Microsoft Insights
18 min
\[this article has recently been published and is subject to change ] overview the data found in this report is populated from shield data will not be available unless you have deployed shield into your environment for instructions on how to install shield, see how to install shield docid 1svdkqczbszh97g7 a6qg for more information about shield, see shi environment lockdown and defense (shield) https //www shi com/it lifecycle services/software lifecycle management/shield the integration between shi one and microsoft gives you incredible visibility into your tenant the platform displays numerous metrics and advanced insights, all in one place the insights tell you what users are actively using, what is being consumed, and what service plans are enabled in your environment to put it simply, this report is designed to guide you in answering what do i own? what are users consuming? what do i do with this information benefits complete visibility and control gain a comprehensive view of which features are being used by users, administrators and systems instantly identify what licenses and capabilities your organization owns and see exactly how they are being consumed proactive compliance and risk management easily spot discrepancies between assigned, consumed, and purchased licenses microsoft insights helps you quickly detect over consumption, reducing compliance and financial risks by revealing when usage exceeds entitlements actionable usage intelligence track user assignments, monitor feature adoption, and unlock detailed consumption patterns this gives you the ability to optimize license allocation, address gaps, and make informed decisions to maximize your microsoft investment sign in go to shi one https //one shi com/ https //one shi com/ sign into shi one using one of the available options and complete the login we recommend signing in with microsoft once you are signed in, click assessments in the left navigation click microsoft insights feature level usage reporting top level metrics top level metrics for microsoft insights the featured metrics at the top display common subscriptions along with the monthly active users (mau), assigned licenses, and purchase licenses the metrics at the top display immediate insights into the most common microsoft service plans by comparing the number of monthly active users and assigned licenses to the number of purchased licenses, you can easily see if your organization is compliant or not subscription type the specific microsoft subscription plan that is being used (e g , microsoft 365 e3) monthly active users (mau) users who actively use the service within the monthly period assigned the number of licenses that have been assigned to an endpoint endpoints are physical devices such as desktop computers, virtual machines, mobile phones, embedded devices, and servers that connect and exchange information with a computer network purchased the number of licenses that have been purchased by your organization, typically through an agreement example in the example above, microsoft 365 e5 has 341 monthly active users, is assigned to 348 endpoints, and there are 350 licenses purchased in this situation, the organization is in good standing because there are 350 purchased licenses, while only 348 have been assigned it's also important to note that of the 348 assigned licenses, only 341 have been used during the reporting period, which means there are 7 licenses underutilized individual usage reports filters the filters at the top of the individual reports allow you to filter users by license by default, the report will be filtered to all users , but you can click on the drop down menu and select any service plan that appears, even unassigned users filters can help you quickly answer questions like are users with e3 licenses using e5 capabilities? are users with e3 licenses in scope for e3 features? columns the reports section breaks down each capability tier into a single column each column has its own set of feature groups, along with the associated features some examples include identity & access conditional access (risk based), identity protection (risk policies), privileged identity management threat protection endpoint detection & response, identity theft protection, cloud app discovery & session control core apps microsoft teams, exchange online, onedrive for business, microsoft 365 apps for enterprise security & compliance safe links / attachments / anti phishing, sensitivity labels (manual) device management device compliance, device management & configuration profiles, app protection policies feature numbers next to each feature you will see summary of the feature in your environment the structure is mau / in scope / purchased mau (monthly active users) users who actively use the service within the monthly period in scope users who have the service plan enabled in their license profile purchased the number of licenses that have been purchased by your organization to understand this information, consider the following two examples example 1 endpoint detection & response feature usage purchased licenses the organization owns 210 licenses for the endpoint detection & response feature endpoints enabled this feature has been enabled on 152 devices or endpoints monthly active users there are 134 people actively using the feature each month in this example, the organization is not overconsuming the endpoint detection & response feature, since active usage ( 134 ) and enabled endpoints ( 152 ) are both below the number of purchased licenses ( 210 ) however, this organization may have more licenses than needed ideally, the number of purchased licenses should closely match the number of endpoints enabled and users actively using the feature it's also important to note that having too many unused licenses may lead to unnecessary costs example 2 identity theft protection feature usage purchased licenses the organization owns 210 licenses for the identity theft protection feature endpoints enabled the feature has been enabled on 275 devices or endpoints monthly active users there are 220 people actively using the feature each month in this example, the organization is overconsuming the identity theft protection feature, since active usage ( 220 ) and enabled endpoints ( 275 ) are both greater than the number of purchased licenses ( 210 ) in other words, this organization is using more licenses than it has purchased and may face issues down the road warnings a warning appears when you have more users using a feature than the number of licenses you have purchased in these situations, we recommend reaching out to your shi representative, who will be able to assist you sometimes, you might notice that the number of monthly active users is higher than the number of users "in scope " this is not an error; it's simply a result of how microsoft calculates and reports these metrics license types you can drill further into each feature to see the associated license type by clicking on the feature this section shows you what license type is consuming the feature example in the above screenshot, we are viewing usage for all users , and want to take a closer look at the identity protection (risk policies) feature, since the bar is red when we click on the feature, we can see it is associated with the following license types in the environment m365 e5 m365 e3 ems e5 / entra p2 add ons m365 e3 m365 f3 unassigned for the first two license types ( m365 e5 & m365 e3 ems e5 / entra p2 add ons ), feature usage is less than or equal to the number of licenses purchased in this case we can see the following breakdown m365 e5 320 in scope 350 purchased ✅ m365 e3 ems e5 / entra p2 add ons 270 in scope 270 purchased ✅ however, for the other three license types ( m365 e3 , m365 f3 , unassigned ), feature usage is greater than the number of licenses purchased in this case, we can see the following breakdown m365 e3 480 in scope 0 purchased ❌ m365 f3 100 in scope 0 purchased ❌ unassigned 10 in scope 0 purchased ❌ in total, the feature is being used on 1,180 devices, but the organization has only purchased 620 licenses to resolve this, there are two options purchase more licenses to cover all usage reduce the number of devices using the feature to match the number of licenses owned not every feature displays the associated license type however, you will still be able to see monthly active users ( mau ), the number of endpoints with the feature enabled ( in scope ), the number of licenses owned ( purchased ) activity microsoft insights considers a feature in use when a qualifying activity is detected within the selected reporting period activity is categorized into one of three usage types; system , user , and admin system (s) automatically generated by microsoft examples policy checks, compliance, security monitoring, etc user (u) activity created by users interacting with microsoft features examples sending emails, joining meetings, opening files, applying sensitivity labels, etc admin (a) activity performed by administrators managing or reviewing microsoft features examples role activations, audit searches, policy changes, investigations, etc every feature will have an associated activity some features only have one activity, while others may have more than one a feature is considered "active" even if its activity is background or administrative in nature, if qualifying telemetry exists during the reporting period some products are measured primarily through user driven actions others reflect value through system driven and admin driven activity some examples include user driven teams exchange sharepoint system & admin defender for identity conditional access intune data loss prevention (dlp) data unavailable the first phase of microsoft insights is pulling in data if you have successfully installed shield, you should see data for the following sections entra id p1 entra id p2 defender for identity if data is not available in the platform or certain columns are grayed out, it is likely due to one of the following reasons shield not installed if shield is not installed in your environment, the system will not be able to display any insights in the report for steps to install shield, see how to install shield docid 1svdkqczbszh97g7 a6qg if you need help, email microsoftinsightshelp\@shi com mailto\ microsoftinsightshelp\@shi com permissions not granted the microsoft graph reports api requires the reports read all permission to be granted for the workload to resolve this issue, make sure the required api permissions have been consented to the entra id or reach out to the user who oversees granting permissions api access not available or enabled this may be because the api has not been turned on yet or does not exist (such as a non public api access) organization does not have service plan or license if a service plan or license is not active for the relevant microsoft products, the system cannot retrieve or display usage information in the report in this situation, you should check to confirm your organization's current service plans and licenses glossary monthly active users (mau) users who actively used or benefited from the service during this period return on investment (roi) a performance metric used to evaluate an investment in scope users who have the service plan enabled in their license profile assigned the number of licenses that are assigned to an endpoint purchased the number of licenses owned by your organization in use qualifying activities are detected within the selected reporting period system driven automatically generated by microsoft user driven activity created by users interacting with microsoft features admin driven activity performed by administrators managing or reviewing microsoft features service plans bundles of features and capabilities grouped together under a single license or subscription service plans define what functionalities are available to users in the organization feature sets collections of related features that work together to deliver specific functionality or address a particular business need feature sets typically focus on a core area, such as security, collaboration, or device management consumption the actual usage of features or services by users, devices, or systems in an environment it measures how much of the licensed capabilities are being actively used capability tiers different levels or categories of features, often organized by complexity or value higher tiers generally include all features from lower tiers, plus additional advanced capabilities