A global healthcare institution with more than 94,000 employees and over 80,000 Microsoft 365 mailboxes had rolled out Microsoft 365 before the pandemic. The rollout moved fast, but governance did not keep up.
By 2022, the organization was running a mixed license estate across F3, E3, and E5 tiers, with no reliable way to track which licenses were in use, who actually needed them, or when provisioned access had gone stale.
Teams had grown without oversight. Users held licenses for products like Visio and Project that they had not touched. Provisioning and deprovisioning happened, but not in any consistent or auditable way.
In a healthcare environment, that is more than just an efficiency problem. Unused licenses with persistent access rights are an exposure. Unmanaged Teams provisioning creates ungoverned data repositories. When you cannot see who has access to what, you cannot control it, and you cannot demonstrate control to auditors or regulators.
The organization was also midway through a major security program, focused on Microsoft 365 security best practices. That work had surfaced how much of the Microsoft 365 estate was effectively unmanaged. There was no chargeback mechanism, no automated way to enforce access policies, and no single source of truth for what was actually happening across the environment.
The team’s existing approach relied on periodic manual reviews and ad hoc reporting. At 94,000 users, that does not scale. By the time a review identified an unused license or an orphaned account, the window for controlling cost or risk had already passed.
Manual processes also could not support the chargeback model the organization needed. Without automated, accurate data on license consumption by team or department, internal cost allocation was guesswork. And without automated enforcement, governance policies existed on paper, but not in practice.
The gap between what the policy said and what the environment actually looked like was wide, and it was widening.
The organization deployed CoreView in 2022 and built out 26 automated governance policies that now execute more than one million workflows annually.
The license management problem was the first priority. CoreView’s workflows run periodic check-ins with users holding licenses for applications like Visio and Project. If a user confirms they do not need the license, or does not respond within a defined window, the license is reclaimed automatically.
This runs continuously, not quarterly. The team now has real data on utilization and a repeatable, auditable process for acting on it.
That same data made chargeback viable. Departments are now billed based on actual consumption, not assigned headcount. The organization has visibility into what each team is using and what it costs.
Provisioning and deprovisioning went from manual to automated. New users get the right access based on their role. When users leave or change roles, access is removed on schedule, not only when someone raises a ticket. That is a meaningful shift in access hygiene for an organization at this scale.
The IT team also gained detailed reporting across the Microsoft 365 estate, covering usage, compliance status, and potential gaps. That reporting feeds directly into the ongoing security program. Issues that previously surfaced only during manual reviews now appear much sooner.
Running more than one million automated governance workflows annually is not just an operational achievement. It means the organization has built a continuous, auditable control layer over its Microsoft 365 environment, something periodic manual reviews could never provide.
For a healthcare organization operating across multiple countries, with data governance and regulatory obligations that vary by jurisdiction, that control layer has real weight. The ability to demonstrate who has access to what, which licenses are active, and how access decisions are being enforced changes the conversation with auditors, regulators, and security leadership.
The organization is now in discussions to extend that control further into Entra ID, configuration history, and access reviews — areas where configuration drift and accumulated access risk tend to concentrate over time in large Microsoft 365 environments.