Most D365 Finance and Supply Chain customers we talk to start from the same quiet assumption: Microsoft knows best how many licenses a company should buy, the price is what it is, and the only real move is to negotiate a few points off at renewal. It is a completely understandable belief, and it is the one this practice was built on unlearning. It is also the single most expensive belief in D365 licensing, because it is half wrong in a specific, fixable way.
Microsoft does set two things: the price of each license tier, and the rules that decide which license a given piece of access requires. What Microsoft does not set, and genuinely cannot see, is how many licenses your particular configuration actually requires. That number is a function of how your security roles are built, and it is entirely yours to change.
What Microsoft actually decides
Two things, both fixed and both public. The first is the list price of each subscription license tier, the same published number for every customer, which a discount can move by a few points but not fundamentally change. The second is the rule set that maps access to a license: the logic that says a given entry point, privilege, or duty requires a particular tier. Those rules are Microsoft's, they are consistent, and they are not up for debate. If a user is capable of a Finance action, that capability requires a Finance license, and no amount of configuration changes that particular fact. All of this is covered in the fundamentals guide, with the exact tiers defined in the glossary.
What Microsoft doesn't decide, and can't
How many of each license you need. That number is not handed down by Microsoft; it is produced, entirely, by your own security configuration, the specific roles, duties, privileges, and entry points assigned across your users. Microsoft prices what you assign. It does not reach into your tenant and check whether your roles were built efficiently, whether an Employee role was quietly customized years ago to require a license it never should have, or whether a single over-scoped privilege is pushing hundreds of users one tier higher than their actual work requires. That gap between what is assigned and what is genuinely needed is invisible on a Microsoft invoice, and it is exactly where the license count is too high.
Why the belief feels true
Because the bill really does arrive as a Microsoft invoice, and nothing on it points back to the configuration that produced it. The license count lives in one place, security configuration, and it is owned by a team that reviews it on a security schedule, for security reasons, with cost rarely in the room. The invoice lives in another place, finance, owned by a team that has no visibility into which privilege inside which role is driving which tier. The two teams that could close the gap are almost never in the same meeting, so the number that finance sees looks fixed, and the configuration that security owns looks like it has nothing to do with the bill. Both halves are wrong, and the belief that nothing can be done is what grows in the space between them.
The proof it isn't just theory
Two published engagements make the point without a single renegotiated price.
The first was a European estate of roughly 700 licensed users with security that was already among the best-configured we have assessed, paying about $105,000 a month. Nothing a discount conversation would have caught, and nothing that looked like waste on the surface. Comparing what was granted against what people actually did brought it to about $65,000 a month, a reduction of roughly 35%. A well-run security team, a clean-looking estate, and the count was still a third too high. Full details in the write-up.
The second was an ordinary estate of roughly 150 users, the usual accumulation of access nobody had revisited. The remediation, generated and deployed as importable security configuration rather than built by hand, cut the monthly bill from a projected $43,000 to about $32,000, a 25% reduction, and the deployment itself took about ninety minutes. That one is covered here.
A discount changes the price of a license you were going to buy anyway. Optimization changes whether you needed it. Microsoft only ever sells you the first conversation, which is why most companies only ever have that one.
"But won't Microsoft penalize us for optimizing?"
This is the fear underneath the belief, and it is worth answering directly. Reducing licenses you can defend as unused is not a loophole and not evasion. It is least-privilege security done correctly: every change tied to evidence of what a user actually does, which is the same documentation an auditor asks for. If anything, the risk now runs the other way. Microsoft's per-user license validation enforcement, rolling out from January 15, 2026 against each customer's renewal date, asks you to prove that each user actually holds a license matching their assigned access. An over-licensed estate with no evidence behind its assignments is the exposed position under that enforcement, not the safe one. Optimizing the count is how you get ahead of the question before it is asked.
Microsoft sets the price. Your security configuration sets the count, and the count is where the real number moves. The belief that nothing can be done is the only belief in the room guaranteed to leave the money on the table, because it is the one that stops anyone from looking at the one thing they actually control.
If your last cost conversation was entirely about discount percentage, the second lever is still sitting untouched in your own security configuration. A good place to see what it looks like in practice is the difference between a discount and an optimization, and how a license requirement rolls up from a single entry point in the first place.
Questions we get asked
Doesn't Microsoft already optimize our licensing through new features?
New features can add value, but they don't reach into your security roles and right-size them. Reducing the license count is a configuration question inside your own tenant, deciding which access each role actually needs, and no Microsoft feature makes that decision for you. Microsoft prices what you assign; it doesn't audit whether what you assigned was built efficiently.
We already assign licenses based on job titles. Isn't that enough?
A job title predicts a role, but the role's actual entry points predict the license. Two people with the same title can genuinely need different licenses, and a single over-scoped privilege can push an entire title one tier higher than it should be. Title-based assignment is usually where over-licensing starts, not where it gets caught.
Will Microsoft penalize us for reducing licenses?
Reducing licenses you can defend as unused is governance, not evasion. Every change ties back to evidence of what a user actually does, which is exactly the documentation an audit wants. The risk now runs the other way: Microsoft's per-user validation enforcement asks you to prove each assignment is justified, so an over-licensed, undocumented estate is the riskier position, not the safe one.
We're paying a lot and it feels like there's no way out. Is there actually something we can do?
Yes. The way out isn't a better discount, it's the license count, and the count is set by security configuration you control. In published engagements we've taken a well-configured estate from $105,000 to $65,000 a month and an ordinary one from a projected $43,000 to about $32,000, neither by renegotiating price. Both came from changing how many licenses the configuration actually required.