person leaves. The offboarding ticket disables sign-in, revokes the badge, closes out the laptop request. The license doesn't come up, because it isn't really an offboarding step. It's a licensing step, and that lives on a different tab, closed out by someone else, on a different day, if at all.

So it just sits there. Assigned to an account that will never sign in again, still counted against however many seats you're paying for.

IT admins are careful about the steps that throw an error when they get skipped. Disabling an account doesn't throw one for the license still attached to it. Microsoft 365 doesn't flag it, doesn't email anyone, doesn't do anything. It just keeps counting the seat as used.

The subscription nobody's watching

Every account holds a license from the day it's created, and every account that goes quiet keeps holding it, because nothing forces the two events to happen together.

Offboarding an employee. The ticket disables the account and closes. Whether the license comes back to the pool depends on whether whoever closed the ticket also remembered to open the licensing tab, which is usually a different person's job.

Provisioning ahead of a start date. Licensing the account early so everything's ready on day one feels responsible. If the start date slips two weeks, or the hire falls through entirely, the license sits idle the whole time, same as if the person had never shown up.

Reconciling once a year, or whenever finance asks. Somebody exports the user list, sorts by last sign-in date, and checks it against the license assignment list by hand, one row at a time. By the time that spreadsheet is done, a few more accounts have gone quiet and aren't in it.

Renewing on a number nobody fully trusts. The renewal conversation happens against whatever consumption figure sits in the last report pulled, not what's actually being used the week the contract is up for review.

None of this is hard. None of it needs a person to notice on purpose, because nothing in the tenant tells you on its own that a license is going to waste. It just keeps billing until somebody happens to go looking.

What we asked Sia to do

Here's that same problem, run against a live Microsoft 365 tenant with 25 Business Premium licenses, four of them assigned. Before running anything, a quick look at two of those four accounts: Raza's showed as disabled, sign-in blocked. Sunil Gupta's was enabled, but had never signed in, not once since it was created.

That's two accounts flagged by eye. The instruction handed to Sia, typed into the Sia CLI, asked for all of them:

"Optimize our corporate Microsoft 365 license pool. Scan the tenant and locate all users holding a Microsoft 365 Business Premium license who are either marked as disabled or have never logged in since creation. Strip their premium license and reclaim it back to the active pool."

Sia broke that into a plan: identify the Business Premium license, scan every user holding one, identify the accounts matching the criteria, strip the license from each, and verify the reclamation actually went through. Then it ran all five steps.

It came back with three accounts, not two. Raza's, disabled, as expected. Sunil Gupta's, never signed in, as expected. And a third, Mohit P's, also never signed in since creation, one that hadn't come up before the scan started. The eyeball check ahead of time had caught two out of three. The scan caught all of them.

A fourth account, Suraj's, kept its license. Active, signed in two days earlier. Sia left it alone.

Before the run: 25 licenses, 4 assigned, 21 available. After: 24 available, one user left holding a Business Premium license. Checked directly in the Microsoft 365 admin center, on the licenses page, where four assigned users had been listed, there was now one.

The same pattern covers the checks that didn't run in this walkthrough. Ask for the same scan across every license SKU in the tenant, not just Business Premium. Done. Ask for it to run again before next quarter's renewal instead of once a year. Done.

Watch it happen

The full scan and reclaim sequence above, run and verified live in the Microsoft 365 admin center. 

Before Sia, with Sia

Before Sia: a disabled account keeps its license until the next audit happens to catch it, whenever that is. With Sia: ask, and the license is back in the pool the same day.

Before Sia: finding unused licenses means exporting a report and checking sign-in dates against assignments by hand, one row at a time. With Sia: one sentence, and the reclaimed licenses come back with names attached, verified.

Before Sia: a delayed hire's license sits idle for weeks because checking for it isn't anyone's specific job. With Sia: the same scan that catches disabled accounts catches these too, without being asked separately.

Before Sia: renewal negotiations run on whatever consumption number is sitting in last quarter's spreadsheet. With Sia: the number is current, checked minutes before the call, not months before it.

Before Sia: finding out at the annual audit that several seats had been sitting empty for most of the year. With Sia: finding out this afternoon, and having them back before the meeting ends.

What Sia actually touches

Sia works directly against Microsoft 365 licensing: the tenant's license pool and consumption count, per-user assignment, account status (enabled, disabled, sign-in blocked), and last sign-in date. This walkthrough covered Business Premium, but the same scan runs against any SKU assigned in the tenant, E3, E5, or add-on licenses, whatever's actually in use.

Stripping a license changes what a real account can do, so it runs through the same governance that lets Sia touch identity and access anywhere in production: a mutation gate with three verdicts, allow, require approval, or block, destructive operations blocked outright, and every action written to an append-only, HMAC-signed audit log that exports with its signatures intact. When finance asks which licenses got reclaimed this quarter and why, the answer is a query against a signed record, not somebody's memory of who ran the scan and when.

This doesn't have to sit only with IT

None of this needs an IT admin exporting reports on a schedule. A FinOps or finance lead can ask Sia directly what the tenant's actually paying for against what's actually being used, no ticket filed, no report requested and waited on. A department manager could ask the same question scoped to just their own team's licenses. Ask Sia to reclaim a license from a department outside that scope, and it won't. Access control didn't go away here either: Sia runs inside the role-based scope you set, so the permission model moves from a person with admin rights doing this by hand to an agent acting inside a policy you defined.

It's the same Sia whether the request comes in through the command line, the web, or the desktop app. The surface is just the door.

What this actually changes

Licenses stop quietly outliving the accounts they're attached to. Renewal conversations run on a number somebody actually checked this week, not a report from last quarter. Offboarding and license reclamation can be the same instruction instead of two separate tickets, only one of which reliably gets filed. And finding out how much you're overpaying stops requiring a spreadsheet and an afternoon.

Nobody sets out to keep paying for seats nobody's using. It just happens quietly, one closed ticket at a time, until somebody asks. Now somebody can ask any day of the week.

Availability

License optimization runs on the Microsoft 365 integration that is in Sia now, across the Sia CLI, the Sia Desktop App, and the web. We deliver Sia as part of the Scogo platform to enterprise customers, so there is no public download.

If your tenant has more licenses assigned than people actually using them, and finding out exactly how many takes a spreadsheet and an afternoon, we want to put Sia in front of it. Start with a pilot at scogo.ai/request-demo.

Autonomous where it is safe, governed where it matters, on the record everywhere.


Written by

Karan Singh

Co-founder & CTO

Published on

Share