Prepare SQL Server Licensing Evidence for Qualified Review
Reconcile SQL Server deployments, acquisition records and proposed AWS placement into a restricted evidence packet. Includes a fictional discrepancy case and a...
Prepare the evidence before comparing licensing options. A SQL Server installation, purchase invoice and CPU chart describe different facts. The review packet must connect them to the exact organization, deployment and proposed hosting arrangement without treating any one artifact as proof of entitlement.
This playbook helps an assessment lead gather a bounded packet for a qualified licensing reviewer. It covers SQL Server deployment identity, authorized acquisition evidence, utilization provenance and proposed AWS placement. It supplies no license allocation formula, legal opinion, audit defense, customer result or saving forecast. The fictional example and offline checks below do not query a server, inspect an account or verify a contract. Infrastructure changes, purchases and license reassignment need separate authority.
1. Name the question and restrict the collection
The assessment lead writes one question: which evidence does the reviewer need to evaluate the proposed SQL Server hosting arrangement for this workload? Specify the legal entity, environments, application family, current locations, candidate target, intended dates and excluded systems. Distinguish a preliminary estimate from a deployment decision. A review for two production instances cannot quietly become permission to inventory every subsidiary or customer tenant.
Agree the record owners before requesting access. The database owner confirms the instance population; infrastructure supplies host and virtualization facts; procurement supplies acquisition and coverage records; the qualified reviewer interprets the applicable rights. Security approves collection, storage, recipients and retention. Someone who can read a purchasing portal may still lack permission to export its contents to a delivery partner. Use the customer's permitted handling process rather than an enquiry form or public issue tracker.
Produce a scope record with an owner, collection cutoff and explicit unknowns. Hold collection if authority or the permitted destination is missing. Resolve that by obtaining approval or narrowing the collection, not by asking an operator to paste confidential agreement pages into chat. This workflow intentionally has no default credential request, discovery agent installation or provider invocation.
2. Preserve records without distributing their sensitive contents
The procurement custodian creates an evidence register. Each entry needs an internal reference, document type, issuer, applicable organization, acquisition or coverage period, storage location, permitted reviewers and capture date. Record amendments and renewal evidence separately, with a relationship to the original agreement. Use an approved digest or immutable repository version where available. A digest can detect byte changes; it cannot establish authenticity, ownership or legal effect.
Keep the raw material in restricted storage. The working manifest should carry references, not product keys, account credentials, personal contact details, invoice bank data or full contract text. Redact a review copy only through the owner's process, retaining a link to the restricted original and a redaction description. Removing an entity name or coverage date can also remove the fact the reviewer needs, so let the reviewer specify the minimum useful disclosure.
If a sensitive export reaches an unintended recipient, stop distribution. Follow the owner's incident process, restrict access and record what was exposed. Do not promise that revoking a shared link deletes previously downloaded copies. Replace the affected packet version, preserve its history securely and ask recipients to acknowledge the corrected handling instruction. The local worksheet supplied here sends nothing and provides no remote erasure mechanism.
3. Inventory installations separately from purchased rights
The database owner gathers approved existing reports or arranges a separately authorized read-only observation. Record each SQL Server instance's full edition string, version/build, environment purpose and observation time. Include service identity and a stable infrastructure reference so aliases, clusters and failovers can be reconciled. Preserve original values beside normalized labels. Treat inaccessible instances as unknown, not absent.
Microsoft's SERVERPROPERTY reference documents installed edition and product version properties. It also says LicenseType is unused and returns DISABLED, while NumLicenses is unused and returns NULL. Those properties cannot supply the purchased license position. An Enterprise installation is an observed software fact; the acquisition and agreement records must establish what may be used and where.
Capture distinct SQL instances even when several share one host. Record their host relationship without counting that host's resources repeatedly in a host-footprint subtotal. Conversely, do not collapse a production primary and a recovery replica into one row because they serve the same application. The reviewer needs the separate deployed roles and their behavior. This manifest is an inventory for review, not a statement that every instance consumes a particular number of licenses.
4. Record the host, virtualization and recovery boundaries
The infrastructure operator connects each installation to its physical host, virtual machine or managed-service resource. Record configured logical processors or vCPUs, the source of that quantity, memory, tenancy/placement evidence where available, and the time window. Keep physical processor/core topology distinct from virtual allocation. A VM report alone may not explain the host pool or where that VM can move.
Document clustering, live migration, autoscaling, failover and recovery arrangements as behaviors, not labels. Which nodes can run the workload, and when? Does a recovery instance serve reports, perform maintenance or receive production traffic? Is a backup restore test creating another running instance? Keep unanswered questions in the discrepancy queue. A name containing passive or DR is insufficient evidence for a licensing interpretation.
Produce a topology record with observed roles, permitted transitions and unresolved mappings. Do not change affinity, disable a replica or shrink processors to make the worksheet look favorable. Those actions can affect availability and performance, and require the application's normal change and recovery gates. The packet records the existing state and each proposed alternative separately.
5. Gather utilization with its observation window
The operations owner attaches authorized CPU, memory, storage and workload evidence with start/end dates, sampling interval, missing periods and source tools. Include whether peak reporting, backup, maintenance and failover events were represented. An average from an idle holiday is a different observation from a full business cycle. Preserve the raw approved export reference and the transformation used to make a summary.
AWS's Optimization and Licensing Assessment guidance describes scoped discovery and utilization collection using several collection approaches, including flat files. That supports collecting inspectable sizing inputs. It does not establish this customer's entitlement, assessment eligibility, completion date or expected savings. This playbook does not enroll a reader in an assessment or install any of its tooling.
Low utilization can motivate a separately evaluated sizing or consolidation option. It does not remove licensing obligations, establish a permitted edition downgrade or prove a smaller target meets the workload's requirements. Record the candidate and the performance validation it still needs. If the window misses the required peak, label sizing provisional and assign the missing observation instead of inventing a multiplier.
6. Bind the acquisition register to the applicable terms
Procurement supplies the program, agreement version, acquired product/SKU, edition, quantity unit, acquisition dates and available coverage evidence. Preserve the original unit, such as a documented pack or server/CAL arrangement, without converting it through a guessed rule. Record Software Assurance or subscription evidence, relevant renewal dates, assignment history and amendments by restricted reference. Unknown coverage remains unknown even when the installation works.
The Microsoft Product Terms SQL Server page requires selecting a licensing program to view applicable terms. A generic product page is not the customer's agreement. Ask the reviewer to identify the applicable program, dated terms and amendments from the authorized record. If that selection cannot be established, the packet may document the gap, but the estimate must keep the affected licensing assumption unresolved.
Do not supply a product key as ownership evidence or treat an invoice quantity as an allocated balance. Other deployments may already use the same acquired position. The reviewer should receive the assignment population, exceptions and evidence of current coverage, rather than a proposed subtraction that excludes inconvenient systems. Contract interpretation belongs with the qualified reviewer; the inventory owner should not infer rights from a search snippet.
7. Keep candidate AWS routes separate
The solution owner creates a scenario record for each candidate: current placement retained, self-managed SQL Server on EC2, or a specified RDS for SQL Server configuration. Record Region, account boundary, exact engine/edition, availability arrangement, configuration date and licensing-model assumption. Do not combine one option's price with another option's rights or managed-service capabilities.
As checked on October 9, 2026, AWS's RDS licensing page documents License Included and Bring Your Own Media (BYOM). License Included includes the SQL Server license in RDS pricing. BYOM uses existing SQL Server licenses with the stated Software Assurance and License Mobility prerequisites; it does not eliminate infrastructure or Windows OS fees. Developer Edition has a non-production restriction. A blanket claim that RDS only offers License Included would therefore be stale.
For a BYOM candidate, record exact current support from AWS's BYOM documentation. Its engine versions are account/Region-specific; current limitations include no in-place major-version upgrade and restrictions on cross-account operations and selected features. A desired media image, edition or migration shape is not automatically supported. This packet does not create media, launch an instance, configure License Manager or establish the customer's mobility rights.
8. Submit mobility and operating-system questions explicitly
Microsoft's License Mobility through Software Assurance guidance identifies eligibility and active coverage checks, a verification process and the distinction from other benefits. It also excludes Windows Server from that License Mobility benefit. Keep SQL Server and Windows Server evidence separate. Do not treat a SQL Server answer as authorization to bring every operating-system license to the same host.
Ask the reviewer to identify required verification, destination/partner applicability, timing, assignment and recovery-use conditions for the specific scenario. Preserve the answer by reference, including exclusions and the evidence it relied on. Avoid substituting an Azure-specific benefit for an AWS arrangement or treating a general outsourcing benefit as unrestricted permission for every provider. This workflow does not interpret the customer's clauses or promise an exception.
The database owner separately records functional constraints. The RDS SQL Server service guide describes managed access restrictions, including no direct host shell access. If the source depends on host-installed software, privileged procedures or a feature excluded by the target, retain that incompatibility as a technical hold. A favorable rights review cannot make an unsupported operating arrangement work.
9. Reconcile discrepancies before handing off the packet
The assessment lead joins deployment and procurement records through explicit references. Confirm the join with both owners. A matching display name can conceal two different machines; a renamed cluster can produce two records for one resource. Preserve aliases and observation dates so corrections can be explained. Do not silently delete duplicates or count one host once per SQL instance.
Use four working dispositions: documented fact, missing evidence, conflicting evidence and qualified interpretation requested. For every open item record its owner, next action, deadline and affected scenarios. A reviewer can accept a packet for investigation while leaving entitlement unresolved. Keep packet receipt, completeness and interpretation as separate statuses.
Proposed evidence workflow. Arrows carry evidence or a review disposition, not credentials, license transfers or application traffic. Completeness alone authorizes no deployment.
The diagram's complete-packet branch means the reviewer can inspect the record. It does not mean licenses are sufficient, a quote is approved or cloud deployment may start. The held branch retains the current operating configuration while the named owner obtains or corrects evidence. Use the separate migration and change process if an operational alteration becomes necessary.
10. Work a fictional mismatch without manufacturing a license balance
Consider fictional application FIN-EXAMPLE. Inventory contains three distinct VMs: production A with 16 configured vCPUs, production B with 8, and recovery C with 8. Two SQL instances run on A. For this stated simultaneous snapshot, the unique-VM allocation is 16 + 8 + 8 = 32 vCPUs across three VMs and four SQL instances. Adding A twice would give 48, an inventory double count. Neither 32 nor 48 is a required or available license count.
The operator labels C passive, but a permitted report export says it serves a nightly report. Procurement supplies an acquisition reference whose coverage attachment is missing. The target proposal assumes RDS BYOM in one Region, but has no selected engine-version/support record. Utilization covers five ordinary working days and omits month-end reporting. No production inventory, customer agreement or AWS response was observed for this fictional case.
The packet remains held for the coverage gap, recovery-role conflict, target-support gap and incomplete utilization window. The next actions belong to procurement, the database owner, the solution owner and operations respectively. Removing C, relabelling the nightly job or multiplying CPU utilization by a purchased quantity would conceal those gaps. The right output is four owned questions, not a claim that BYOM saves money or that the source may be retired.
11. Review checklist: complete a reusable record
Use the anonymous SQL licensing evidence worksheet. It contains a blank Markdown record, a machine-readable blank packet, the fictional discrepancy packet and an offline completeness checker with tests. It contains no entitlement calculator, provider client, customer record, media upload or remote submission. Keep sensitive documents in your approved repository and supply only permitted references.
- Scope and authority
- Record entity, workload, environments, cutoff, collection permission, recipient permission and excluded records.
- Deployment identity
- Record unique host/VM/resource identities, SQL instance mapping, full edition/build and observed purpose. Keep physical and virtual quantities distinct.
- Utilization and continuity
- Record the observed window, gaps, relevant peaks, recovery behavior and referenced exports. Never infer rights from CPU use.
- Acquisition and coverage
- Reference the applicable agreement, product unit, acquired position, amendments, assignment population and coverage evidence without exposing keys.
- Target scenario
- Record exact service, Region, edition/version, hosting arrangement and licensing assumption; attach current support evidence or an owned hold.
- Discrepancies and receipt
- Retain conflicting versions, owner/action/date for each gap and reviewer acknowledgement. Record interpretations separately from packet completeness.
With Node installed, extract the named archive and run node --test evidence.test.mjs, then node evidence.mjs fictional-packet.json. The result should identify the fictional holds and its unique-VM footprint. A blank packet must hold. The checker validates a small supplied record and declared evidence statuses; it cannot authenticate references, establish representativeness, interpret agreements or approve licensing, pricing or execution. Its flags remain false even for a structurally complete packet.
12. Stop conditions, correction and recovery
Stop when the collection permission expires, a secret appears, a recipient is unapproved, scope changes, or two records disagree about a material fact. Pause new collection and distribution; do not stop a production database as part of this evidence procedure. The record owner determines whether the existing configuration can remain within normal operating controls. An alleged licensing issue needs prompt qualified handling, not an automated deletion or a promise that delay is harmless.
Correct by versioning the packet. Preserve the previous discrepancy, replacement evidence and the person responsible for the correction in restricted storage. Reopen the affected review if edition, host pool, deployment role, target model, coverage or proposed dates change. A later complete packet does not erase the earlier conflict or validate an estimate issued from it.
If files must be disposed of, use the customer's approved retention and incident process. Keep disposal status unknown until the authorized custodian verifies the relevant locations, exports and recipient copies. Revoked access, an expired link or deletion of your local ZIP cannot prove all copies are gone. The public companion holds no real data and supplies no remote disposal command.
13. Close the collection task with a bounded handoff
The assessment lead can close collection when every scoped resource is accounted for, evidence provenance and handling are recorded, material conflicts are assigned, and the qualified reviewer acknowledges the exact packet version. Closure may mean a complete packet for interpretation or a documented held packet accepted for investigation. It never means an unresolved entitlement has passed. If the reviewer needs another document or a longer observation window, retain that item as open and name the next owner.
The estimate owner should carry only reviewed, scenario-specific assumptions into a comparison. Keep license-included charges, existing obligations, proposed license use, review costs and retained source commitments separate. Use the migration overlap budget after the relevant assumptions have an evidence basis. This playbook makes no funding claim and grants no purchase, contract termination, reassignment or deployment authority.
Start with one workload's deployment population and ask procurement for the smallest authorized agreement/coverage reference set that can answer the reviewer’s question. Then resolve one conflict before enlarging the assessment. An optional AWS migration enquiry can scope evidence preparation and technical acceptance work; do not submit agreements, credentials or customer data through the public form. Secure handling and qualified licensing responsibilities must be agreed separately.
Related resources
Database Selection: A Workload and Operations Decision Guide
Select a database from access patterns, transaction boundaries, consistency and operating constraints. Includes an illustrative decision matrix and validation worksheet.
AWS Migration Business Case: Who Funds the Overlap?
Build an AWS migration budget that includes dual running, retained commitments, customer effort, acceptance delays and conditional funding before approving a move.