Join our Newsletter — 33% off our NHI Course

Why do unused licences become an identity governance issue?

Unused licences are dormant entitlements. If teams do not reclaim them during leaver processing, role changes, or periodic reviews, the organisation loses control over both cost and access hygiene. That makes licence recovery part of identity lifecycle management, not just software asset management.

Why dormant licences turn into an access-governance problem

Unused licences are not just a commercial waste item. They represent access that was granted once and then left to linger, which means the entitlement itself can outlive the need for it. In practice, that pushes licence management into the same control space as access governance, because someone still has to answer whether the entitlement should be retained, reclaimed, or retired.

That matters because entitlement drift usually grows quietly. If a licence is not tied to a clear owner, expiry rule, or review cadence, it can remain active long after the original business need has changed. IAM and IGA Basics is a useful reference point here because it frames entitlement management as a lifecycle discipline, not a one-time provisioning step.

The governance issue is therefore not the licence record itself, but the control failure that allows dormant access to remain outside normal leaver, mover, and review processes. Once that happens, the organisation loses visibility into who still benefits from the entitlement, whether the access is still justified, and whether the licence pool reflects current business reality.

Where the hidden risk sits in licence recovery

The risk is usually cumulative rather than dramatic. A single unused licence may look harmless, but across teams it can indicate weak joiner-mover-leaver handling, poor ownership, or review fatigue. That is why licence recovery belongs with access certification and role hygiene, not only with procurement or software asset tracking. Access Reviews and Certification Guide helps show why unused access should be closed out through a governed review process.

Unused licences can also conceal broader entitlement sprawl. If reclaimed access is not actually revoked, or if a user keeps access through a duplicate account, role copy, or exception, the organisation may believe the licence was recovered while the access path remains live. Joiner-Mover-Leaver (JML) Guide is relevant because licence recovery becomes reliable only when it is linked to the same lifecycle events that create and remove access.

For teams managing many roles and entitlements, the practical danger is role bloat. A licence that is never reclaimed often points to a role that is too broad, too sticky, or too loosely owned. Role Mining and Role Design Guide is a strong companion for understanding why dormant licences are often a symptom of deeper role design issues.

What good licence governance looks like in practice

Healthy practice treats unused licences as a control signal. They should be owned, reviewed, and reclaimed through a defined process, with clear handoff between IT, application owners, and identity governance teams. IGA Buyer’s Guide is useful because it reflects the operational reality that lifecycle, requests, reviews, and connectors need to work together if entitlements are to stay clean.

Practitioners should also distinguish between cost recovery and access recovery. Reclaiming a licence to save budget is helpful, but the security value only appears when the entitlement is actually removed, recertified, or reissued under a current business need. That is why dormant licence cleanup should be measured as an identity hygiene activity, not just a finance exercise.

At scale, the key question is whether unused entitlements are being detected early enough to prevent accumulation. If the organisation can show that licence recovery is triggered by leaver events, mover events, and periodic access reviews, then licence sprawl becomes manageable. If not, dormant licences will keep expanding the gap between what the business thinks is assigned and what the access layer still allows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Unused licences are dormant entitlements that require ongoing account and entitlement management.
Recommendation — Track unused licences as account sprawl and remove or reclaim access through account-management workflows.
NIST SP 800-53 Rev 5 AC-2 — Account Management Licence recovery is part of managing account lifecycle, inactive access, and revocation.
AC-6 — Least Privilege Unused licences often indicate access that exceeds current need and should be reduced.
Recommendation — Revoke dormant entitlements through AC-2 lifecycle reviews and removal actions. Reduce standing access to the minimum needed and remove licences that no longer serve an active role.
ISO/IEC 27001:2022 A.5.16 — Identity management Dormant licences are an identity governance issue because they reflect unmanaged entitlement lifecycles.
A.5.18 — Access rights Unused licences still represent access rights that should be reviewed and withdrawn when no longer required.
Recommendation — Maintain ownership and lifecycle control over licences and entitlements. Review access rights regularly and withdraw licences that are no longer justified.
CSA Cloud Controls Matrix IAM — Identity & Access Management Licence recovery is an IAM governance activity because it governs entitlement assignment and removal.
Recommendation — Align licence cleanup with IAM processes for provisioning, review, and deprovisioning.

Practitioner Guidance

What to verify: Confirm that every reclaimed licence is tied to an actual entitlement change, not just a ticket closure or cost-saving action. If the account still exists, the role still grants access, or a secondary path remains active, the governance problem has not been solved.

Decision rule: If the licence can confer access to a production or regulated system, treat recovery as a lifecycle control first and a budget control second. If it is tied to a low-risk tool with no meaningful access consequence, the process can be lighter, but it still needs ownership and expiry logic.

What practitioners underestimate: Dormant licences often persist because no single team feels accountable for them. The strongest programmes make reclaim decisions part of the same review cycle that handles movers, leavers, and periodic entitlement certification.

Practitioner takeaway: The governance issue is not that licences cost money when unused, it is that unused entitlements reveal where access can outlive need unless lifecycle controls are explicitly closing the loop.