Shared Workstations: The E3 Licences Your Audit Will Never Find
Every licence audit has a blind spot, and it's shaped like a shared PC.
Run any over-provisioning report and it asks the same question: does this person use desktop apps? If yes, they need a plan with desktop apps. Reception staff, warehouse crews, ward nurses and site teams all answer yes — Word and Excel launched on the machine they share. So they stay on E3, year after year, and no report ever flags them.
But the desktop entitlement isn't theirs. It belongs to the machine.
Why the usual reports miss it
Microsoft's usage reports and most third-party tools tell you which apps a user touched and on which client — desktop, web or mobile. What they don't tell you is whose machine it was.
A warehouse supervisor who signs in to a shared terminal for twenty minutes a shift generates the same "desktop Office" signal as a developer on a dedicated laptop. The activity is identical. Only the ownership differs, and ownership is the part nobody measures.
This matters because desktop apps are the single most expensive fork in Microsoft 365 licensing. It's most of the gap between E3 and E1, and it's the gate every downgrade recommendation runs into.
Finding shared machines in data you already have
Entra sign-in logs carry a device object on each event — device ID, name, operating system, and whether it's managed. It ships with the same permission you already need to read sign-in logs, so there's usually nothing new to consent to.
Aggregate those events per device rather than per user and shared machines announce themselves: twenty-six people on one workstation over ninety days is not somebody's laptop.
Three warnings, all of which will bite you.
Microsoft redacts identifiers
Sign-in logs sometimes return the literal string {PII Removed} in place of a device ID. Every redacted event carries the same string, so a naive count collapses them all into one phantom machine — which then looks like the most heavily shared device in the tenant, because it has more distinct users than anything real.
Filter it out and count those events as unattributed. Then report your attribution coverage, because a device inventory built from 60% of sign-ins is a floor, not a census.
Counting distinct users is the wrong test
The obvious rule is "three or more people used it, so it's shared." That rule decays. Distinct-user counts only ever grow as your evidence window fills, so given ninety days every laptop eventually collects a colleague, an IT technician and a covering manager — and gets flagged.
The better test is whether anyone owns the machine. Work out what share of sign-ins belongs to the busiest user. Above roughly 70% it's a personal device with visitors, however many distinct names appear. Below 20–30% with a dozen users, nobody owns it.
In one 800-device tenant, that single change reclassified 80 machines from "shared" back to "personal" — about a quarter of everything the distinct-user rule had flagged.
One person, several shared machines
If someone floats between three shared terminals, don't count their potential saving three times. Attribute each user to the machine they use most, or your tenant-wide total becomes fiction. This is the same discipline that makes deduplicated savings figures trustworthy.
The licensing question is harder than the detection
Finding the machines is the easy half. Deciding what to put on them is where it gets expensive if you rush.
Office 365 E1 has no desktop Office at all. If the shared PC runs installed Word and Excel, E1 alone breaks it. You need a plan that includes the apps, which means Shared Computer Activation — and SCA support differs between the business and enterprise editions of Microsoft 365 Apps. Without it, every user signs in and out of Office on that machine, and your rollout dies on day one from support tickets.
Business-family plans cap at 300 seats per tenant. Not 300 users — 300 seats of those SKUs. Large tenants can run them legitimately, but the cap is real and you can hit it mid-rollout.
Check whether your "device" licence is actually sold per device. Defender for Endpoint, for example, is licensed per user in most commercial agreements. That completely changes the arithmetic: instead of downgrading users and buying one machine licence, you downgrade users and keep buying a per-user add-on. The amortisation you were counting on across five people sharing a terminal simply isn't there.
Ask your reseller the specific question before you model it: can I license this per device for a shared workstation, or do I need a licence for every person who signs in?
Do the maths per machine, not per user
The two halves are one number. A shared machine only saves money if what its users stop costing exceeds what the machine starts costing:
- Total what the machine's users cost today — their actual assigned licences, priced.
- Total what they'd cost on the target plan — including any add-ons they keep.
- Add any per-machine licence, once, not per person.
- Compare. If the net is small, don't do it.
That last step is the one people skip. A machine with two users and a modest gap isn't worth the relicensing, the support tickets and the change record. Four people on one terminal moving off a premium plan usually is.
Be honest about unpriced SKUs too. If half the licences a user holds have no cost recorded, your "current cost" is a floor and your saving is understated — which is better than the reverse, but only if you say so.
A worked shape
A mine site with 800 devices and 1,175 licensed staff. Distinct-user counting flagged 306 shared machines; the ownership test cut that to 226 real ones. The genuinely shared terminals carried 20–26 users each with no user above 35% of sign-ins.
The staff on those machines had never appeared in a single over-provisioning report, because every one of them showed desktop Office activity. They weren't waste in the usual sense — they were correctly licensed for a machine that wasn't theirs.
Where to start
You don't need tooling for the first pass. Pull thirty days of sign-in logs, group by device, and look at anything with more than five distinct users and no dominant one. Then check what those people are licensed for. If they're on a premium plan and they only ever touch a shared terminal, you've found something your last three audits missed.
SeatPrune builds this device picture from sign-in history automatically, applies the ownership test, and shows the per-machine break-even with both halves — what the users stop costing and what the machine starts costing. It'll also tell you when a machine isn't worth touching, which is the part that makes the rest believable.
Add it to your pre-renewal audit alongside the usual suspects. Shared workstations won't be the biggest line in your savings report. They'll be the one nobody else found.
Ask who owns the machine, not how many people used it. A laptop three colleagues borrowed is still a laptop. A terminal twenty-six people share belongs to nobody — and shouldn't be licensed as though it belongs to everyone.
Find out what your tenant is wasting
SeatPrune audits your Microsoft 365 licenses and prices every finding in $/month. Free up to 200 users.
Start Free