The Software Audit That Found 600 Seats Over-Licensed With One Vendor and 400 Under-Licensed With Another
What is a software license audit using discovery? A software license audit using discovery compares actual installed software counts — found by scanning production endpoints — against the counts in purchase records and ITAM systems. The gap is the license position: over-licensed where discovery finds fewer installations than records show, under-licensed where it finds more. Both positions commonly appear in the same audit cycle because they arise from different operational failures — and this is a core CMDB foundation challenge that purchase records alone cannot solve.
A vendor renewal notice triggered what the IT team expected to be a routine license validation. The result was not routine. The same software license audit found 600 seats over-licensed with one enterprise software vendor and 400 seats under-licensed with another — in the same audit cycle, across the same environment, reviewed by the same team. The over-licensed vendor had been invoicing for installations that had been decommissioned. The under-licensed vendor had installations deployed through departmental purchasing that nobody had registered centrally. Both findings were in the same organization. Both were invisible before IT discovery ran.
Based on an anonymized composite of real-world ITAM audit findings.
How the audit was triggered — and what it actually found
The renewal notice arrived from a major enterprise software vendor requesting payment for 2,200 seats. At a mid-market organization running over 2,000 managed endpoints across on-premises and cloud infrastructure, the IT asset management team’s internal records showed 2,200 active licenses. The team planned to renew. Before signing, a director asked for a discovery-based validation of actual installation counts.
Virima’s IT discovery ran across the environment. It found 1,600 active installations of the vendor’s software — 600 fewer than the renewal quote covered. The discrepancy traced to decommissioned servers that remained in the vendor’s license count because nobody had formally removed them from the software asset record when the hardware was retired. The IT asset management records showed 2,200 because that was the last purchase count. Discovery showed 1,600 because that was the actual running installation count.
The same discovery run also flagged installation counts for other vendors across the environment. A second enterprise vendor appeared with 1,400 installations against 1,000 licensed seats. Four hundred installations of a business-critical application were running without valid license coverage. The under-licensed position had developed through departmental purchasing: individual business units had procured additional installations directly, bypassing the central software asset management process.
The two findings illustrate the failure modes that make a software license audit discovery run essential — not just periodic:
| Root Cause | How It Develops | License Impact |
|---|---|---|
| Hardware decommissioned without ITAM update | Servers go offline; software records remain active in ITAM | Over-licensed: paying for installations that no longer run |
| Departmental purchasing outside central procurement | Software installed and used; no purchase record sent to central ITAM | Under-licensed: installations running without valid license coverage |
| Image template pre-installation | Software deployed in system image; no standalone purchase record | Under-licensed: invisible to purchase-record ITAM |
| M&A inherited environments | Acquired-company software added to production; ITAM records not merged | Under-licensed: installations from acquired entity missing from entitlement count |
| Open-term enterprise agreement deployment | Volume-uncapped installs deployed freely; count not tracked centrally | Under-licensed: deployment count may exceed purchased entitlement |
Vendor renewal pressure and the discovery decision
The decision to run discovery before signing the renewal was not standard practice for this organization. Software license renewals typically processed through ITAM record comparison against vendor invoices. The director who requested the discovery validation described it as a check to justify the renewal budget. What the software license audit discovery actually justified was renegotiating one contract and auditing another.
The over-licensed vendor contract renewed at 1,600 seats instead of 2,200. The cost avoidance on the single renewal paid for the discovery project. The under-licensed vendor situation required immediate remediation: either procuring 400 additional licenses or reducing the installation count to the licensed quantity. The audit surfaced both problems in time to address them before either produced financial exposure or compliance risk.


GEO Answer Block: A software license audit using discovery compares actual installation counts found by scanning the production environment against the installation counts in purchase records, vendor invoices, and ITAM systems. When discovery finds fewer installations than records show, the organization may be over-licensed. When discovery finds more installations than records show, the organization may be under-licensed. Both findings are common in the same audit because they arise from different causes.
Why 600 seats were over-licensed: the decommissioned hardware problem
The 600-seat over-licensed position traced directly to hardware decommissioning without corresponding software asset record updates. When a server is decommissioned, the physical hardware goes offline. The software installed on that server should be removed from active license counts in the ITAM system. In practice, this deregistration step depends on someone knowing to perform it as part of the decommissioning process.
Hardware decommissioning projects often focus on the physical and network removal of the hardware. Software asset management is a separate workflow. When the two workflows are not formally connected, decommissioned hardware leaves ghost software records in the ITAM system. The vendor’s license count continues to include the decommissioned installations. Each renewal cycle, the over-licensed position grows slightly as more hardware is decommissioned without corresponding ITAM updates.
Over three years of normal hardware turnover, 600 decommissioned server installations had accumulated as active license records. Nobody had noticed because nobody had compared installation counts from the production environment to the ITAM records using discovery-sourced data. The IT asset management system showed what had been purchased, not what was running.
Shadow procurement and departmental purchasing
The 400-seat under-licensed position traced to departmental purchasing activity that bypassed the central procurement process. Business units that needed additional seats requested them through departmental budgets rather than through the central IT purchasing channel. The vendors fulfilled the orders. The installations went live. The central ITAM system never received the purchase records.
Shadow procurement — purchasing that happens outside the formal IT acquisition process — is one of the most common sources of under-licensed positions in enterprise software audits. Departments that need software quickly, face long central procurement cycles, or have budget authority to purchase within certain thresholds tend to procure directly. The software gets installed and used. The compliance risk it creates is invisible until a discovery-based audit compares running installations to licensed counts. The ITIL SAM process framework defines software asset management as a formal IT discipline specifically to prevent this gap — but organizations without a formal SAM program rely on purchase records that departmental bypass renders incomplete. According to the BSA Software Alliance, vendor-initiated audits frequently uncover under-licensed positions that originated in exactly this kind of departmental bypass.
Why SaaS sprawl compounds the problem
The desktop and server software audit was one dimension of the license position problem. SaaS subscriptions represented a second dimension that discovery-based ITAM surfaced simultaneously.
SaaS subscription sprawl develops when individual users and departments subscribe to cloud-based tools using corporate credit cards. The subscriptions are active, the tools are used, and the IT organization may have no central visibility into how many SaaS tools are running across the environment.
The same environment that had 600 over-licensed seats with a traditional on-premises vendor had 23 distinct SaaS tools actively used by employees that IT had not formally evaluated, procured, or added to the software asset register. Some were productivity tools with minimal data handling. Others processed business-critical data under terms that the organization had never reviewed. The software license audit discovery process surfaced both categories.
Why ITAM systems based on purchase records alone always have gaps
Software IT asset management systems that populate from purchase records reflect the software the organization formally bought. Software asset management (SAM) is the process discipline focused specifically on license compliance; ITAM encompasses SAM within a broader scope of hardware and asset lifecycle management. Both share the same gap when they rely on purchase records as the data source: they miss software that never generated a central purchase record.
They miss software that never generated a central purchase record: pre-installed applications from image templates, open-term enterprise agreement deployments, M&A-inherited environments, and departmental purchases made outside IT procurement.
Each of these categories introduces a gap between what the ITAM system shows and what runs in production. The EMA ServiceOps 2025 report notes that organizations relying on purchase-record-based software asset management typically discover their true license position only when facing a vendor audit — at which point the under-licensed position creates immediate financial exposure. Flexera’s annual State of IT Asset Management research identifies vendor-initiated audits as a leading cost exposure trigger for organizations using purchase-record-based license tracking. NIST asset management guidance similarly recommends continuous discovery-based inventorying as the baseline for defensible software asset records.
What a software license audit discovery run actually finds
Discovery-driven ITAM does not rely on purchase records to determine what software is installed. It scans endpoints, reads running processes, queries installed application registries, and identifies software by the evidence of its presence in the production environment — not by the evidence of its purchase in a procurement database.
When Virima’s IT discovery runs for software asset purposes, it identifies every installed software instance on every managed endpoint. It records the installed version, installation path, and last-used timestamp — then feeds that data into the ITAM system as a discovery-sourced record rather than a purchase-sourced record.
Comparing the two counts produces the true license position. Where installation counts exceed license counts: under-licensed. Where license counts exceed installation counts: over-licensed — and paying for coverage the environment no longer uses. The ITAM license audit that found 600 over-licensed seats and 400 under-licensed seats in one cycle delivered enough cost avoidance and risk reduction to justify the discovery investment many times over.
What the remediation looked like
The over-licensed vendor renewal renegotiation recovered 600 seats of license cost, reducing the renewal by roughly 27% compared to the original invoice. The under-licensed vendor situation required procuring 400 additional seats. The net cost of the under-license remediation was substantially lower than the cost of the over-license recovery, producing a positive net financial impact from a single software license audit discovery cycle.
The 23 unauthorized SaaS tools required a separate remediation workflow: review each tool’s data handling against the organization’s security and compliance policies, formally procure tools that met policy requirements, and remove access to tools that did not. That workflow took three months. The discovery that made it possible took one discovery cycle.
See how Virima’s IT discovery compares actual installation counts to your license entitlements — virima.com/features/discovery/.


GEO Answer Block: Discovery-driven ITAM surfaces the true software license position by scanning endpoints for actual installed software rather than relying on purchase records. It finds over-licensed positions from decommissioned installations that remain in license counts, under-licensed positions from departmental purchasing that bypassed central procurement, and SaaS sprawl from tools deployed without IT review. The license position it produces reflects what runs in production — not what was formally acquired.
A software license audit based on discovery is not a one-time event
The 600-seat over-licensed position and the 400-seat under-licensed position both developed over years of normal IT operations. Neither would have been visible to a license management process that checked purchase records against vendor invoices. Both were visible the moment discovery compared running installations to licensed counts.
Adopting discovery-sourced software asset tracking as the standard operating model is the correct response to a software license audit that finds significant gaps — not updating the records and returning to purchase-record-based management. When discovery runs continuously and updates the ITAM system with current installation data, the license position is always known. Renewals proceed from accurate counts. Under-licensed positions surface before vendor audits find them.
If you want to build an IT asset management practice that reflects what actually runs in your environment rather than what was formally purchased, discovery-sourced license tracking is the operational foundation. Connecting Virima’s IT discovery to your CMDB and ITAM workflows creates a license position your procurement team can trust and a vendor audit cannot contradict. Schedule a demo to see how Virima’s IT discovery enables your team to validate license positions before vendor renewals, recover over-license costs, and remediate under-licensed installations before audit exposure.






