Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Somewhere in your client list, someone's using a license nobody paid for. You'll find out from the vendor or from your own audit, and the second one is a lot cheaper. Here's how to run a software license audit, handle the letter if it lands first, and turn the checks into paid work.

TL;DR

  • Definition. A software license audit checks every installed or assigned license against what the organization legally owns.
  • Frequency. Flexera's 2026 report says 48% of organizations were audited in the past year.
  • Penalty. Under Microsoft's customer agreement, 5% or more unlicensed use means 125% pricing plus audit costs.
  • Clock. Autodesk gives 15 days to respond, Microsoft 30 days' notice, Oracle 45.
  • Opportunity. An MSP that audits first saves the client the penalty and gets a billable service.

What Is a Software License Audit?

A software license audit checks every piece of software installed, assigned or used in an organization against the licenses it owns. A vendor can run it, usually through a third-party auditor, or you can run it on yourself. The output is a gap: what you use without a license, and what you pay for and don't use.

Vendors don't always call it an audit. A "license review," a "SAM engagement" or a friendly spreadsheet request from Adobe or Oracle can turn contractual fast, so treat any of them as the start of one.

Flexera's 2026 report (512 respondents, June 2026) found 48% of organizations were audited in the last year, yet only 36% have full visibility of their IT estate. Microsoft audits most often. Oracle's share jumped from 24% to 38% in a year.

Why Audit Letters Land on MSP Desks Now

The last 18 months have been busy. In May 2025, Broadcom sent cease-and-desist letters to VMware perpetual-license holders whose support had lapsed. The letters told them to remove every patch installed after support ended and warned of audits. Dean Colpitts, CTO of Canadian MSP Members IT Group, said one of his clients got its letter six days after its support contract expired.

The lawsuits followed. VMware sued Siemens in March 2025 over roughly 23,000 US deployments, per Network World's timeline. Tesco has a UK High Court claim of at least £100M against Broadcom, VMware and Computacenter. Somewhere, a Broadcom account manager is having a great quarter.

Then Broadcom went further. Its June 2026 VMware Cloud Foundation terms require a compliance report every 180 days, and if you miss one, management features get degraded and support is suspended. Broadcom has built the audit into the product.

Oracle is on a similar path with Java. Its price list charges $15 per employee per month for organizations under 1,000 staff, and "employee" counts everyone on payroll, not just people running Java. A Dimensional Research survey reported by The Register found 73% of Oracle Java users had been audited in three years. The survey was commissioned by Azul, which sells a Java alternative, so read it with that in mind.

The MSP angle shows up in the details. Vendor telemetry doesn't care whose laptop is running the software. In January 2026, Autodesk contacted an MSP's client with a list of the MSP's own staff usernames, software versions and days of use, then asked the client for the MSP's contact details.

The comments add more: a fully licensed shop flagged after a domain migration left licenses tied to old accounts, and an MSP that paid Malwarebytes after techs ran the free version on client machines. Your tooling habits end up in your client's audit.

What Triggers a Software License Compliance Audit?

Vendors rarely pick targets at random. A software license compliance audit usually follows a signal the vendor can see from its side of the contract. Knowing the signals tells you where to look first.

TriggerWhat the vendor seesWhat to check first
Renewal or true-upYour counts versus last year'sHeadcount growth, new sites, new servers
Support lapses or downgradesA customer still running the product without payingPatches installed after the support end date (Broadcom's letter targeted exactly this)
Merger, acquisition or new legal entityLicenses tied to an entity that changedWhich entity signed the agreement, and whether licenses transfer
Product telemetryInstalls, usernames, days of useFree or trial versions on work machines, installs on the wrong domain
Tenant signalsOne license unlocking a feature for everyonePremium identity features like Conditional Access used tenant-wide
Spend dropA customer who cut the budget but not the usageDowngraded tiers, cancelled SKUs still deployed

The tenant-signal row is the one MSPs tend to meet first, because it lives in the systems you administer. A single Entra ID P1 license in a tenant doesn't license every user for P1 features. Microsoft can see that from its side.

How to Run a Software License Audit in 5 Steps

The internal audit uses the same five steps as the vendor's, just on your schedule. Run it per client, once a year at minimum, and before any renewal of a major agreement.

  1. Scope it. List every vendor, contract and legal entity in play, and the audit clause of each. Evidence: the agreements themselves, including which entity signed.
  2. Inventory what's installed and used. Pull installed software per device, user accounts per tenant, and SaaS sign-ins from your identity provider. Evidence: tool-generated reports with a date, not hand-built spreadsheets.
  3. Gather what's owned. Collect reseller invoices, Microsoft reseller (CSP) subscriptions, volume agreements, license keys and PDFs from vendor portals. Evidence: proof of entitlement for every product in scope.
  4. Reconcile. Match step 2 against step 3, product by product and version by version. Evidence: a gap list with an owner and a cost for each line.
  5. Fix and document. Buy what's missing, remove what shouldn't be there, reclaim what's idle, and file the evidence. Evidence: an audit pack you could hand to an auditor tomorrow.

Step 2 is where the time goes. Pulling installed software from 300 endpoints by hand is a day nobody wants. This is where an IT asset lifecycle view pays off, and where your RMM data does the heavy lifting.

OpenFrame pulls live endpoint inventory through osquery. That lets a tech ask Mingo, OpenFrame's AI agent, what's installed on which devices and get the answer from the machines themselves. Flamingo's published pricing puts a software inventory audit at 30 minutes and $24 by hand, against about a minute and $0.05 with Mingo. Matching installs to licenses in step 4 is still your job. OpenFrame doesn't track license entitlements.

For clients who want a dedicated asset register, Snipe-IT is the open-source option we've reviewed. It holds licenses, seats and assignments, so step 3 and step 4 live in one place.

Don't skip SaaS. Tools bought on a credit card never show up in an endpoint scan. Check SSO logs, OAuth grants and expense reports, the same places you'd look for shadow IT.

Software License Compliance Audit Checklist

Copy this per client. The owner column matters more than it looks. If nobody owns a line, nobody will have the evidence when an auditor asks for it.

ItemOwnerEvidenceDone
All vendor agreements and audit clauses on fileMSP account managerSigned agreements, entity names☐
Microsoft customer agreement acceptance recordedMSP (if you're the reseller)Attestation date and signatory in Partner Center☐
Installed software per deviceMSP techDated inventory export☐
Users and licenses per tenantMSP techTenant license report☐
Premium features versus premium licensesMSP techConditional Access and security feature usage versus P1/P2 counts☐
SaaS apps outside IT's approvalMSP tech + client financeSSO logs, OAuth grants, card statements☐
Server, virtualization and database licensingMSP engineerCore counts, host lists, VMware support dates☐
Java installs and versionsMSP techScan for Oracle JDK versus OpenJDK☐
Named-user products (Adobe, Autodesk)Client adminUser list, no shared or generic accounts☐
Leavers still holding licensesClient HR + MSPOffboarding tickets matched to license reclaim☐
Open-source licenses in client-built softwareClient dev leadDependency scan or SBOM☐
Who owns compliance in the MSAMSP ownerThe signed MSA clause☐

The leavers line is a quiet cost. Licenses tied to people who left months ago are pure waste. Build license return into your client offboarding checklist and the problem shrinks every month.

The First 30 Days After an Audit Letter

A letter has arrived. Before anyone replies, pull the contract and find the audit clause. Every deadline that matters is in there, and they're shorter than you'd expect.

Here's what the vendors' own terms say. Microsoft's customer agreement gives 30 days' notice. Oracle's master agreement gives 45 days' written notice, then 30 days to fix any shortfall, and Oracle pays none of your costs. Adobe's 2025 terms give 30 days to hand over data. Autodesk's March 2026 terms give 15 calendar days to submit results, including machine IDs and Windows usernames.

WhenWhat to doWhy
Days 0-2Confirm the letter is a contractual audit, not a sales email. Find the agreement, the signing entity and the audit clauseSales outreach dressed as compliance is common. The clause sets your deadlines
Days 0-2Tell the client's leadership. Name one point of contactMixed messages to an auditor cost you later
Days 3-7Bring in legal counsel. Sign an NDA with the auditorMicrosoft's MBSA gives 14 days to complete the auditor NDA
Days 3-10Negotiate scope and timeline at the kickoff callScope is easiest to limit before any data leaves the building
Days 5-20Run your own inventory and reconciliation firstYou want to know the answer before the auditor tells you
Days 10-30Hand over tool-generated data, within scope onlyVolunteering out-of-scope data widens the audit
After findingsCheck every count and formula. Don't accept findings in writing until reviewedThe auditor's first number is an opening position

That last point comes from SAMexpert, an independent Microsoft licensing consultancy. Their August 2026 session walks through the full Microsoft process, including why the audit is won or lost in the data-collection phase and why SAM tool dashboards don't hold up against the auditor's counting method. It's long, but the first 15 minutes cover what to do in the first 48 hours.

One more thing about ignoring a letter. Oracle's clause lets it terminate support, licenses or the whole master agreement if you don't fix a shortfall in 30 days. Autodesk requires you to buy immediately. Silence doesn't make the audit go away. It just runs out your clock.

What an Audit Finding Costs: A Worked Example

The penalty math is in the contract, so you can work it out before an auditor does. Here's a hypothetical to show the shape of it.

Take a client with 60 Microsoft 365 Business Standard licenses, at the $14 per user per month list price that took effect in July 2026 (The Register). An audit finds 62 people using the suite. Six of the 60 licenses still sit with people who left, and 8 current staff have been working without a license of their own for 12 months. That's 8 unlicensed users out of 62, or 13%, well past Microsoft's 5% threshold.

Under the Microsoft Customer Agreement, the client must "acquire sufficient licenses to cover its unlicensed use at 125% of the then-current Customer price." Because the gap is over 5%, it also reimburses Microsoft's verification costs.

Line (hypothetical)MathCost
Back-licensing 8 users for 12 months at 125%8 × $14 × 12 × 1.25$1,680
Microsoft's audit costsOver the 5% threshold, so the client paysNot published, varies by audit
Going forward, buying 8 new licenses8 × $14 × 12$1,344 per year
Going forward, reassigning the 6 leavers' licenses and buying 22 × $14 × 12$336 per year

Two things jump out. First, the penalty itself is survivable at this size. What hurts is the audit cost on top, plus the hours your team spends answering an auditor instead of closing tickets.

Second, the gap and the fix were sitting in the same tenant. Six idle licenses covered most of the shortfall, and reclaiming them saves $1,008 a year against buying fresh. An internal audit a year earlier would have caught both sides and skipped the penalty entirely.

This pattern isn't limited to small tenants. Zylo's 2026 index puts unused SaaS licenses at 36% on average across its customers. Those are larger organizations than a typical MSP client, but idle seats show up at every size.

Now swap the vendor. Autodesk's terms have no 5% threshold. Any shortfall means buying at least its full value plus Autodesk's audit costs. Run the same exercise on an Autodesk shortfall and there's no margin to absorb even one unlicensed seat.

Where MSPs Carry License Risk

Here's the part the generic audit guides skip. An MSP sits in the middle of the licensing chain, and some of that chain carries your name.

Start with what the Microsoft Partner Agreement says, and what it doesn't. If you resell through CSP, you must secure the client's acceptance of the Microsoft Customer Agreement and record it, with the date and signatory. Since October 7, 2025, partners who attested before April 2023 and haven't re-attested are blocked from new purchases and license changes. You also keep licensing records for five years, including after you leave the program. What the agreement doesn't contain is a clause making you liable when a client deploys more than it bought. Your exposure is your own records, your attestations and your contract with the client.

If you host, SPLA puts the reporting on you directly. You self-report usage every month. SAMexpert's SPLA guide (February 2026) notes under-reporting costs 125% of list price, you pay the audit costs over 5% non-compliance, and Microsoft can audit up to two years after the agreement ends.

Costs are moving too. Microsoft adds a 5% uplift to CSP software subscriptions billed monthly from October 1, 2026, covering Windows Server, SQL Server and CALs.

VMware hosting changed even more. Broadcom closed its VMware cloud partner program in January 2026, with open deals due to close by March 31. If you host VMware for clients, your licensing path has changed twice in a year.

Then there's the client relationship, which no contract fully protects. In this r/msp thread, an MSP with 80 client tenants describes Microsoft sending a license letter to nearly every client. The shortcut was a common one: a single Entra ID P1 license bought on a vendor's advice, then Conditional Access used across every tenant. Clients got 90 days to true up. Two of them left.

The lesson is simple. One license that unlocks a feature isn't the same as licensing everyone who uses it. Check the feature against the license, not just the license against the invoice.

Your MSA should say who owns compliance. MSP lawyers publish three common patterns. In the first, the client guarantees its own licensing and indemnifies you, and Rob Scott of Scott & Scott publishes sample wording for it. In the second, each side covers its own mistakes, matched to your professional liability insurance. In the third, vendor license terms pass straight to the client, and the MSP states it isn't the client's compliance officer. CompassMSP's MSA, updated March 2026, uses that exact phrasing. Which one fits is a question for your lawyer, not a blog post. Have your MSA reviewed if it's silent on licensing.

Open-Source Licenses Count Too

Commercial vendors aren't the only licensors. Open-source licenses come with obligations, and copyleft licenses like the GPL and AGPL come with the strictest ones. If a client builds and ships software, or gets acquired, those obligations get checked.

Black Duck's 2026 OSSRA report audited 947 commercial codebases, many as part of M&A deals. 68% had license conflicts, up from 56% the year before. Black Duck called it "the largest single-year jump we've recorded." A further 8% of components had no license detected at all.

For MSPs, the relevant case is usually a client's own software team, or a self-hosted open-source tool in your stack. AGPL matters most when you modify a tool and offer it over a network. We went through the AGPLv3 question in our Grafana Loki review. Add a dependency scan to the checklist for any client that ships code.

Turning License Audits Into a Service

Every step above takes skill, and clients will pay for skill. Steven Kelley of Software Licensing Advisors put it plainly in ChannelE2E in March 2026: "Microsoft has commoditized the transaction. It hasn't commoditized the expertise." He reports partners charging $10,000 to $25,000 for Enterprise Agreement management.

Your clients are smaller than EA customers, but the logic scales down. Software license audit services usually come in one of three shapes. You can bundle a license review into a premium QBR or vCIO package. You can charge a fixed quarterly fee for larger tenants. Or you can run the first audit, show the savings, and price the ongoing review against the value found.

The third one sells itself. In the worked example above, reclaiming idle seats saves the client $1,008 a year before you've charged a cent. That's an easy conversation at a QBR.

Treat it like any other recurring service. Put a license reconciliation on the calendar every quarter, deliver a one-page report (gaps, idle seats, renewal dates, risk flags), and keep the audit pack current. If you already run an MSP stack audit on your own tools, you have the template. Point it at the client.

The client gets a smaller bill and a clean answer when the letter comes. You get recurring revenue and a reason to be in the room before renewals. Your techs get fewer fire drills.

License Audit Software: What to Use

License audit software falls into three groups. Pick based on what's missing from your stack, not on the longest feature list.

Discovery and inventory tools answer "what's installed where." Lansweeper comes up in r/sysadmin threads about Oracle Java audits. Open-source options like Snipe-IT and the tools in our open-source inventory roundup cover the basics without a license bill of their own. Your RMM agent data belongs in this group too.

Software asset management (SAM) platforms do the reconciliation. Flexera, Snow (now part of Flexera) and USU match entitlements to usage and model vendor-specific rules like Oracle processor licensing. They're built for enterprises, and priced like it.

SaaS management platforms like Zylo and Tropic track seat usage in cloud apps, which endpoint scans miss. They make sense once a client's SaaS spend is large enough to justify another subscription.

For an MSP, the cheapest combination is usually the inventory you already have plus a disciplined quarterly reconciliation. OpenFrame covers the inventory half. It's open, AI-native infrastructure for IT and security, and endpoint inventory through osquery is part of Gen1 at $1 per device per month. The reconciliation half is the checklist above and a tech who owns it.

Get Ahead of the Letter

Vendor audits aren't slowing down. Broadcom built compliance reporting into VMware, Oracle moved Java audits from emails to formal notices, and Microsoft is writing to tenants over premium features used without premium licenses. The letter is coming either way. The difference is whether you've already run the numbers when it lands.

Start with one client this month. Run the five steps, fill in the checklist, and bring the idle-seat number to the next QBR. If the inventory step is the one eating your week, see how OpenFrame pulls it from live endpoints.

For the tools side, our roundup of free IT asset management software is the next read.

Conrad Lunderstedt

Conrad Lunderstedt

Solution Architect

I'm Conrad, Solution Architect at Flamingo. I've spent about 26 years in IT, roughly half of it inside MSPs and the rest in enterprise environments, so I've watched vendor decisions get made on both sides of that line. Now I spend my days talking with MSPs about the stack they already run, and helping them work through the requests and issues that come with it.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Software License Audits

A common grouping is proprietary licenses, subscription or SaaS licenses, permissive open-source licenses like MIT and Apache, and copyleft open-source licenses like the GPL and AGPL. Proprietary and subscription licenses are what vendor audits check. Copyleft obligations usually get checked in M&A due diligence.
An internal audit for a small client can take a few days once inventory is automated. A vendor audit runs on the contract's clock, from 15 days to submit results under Autodesk's terms to 45 days' notice under Oracle's, and findings and negotiation can stretch it to months.
Usually not, if the agreement has an audit clause. Microsoft, Oracle, Adobe and Autodesk agreements all give the vendor audit rights, and Oracle can terminate licenses if a shortfall isn't fixed within 30 days. You can negotiate scope, timeline and an NDA, so have counsel review the clause.
Run a full audit per client at least once a year and before any major renewal. Add a lighter license reconciliation every quarter, which catches leavers still holding licenses before the waste adds up.
Under Microsoft's customer agreement, the client does. If unlicensed use reaches 5%, it buys the missing licenses at 125% of the current price and reimburses Microsoft's audit costs. The MSP's exposure comes from its own reseller records, SPLA reports and what the MSA says about compliance.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.