A Microsoft licence can look like a small monthly cost until it is multiplied across every employee, device, add-on and renewal term. This Microsoft licensing guide is designed to help UK organisations make confident decisions: giving people the tools they need without paying for capability that will never be used.

The right answer is rarely simply “buy the cheapest plan” or “give everyone the same licence”. Licensing should reflect how people work, what data they access, the security controls the organisation needs and the systems already in place. Get those decisions right and Microsoft 365 becomes a reliable platform for productive, secure day-to-day work. Get them wrong and costs, risk and administrative effort tend to grow together.

Start with roles, not product names

Microsoft’s product catalogue changes regularly, and individual plan names can make comparison harder than it needs to be. Begin with your workforce instead. A finance manager handling confidential files has different requirements from a shop-floor employee who only needs access to Teams and company communications. A member of the IT team may need security administration tools that would be unnecessary for most colleagues.

Map users into a small number of practical profiles, such as office-based staff, mobile workers, frontline staff, shared-device users and administrators. For each profile, establish whether they need desktop Office applications, business email, Teams meetings and calling, mobile device management, advanced threat protection, access to shared files or specialist applications.

This exercise prevents a common mistake: assigning the highest available licence to everyone because it seems simpler. Standardising can reduce administration, but over-licensing 80 people to meet the needs of 10 is not efficient. Equally, a low-cost licence that lacks a necessary security feature can create far more work later.

Microsoft licensing guide: understand the main building blocks

For many small and mid-sized organisations, Microsoft 365 Business plans are the natural starting point. They combine familiar productivity applications with cloud services such as Exchange Online, OneDrive, SharePoint and Teams. The most suitable tier depends on how staff work and how much protection or device management is required.

Business Basic is generally suited to users who work primarily in a browser or on mobile devices and do not require installed desktop Office applications. Business Standard adds the desktop applications that many office teams still rely on. Business Premium adds security and management capabilities, including Intune and advanced identity and threat protection features, making it a strong option for organisations managing laptops, remote workers and sensitive data.

Larger or more complex environments may need Microsoft 365 Enterprise plans. These can offer more advanced compliance, security, analytics and telephony options, but the step up should be driven by a defined requirement rather than the assumption that enterprise products are automatically better.

There are also important add-ons. Teams Phone can provide cloud calling, but it is not the same as a calling plan or connectivity service. Power BI, Power Apps, Project, Visio, Microsoft Defender services and Copilot may each require separate licensing or a particular base plan. Before approving an add-on, check both the intended use and its licensing prerequisites.

Treat security licences as an operational decision

Security is often where licensing has the greatest operational impact. An organisation may have email protection, multi-factor authentication and device management available through its subscriptions, yet fail to configure or apply them consistently. In that situation, the cost of the licence is not delivering its full value.

Business Premium is often a sensible fit where an organisation needs to manage company devices, enforce encryption, control access to business data and reduce the risk of compromised accounts. It can be particularly valuable for hybrid teams, organisations with limited internal IT resource and businesses handling personal, financial or commercially sensitive information.

However, a higher licence tier does not remove the need for good configuration and clear processes. Security controls need to be set up around the way your organisation works. A restrictive policy can disrupt legitimate work; a weak policy can leave a gap an attacker will exploit. The aim is proportionate protection that staff can use reliably.

Check what is already included before buying more

It is easy to acquire overlapping tools when different departments make separate decisions. For example, an organisation may pay for a third-party mobile device management platform while also licensing Microsoft Intune. It may buy a standalone email security service without reviewing the protection already available through Microsoft 365. Neither choice is necessarily wrong, but it should be deliberate.

A licensing review should compare subscriptions against active usage, existing contracts and real business requirements. Look for dormant accounts, licences assigned to leavers, duplicate security products and licences that include applications nobody uses. Also identify gaps, such as unmanaged laptops or shared mailboxes that do not have clear ownership.

Do not judge a product only by its headline feature list. A specialist third-party tool may remain the better choice where it provides a function Microsoft does not, integrates with critical systems or meets a sector-specific compliance need. The point is to avoid paying twice without a reason.

Plan properly for shared devices, contractors and growth

User-based licensing works well for named employees, but it needs closer attention in environments with shift workers, agency staff, classrooms, shared PCs or temporary projects. A shared mailbox may not need a paid user licence in every circumstance, while a person accessing Office applications, email or protected resources usually needs their own appropriate entitlement.

Avoid sharing named user accounts to reduce costs. It makes access control, audit trails and offboarding much harder, and it can create licensing and security problems. Individual identities support multi-factor authentication, clearer accountability and faster removal of access when someone leaves.

Growth matters too. A licence model that works for 25 people can become difficult to manage at 100 if approvals, allocation and renewal dates are handled informally. Keep a clear record of who owns each subscription, who can approve additions and how licences are reclaimed during the leaver process.

If your organisation uses frontline or shared-device licences, validate the intended use carefully. Microsoft licensing terms and available features can differ by product and agreement, so assumptions made from a product name alone are risky.

Choose a buying route that supports control

Most UK organisations buy Microsoft subscriptions through a Cloud Solution Provider, often called a CSP, or directly from Microsoft. A CSP can provide consolidated billing, renewal management and practical advice, which is useful when your licensing includes a mix of base plans, security services and telephony.

The commercial model also matters. Some subscriptions provide flexibility to adjust numbers, while others may offer lower pricing in exchange for a longer commitment. The best option depends on the stability of your headcount, cash flow preferences and expected changes to your IT estate. A growing organisation may value flexibility more than a modest saving; a stable organisation may prefer predictable annual costs.

Public sector bodies, schools, academy trusts, charities and eligible non-profit organisations may have access to different programmes or pricing. Eligibility, product availability and terms should be checked rather than assumed, particularly where a group structure includes several legal entities.

Do not overlook Windows, servers and legacy systems

Microsoft 365 licensing is only part of the picture. Windows licensing can depend on whether a device has an eligible underlying licence, how it is used and whether virtual desktops or remote access are involved. Older on-premises servers, Remote Desktop Services and SQL Server can introduce their own server, user or device access requirements.

This is where a quick online comparison can be misleading. A move to cloud services may simplify parts of the estate, but it does not automatically remove all legacy licensing obligations. Document the applications and servers still in use, including systems kept for manufacturing equipment, finance processes or archive access. Then plan changes with the operational consequences in view.

Build licensing into your regular IT governance

Licensing should be reviewed throughout the year, not only when a renewal quote arrives. Monthly checks can catch inactive accounts and unexpected growth. Quarterly reviews are a sensible point to assess new features, security needs and whether teams are actually using the services they are funded to use.

Before renewal, compare licence counts with HR records, review upcoming projects and check any changes in working patterns. If you are considering Copilot or other AI services, begin with data governance, permissions and use cases. Buying licences before addressing oversharing in SharePoint or unclear ownership of documents can increase rather than reduce risk.

A well-managed Microsoft estate is not about owning every available feature. It is about giving each person the right tools, protecting the information they handle and keeping costs understandable. For organisations that need a second opinion, CETSAT can turn a complicated licensing position into a practical plan that supports secure, dependable work.

Stoic sysadmin plotting a midnight patch — CETSAT-approved glare ready to block malware

Chat with Dave