Most organizations manage D365 Finance & Supply Chain licensing as a procurement checkbox: pull a user count, buy that many seats, revisit at renewal. Effective licensing management is a security governance discipline, not a procurement one, and treating it as the latter is where most of the overspend on this site's case studies came from.
Everything we've published this month traces back to the same underlying method. We call it Evidence-First, and it runs in three stages: establish who's really in the system, find exactly which access is driving cost, and optimize against real usage rather than assumptions. This piece is the map. Each stage links to the articles that go deep on it.
Stage 1: Establishing a trustworthy user population
Before analyzing a single role, we define who is actually in the system. That means cross-checking D365 user lists against Entra ID to catch accounts deleted at the tenant level but still active in the ERP, isolating application users and integration accounts that don't require a license at all, and comparing standard activity-aging reports against real telemetry so quiet-but-active users don't get mistaken for inactive ones.
This stage doesn't solve licensing on its own. It makes every stage after it trustworthy. Full walkthrough: The First Hour of a Real D365 Licensing Review Isn't About Roles. The specific data we pull here, and why each piece matters, is broken down in What We Actually Collect for a D365 License Analysis, and Why Each Piece Matters.
Stage 2: Role model and entry-point analysis
Role names are frequently deceptive. A role called "Sales Clerk" can carry an entry point that quietly requires a Finance license. We look past the label to the specific duties and privileges underneath, tracing exactly which entry point is responsible for a given license tier rather than accepting the role's name at face value. For users working primarily through integrations, where UI telemetry stays silent by design, we validate against transactional data instead of assuming inactivity.
The mechanics of how that requirement actually gets calculated, entry point up through privilege, duty, role, and user, are covered in full in our roll-up series: Part 1, how requirements roll up from a single entry point, Part 2, how one extra privilege triggers an attached license, and Part 3, the five ways a "standard" role quietly stops being standard. For the specific roles that carry no license requirement at all, see our quick reference, and for the deeper case for why role names alone aren't enough, see The Roles Doing Too Much. For exactly how a privilege gets marked keep, downgrade, or drop from real usage evidence, see How We Decide What Stays, What Goes Read-Only, and What Goes Away and its follow-up, Inside an Evidence-Based Disposition.
The goal of this stage isn't cleanup. It's finding the exact access path responsible for a cost, so any change that follows is targeted instead of guessed.
Stage 3: Operational optimization
Optimization should never be mechanical. Deactivating a user because they haven't logged in for 30 days can disrupt a business cycle that only happens quarterly. We capture telemetry across real business cycles, month-end close, inventory peaks, invoicing runs, so nothing essential gets missed, then pair that telemetry with security analysis to build a defensible, evidence-backed security model rather than a maximally aggressive one. What telemetry can and can't tell you on its own is covered in this piece.
A licensing review is not a one-time exercise measured by how many licenses got removed. It's a repeatable operating model, backed by real system evidence, that protects you from both unnecessary spend and audit risk at the same time.
What this looks like on a real engagement
All three stages, applied together, are what produced the numbers behind our four published case studies, and the newest one, where the biggest lever turned out to be an integration authenticating as a person instead of a service account. The framework doesn't change from engagement to engagement. What changes is which stage turns out to hold the biggest opportunity, and that's exactly why all three get run every time, not just the one that looked most promising at a glance.