Microsoft licensing on third-party clouds covers the rules for running software licensed from Microsoft on servers that the customer does not manage itself, such as Amazon Web Services (AWS) EC2 instances, Google Cloud virtual machines or a regional hosting company. The starting point in the Microsoft Product Terms is restrictive: “Except as expressly permitted here or elsewhere in these Product Terms, Customer is not permitted to use or access software on devices that are under the management or control of a third party.”[3] The permitted routes are dedicated hardware at an Authorized Outsourcer, the Flexible Virtualization Benefit, Cloud Solution Provider-Hosters, License Mobility through Software Assurance, and product-specific exceptions.
Which route is available depends on who the provider is. Since 1 October 2019 Microsoft has distinguished a small group of large cloud providers, the Listed Providers, from all other hosters.[1] Licenses bought through a cloud provider’s own license-included offerings are licensed by that provider under its own agreement with Microsoft and are outside the scope of this article.
Listed Providers and Authorized Outsourcers
The Glossary defines Listed Providers as “entities identified by Microsoft at http://aka.ms/listedproviders”, and allows a customer that is already using an outsourcer when it becomes a Listed Provider to continue using it in its former capacity for one year.[2] The October 2019 list names four entities and their affiliates: Alibaba, Amazon, Google and Microsoft. The list adds that the designation “affects all services running on a Listed Provider (for example, VMware Cloud on AWS).”[1]
An Authorized Outsourcer is “any third party service provider that is not a Listed Provider and is not using Listed Provider as a Data Center Provider as part of the outsourcing service.”[2] A regional hoster that runs its service on AWS or Google Cloud infrastructure is therefore not an Authorized Outsourcer (rule).
The core restriction is stated on Microsoft’s Listed Providers page: “Beginning October 1, 2019, on-premises licenses purchased without Software Assurance and mobility rights cannot be deployed with dedicated hosted cloud services offered by Listed Providers.”[1] See the Listed Providers restriction and the rule.
Outsourcing routes
The Universal License Terms list three outsourcing permissions:[3]
| Route | Who may host | License requirement | Hardware |
|---|---|---|---|
| Outsourcing on Dedicated Devices | Authorized Outsourcers | Any license | Devices that “are and remain fully dedicated to Customer’s use” |
| Flexible Virtualization Benefit | Authorized Outsourcers | Subscription licenses or licenses with active SA (including CALs) | Dedicated or shared servers |
| Outsourcing on Cloud Solution Provider-Hosters | CSP-Hoster partners | Subscription licenses or licenses with active SA (including CALs) | The partner’s devices |
None of these routes is open to Listed Providers, because each depends on the Authorized Outsourcer or CSP-Hoster status of the partner (rule). The Flexible Virtualization Benefit has its own rule. On Listed Provider infrastructure the main contractual route is License Mobility through Software Assurance.
License Mobility through Software Assurance
License Mobility through Software Assurance lets a customer “move its licensed software to shared servers under any of its Licenses which are designated as having License Mobility for which it has SA”. The customer must deploy “only with Microsoft Azure Services or qualified License Mobility through Software Assurance Partner” and “Complete and submit the License Mobility verification form” with each partner. Software may not move back or to another provider “on a short term basis (not within 90 days of the last assignment)”.[4] The Product Terms add: “License Mobility through SA rights also apply to Listed Providers’ Servers that are dedicated to Customer’s use, subject to these same terms and conditions.”[4] A Listed Provider dedicated host is therefore treated like shared infrastructure for this purpose (rule); the existing License Mobility rule records the per-core ratios.
The number of cores or operating system environments each license covers on shared servers is fixed by a table in the Software Assurance Benefits:[4]
| License model | License with active SA | Permitted on shared servers |
|---|---|---|
| Per Core (all eligible products, for example SQL Server) | Each Core License | One virtual core, subject to a minimum of 4 cores per OSE |
| Server/CAL (SQL Server) | Each Server License | 1 OSE |
| Per Core/CAL (Windows Server) | Each External Connector License | 1 OSE |
| Management Servers (System Center 2025 Standard / Datacenter) | Every 16 Management Licenses | 2 or 10 Managed OSEs per Licensed Server |
SQL Server
All editions of SQL Server except Parallel Data Warehouse are License Mobility designated.[5] A SQL Server Enterprise or Standard virtual machine on AWS or Google Cloud with eight virtual cores therefore needs eight core licenses with active SA (or subscription licenses), and a two-core virtual machine still needs four. Under License Mobility, the customer “may run passive fail-over Instances in one OSE on the qualifying shared servers in anticipation of a fail-over event”, provided the licenses otherwise needed for the passive instances do not exceed those of the production instances on the same partner’s servers.[4] The broader SQL Server fail-over rights (one Fail-over OSE for any purpose plus two disaster-recovery Fail-over OSEs, one of them on Azure) do not apply under License Mobility.[5] These rules are covered in more detail in SQL Server licensing.
Windows Server
Windows Server Standard and Datacenter core licenses are not License Mobility designated; in the Windows Server Software Assurance table License Mobility applies to the External Connector only.[6] Customers who want Windows Server on a Listed Provider therefore generally rely on the provider’s license-included images rather than their own core licenses, while Azure Hybrid Benefit is the equivalent right on Microsoft Azure (see Windows Server licensing).
Desktop and developer software
Microsoft grants a named exception for virtual desktops on Amazon WorkSpaces: “Notwithstanding anything in the Outsourcing Software Management clause to the contrary, each Licensed User of an Eligible Product may install and run in Amazon WorkSpaces their permitted instances” of Microsoft 365 Apps for enterprise or business on the Monthly Enterprise or Current Channel, plus listed client applications such as Project, Visio, Teams and Power Automate when the user holds the matching plan.[7] Eligible Products are Microsoft 365 E3, E5 and E7, A3 and A5, G3 and G5, Business Premium and the Microsoft 365 E3/A3/G3 Unattended License; the Unattended License was added on 1 July 2026 (rule).[7][8]
Visual Studio subscriber software follows the same split. Microsoft’s white paper allows it on dedicated hardware hosted by a third party that is an Authorized Outsourcer and not a Listed Provider, and in most cases in Azure virtual machines.[9] See Visual Studio subscriptions licensing.
Counting considerations
Moving licenses into and out of hosted environments is limited by the general reassignment rule: “Customer may reassign a License to another device or user, but not less than 90 days since the last reassignment of that same License”, except for permanent hardware failure, end of employment or contract, or temporary cover for an absence.[3] License Mobility carries its own 90-day limit on moving between providers or Server Farms.[4] Because SA or subscription status is the precondition for most routes, the rights end when coverage lapses; the Product Terms state that SA-based rights “end at the expiration of the SA coverage for the License, unless otherwise noted”.[3] The customer also remains “responsible for all of the obligations under its volume licensing agreement regardless of the physical location of the hardware upon which the software is used.”[3] See the reassignment rule.
Out of scope
- Azure Hybrid Benefit, Azure dedicated hosts and SQL Server fail-over to Azure: see SQL Server licensing and Windows Server licensing.
- License-included offerings sold by AWS, Google Cloud or Alibaba Cloud, and their pricing.
- The Services Provider License Agreement (SPLA) used by hosters to license their own services.
- Microsoft 365 and other Online Services, which are not deployed on customer infrastructure.
- A general, vendor-neutral treatment of bring-your-own-license: see Cloud / BYOL.