Back to blog

How to Reclaim Unused M365 Seats Before EA Renewal

Benny Rosner
How to Reclaim Unused M365 Seats Before EA Renewal

Before your Enterprise Agreement renewal, take steps to reclaim unused M365 seats so you don’t roll wasted spend into the next contract. The average enterprise is paying for somewhere between 12% and 22% of Microsoft 365 seats assigned to users who haven’t signed in for 90 days or more. Broader estimates that factor in underutilized and unassigned licenses push that figure closer to 56%. Every one of those seats rolls forward into the next multi-year commitment unless you actively remove them. Microsoft expects a signed order roughly 30 days before expiration, and most IT teams begin the renewal conversation several months before that deadline, meaning the window to act is narrower than it looks.

This article walks through the exact process to locate orphaned, inactive, and overprovisioned seats, run the safety checks that protect your data, execute the removal with Microsoft Graph PowerShell, and build the automation layer that prevents drift from returning. If you want that detection work done for you without building the internal workflow from scratch, Chronom AI delivers a named-user, named-SKU savings report within 48 hours using a read-only tenant scan. But if you want the full DIY playbook, here it is.

What orphaned and overprovisioned M365 seats are really costing you

Many organizations lack feature-level visibility into how their licenses are actually used, and that gap is where recoverable spend hides. Without feature-level usage data, you can’t tell whether a significant share of your E5 seats are being used like E3, or whether a dozen accounts for former employees were never deprovisioned after offboarding. The Microsoft 365 Admin Center shows sign-in timestamps, not whether a user ever opened Defender, touched Purview, or prompted Copilot once.

There are three categories of waste worth targeting before an EA negotiation. Orphaned accounts are the clearest: departed employees whose accounts were never disabled and whose licenses kept billing silently. Inactive users who haven’t authenticated in 60 to 90 days are the next layer, and they often outnumber orphans significantly. The third category, overprovisioned users assigned E5 when their actual feature usage maps entirely to E3, carries the highest per-seat dollar value. According to recent 2026 SaaS spend analyses, roughly 31% of enterprise Microsoft 365 licenses fall into underutilized or dormant categories. A single E5-to-E3 downgrade saves approximately $14 to $16 per user per month based on current Microsoft commercial list pricing, which adds up fast at scale.

EA renewal is the hard deadline for reclaiming unused M365 seats. Microsoft Enterprise Agreements lock seat counts at renewal. If you don’t remove or downgrade seats before the renewal window closes, you commit to paying for them for the next one to three years. Organizations that run this process three to six months before renewal walk into Microsoft negotiations with data-backed evidence of what they actually consume, a fundamentally different conversation than guessing at utilization. License drift compounds between renewals too: every onboarding event, every temporary project license, and every Copilot pilot that never got reviewed adds to the baseline you’ll defend at the next EA.

How to locate and reclaim unused M365 seats in your tenant

What the Admin Center shows, and what it misses

Detection is where most teams get stuck because the Admin Center’s Active Users report has real limitations. The UI shows trends for only 7, 30, 90, or 180 days. Data carries a 24 to 48 hour reporting delay. User identities are masked by default unless you enable detailed reporting in settings. Most importantly, the report confirms authentication activity, not whether a user actually used any M365 service beyond logging in. This pass finds obvious orphans but misses overprovisioned users who sign in regularly but never touch E5-specific features.

Starting with the Admin Center

For a fast first pass, go to the Reports section in the Admin Center, open the Active Users report, and filter for users inactive over the past 30 and 90 days. Then check the Licensing page to surface unassigned seats sitting in your tenant. For smaller tenants this can take as little as 15 minutes; medium-to-large environments will need more time. Either way, treat it as a starting point, not a complete picture.

Going deeper with PowerShell

The PowerShell layer gives you the full inactive-user picture. Using the Microsoft Graph PowerShell module, the Get-MgUser cmdlet with the SignInActivity property returns each user’s last sign-in timestamp. Pair that with Exchange Online PowerShell’s Get-EXOMailboxStatistics for LastLogonTime, and you get a joined CSV that shows both authentication inactivity and mailbox inactivity in a single export. The key threshold logic is simple:

$cutoff = (Get-Date).AddDays(-90)

Adjust the 90-day value to match your organization’s inactivity policy, then filter users where either signal falls before that cutoff. Export the result to CSV and you have your detection list before any EA negotiation conversation starts.

Identifying overprovisioned users with Graph API

For per-user service-plan granularity, the Microsoft Graph endpoint GET /users/{user-id}/licenseDetails returns the provisioning status for each service plan inside a SKU, with statuses like Success or Disabled. This is how you begin identifying E5 users with Defender for Office 365, Entra ID P2, and Purview all showing minimal engagement signals. Feature-level telemetry beyond provisioning status requires deeper tooling. Chronom AI reads 40+ usage patterns through the Graph API to name exact downgrade candidates with the specific annual dollar value recoverable per user, the level of specificity that makes a savings case defensible to finance and the board.

Safety checks to run before removing any license

Removing a license without a data-preservation review is how organizations create compliance incidents. The sequence below is non-negotiable and should be completed in this exact order before any seat is reclaimed.

Block sign-in first

Block sign-in by disabling the account and revoking active sessions in Microsoft Entra ID using Update-MgUser or the Admin Center toggle. This prevents further activity while the data review is underway, creates a clean audit timestamp, and carries no data risk because it’s fully reversible.

Verify data continuity before removal

Check Microsoft Purview for any active legal or compliance holds. Microsoft’s own guidance requires you to resolve all holds before removing a license in a former-employee workflow. Confirm whether OneDrive files need to be transferred to another owner, and determine if the mailbox needs to stay accessible after the license is removed.

When ongoing email access is required, converting to a shared mailbox is the right call. It removes the user license cost while preserving the mailbox indefinitely at no per-user license fee. One critical retention fact worth emphasizing on its own: Microsoft retains Exchange data for only 30 days after license removal by default. After that window closes, the data is permanently gone unless Purview retention policies or legal holds extend it.

Document every decision before executing

Log who approved the reclamation, which SKUs were affected, the date of the last activity signal, and whether data was transferred or preserved. A simple CSV capturing the pre-removal state is sufficient. This documentation protects IT teams during compliance reviews and makes the reclamation defensible to finance and legal stakeholders months later.

Reclaim unused M365 seats with PowerShell: bulk execution

Once the safety checks are complete and documented, the actual license removal is straightforward with Microsoft Graph PowerShell. The current Microsoft-recommended cmdlet is Set-MgUserLicense with -RemoveLicenses and -AddLicenses @(). The compact loop pattern to remove licenses from all inactive candidates looks like this:

$licensedUsers = Get-MgUser -Filter ‘assignedLicenses/$count ne 0’ -ConsistencyLevel eventual -CountVariable licensedUserCount -All -Select UserPrincipalName,DisplayName,AssignedLicenses

foreach ($user in $licensedUsers) { $licensesToRemove = $user.AssignedLicenses | Select-Object -ExpandProperty SkuId Set-MgUserLicense -UserId $user.UserPrincipalName -RemoveLicenses $licensesToRemove -AddLicenses @() }

For organizations working from a CSV of specific targets generated during the detection step, feed UPNs from Import-Csv into the same Set-MgUserLicense call. This gives you precise control: you reclaim exactly the users the safety-check process approved, not a broad sweep.

When a license is removed from a user, the consumed unit count for that SKU drops by one immediately. There’s no separate pool object to manage, removing 50 inactive E5 users from license assignment makes those 50 seats instantly available for reassignment. The financial value is captured at EA renewal by presenting a lower required seat count backed by vendor-agnostic usage data. That figure is what you bring into the Microsoft negotiation to justify a reduced seat commitment.

Preventing license drift from rebuilding after reclamation

A one-time cleanup without a prevention layer is deferred sprawl. License drift starts rebuilding the week after cleanup through new hires, project-based grants, and Copilot pilots that don’t get reviewed. The automation layer below is what separates a clean tenant from one that perpetually rediscovers the same waste at every renewal.

Group-based licensing and offboarding automation

Entra ID group-based licensing is the most effective structural fix. Licenses are assigned and removed by group membership, so when HR triggers an offboarding event and removes a user from the licensed group, the seat is automatically reclaimed without any manual IT action. Pair this with Power Automate or Azure Automation runbooks that trigger on HRIS termination events to block sign-in, queue the data review, and remove users from license groups after a defined grace period. This approach moves license reclamation from a reactive audit to an automated process that runs continuously.

Setting a renewal-tied review cadence

Set a review cadence tied to your renewal cycle. Quarterly sign-in and usage reports with automated threshold alerts, triggered when inactive seat counts exceed a defined number, give you a consistent signal before drift becomes material. For organizations running Microsoft 365 Copilot at scale, sign-in data alone is insufficient: a user can authenticate daily without ever prompting Copilot. Per-user interaction telemetry is the signal that matters for validating Copilot ROI and deciding whether to renew or reduce seat counts at the next EA.

Teams with the Graph PowerShell skills, the time, and the internal process to run reclamation quarterly can operate the DIY path described here. For organizations approaching a multi-year EA renewal with $500K or more in Microsoft spend, the calculus changes. Having a platform that reads feature-level usage across 40+ patterns, names every reclamation candidate with dollar amounts, and optionally executes the approved changes removes execution risk from the IT team entirely. Chronom AI’s read-only tenant scan delivers that named-user, named-SKU savings report within 48 hours, with no change to tenant configuration until the team approves specific actions, the difference between knowing what to cut and having it cut correctly before your renewal counter resets.

Get your savings report before the renewal window closes

Reclaiming unused M365 seats is not a complex project. It’s a detection problem followed by a checklist problem. Find the inactive, orphaned, and overprovisioned accounts using PowerShell and Graph API queries, run the data-preservation checks in the correct sequence, execute the removal with Set-MgUserLicense, and build the group-based licensing automation to prevent drift from returning. Complete that process before your EA renewal window closes, and you walk into a Microsoft negotiation with real consumption numbers, not estimates.

That recoverable spend is already sitting in your tenant. The only question is whether you surface it before your next renewal locks it in for another three years. If you want the detection handled without building the internal workflow from scratch, reach out to the Chronom AI team. The 48-hour scan surfaces exactly what’s recoverable, who it should be reclaimed from, and what the annual dollar value is at the individual SKU level.

One Audit. Real Savings.
Zero Risk.

Get a comprehensive audit of your environment and see exactly how much you can save in under 15 minutes.

See a Sample Report
Read-only Access No Credit Card SOC 2 Compliant

When's your next Microsoft renewal?

Your date changes what's worth your time right now. Signing soon? We work to your deadline. Months out? We start cutting today. Either way, you save.