What you are probably paying for twice in Microsoft 365
Most organisations run third-party tools that duplicate something already included in the licence they hold. Here is where the overlap usually sits.
Microsoft 365 licensing is difficult to reason about for a structural reason: the bundles are assembled from components that are also sold separately, the components are renamed regularly, and nobody in the organisation owns the question of what is already included.
The result is consistent. Organisations buy a bundle, deploy a fraction of it, and separately pay for third-party products that duplicate what they already own.
This is not an argument that the Microsoft component is always better. Sometimes it is clearly worse. It is an argument for knowing which decision you are making.
Where the overlap usually is
Device management. Intune is included in the business and enterprise bundles that most organisations already hold. Environments running a separate MDM alongside a licence that includes Intune are common. Sometimes that is the right call — the third-party platform genuinely does something Intune does not, particularly for complex or mixed fleets. Sometimes it is inertia and nobody has checked.
Multi-factor authentication and conditional access. Basic MFA is available to every tenant. Conditional Access requires a specific licence tier, but that tier is inside several common bundles. Organisations paying separately for an MFA product while holding a licence that includes Conditional Access are paying twice for a weaker outcome, because the built-in version integrates with device compliance and the bolt-on does not.
Email security. The bundles include a mail filtering and attachment-detonation layer. Many organisations run a third-party secure email gateway in front of it as well. That can be a deliberate defence-in-depth decision. It is more often historical, from before the included capability existed.
Endpoint protection. Microsoft’s endpoint detection is included at the higher tiers. It has become genuinely competitive, and paying for a separate EDR product while holding that entitlement is worth a conscious decision rather than a renewal.
Information protection and labelling. Sensitivity labels and data loss prevention are included at the tiers most enterprise and government customers hold, and are deployed in a minority of them.
Telephony and meetings. Overlap here is usually the other way: organisations pay for a conferencing product and a phone system that the bundle would cover, or hold voice entitlements they never enabled.
Backup. The one place there is no overlap, and where people assume there is. Microsoft 365 is not backed up by Microsoft in the sense organisations mean. Retention is not backup, and if you are not paying for something here you are almost certainly exposed.
Why this persists
- Renewals are handled as a line item, not as a review. The question asked is “same again?” rather than “what does this include now?”
- The bundles change underneath you. Capabilities move between tiers and get renamed. A comparison done two years ago is not current.
- Nobody owns the whole picture. Security owns the security tools, infrastructure owns the platform, procurement owns the contract, and the overlap sits in the gaps between them.
- Per-user licences are assigned and never revoked. Departed staff, shared mailboxes with full licences, and service accounts on premium tiers accumulate quietly.
How to actually check
Start with the entitlement, not the spend. List what your current licences include, tier by tier, from the current documentation rather than from memory. This is dull and it is where all the value is.
Then list what you pay for separately. Every security, management and productivity product with its own invoice.
Intersect the two. Each overlap gets a decision: keep the third party for a stated reason, or retire it. “We have always had it” is not a reason, and neither is “the Microsoft one is not as good” without someone having looked recently.
Audit assignment separately. Licences on departed users, premium tiers on service accounts, and shared mailboxes over the free threshold. This is usually the fastest saving available and it needs no product decisions at all.
Then check what you own and have not deployed. This is where the real return is. Conditional Access, sensitivity labels and device compliance are frequently sitting unused in a licence that has been paid for over several years.
The honest caveat
Consolidating onto one vendor is a concentration decision, not just a cost one. A single identity, management and security stack from one provider means a single vendor incident affects all of it at once. That is a legitimate reason to keep a second product, and it is a better reason than the one most organisations are actually running on, which is that nobody has looked.
More on how we run a Microsoft 365 workplace, and on what Microsoft 365 does not protect.