The method

Why the numbers hold up.

Any tool can list dormant accounts. The bar is what happens next: a total that survives a finance team's questions, a saving that is only claimed when a licence actually came off the invoice, and a finding that is named even when it cannot be proved. This page is how WantNot gets there.

A saving means the invoice changed

When a finding disappears, most tools call it a saving. Often it isn't — a dormant user who comes back from leave still holds their licence, and you are still paying for it.

WantNot watches the licence assignment snapshot, not just the findings. A resolution is only counted when the licence was genuinely released or the seat count cut. Findings that stop being flagged for any other reason are reported as absorbed — still assigned, still billed.

The headline is the change in committed spend, because that is the figure that appears on the invoice. Reclaimed numbers are what you take to a renewal.

It is the difference between a number you can present, and one that falls apart the moment somebody checks it.

Reclaimed Licence removed or seat count cut $8,412
Absorbed Still assigned, still billed $3,180
New since last scan Fresh findings to work $1,944
Only $8,412 is claimed as a saving. The rest is shown, and explained, but never counted.

Why it matters: if absorbed findings were counted as savings, the product would reward its own blind spots. A licence that was never released is not money back — it is next month's invoice.

What WantNot looks for

Five finding types, ordered by how easily each one survives an argument with a finance team. The hottest are unarguable; the last needs a human to confirm.

01
Certain · the most defensible finding

Unassigned seats

Purchased and assigned to nobody. The seat count exceeds the people in it — licences bought, billed, and never given a user.

  1. Purchased count vs assigned count, per SKU.
  2. Seats with no assignee are listed, not estimated.
  3. Could it be argued? Only a reserved-seat policy counts, and it should be visible in the admin centre — so check.
Certain
02
Certain

Disabled accounts

The account was switched off when someone left. The licence stayed attached — and kept billing. Purely administrative waste.

  1. Licence map crossed with the account's disabled flag.
  2. Every disabled account with a licence is listed.
  3. An account disabled for a planned re-provision is the only story, and it is a short one.
Certain
03
Likely · background activity counts

Dormant users

No sign-in in 90 days — interactive or background. A mailbox that still syncs is not flagged, because it is being used.

  1. Last sign-in, with background activity counted.
  2. 90-day window, configurable per tenant.
  3. The one dispute is leave of absence, which is why this is Likely, not Certain. Return from leave reports the same user as absorbed, never reclaimed.
Likely
04
Likely · grace for new starters

Never signed in

Licensed at provisioning and never once used. New starters get a 45-day grace window, because onboarding is not waste.

  1. Licenced accounts with no sign-in history.
  2. Grace window keeps onboarding out of the report.
  3. After the window the licence has served no purpose; a human confirms before anything counts.
Likely
05
Review · needs a human

Redundant licences

A standalone SKU whose every service is already inside a bundle the same user holds. Computed from service plans, so it stays right as Microsoft reshuffles them.

  1. Service-plan overlap, not name matching.
  2. Survives product renames and bundle changes.
  3. A standby licence can be intentional. That is why this one is flagged for review, never auto-counted.
Review

The differentiator

Sliced by people, not SKUs

Microsoft's own reports age out a licence one SKU at a time. It has never had a reason to collect all of a single person's waste into one place — because the whole point of a licence is to keep paying for it.

WantNot collates findings by the person who holds them, then rolls each person up by department, role and user type. A user with six idle licences shows up as six lines under their name instead of six rows scattered through a ledger — and one conversation closes the lot of them at once.

That aggregation is the part Microsoft never builds.

It costs no extra permission: department, role and user type are attributes that already come back with the read-only user scope WantNot holds.

Ava Mercado ava@example.com · Finance Dormant $2,406/yr
M365 E3 never signed in Never signed in$720/yr
Visio Plan 2 dormant 90+ days Dormant$354/yr
Power BI Pro redundant — in M365 E3 Redundant$300/yr
Project Plan 3 dormant 90+ days Dormant$756/yr
Power Automate never signed in Never signed in$276/yr
M365 E3 3 seats, no assignee Unassigned$2,160/yr
M365 E3 dormant 90+ days Dormant$720/yr
Azure AD Premium P1 never signed in Never signed in$384/yr
Visio Plan 1 dormant 90+ days Dormant$204/yr
Financials Premium redundant Redundant$436/yr
M365 E3 1 seat, no assignee Unassigned$720/yr
Sales Enterprise never signed in Never signed in$792/yr

Sorted by who costs the most · $7,822 across the accounts shown

Totals that reconcile

A number nobody can re-derive is a number that will be argued. Every report is built so a reader armed with a calculator gets the same answer.

01

Summed from raw values, never from strings

Each finding rounds its own annual figure while the scan rounds the sum of the monthly ones — a dollar can differ legitimately. Totals are computed from the raw numbers, so a bottom line never lands a dollar under its headline.

02

A filtered table states both figures

When a view shows a subset — filtered, truncated, or per-person — the subset and the full total are stated separately. A bottom line that silently covers only the rows on screen would disprove the headline instead of proving it.

03

Spend change is read, not summed

The change in committed spend is the one column never totalled from rows. It is read from the endpoints directly, because a missing comparison would let the intermediate terms cancel and still total to a believable answer.

If the headline and the line items ever disagree by more than a dollar, the report says so out loud and names the gap, rather than hiding it. A mismatch found by the reader is a lost renewal.

What it can't see, it names

Every data source is missing something. A tool that quietly covers less than its reader assumes is the failure this product exists to avoid, so the gaps are part of the report.

01

Missing data is declared, not disguised

The usage report has no sign-in-blocked column; no export carries service plans; a missing licences file makes purchased counts unknowable. Each of those is said in the report that uses it.

02

A finding that can't be detected is still named

If a permission or attribute is missing, the affected finding type is reported as unavailable — the total visibly covers less, rather than pretending to cover everything.

03

Silent fallbacks speak

Every safe fallback — a missing hash key, a missing permission — emits a warning or a health field. There is no control that is believed to be on and is not.

Read-only, and that's enforced

Three permissions, all read. Nothing WantNot holds can change anything in a tenant.

01

Instant Audit — delegated, and gone when you are

Runs in the browser with your administrator sign-in. The access is held only while the tab is open, and nothing is stored anywhere.

02

Continuous — consent once, then read-only scans

An administrator grants app-level consent once; scans run nightly with the same three read scopes and nothing more.

03

Anything that writes is inert

The one capability that could change a directory exists but is disarmed. It is never triggered by a timer; a human initiates it, a preview always precedes it, and the plan must be confirmed before anything runs.

NUNAN VENTURES