How it works

A Windows app reads. The portal prices. You decide what to release.

The app signs in to your tenant as you and reads licenses, users, guests, sign-in activity and mailboxes; it never writes. The portal runs the eleven checks, prices every finding, builds the report and keeps every run, so the figure can be watched over time.

01

Sign in and run

Start the app on a Windows computer and press Run. It opens Microsoft's own sign-in page for your administrator account and shows a consent card that names each permission it asks for: read permissions only. When consent is granted, the app reads the tenant, seals the run on your computer and uploads it to your workspace.

  • Signing in never starts a run by itself; the run starts when you press Run.
  • Sign-ins stay in memory on your computer and are never sent to the portal.
  • The shared-mailbox check reads Exchange Online with the same administrator sign-in.

Consent card

Granted: 5 of 5

Example
Read permissionsasked on Microsoft's sign-in page
PermissionWhat it reads
Organization.Read.Allsubscriptions, purchased and assigned units
Directory.Read.Alllicenses, service plans, assignment states
User.Read.Allusers, guests, account state, creation date
AuditLog.Read.Allsign-in activity
Reports.Read.Allusage, optional

Plus the Exchange Online administrator read for shared, room and equipment mailboxes. No write permission.

02

The portal runs the checks and prices the waste

Every check is decided from the run document: unassigned units per subscription; overlaps from the service plans of your own subscriptions, not a hand list; disabled, stale and never-activated users from the account state and the sign-in activity; guests; mailboxes holding a license; assignments in error; add-ons without their base. Each finding is priced at Microsoft's list price for its SKU, or at the price you typed in for the tenant.

  • The list price table is a signed data file the portal checks at startup; its version and as-of date are on the report. The app never sees a price.
  • Your own price per SKU per tenant (a CSP price, an enterprise agreement price) wins over the list; the report says which figures use it.
  • A SKU the table does not know shows "price not known" and counts as zero until you type a price.

Check 2 · Overlapping licenses

2 users, $44 a month

Example
One SKU's service plans cover the other'sfrom the service plans of your subscriptions
UserHoldsDropA month
Ana RuizBusiness Premium + E3Business Premium$22.00
Daniel KimE3 + Exchange Online Plan 1Exchange Online Plan 1$4.00
Sofia BergE3 + E5 (E5 covers E3)E3$36.00

What to do: remove the covered SKU from the user, or from the group that assigns it.

03

Read the report, export it, fix it in the admin center

The first page is the savings card: potential savings a month and a year, with three headline counts beside it. Under it, one section per check with its monthly cost, its count, and the users or subscriptions with the facts that put them there: the SKU, how it was assigned, the last sign-in, the state. Each section ends with a "what to do" line: release the license, remove from the group, convert to a shared mailbox.

  • CSV per section and a PDF of the whole report with the tenant's name, the date and the run id.
  • The fixing is yours, in the admin center. The product has no write permission, so nothing happens in the tenant until you do it.
  • Run again after the cleanup and watch the figure fall.

Potential savings

Example

$1,842 a month$22,104 a year, at Microsoft's list prices

contoso.onmicrosoft.com · run of Oct 9 · list price table 2026.10, as of Oct 1

  • 23unassigned licenses
  • 11licensed users disabled or stale
  • 4overlapping licenses

Read-only. Nothing in the tenant was changed.

04

Watch it over time

Every run is kept as a record. The dashboard is the same page kept over time: the newest run, a trend line of monthly waste per run, and "since last run": what was fixed, what is new, what is unchanged. With Watch and MSP, runs are scheduled, weekly by default and daily at most, as a Windows task on a computer you choose, with an app registration your organization owns and a certificate whose private key stays on that computer.

  • A mail to the owners when the waste figure moves by more than your threshold ($100 or 20 %, whichever is larger, by default).
  • A mail when a subscription or a trial comes within 60 days of its end.
  • History kept 400 days with Watch and MSP; 30 days with the Preview and the One-time report.

The dashboard · monthly waste per run

Down $568 since August

Example
  • Since last run: 3 fixed
  • 1 new
  • 7 unchanged
For managed service providers

One workspace, many tenants, one table.

One Windows app, one sign-in per tenant by your administrator account on Microsoft's own page, or the tenant's own app registration for scheduled runs. Each tenant is registered by the app and confirmed by a member on the pairing page. The workspace dashboard is a table of tenants with their waste figure and last run: the page you sell from.

Two parts

What runs where.

The split is deliberate: whatever signs in to your tenant runs on a computer you control, and nothing anywhere writes to it.

The Windows app, on your computer

Signs in to Microsoft as you, reads licenses, users, guests, sign-in activity and mailboxes, seals the run and uploads it. Runs scheduled runs as a Windows task. Sign-ins stay in memory and are never written to disk. It never receives a price and never runs anything the portal tells it to.

The portal, in your browser

Holds your workspace, your team and every run of every tenant, encrypted at rest. Runs the checks, prices the findings, builds the report, the CSV and the PDF, keeps the history and the trend, and sends the alerts. It holds no credential for your tenant and cannot sign in to it.

GlacierPoint Scan finds configuration weaknesses and sets priorities; GlacierPoint Snapshot preserves configuration history and recovers supported settings; GlacierPoint Ledger reads the licenses and seats and prices what is unused.

Try it on your own tenant.

The free Preview runs every check on one tenant, up to 3 times, with the savings card and every count and cost. You need a Windows computer and an administrator account for the tenant.