Once you know who's actually in scope and which roles are driving cost, the last question is whether the access those roles grant is actually being used. That's where telemetry does its real work, and also where it's easiest to trust it further than it deserves.
Configure it correctly, or don't trust it at all
Telemetry is one of the strongest inputs in a licensing review, but only when it's collected properly. A short or randomly-timed extract will tell a misleading story. The working standard: capture at least two weeks, cross real business cycles like month-end close, inventory activity, or invoicing runs, raise the export limit past the default threshold, and account for multi-environment production tenants. A single license covers every production environment inside the same tenant, so activity in more than one doesn't imply a second license requirement.
Pair it with security analysis, not on its own
Security analysis shows what a user or role can access. Telemetry shows what actually got touched. Neither answers the full question alone, but together they measure real utilization at the role, duty, and privilege level, which is what turns "this role has access to X" into "this role has never used X in two weeks of real activity." From there, revoking unused duties and privileges is a defensible, evidence-backed decision rather than a guess.
Then move from role cleanup to user cleanup
Adding a user-role association view to the same picture answers a sharper question than role design alone: is this specific person actually using this specific role? That's the bridge between security cleanup and license optimization. It's where you find users holding roles they never touch, and where a tighter user-to-role assignment usually produces the clearest, least disruptive savings in the whole review.
The goal was never the maximum number of removals. It's the cleanest security model that still supports the business, and telemetry paired with security analysis is what tells you where that line actually sits.
Four known limits worth respecting
- Telemetry doesn't reliably capture every action or output menu item. Its silence on a button or report isn't proof nobody uses it. Validate before removing access tied to broader functional areas that depend on it.
- A user can appear to require two base licenses. Treat that as a reporting anomaly, not a purchase order. The practical read is to use the more expensive applicable workload, since it covers the lower one.
- Thin-client and integration activity can still be invisible. A user can remain genuinely active while both user activity aging and telemetry stay quiet. Transactional evidence and role-association checks still matter here, not just the telemetry export.
- Optimization was never meant to be mechanical. The right outcome isn't the largest possible cleanup number. If the data is incomplete on a given point, validate first and clean up second, not the other way around.
None of this makes telemetry less valuable. It makes it exactly as valuable as good evidence usually is: strong enough to build real decisions on, and honest enough about its own blind spots that those decisions hold up under scrutiny later.