All baseline controls
Licensingmedium priority

Enabled accounts hold a licence

Paid licence assignments on enabled accounts. Part of the standard Alignr Baseline library for proactive technical alignment.

Join Waitlist for Early Access
WHAT THIS CONTROL CHECKS

Paid licence assignments on enabled accounts

An account left enabled should hold at least one paid licence — an enabled, unlicensed account is either a stale service identity that should be disabled or a licence assignment that quietly slipped.

Interpret the result in context

Some enabled identities legitimately do not need a paid licence. Apply this standard to the appropriate account population and record exclusions rather than assigning licences indiscriminately.

YOUR STANDARD

Configure the expectation.

Use this baseline as a starting point. You can also build your own controls and standards from integration data, with client-specific requirements and documented exceptions.

A fixed baseline expectation

This shipped control has no adjustable numerical threshold. Review its applicability and record approved exclusions for the client.

FROM FINDING TO ACTION

Review. Remediate. Verify.

Use one-click remediation where the integration and action support it, or the evidence to guide the technician’s next step.

  1. 01

    Confirm the account’s purpose and whether a paid licence is required.

  2. 02

    Assign the appropriate licence, disable an unused account, or record an approved exclusion.

  3. 03

    Refresh the account and licence-assignment evidence.

A completed action is only part of the record. Refresh the supporting evidence to establish whether the finding has cleared.

Make your baseline part of every client review.

Connect checks, findings and remediation to the same client record.

Join Waitlist for Early Access