Microsoft 365 Licenses: Allocation, Accounts and Copilot Usage
Open Tasks → Monitor → M365 Licenses. If your company has more than one Microsoft 365 tenant, choose one from the tenant list. The page identifies the tenant through your connected Azure cloud account; Microsoft 365 licenses are not scoped to an Azure subscription, so the page works without selected subscriptions and ignores the subscription filter.
The page requires the M365 Licenses feature set and the microsoft_365_licenses.view permission. Company administrators control the feature set in the company Feature Sets settings, and parent restrictions apply. It is independent of Azure Hybrid Benefit and Cost Optimization. Built-in roles that already view licensing receive the permission; custom roles must grant it separately. Disabling the feature set hides the page and its data but does not change Microsoft consent or stop tenant collection.
Review the tabs
| Tab | What you can review |
|---|---|
| Overview | Estimated unused license value, where the license value goes, key figures and Which licenses can be reclaimed? |
| Licenses | Every product by type (Paid, Free & Trial, Capacity, Unclassified), with purchased and assigned seats, seat-state bars and list prices |
| Accounts | Assigned licenses, enabled/disabled status and last successful Entra sign-in; review disabled accounts, older sign-ins or unknown evidence, and export CSV |
| Usage & Copilot | Office application and active-user reports over 30 days, and licensed Microsoft 365 Copilot reports over 28 days |
Select any column heading to sort a table. Select a product to see where its seats are and what to do. Seat bars use the same colours everywhere: teal for seats in use, grey for accounts with no sign-in for 90+ days, coral for disabled accounts and sand for unassigned seats.
Totals show Unknown when the evidence is incomplete, rather than zero. When a list cannot show every collected record, a note below it gives the number not shown. A snapshot older than 48 hours is marked Needs Refresh. Microsoft report refresh dates are shown separately because reporting can lag collection.
Before you act
- Unassigned seats are capacity to review at renewal or when changing a purchase quantity. Unassigning a license does not reduce charges under a purchase commitment; the bill changes only when the purchased quantity is reduced.
- Disabled accounts with licenses are worth reviewing, but shared mailboxes, service and resource accounts can need their licenses.
- No sign-in for 90+ days is a login-recency signal, not proof that Office or Copilot is unused. Missing timestamps stay unknown.
- Free, trial and capacity products are never counted as savings.
Confirm account ownership and purpose before removing licenses. GitHub Copilot licensing and token charges need separate provider access and are not part of these reports.
Understand the estimates
Estimates use Microsoft list prices for an annual commitment, excluding tax. Each market uses Microsoft's own regional price pages, without converting from USD. They are not your billed spend or guaranteed savings: negotiated, reseller and existing-agreement prices can differ, so check your invoice before changing a purchase quantity.
The estimate covers unassigned paid seats, paid licenses on disabled accounts, and paid licenses on enabled accounts with no successful sign-in for 90 days. These groups do not overlap.
Not every product has a list price in every market. The line above the summary shows the coverage, for example Priced 3,220 of 5,011 paid seats, and counts any products whose pricing is unknown. When coverage is incomplete, money totals cover the priced products only, and the headline is marked partial. Seat counts, utilization and account reviews always include every paid product. Products without a price stay in Which licenses can be reclaimed? after the priced ones, showing their seat counts and No list price. On the Accounts tab, an account's estimate is marked Partial when one of its licenses has no price.
Choose the estimate currency
The picker at the right of the tab row, for example Prices in NZD, sets the currency. By default it uses the currency of the tenant's connected Azure subscriptions; hover over it to see that. Your Microsoft 365 invoice can use a different currency, so choose another one to override it, or Use Tenant Currency to go back. Changing tenants returns to the tenant's currency. If the subscriptions use conflicting or unknown currencies, the picker shows Choose Currency, and the inventory stays visible without money values.
Supported currencies are AUD, BRL, CAD, CHF, DKK, EUR, GBP, INR, JPY, KRW, NOK, NZD, SEK, TWD and USD. GBP uses UK prices, CAD Canadian prices and EUR Irish prices; the others use their own regional listings. RUB is recognized but has no verified prices yet, so its money values stay unavailable. Where several countries share a currency, choosing a purchasing country is not yet supported.
The picker changes only this page's estimate. It does not change billing settings, your currency preferences elsewhere or the selected subscriptions. Demo companies show fictional USD prices.
Snapshots collected before local prices were introduced can contain prices converted from USD; the page says so until the next tenant scan replaces them. Contract prices and Partner Center invoice data are not yet supported.
Export a Word report
Choose Export → License Report (Word) at the right of the tab row to download a branded Word report for the selected tenant. It opens with a one-page summary of key figures, where the license value goes and the top actions. It then lists the licenses to reclaim, with seat bars; the disabled and inactive accounts to review; and usage and Copilot. The full license inventory, pricing basis, assumptions and data coverage close the report. Money uses the page's estimate currency; without one, the report shows quantities only. Long tables show the first 25 rows, and the page holds the rest. Exporting requires the Data Exports feature.
Update missing access
Each source is collected separately, so the page shows whatever is available:
| Evidence | Microsoft Graph application permission |
|---|---|
| License inventory | LicenseAssignment.Read.All |
| Accounts and assigned licenses | User.Read.All |
| Successful sign-in activity | AuditLog.Read.All, plus supporting Entra ID licensing |
| Office and Copilot usage reports | Reports.Read.All |
When a source is denied, the page shows an access notice that lists the permissions to review. Denied access is the most likely cause, but tenant consent, authentication and Microsoft product requirements can also limit a source.
- A company administrator who can manage cloud accounts selects Update Access in the notice, or opens the cloud account and chooses Edit → Repair Access.
- A tenant administrator reviews the requested permissions and grants consent.
- The next tenant scan collects the new evidence. To collect sooner, run a tenant sync from Cloud Accounts; the M365 Licenses step appears first in its progress.
The page reads saved results and checks for new ones periodically; it has no scan or refresh button of its own. Other collection problems show a short notice in the affected tab and point to the tenant scan in Cloud Accounts. For manual setup, follow Microsoft Graph application permissions. If you cannot manage cloud accounts, ask your company administrator.
Usage report privacy
Microsoft 365 can conceal user names in usage reports. Optional ReportSettings.Read.All lets the page show the tenant's privacy setting, but reports are collected without it, and the default Update Access flow does not request it. The page never changes privacy settings or matches concealed report names to accounts. Missing or concealed activity is not zero activity, and the reports contain no mailbox contents, documents, chat messages or Copilot prompts.
How estimates refresh
Each tenant scan collects the latest quantities and recalculates the estimates. Price updates take effect after a Spotto release and the next tenant scan. Choosing a currency never starts a scan.
Large tenants and interrupted scans
The tenant scan saves progress as it collects each directory page. Slow or temporarily throttled reads retry automatically and continue the same scan; the M365 Licenses step stays in progress. The page continues to show the last saved snapshot until the new collection finishes. Missing permissions finish with access guidance rather than endless retries.
If a source remains incomplete after retries, observed accounts and successful sign-in dates are retained. At least marks confirmed account counts, and account-based estimates are minimums; missing sign-in dates stay Unknown. Other assigned includes assignments whose recent activity has not been established. The Word report follows the same rules. Totals use all collected licensed-account evidence, even when the displayed account list is shortened.