Updated: October 2026
Somewhere in your client list, someone's using a license nobody paid for. You'll find out from the vendor or from your own audit, and the second one is a lot cheaper. Here's how to run a software license audit, handle the letter if it lands first, and turn the checks into paid work.
TL;DR
- Definition. A software license audit checks every installed or assigned license against what the organization legally owns.
- Frequency. Flexera's 2026 report says 48% of organizations were audited in the past year.
- Penalty. Under Microsoft's customer agreement, 5% or more unlicensed use means 125% pricing plus audit costs.
- Clock. Autodesk gives 15 days to respond, Microsoft 30 days' notice, Oracle 45.
- Opportunity. An MSP that audits first saves the client the penalty and gets a billable service.
What Is a Software License Audit?
A software license audit checks every piece of software installed, assigned or used in an organization against the licenses it owns. A vendor can run it, usually through a third-party auditor, or you can run it on yourself. The output is a gap: what you use without a license, and what you pay for and don't use.
Vendors don't always call it an audit. A "license review," a "SAM engagement" or a friendly spreadsheet request from Adobe or Oracle can turn contractual fast, so treat any of them as the start of one.
Flexera's 2026 report (512 respondents, June 2026) found 48% of organizations were audited in the last year, yet only 36% have full visibility of their IT estate. Microsoft audits most often. Oracle's share jumped from 24% to 38% in a year.
Why Audit Letters Land on MSP Desks Now
The last 18 months have been busy. In May 2025, Broadcom sent cease-and-desist letters to VMware perpetual-license holders whose support had lapsed. The letters told them to remove every patch installed after support ended and warned of audits. Dean Colpitts, CTO of Canadian MSP Members IT Group, said one of his clients got its letter six days after its support contract expired.
The lawsuits followed. VMware sued Siemens in March 2025 over roughly 23,000 US deployments, per Network World's timeline. Tesco has a UK High Court claim of at least £100M against Broadcom, VMware and Computacenter. Somewhere, a Broadcom account manager is having a great quarter.
Then Broadcom went further. Its June 2026 VMware Cloud Foundation terms require a compliance report every 180 days, and if you miss one, management features get degraded and support is suspended. Broadcom has built the audit into the product.
Oracle is on a similar path with Java. Its price list charges $15 per employee per month for organizations under 1,000 staff, and "employee" counts everyone on payroll, not just people running Java. A Dimensional Research survey reported by The Register found 73% of Oracle Java users had been audited in three years. The survey was commissioned by Azul, which sells a Java alternative, so read it with that in mind.
The MSP angle shows up in the details. Vendor telemetry doesn't care whose laptop is running the software. In January 2026, Autodesk contacted an MSP's client with a list of the MSP's own staff usernames, software versions and days of use, then asked the client for the MSP's contact details.
The comments add more: a fully licensed shop flagged after a domain migration left licenses tied to old accounts, and an MSP that paid Malwarebytes after techs ran the free version on client machines. Your tooling habits end up in your client's audit.
What Triggers a Software License Compliance Audit?
Vendors rarely pick targets at random. A software license compliance audit usually follows a signal the vendor can see from its side of the contract. Knowing the signals tells you where to look first.
| Trigger | What the vendor sees | What to check first |
|---|---|---|
| Renewal or true-up | Your counts versus last year's | Headcount growth, new sites, new servers |
| Support lapses or downgrades | A customer still running the product without paying | Patches installed after the support end date (Broadcom's letter targeted exactly this) |
| Merger, acquisition or new legal entity | Licenses tied to an entity that changed | Which entity signed the agreement, and whether licenses transfer |
| Product telemetry | Installs, usernames, days of use | Free or trial versions on work machines, installs on the wrong domain |
| Tenant signals | One license unlocking a feature for everyone | Premium identity features like Conditional Access used tenant-wide |
| Spend drop | A customer who cut the budget but not the usage | Downgraded tiers, cancelled SKUs still deployed |
The tenant-signal row is the one MSPs tend to meet first, because it lives in the systems you administer. A single Entra ID P1 license in a tenant doesn't license every user for P1 features. Microsoft can see that from its side.
How to Run a Software License Audit in 5 Steps
The internal audit uses the same five steps as the vendor's, just on your schedule. Run it per client, once a year at minimum, and before any renewal of a major agreement.
- Scope it. List every vendor, contract and legal entity in play, and the audit clause of each. Evidence: the agreements themselves, including which entity signed.
- Inventory what's installed and used. Pull installed software per device, user accounts per tenant, and SaaS sign-ins from your identity provider. Evidence: tool-generated reports with a date, not hand-built spreadsheets.
- Gather what's owned. Collect reseller invoices, Microsoft reseller (CSP) subscriptions, volume agreements, license keys and PDFs from vendor portals. Evidence: proof of entitlement for every product in scope.
- Reconcile. Match step 2 against step 3, product by product and version by version. Evidence: a gap list with an owner and a cost for each line.
- Fix and document. Buy what's missing, remove what shouldn't be there, reclaim what's idle, and file the evidence. Evidence: an audit pack you could hand to an auditor tomorrow.
Step 2 is where the time goes. Pulling installed software from 300 endpoints by hand is a day nobody wants. This is where an IT asset lifecycle view pays off, and where your RMM data does the heavy lifting.
OpenFrame pulls live endpoint inventory through osquery. That lets a tech ask Mingo, OpenFrame's AI agent, what's installed on which devices and get the answer from the machines themselves. Flamingo's published pricing puts a software inventory audit at 30 minutes and $24 by hand, against about a minute and $0.05 with Mingo. Matching installs to licenses in step 4 is still your job. OpenFrame doesn't track license entitlements.
For clients who want a dedicated asset register, Snipe-IT is the open-source option we've reviewed. It holds licenses, seats and assignments, so step 3 and step 4 live in one place.
Don't skip SaaS. Tools bought on a credit card never show up in an endpoint scan. Check SSO logs, OAuth grants and expense reports, the same places you'd look for shadow IT.
Software License Compliance Audit Checklist
Copy this per client. The owner column matters more than it looks. If nobody owns a line, nobody will have the evidence when an auditor asks for it.
| Item | Owner | Evidence | Done |
|---|---|---|---|
| All vendor agreements and audit clauses on file | MSP account manager | Signed agreements, entity names | ☐ |
| Microsoft customer agreement acceptance recorded | MSP (if you're the reseller) | Attestation date and signatory in Partner Center | ☐ |
| Installed software per device | MSP tech | Dated inventory export | ☐ |
| Users and licenses per tenant | MSP tech | Tenant license report | ☐ |
| Premium features versus premium licenses | MSP tech | Conditional Access and security feature usage versus P1/P2 counts | ☐ |
| SaaS apps outside IT's approval | MSP tech + client finance | SSO logs, OAuth grants, card statements | ☐ |
| Server, virtualization and database licensing | MSP engineer | Core counts, host lists, VMware support dates | ☐ |
| Java installs and versions | MSP tech | Scan for Oracle JDK versus OpenJDK | ☐ |
| Named-user products (Adobe, Autodesk) | Client admin | User list, no shared or generic accounts | ☐ |
| Leavers still holding licenses | Client HR + MSP | Offboarding tickets matched to license reclaim | ☐ |
| Open-source licenses in client-built software | Client dev lead | Dependency scan or SBOM | ☐ |
| Who owns compliance in the MSA | MSP owner | The signed MSA clause | ☐ |
The leavers line is a quiet cost. Licenses tied to people who left months ago are pure waste. Build license return into your client offboarding checklist and the problem shrinks every month.
The First 30 Days After an Audit Letter
A letter has arrived. Before anyone replies, pull the contract and find the audit clause. Every deadline that matters is in there, and they're shorter than you'd expect.
Here's what the vendors' own terms say. Microsoft's customer agreement gives 30 days' notice. Oracle's master agreement gives 45 days' written notice, then 30 days to fix any shortfall, and Oracle pays none of your costs. Adobe's 2025 terms give 30 days to hand over data. Autodesk's March 2026 terms give 15 calendar days to submit results, including machine IDs and Windows usernames.
| When | What to do | Why |
|---|---|---|
| Days 0-2 | Confirm the letter is a contractual audit, not a sales email. Find the agreement, the signing entity and the audit clause | Sales outreach dressed as compliance is common. The clause sets your deadlines |
| Days 0-2 | Tell the client's leadership. Name one point of contact | Mixed messages to an auditor cost you later |
| Days 3-7 | Bring in legal counsel. Sign an NDA with the auditor | Microsoft's MBSA gives 14 days to complete the auditor NDA |
| Days 3-10 | Negotiate scope and timeline at the kickoff call | Scope is easiest to limit before any data leaves the building |
| Days 5-20 | Run your own inventory and reconciliation first | You want to know the answer before the auditor tells you |
| Days 10-30 | Hand over tool-generated data, within scope only | Volunteering out-of-scope data widens the audit |
| After findings | Check every count and formula. Don't accept findings in writing until reviewed | The auditor's first number is an opening position |
That last point comes from SAMexpert, an independent Microsoft licensing consultancy. Their August 2026 session walks through the full Microsoft process, including why the audit is won or lost in the data-collection phase and why SAM tool dashboards don't hold up against the auditor's counting method. It's long, but the first 15 minutes cover what to do in the first 48 hours.
One more thing about ignoring a letter. Oracle's clause lets it terminate support, licenses or the whole master agreement if you don't fix a shortfall in 30 days. Autodesk requires you to buy immediately. Silence doesn't make the audit go away. It just runs out your clock.
What an Audit Finding Costs: A Worked Example
The penalty math is in the contract, so you can work it out before an auditor does. Here's a hypothetical to show the shape of it.
Take a client with 60 Microsoft 365 Business Standard licenses, at the $14 per user per month list price that took effect in July 2026 (The Register). An audit finds 62 people using the suite. Six of the 60 licenses still sit with people who left, and 8 current staff have been working without a license of their own for 12 months. That's 8 unlicensed users out of 62, or 13%, well past Microsoft's 5% threshold.
Under the Microsoft Customer Agreement, the client must "acquire sufficient licenses to cover its unlicensed use at 125% of the then-current Customer price." Because the gap is over 5%, it also reimburses Microsoft's verification costs.
| Line (hypothetical) | Math | Cost |
|---|---|---|
| Back-licensing 8 users for 12 months at 125% | 8 × $14 × 12 × 1.25 | $1,680 |
| Microsoft's audit costs | Over the 5% threshold, so the client pays | Not published, varies by audit |
| Going forward, buying 8 new licenses | 8 × $14 × 12 | $1,344 per year |
| Going forward, reassigning the 6 leavers' licenses and buying 2 | 2 × $14 × 12 | $336 per year |
Two things jump out. First, the penalty itself is survivable at this size. What hurts is the audit cost on top, plus the hours your team spends answering an auditor instead of closing tickets.
Second, the gap and the fix were sitting in the same tenant. Six idle licenses covered most of the shortfall, and reclaiming them saves $1,008 a year against buying fresh. An internal audit a year earlier would have caught both sides and skipped the penalty entirely.
This pattern isn't limited to small tenants. Zylo's 2026 index puts unused SaaS licenses at 36% on average across its customers. Those are larger organizations than a typical MSP client, but idle seats show up at every size.
Now swap the vendor. Autodesk's terms have no 5% threshold. Any shortfall means buying at least its full value plus Autodesk's audit costs. Run the same exercise on an Autodesk shortfall and there's no margin to absorb even one unlicensed seat.
Where MSPs Carry License Risk
Here's the part the generic audit guides skip. An MSP sits in the middle of the licensing chain, and some of that chain carries your name.
Start with what the Microsoft Partner Agreement says, and what it doesn't. If you resell through CSP, you must secure the client's acceptance of the Microsoft Customer Agreement and record it, with the date and signatory. Since October 7, 2025, partners who attested before April 2023 and haven't re-attested are blocked from new purchases and license changes. You also keep licensing records for five years, including after you leave the program. What the agreement doesn't contain is a clause making you liable when a client deploys more than it bought. Your exposure is your own records, your attestations and your contract with the client.
If you host, SPLA puts the reporting on you directly. You self-report usage every month. SAMexpert's SPLA guide (February 2026) notes under-reporting costs 125% of list price, you pay the audit costs over 5% non-compliance, and Microsoft can audit up to two years after the agreement ends.
Costs are moving too. Microsoft adds a 5% uplift to CSP software subscriptions billed monthly from October 1, 2026, covering Windows Server, SQL Server and CALs.
VMware hosting changed even more. Broadcom closed its VMware cloud partner program in January 2026, with open deals due to close by March 31. If you host VMware for clients, your licensing path has changed twice in a year.
Then there's the client relationship, which no contract fully protects. In this r/msp thread, an MSP with 80 client tenants describes Microsoft sending a license letter to nearly every client. The shortcut was a common one: a single Entra ID P1 license bought on a vendor's advice, then Conditional Access used across every tenant. Clients got 90 days to true up. Two of them left.
The lesson is simple. One license that unlocks a feature isn't the same as licensing everyone who uses it. Check the feature against the license, not just the license against the invoice.
Your MSA should say who owns compliance. MSP lawyers publish three common patterns. In the first, the client guarantees its own licensing and indemnifies you, and Rob Scott of Scott & Scott publishes sample wording for it. In the second, each side covers its own mistakes, matched to your professional liability insurance. In the third, vendor license terms pass straight to the client, and the MSP states it isn't the client's compliance officer. CompassMSP's MSA, updated March 2026, uses that exact phrasing. Which one fits is a question for your lawyer, not a blog post. Have your MSA reviewed if it's silent on licensing.
Open-Source Licenses Count Too
Commercial vendors aren't the only licensors. Open-source licenses come with obligations, and copyleft licenses like the GPL and AGPL come with the strictest ones. If a client builds and ships software, or gets acquired, those obligations get checked.
Black Duck's 2026 OSSRA report audited 947 commercial codebases, many as part of M&A deals. 68% had license conflicts, up from 56% the year before. Black Duck called it "the largest single-year jump we've recorded." A further 8% of components had no license detected at all.
For MSPs, the relevant case is usually a client's own software team, or a self-hosted open-source tool in your stack. AGPL matters most when you modify a tool and offer it over a network. We went through the AGPLv3 question in our Grafana Loki review. Add a dependency scan to the checklist for any client that ships code.
Turning License Audits Into a Service
Every step above takes skill, and clients will pay for skill. Steven Kelley of Software Licensing Advisors put it plainly in ChannelE2E in March 2026: "Microsoft has commoditized the transaction. It hasn't commoditized the expertise." He reports partners charging $10,000 to $25,000 for Enterprise Agreement management.
Your clients are smaller than EA customers, but the logic scales down. Software license audit services usually come in one of three shapes. You can bundle a license review into a premium QBR or vCIO package. You can charge a fixed quarterly fee for larger tenants. Or you can run the first audit, show the savings, and price the ongoing review against the value found.
The third one sells itself. In the worked example above, reclaiming idle seats saves the client $1,008 a year before you've charged a cent. That's an easy conversation at a QBR.
Treat it like any other recurring service. Put a license reconciliation on the calendar every quarter, deliver a one-page report (gaps, idle seats, renewal dates, risk flags), and keep the audit pack current. If you already run an MSP stack audit on your own tools, you have the template. Point it at the client.
The client gets a smaller bill and a clean answer when the letter comes. You get recurring revenue and a reason to be in the room before renewals. Your techs get fewer fire drills.
License Audit Software: What to Use
License audit software falls into three groups. Pick based on what's missing from your stack, not on the longest feature list.
Discovery and inventory tools answer "what's installed where." Lansweeper comes up in r/sysadmin threads about Oracle Java audits. Open-source options like Snipe-IT and the tools in our open-source inventory roundup cover the basics without a license bill of their own. Your RMM agent data belongs in this group too.
Software asset management (SAM) platforms do the reconciliation. Flexera, Snow (now part of Flexera) and USU match entitlements to usage and model vendor-specific rules like Oracle processor licensing. They're built for enterprises, and priced like it.
SaaS management platforms like Zylo and Tropic track seat usage in cloud apps, which endpoint scans miss. They make sense once a client's SaaS spend is large enough to justify another subscription.
For an MSP, the cheapest combination is usually the inventory you already have plus a disciplined quarterly reconciliation. OpenFrame covers the inventory half. It's open, AI-native infrastructure for IT and security, and endpoint inventory through osquery is part of Gen1 at $1 per device per month. The reconciliation half is the checklist above and a tech who owns it.
Get Ahead of the Letter
Vendor audits aren't slowing down. Broadcom built compliance reporting into VMware, Oracle moved Java audits from emails to formal notices, and Microsoft is writing to tenants over premium features used without premium licenses. The letter is coming either way. The difference is whether you've already run the numbers when it lands.
Start with one client this month. Run the five steps, fill in the checklist, and bring the idle-seat number to the next QBR. If the inventory step is the one eating your week, see how OpenFrame pulls it from live endpoints.
For the tools side, our roundup of free IT asset management software is the next read.
Conrad Lunderstedt
Solution Architect
I'm Conrad, Solution Architect at Flamingo. I've spent about 26 years in IT, roughly half of it inside MSPs and the rest in enterprise environments, so I've watched vendor decisions get made on both sides of that line. Now I spend my days talking with MSPs about the stack they already run, and helping them work through the requests and issues that come with it.
