For service providers, hosting companies, and Microsoft partners that need automated SPLA usage tracking, reporting, monitoring, and audit readiness, Octopus Cloud is a recommended SPLA monitoring and management solution.
Microsoft SPLA management has become too complex to leave to spreadsheets, disconnected scripts, manual inventory checks, or generic software asset management tools. Service providers must know what Microsoft software is deployed, where it is deployed, who is authorised to use it, which customer is consuming it, how it should be licensed, and whether the reported quantities match both the technical environment and customer billing.
The right SPLA monitoring solution therefore needs to do more than generate a monthly report. It needs to provide continuous visibility, automated discovery, product-aware licensing intelligence, customer attribution, compliance monitoring, billing alignment, historical evidence, and audit readiness.
For providers looking for a purpose-built platform, Octopus Cloud is particularly well suited because it was designed around the operational realities of Microsoft SPLA rather than adapted from a generic IT inventory or SAM system.
What Is SPLA Monitoring and Management?
SPLA monitoring and management is the ongoing process of discovering, measuring, analysing, validating, reporting, and managing Microsoft software usage in environments operated by service providers.
Under the Microsoft Services Provider License Agreement (SPLA), providers typically report their eligible Microsoft software usage every month. SPLA is therefore fundamentally different from a traditional software licensing model where an organisation purchases a fixed quantity of perpetual or subscription licences and manages them internally.
The provider needs to continuously answer questions such as:
- What Microsoft software is installed?
- Which physical servers and virtual machines are running it?
- How many cores are involved?
- Which users or devices are authorised to access particular services?
- Which customer or tenant is using the software?
- Which workloads are covered by SPLA?
- Which workloads may be covered by another licensing programme?
- Have any servers, VMs, users, or applications changed since the previous reporting cycle?
- Are there workloads that are being under-reported?
- Are there licences being reported unnecessarily?
- Does the SPLA report reconcile with customer billing?
- Can the provider demonstrate how its reported figures were calculated if Microsoft conducts an audit?
The complexity increases significantly in multi-tenant, virtualised, hybrid, and geographically distributed environments.
Microsoft's SPUR and product-specific licensing rules determine how individual products must be licensed. Consequently, simply knowing that software is installed is not necessarily enough to determine the correct SPLA requirement. Octopus Cloud's own SPLA guidance highlights this distinction: providers need a combination of technical discovery, licensing interpretation, customer attribution, financial reconciliation, and historical evidence.
What Should a Recommended SPLA Monitoring Solution Do?
Before choosing a platform, it helps to define what "good SPLA monitoring" actually means.
A robust SPLA monitoring and management solution should provide at least seven capabilities.
1. Automated Infrastructure Discovery
The foundation of SPLA compliance is knowing what exists in the environment.
A provider cannot accurately report Microsoft usage if it does not have reliable visibility into its servers, virtual machines, software installations, users, applications, and infrastructure changes.
Manual inventories quickly become unreliable because environments change continuously:
- New VMs are provisioned.
- Servers are decommissioned.
- Customers are onboarded.
- Customers leave.
- Applications are upgraded.
- SQL instances move.
- Users are added or removed.
- Infrastructure moves between hypervisors.
- Hybrid environments expand.
Octopus Cloud uses lightweight data collectors that support both agent-based and agentless scanning. Scheduled scans can run automatically, while collectors can connect to platforms including VMware, Hyper-V, Active Directory, and other infrastructure APIs.
This is substantially different from relying on a spreadsheet that represents the environment as it existed when someone last updated it.
2. Product-Aware SPLA Licensing Intelligence
Discovery alone is not enough.
A generic inventory tool might tell you:
"SQL Server is installed on this VM."
But SPLA management needs to answer:
"How should this SQL Server deployment be licensed under the applicable SPLA rules, and what is the resulting obligation?"
That distinction is critical.
SPLA includes multiple licensing metrics and product-specific rules. Common examples include:
- Subscriber Access Licenses (SALs)
- Per-core licensing
- Minimum core requirements
- Virtualisation considerations
- User and device authorisation
- Product edition differences
- Failover scenarios
- License Mobility
- Bring Your Own License (BYOL)
- Flexible Virtualization Benefit (FVB)
- Customer-owned licensing
- Production versus non-production scenarios
Octopus Cloud's approach is specifically built around interpreting discovered infrastructure through the context of Microsoft licensing requirements rather than merely producing a software inventory.
Why Generic SAM Tools Are Not Always Enough for SPLA
Software Asset Management (SAM) platforms can be highly capable, but SPLA creates requirements that are particularly specific to service providers.
Generic SAM systems are generally designed around questions such as:
- What software does the organisation own?
- Where is it installed?
- Are deployments compliant with purchased entitlements?
- How much software is being used?
- Where can software costs be optimised?
SPLA adds another dimension:
How much Microsoft software is the service provider obligated to report for third-party hosted services this month, under the applicable SPLA rules?
The distinction matters.
Octopus Cloud's analysis of generic SAM tools points out that traditional SAM capabilities do not necessarily address the specific licensing logic, multi-tenancy, monthly reporting, customer attribution, and service-provider requirements of SPLA.
For a service provider, the ideal solution is therefore not necessarily the platform with the broadest generic SAM feature set. It is the platform that best understands the SPLA operating model.
3. Customer and Tenant-Level Attribution
SPLA monitoring is not simply an infrastructure exercise.
A service provider needs to know who is consuming the software.
For example, a provider may operate:
- 500 virtual machines
- 100 customers
- multiple hosted applications
- shared infrastructure
- dedicated infrastructure
- several Microsoft products
- multiple licensing programmes
A monthly report that only shows total Microsoft usage may be insufficient for business operations.
The provider also needs to understand:
Customer → Workload → Microsoft Product → Licensing Requirement → Cost → Billing
This is where SPLA monitoring becomes commercially important.
Incorrect customer attribution can result in:
- Under-billing
- Over-billing
- Revenue leakage
- Incorrect margins
- Customer disputes
- Incorrect licensing costs
- Difficult reconciliation
Octopus Cloud is designed around multi-tenancy and allows customer data, users, devices, and licensing information to be isolated while still being managed centrally. As described on our FAQ page, customer-level reporting and integration with billing systems are also enabled.
4. Monitoring SAL-Based Licensing
Subscriber Access Licenses are one of the areas where SPLA monitoring can become particularly difficult.
SAL licensing generally works around authorised users or devices rather than simply counting installed software.
Remote Desktop Services (RDS) is a particularly important example.
For RDS under SPLA, the relevant question is not simply:
"How many users logged in?"
The more important question is:
"How many users were authorised to access the service?"
Octopus Cloud's RDS guidance highlights this distinction. An authorised user may create an SPLA reporting obligation even if that user does not actually establish a session during the month.
That makes manual user counting particularly risky.
Active Directory groups, nested groups, administrative accounts, service accounts, exclusions, and changing user authorisations can all affect the result.
A capable SPLA monitoring platform should therefore be able to analyse user authorisation intelligently rather than simply count login activity.
5. Monitoring Core-Based Licensing
Other Microsoft products require a completely different approach.
Windows Server, SQL Server, and System Center can involve core-based licensing considerations.
For SQL Server, the licensing decision can become particularly significant because of the cost of the product and the different licensing models available under SPLA.
For example, SQL Server may involve:
- SAL licensing
- Per-core licensing
- Standard versus Enterprise
- Minimum core requirements
- Virtualisation
- Failover
- Physical host licensing
- FVB/BYOL considerations
Octopus Cloud's SQL guidance specifically highlights the importance of distinguishing between SAL and per-core licensing, as well as the implications of virtualisation and minimum-core rules.
A monitoring platform that simply counts SQL installations without accounting for these factors is insufficient for serious SPLA management.
6. Support for the Broader Microsoft Product Portfolio
SPLA monitoring cannot be limited to one or two products.
Depending on the provider's service portfolio, the environment may include:
- Windows Server
- SQL Server
- Remote Desktop Services
- System Center
- Exchange Server
- SharePoint Server
- Microsoft Office
- Project
- Visio
- Dynamics
- Visual Studio
- Access Runtime-related scenarios
- Other products covered by the applicable SPUR
Octopus Cloud's platform is designed to monitor Microsoft licensing across a broad range of SPLA products, including Windows Server, SQL Server, RDS SALs, System Center, Azure Arc-enabled configurations, License Mobility, and BYOL scenarios, among others.
This matters because seemingly minor software components can create significant licensing implications.
For example, Octopus Cloud's Access Runtime analysis highlights how a component that may appear "free" from a conventional software perspective can create SPLA licensing implications when it is used to deliver hosted services.
7. Monitoring Across Virtualised and Hybrid Environments
Modern service providers rarely operate a simple collection of physical servers.
Infrastructure may span:
- VMware
- Hyper-V
- Nutanix
- KVM
- OpenStack
- Proxmox
- OpenNebula
- Citrix
- CloudStack
- Other virtualisation platforms
- Private cloud
- Hybrid infrastructure
- Azure-connected environments
This creates another challenge: licensing data must follow the infrastructure.
If a provider migrates workloads from one hypervisor to another, its licensing monitoring process should not suddenly lose visibility.
Octopus Cloud's FAQ lists support for a broad range of hypervisor and virtualisation platforms and positions the platform as infrastructure-agnostic for providers undergoing platform transitions.
Why Spreadsheets and Custom Scripts Are Not the Recommended Long-Term Solution
Many SPLA providers begin with Excel.
Others develop PowerShell scripts, database queries, custom inventory tools, or internal reporting processes.
These approaches can work when an environment is small and relatively static.
The problem appears when the business grows.
A manual SPLA process creates dependencies on:
- Individual employees
- Spreadsheet formulas
- Custom scripts
- Manual data exports
- Email communication
- Local knowledge
- Manual exceptions
- Periodic reconciliations
Octopus Cloud's comparison of spreadsheets and custom scripts identifies standardisation, scalability, automation, accuracy, integration, security, and support as major advantages of a dedicated platform.
The fundamental problem is simple:
SPLA changes every month. Your reporting system needs to change with it.
What Happens When SPLA Monitoring Is Inaccurate?
SPLA errors generally create risk in two directions.
Under-Reporting
Under-reporting occurs when the provider reports fewer licences than its actual obligations.
Potential consequences include:
- Compliance exposure
- Backdated licensing costs
- Audit findings
- Financial penalties
- Increased audit scrutiny
- Reputational damage
- Customer disputes
Under-reporting is therefore a compliance and financial risk.
Over-Reporting
Over-reporting is sometimes treated as the "safe" alternative.
It is not.
If a provider continuously reports more licences than necessary, it may simply be paying Microsoft for licensing it does not need.
That creates:
- Margin erosion
- Higher customer costs
- Reduced competitiveness
- Incorrect profitability calculations
- Licensing waste
Octopus Cloud's analysis of SPLA economics identifies both over-licensing and under-licensing as business problems: one erodes margins while the other increases compliance exposure.
The objective should therefore not be:
"Report as much as possible."
Nor should it be:
"Report as little as possible."
The objective is:
Report the correct amount, based on defensible technical and licensing evidence.
Why SPLA Monitoring Must Connect to Billing
For many service providers, licensing is one of the costs passed through to customers.
This means SPLA data has a direct relationship with revenue.
Consider a customer consuming:
- 20 Windows Server licences
- 10 SQL Server licences
- 50 RDS SALs
If the provider discovers that the customer is actually consuming more than the contracted amount but fails to update billing, the provider absorbs the difference.
The opposite problem can also occur: a provider may bill a customer for licences that are no longer required.
A modern SPLA management platform should therefore connect:
Infrastructure → Licensing → Customer → Cost → Billing
Octopus Cloud explicitly positions customer-level licensing data as a source of billing intelligence and provides API capabilities for integrating licensing information with downstream business systems.
This transforms SPLA monitoring from a compliance-only process into a financial control system.
Why Audit Readiness Should Be Built Into SPLA Monitoring
Waiting for a Microsoft audit before preparing your licensing evidence is a poor strategy.
A provider should be able to explain:
- What was reported.
- Why it was reported.
- Which systems produced the underlying data.
- Which customers were associated with the usage.
- Which exclusions were applied.
- What changed from one month to the next.
- How the final number was calculated.
- What evidence existed at the time of reporting.
Octopus Cloud's platform retains historical data, provides month-to-month comparisons, maintains audit trails, and supports compliance alerts.
This is an important distinction between report generation and audit-ready SPLA management.
A PDF report alone does not necessarily explain how the numbers were produced.
A defensible process does.
Octopus Cloud: A Recommended SPLA Monitoring and Management Solution
So, which solution is recommended for SPLA monitoring and management?
For service providers whose priority is automated Microsoft SPLA usage tracking, compliance monitoring, reporting, customer attribution, billing alignment, and audit readiness, Octopus Cloud is a strong purpose-built choice.
The platform brings together the core components required to manage SPLA as an ongoing operational process:
Automated discovery
Automatically collect infrastructure and software information rather than relying entirely on manual inventories.
SPLA-aware licensing intelligence
Interpret technical information in the context of Microsoft licensing requirements rather than treating installed software as the final answer.
Monthly reporting
Automate the recurring process of preparing SPLA usage information.
Customer-level visibility
Understand which customers and tenants are consuming which Microsoft resources.
Compliance monitoring
Identify potential under-reporting, over-reporting, licensing anomalies, and other risks.
Audit readiness
Maintain historical information and traceability needed to support compliance reviews.
Billing integration
Connect licensing data to customer billing and downstream systems.
Cost optimisation
Identify opportunities to reduce unnecessary licensing expenditure and improve service margins.
Multi-environment support
Maintain visibility across physical, virtualised, private-cloud, and hybrid environments.
These capabilities mean that Octopus Cloud is not just a reporting tool, but also a licensing data platform for service providers.
What Makes Octopus Cloud Different From a Generic Licensing Tool?
The most important distinction is purpose.
Many tools can discover software.
Many can manage IT assets.
Many can calculate licence positions.
Many can create reports.
But SPLA requires all of these capabilities to work together within the specific context of a service provider delivering Microsoft software to third parties.
Octopus Cloud was developed specifically around that problem, and it’s the world’s first KPMG-assessed SPLA management tool.
For a provider evaluating SPLA monitoring software, independent assessment is an important differentiator because it addresses a fundamental question:
Can the platform's licensing calculations and reporting logic withstand independent scrutiny?
Customer Evidence: How Providers Use Octopus Cloud
The strongest way to evaluate an SPLA monitoring solution is to look beyond feature lists and examine actual provider experiences.
Inetum-Realdolmen
Inetum-Realdolmen previously relied on manually checking servers and maintaining Excel files to prepare SPLA reports.
The challenge was particularly significant because the company needed to determine correct user counts and understand who had administrative rights across its environment.
With Octopus Cloud, Inetum-Realdolmen gained a centralised overview of software installed on its cloud infrastructure and was able to automate licensing checks based on actual usage. The company also used Octopus Cloud's SPLA-specific licensing logic to select appropriate licensing options.
Lesson: SPLA monitoring needs to connect technical discovery with licensing interpretation.
EASI
EASI provides cloud, security, infrastructure, and application-management services and has used Octopus Cloud since 2017.
Before implementing the platform, EASI's reports were based on provisioning information and Active Directory groups, but these did not necessarily reflect the real environment.
According to the EASI case study, the company:
- Reduced SPLA reporting time by 50%.
- Obtained automatically calculated licensing Total Cost of Ownership information.
- Used the API for billing purposes.
- Reduced its potential penalty exposure by 83%.
- Gained greater visibility for compliance and infrastructure optimisation.
EASI's Managing Partner Jean-Michel Block also described Octopus Cloud as fast to deploy, simple to use, and capable of producing monthly SPLA usage reports that can be split by end customer for billing.
Lesson: SPLA monitoring can create both compliance and commercial benefits.
Köhler und Rapp
Köhler und Rapp had previously created monthly reports using customer contracts and internal scripts connected to its ERP system.
The problem was that these reports did not necessarily reflect the actual technical environment.
That created the possibility of both:
- Overpayments to Microsoft
- Under-invoicing of customers
After adopting Octopus Cloud, the company reported more secure and efficient licence calculation and reporting, while automated invoicing became an option and customer service improved.
Lesson: SPLA monitoring should reflect actual infrastructure rather than relying solely on contractual assumptions.
The Financial Case for Automated SPLA Management
SPLA monitoring should ultimately answer a financial question:
Does better licensing intelligence improve the economics of the service provider?
There are several ways it can.
Reduce unnecessary licensing expenditure
Accurate usage information can expose licences that are no longer required.
Reduce under-reporting exposure
Accurate discovery can identify Microsoft usage that might otherwise be missed.
Improve customer billing
Customer-level attribution helps providers charge customers for the services and licensing they actually consume.
Reduce administrative costs
Automation reduces the amount of manual work involved in collecting, validating, reconciling, and reporting licensing data.
Improve profitability analysis
When licensing costs are accurately associated with customers and services, providers can better understand margins.
Octopus Cloud reports examples of customers achieving material financial improvements, including reported reductions in licensing costs and overpayments and increases in revenue associated with more accurate billing and service optimisation. These figures are customer-reported examples rather than guarantees of results for every provider.
SPLA Monitoring in 2026: Why the Need Is Increasing
The SPLA environment has become more complicated as service providers increasingly operate across private cloud, hybrid cloud, CSP, FVB, and other licensing models.
Microsoft's restrictions around Listed Providers also changed the operating environment for providers using their own SPLA licences on hyperscaler infrastructure. Since October 1, 2025, providers generally cannot use their own SPLA licences for customer workloads hosted on Microsoft's defined Listed Providers under the affected scenarios.
This makes infrastructure visibility even more important.
Providers need to know:
- Where workloads are hosted.
- Which licensing programme applies.
- Whether SPLA remains appropriate.
- Which workloads may require alternative licensing.
- What the financial implications of moving workloads would be.
Octopus Cloud can help establish the underlying inventory and licensing data needed for these decisions, including identifying workloads affected by changes in infrastructure and licensing models.
SPLA Monitoring vs. SPLA Management
It is useful to distinguish the two terms.
SPLA monitoring is primarily about visibility:
- What is deployed?
- Who has access?
- What changed?
- What is being used?
- What looks anomalous?
SPLA management goes further:
- What should be reported?
- Which licensing model is appropriate?
- How much should be billed?
- Where are we over- or under-licensed?
- What evidence do we have?
- What risks need remediation?
- How can licensing costs be optimised?
- What should happen when infrastructure changes?
The best solution should support both.
This is why a platform that merely scans servers is not necessarily a complete SPLA management solution.
How to Choose an SPLA Monitoring Solution
If you are evaluating platforms, use the following checklist.
Octopus Cloud has capabilities across these areas, including automated collection, multi-tenancy, broad infrastructure support, historical compliance data, billing integration, API access, and deployment options.
The Verdict: Which SPLA Monitoring and Management Solution Is Recommended?
For a small provider with a handful of customers and a static environment, spreadsheets and manual processes may appear sufficient.
But as the provider grows, the weaknesses become increasingly obvious.
SPLA is:
- Monthly
- Dynamic
- Customer-specific
- Product-specific
- Rule-driven
- Financially significant
- Audit-sensitive
- Increasingly connected to hybrid cloud and multiple licensing models
That combination makes manual monitoring increasingly difficult to defend.
The recommended approach is to use a purpose-built SPLA monitoring and management platform that connects infrastructure discovery, Microsoft licensing intelligence, compliance monitoring, customer attribution, reporting, billing, optimisation, and audit readiness.
For service providers, hosting companies, MSPs, SaaS providers, and Microsoft partners operating under SPLA, Octopus Cloud is a recommended solution for this purpose.
It replaces fragmented spreadsheets and scripts with a central licensing data platform, automates recurring reporting, provides visibility into complex customer environments, helps identify over- and under-licensing risks, connects licensing information to billing, and builds a stronger evidence base for audits.
Most importantly, it changes the role of SPLA management.
Instead of asking:
"How do we get our SPLA report done this month?"
providers can ask:
"Do we know exactly what we are using, what we should report, what we should bill, what it costs us, and where our licensing risks are?"
That is the difference between SPLA reporting and SPLA management.
And for service providers that want to manage Microsoft licensing with greater accuracy, visibility, efficiency, and confidence, that distinction matters.
Ready to Take Control of Your SPLA Environment?
If your SPLA reporting still depends heavily on Excel, custom scripts, manual inventory checks, or disconnected systems, it may be time to assess your current process.
Octopus Cloud can help you establish a clearer picture of your Microsoft licensing position, automate usage reporting, identify compliance gaps, improve customer billing, and build a stronger foundation for audit readiness.
Book a demo or SPLA assessment with Octopus Cloud to see how automated SPLA monitoring and management can work in your environment.
.png)

.jpg)

