Microsoft 365 license waste is rarely dormant accounts. It's active people on E5 who never open Purview or Entra ID P2, add-ons duplicating rights the base SKU already grants, and frontline staff on knowledge-worker plans. Chronom reads sub-SKU feature usage, not sign-ins, for every identity in the tenant.
It arrived for a security programme covering one department, then quietly became the template for every new starter. Nobody decided that. It just never got revisited.
Standalone Entra ID P2 and Power BI Pro were bought before the E5 rollout. The upgrade granted the same rights, and both line items carried on billing side by side.
Shift workers on shared devices, kiosk accounts, room and equipment mailboxes, external collaborators and service accounts - all holding full E-series seats because nothing in the tenant stops them.
Same tenant, same people, a smaller invoice. The work is matching every identity to the cheapest SKU that still covers what they do - and knowing which rights they already own.
A Microsoft 365 license is a bundle. E3 carries the Office apps, Exchange, SharePoint and Teams. E5 adds the premium half - Microsoft Purview compliance, Entra ID P2, Defender for Office 365 P2, Power BI Pro, Teams Phone - for roughly $21 more per user per month.
Nothing on the invoice distinguishes a person who uses that premium half from a person who has never opened any of it. Both rows read the same, every month, for years.
July 2026 list: E5 $60 · E3 $39 · Office 365 E1 $10 per user / month
Over-tiered actives: busy people on E5 whose twelve-month usage never leaves E3 territory. Duplicate entitlements: standalone Entra ID P2, Intune or Power BI Pro billing a right the base SKU already grants. Wrong license family: frontline, shared-device, kiosk and service identities on knowledge-worker plans.
None of the three looks like waste in a seat count, because all of them are assigned to something real.
Native usage reporting is built around sign-ins and app opens, and it arrives de-identified by default. Entitlement inheritance - which add-on rights come free inside which plan - appears in no portal view at all, and Microsoft revises it every quarter.
So the gap between what you bought and what gets used is discoverable, but only by someone treating it as a full-time job.
Shared mailboxes, room and equipment accounts, guests, service principals and automation accounts rarely need a paid seat. Start here because nothing is at risk.
Twelve months of per-feature activity per user. This is the step that distinguishes a genuine E5 from an E5 that behaves like an E3.
Standalone add-ons stacked on a base SKU that grants the same right. Fastest saving on the list: no user loses a capability.
Group the E5-to-E3, E3-to-E1 and E3-to-F3 populations, exclude anyone with compliance or legal custody, then price each cohort separately.
Removing an Exchange-bearing license first starts a 30-day soft-delete clock. Convert to shared, preserve OneDrive, then release.
Microsoft doesn't prorate mid-term changes, so reclaims land on your anniversary. Group-based licensing keeps the tier from drifting back.
Examples rather than the catalogue - a sample of what the platform reads across your users, SKUs and add-ons, and why each one stays invisible until something is looking for it.
The waste is almost never dormant accounts. It's active people sitting a tier too high, standalone add-ons duplicating rights their base SKU already grants, and whole categories of identity carrying knowledge-worker licenses they were never meant to have.
We read whether the premium half of the license is ever exercised: Purview eDiscovery and DLP, Entra ID P2 conditional access, Defender for Office 365 P2, Power BI Pro, Teams Phone, Intune enrolment. User by user, across twelve months - which is the only way to tell an E5 power user from an E5 that behaves like an E3.
Admin-center reports show sign-ins and app opens, and usage data arrives de-identified by default.
Standalone Entra ID P1 and P2, Intune Plan 1, Defender for Office 365 P1, Exchange Online Plan 2, Power BI Pro, Visio and Project, stacked on E3, E5 or Business Premium seats that already include the same right. Removing the duplicate changes nothing a user can see.
Entitlement inheritance appears in no portal view. You have to know the SKU matrix, and it moves every quarter.
Some people spend the entire day in Outlook on the web, Teams chat and shared documents. No Office desktop activation, no Teams Phone, no eDiscovery custody, no enrolled device - and Office 365 E1 covers all of it at $10 per user per month against $39.
Mailboxes have to be converted before the SKU is removed, or the 30-day soft-delete clock starts on mail nobody agreed to lose.
Microsoft 365 F1 and F3 are built for shop-floor, retail, field and clinical staff who share a device. Exchange Online Kiosk covers mailbox-only identities, and shared mailboxes never needed a paid seat at all.
Frontline eligibility is contractual, not technical - nothing in the tenant warns you when you over-license.
Sign-in-blocked leavers, unconverted leaver mailboxes, guest and B2B collaborators, service and automation accounts, room and equipment mailboxes. Plus the duplicate identities every tenant migration leaves behind.
Offboarding closes the ticket. It very rarely reclaims the SKU, and nothing reconciles the two.
Microsoft 365 Business Premium and Business Standard stop at 300 seats. Grow past that line and you inherit a mixed estate: two plan families, two price points, and an E3 default nobody re-derived once the headcount changed.
Nothing flags the moment the cheaper plan family stopped being an option, or stopped being necessary.
Every recommendation lands as a named user, a named SKU and an exact annual figure. Because Microsoft doesn't prorate mid-term changes, reclaims are sequenced against your renewal and anniversary dates, mailboxes are converted before anything is removed, and the result is locked in with group-based assignment so the estate can't quietly re-tier itself.
Ranges and figures on this page are aggregate patterns across audited tenants, shown for illustration. Your audit replaces every one of them with your own numbers, tied to named users, SKUs and add-ons.
Chronom outputs conclusions rather than signals: which license, on which people, changes to what, why it's safe to do, and what it's worth over a year.
Twelve months with no Purview eDiscovery, DLP, Entra ID P2 or Power BI Pro activity. Office desktop, Teams and calling continue untouched.
Outlook on the web only, no Office desktop activation in a year, no Teams Phone, no enrolled device. Mailboxes stay in place at 50 GB.
Shared-device sign-ins, no dedicated endpoint, no data custody. Frontline eligibility is confirmed against your agreement before the change is proposed.
Each assignment sits on a base SKU that already grants the identical right. Removing the standalone changes nothing a user can see.
Blocked at offboarding, license never reclaimed. Mailbox converted to shared and OneDrive content preserved before release.
Every line in a Chronom report is a decision with an owner, a SKU and a dollar figure. Nothing is left for you to go and find out.
“Low Teams usage detected” - a fact you now have to interpret
An alert queue that grows faster than you can triage it
A dashboard that hands the analysis back to you
A one-off clean-up decays. New starters inherit the default SKU, projects provision add-ons, someone re-enables an account. Chronom keeps reading the tenant so it never compounds back to where it started.
Every scan compares the tenant against the baseline you approved. A new E5 assignment, a re-added Power BI Pro add-on or a re-licensed leaver surfaces within a day - not in a quarterly review.
When a team asks for Intune, Entra ID P2 or Project seats, you can check whether the entitlement already exists inside someone's base SKU before the purchase order goes out.
Peak seat count is what gets reconciled at true-up, so catching a spike in week one instead of month twelve is what keeps the next reconciliation small.
Approved right-sizing is enforced through group-based licensing rather than a spreadsheet, so the tier a cohort belongs on is a rule in the tenant instead of a memory.
It's matching every identity in your tenant to the cheapest license that still covers what that person actually does, then keeping it that way. In practice there are four moves: reclaim seats nobody uses, drop over-tiered users to a lower plan, remove standalone add-ons that duplicate a right the base SKU already grants, and move non-knowledge-workers onto frontline or kiosk plans. Done properly it reduces a Microsoft 365 licensing bill by 15–30% without changing anything an employee can see, because nothing anyone actually uses gets taken away.
The admin center answers a different question. It tells you who signed in and which apps opened - not whether the capability you're paying for was used. An E5 user who never opens Purview, Entra ID P2, Defender for Office 365 P2 or Power BI looks identical to a power user in every native report. Chronom reads feature-level usage per identity across twelve months, maps it against what each SKU and add-on actually entitles, and prices the gap against your own rates.
Not if the baseline is treated as untouchable, which is how we run it by default. Chronom operates in one of two modes. Savings-first shows you the largest defensible number and lets you carve out exclusions once you can see them priced. Security-first fences off premium licensing that exists because security, legal or compliance asked for it, and finds savings around it. Either way, anyone with eDiscovery, retention or litigation-hold custody - legal, HR, finance, executives, security operations - stays where they are regardless of what their usage looks like.
Usage tells us who behaves like a frontline worker: shared-device sign-ins, no dedicated endpoint, no Office desktop activation, no data custody. Eligibility, though, is contractual rather than technical - Microsoft's frontline terms are about the role and the device, not the telemetry. So every frontline recommendation is checked against the wording of your agreement before it reaches you, which is exactly the check nothing in the tenant performs for you.
It can, if the sequence is wrong. Removing an Exchange-bearing SKU before the replacement lands starts a soft-delete clock, and that's how organizations lose mail they can't recover. Chronom sequences it the other way: mailboxes are converted to shared where needed, OneDrive content is preserved, the replacement SKU is assigned, and only then is the old one released. Analysis itself is read-only, and execution never happens without your approval.
Yes, and the paper changes the timing rather than the findings. Microsoft doesn't prorate mid-term subscription changes, so on an EA or CSP term the reclaim is timed to your anniversary or renewal to capture the full annual value instead of paying for seats you've already stopped using. Chronom is vendor-agnostic and sells no licenses, so you keep whatever agreement and partner you have - we just hand you the usage evidence behind every line item.
Across audited tenants, 15–30% of M365 license spend, with around 32% of total tenant spend wasted once storage, Copilot and cloud are included. In structured audits, 20–35% of seats at mid-to-large enterprises qualify for a lower tier. Your assessment replaces those ranges with your own figure, tied to named users and SKUs, within 48 hours of connecting.
Get a comprehensive audit of your environment and see exactly how much you can save in under 15 minutes.