Microsoft Open License: What It Was and What Replaced It
A practical guide to the Microsoft Open License program: how it worked, why it retired, what happens to your existing licenses, and the CSP alternatives.
If you bought Microsoft software for a small or midsize business any time between the late 1990s and 2021, you probably bought it through a Microsoft Open License agreement. The program is now closed to new orders, which leaves a lot of organizations holding license keys they still rely on and no clear picture of what they own, what expired, and what they need to buy instead. This guide walks through how the program worked, what replaced it, and the contractual terms that still bind you. It is educational rather than legal advice, so talk to a qualified attorney or licensing specialist before making decisions about a live agreement.
What Is a Microsoft Open License?
A Microsoft Open License is a volume licensing agreement that let small and midsize organizations buy Microsoft software licenses in bulk at a discount, without the commitment of an Enterprise Agreement. It was the entry-level tier of Microsoft volume licensing, aimed at organizations with roughly five to 250 devices or users.
The core mechanics were straightforward:
- Minimum purchase of five licenses on the initial order. After that you could add single licenses.
- A two-year agreement window. Once opened, the agreement stayed active for two years, during which you could place additional orders at the same discount level.
- Perpetual licenses. You owned the right to run that version of the software indefinitely.
- Optional Software Assurance. Bought per order, it added version upgrade rights and support benefits for the term.
- One license confirmation per agreement, holding your authorization number and license number, which you needed to download media and keys.
Compared with buying retail boxes, Open License gave you volume pricing, a single set of keys for imaging machines, and a central record of entitlements. Compared with an Enterprise Agreement, it required no organization-wide standardization and no 500-seat minimum.
The Three Programs in the Open Family
"Open License" is often used loosely to mean all of Microsoft's Open programs. There were actually three distinct offerings, and knowing which one you signed matters when you audit what you still own.
| Program | Term | License type | Software Assurance | Payment |
|---|---|---|---|---|
| Open License (Open Business) | Two-year ordering window | Perpetual | Optional, per order | Upfront per order |
| Open Value | Three years | Perpetual after full term | Included | Three annual payments |
| Open Value Subscription | Three years | Non-perpetual | Included | Annual, adjustable count |
Open License was transactional. You bought what you needed when you needed it, and nothing obligated you to buy more.
Open Value was an agreement rather than a purchase order. It required a three-year commitment, included Software Assurance on everything, and spread the cost across three annual installments. Organization-wide options gave an extra discount if you standardized a product across all qualifying desktops.
Open Value Subscription was the rent-do-not-own version. It carried the lowest annual cost, allowed you to reduce your seat count at each anniversary, and gave you no perpetual rights unless you exercised a buy-out at the end.
There were also Academic, Government, and Charity variants of each, priced differently but structurally identical.
Why the Microsoft Open License Program Was Retired
Microsoft closed the Open License program to new business on January 1, 2022. After that date resellers could no longer place new orders, add licenses to existing agreements, or renew Software Assurance under Open License.
The reasoning was consistency. Microsoft consolidated small and midsize purchasing into the Cloud Solution Provider (CSP) program, where partners sell both cloud subscriptions and, since the same transition, perpetual on-premises software. That put one commercial motion behind Microsoft 365, Azure, and traditional server licenses, all governed by the Microsoft Customer Agreement rather than a stack of legacy volume licensing agreements.
Microsoft has continued to narrow the remaining Open programs for commercial customers, pushing renewals toward CSP and the Microsoft Customer Agreement. Because these retirement dates have shifted more than once and differ by segment, confirm the current position with your reseller and against the official Microsoft Product Terms before you plan a renewal. Do not budget against a date you read in a forum post.
What Happens to Your Existing Microsoft Open License Agreements
Retirement of a purchasing program is not revocation of the licenses you bought. This distinction trips up a lot of IT managers, so it is worth being precise.
- Perpetual licenses stay perpetual. A Windows Server 2019 license bought under Open License in 2020 is still yours. Your right to run it does not expire because the program closed.
- Your activation keys keep working. MAK and KMS keys issued against your agreement continue to activate the versions you are entitled to.
- Software Assurance benefits end when the term ends. No renewal path under Open License means no more version upgrade rights, no more training vouchers, no more SA support incidents.
- You freeze at your last entitled version. Without SA, upgrading to a newer release requires a new purchase through CSP.
- Downgrade and reassignment rights survive, governed by the Product Terms in effect when you bought.
The practical risk is not enforcement, it is drift. Organizations keep running server products years past their support lifecycle because nobody noticed that SA lapsed. Unsupported software that processes personal data is a security problem before it is a licensing problem, and under GDPR Article 32 you are required to implement appropriate technical measures to protect personal data. Running an operating system that no longer receives security updates is hard to defend as appropriate.
Build a Licensing Inventory Now
If you inherited an Open License estate, reconstruct it while the records are still accessible:
- Pull every license confirmation you can find, keyed by authorization number.
- Match each entitlement to what is actually installed and running today.
- Note the SA end date for each product line.
- Record which products are past Microsoft's end of support.
- Keep reseller invoices. In a compliance verification, the invoice plus license confirmation is your proof.
Microsoft Open License vs CSP and the Other Volume Options
If you are replacing an expired Open agreement, these are the realistic destinations.
| Option | Best for | Term | Notes |
|---|---|---|---|
| CSP (Cloud Solution Provider) | 1 to 300 seats, most SMBs | Monthly or annual | Bought through a partner, covers cloud and perpetual software |
| Microsoft Customer Agreement direct | Organizations buying Azure directly | Rolling | Self-service, no partner margin or partner support |
| Enterprise Agreement | 500+ users or devices | Three years | Volume commitment, organization-wide options |
| MPSA | Mixed transactional buying | Rolling | Legacy transactional agreement, largely superseded |
| SPLA | Hosters and managed service providers | Monthly | Required if you rent software access to third parties |
For most former Open License customers, CSP is the direct replacement. Pricing is partner-set rather than published on a price list, so quotes vary, and it is worth getting two or three. If you host software for customers, note that CSP does not permit you to provide services to third parties. That scenario needs a Services Provider License Agreement, which we cover in the guide to Microsoft SPLA licensing.
For the larger end of the market, the trade-offs between transactional buying and a committed three-year deal are set out in our comparison of Microsoft Enterprise Agreement licensing and the broader overview of Microsoft volume licensing programs.
Where the Terms Actually Live
A common misconception is that the Open License agreement document contains your usage rights. It does not. The agreement is a purchasing framework. The rights and restrictions come from a separate document that Microsoft updates monthly.
The Microsoft Product Terms is the controlling document for use rights, and it replaced the older Product List and Product Use Rights documents. It defines licensing models per product, downgrade rights, virtualization rights, and restrictions. Which version applies to you depends on when you bought and whether you have active Software Assurance, so archive the Product Terms PDF that was current at the time of each purchase. Our breakdown of the Microsoft Product Terms explains how to read it.
The Microsoft Products and Services Data Protection Addendum (DPA) is the data protection half. It sets out Microsoft's obligations as a processor for online services, incorporates the Standard Contractual Clauses for international transfers, and describes security commitments. It applies to online services rather than to perpetual on-premises software you install and run yourself.
The Microsoft Online Subscription Agreement or Microsoft Customer Agreement covers cloud subscriptions bought through CSP or direct.
Keep all three in your contract file. During a dispute or an audit, "we thought we could do that" is not an argument. The Product Terms text is.
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate NowMicrosoft Open License and Data Protection Compliance
Licensing and privacy compliance intersect in a way that often gets missed, because the two live with different teams.
On-premises software you bought under Open License generally does not make Microsoft a processor. If you run Exchange Server or SQL Server on your own hardware, you are the controller and the processor of that data. The Open License agreement is a software license, not a data processing agreement. Nobody at Microsoft touches the personal data in that database.
Microsoft online services do make Microsoft a processor. The moment you move mailboxes to Exchange Online, files to SharePoint Online, or workloads to Azure, personal data is being processed by a third party on your instructions. GDPR Article 28(3) requires that relationship to be governed by a written contract covering subject matter, duration, nature and purpose of processing, categories of data subjects, and the processor's obligations. Microsoft satisfies that through the DPA rather than through your license agreement.
That has three concrete consequences for compliance work:
- Your Article 30 records of processing must list Microsoft as a processor for the relevant activities, with the categories of data involved and the transfer mechanism relied on.
- Your privacy notice must disclose the recipients. GDPR Articles 13(1)(e) and 14(1)(e) require you to identify the recipients or categories of recipients of personal data.
- International transfers need a lawful basis under Chapter V. Microsoft relies on the Standard Contractual Clauses under Article 46(2)(c), supplemented by the EU Data Boundary commitments for EU customer data. If you are a UK organization, check that the UK Addendum to the SCCs is in scope.
Enforcement here is not theoretical. Data protection authorities including the European Data Protection Supervisor have examined public-sector use of Microsoft services and the adequacy of the contractual terms behind them. Fines under Article 83 reach up to 20 million EUR or 4% of global annual turnover, whichever is higher, and inadequate processor contracts are a recurring finding.
Under the CCPA, the parallel requirement is in Section 1798.100(d) and the service provider definition at Section 1798.140(ag), which require a contract prohibiting the service provider from retaining, using, or disclosing personal information for any purpose other than performing the services.
How Microsoft Licensing Shows Up in Your Public Documents
Two documents on your own website are affected by the Microsoft services you run, and both are easy to leave stale.
Your privacy policy. If Microsoft services handle customer or employee personal data, name them in your list of third parties or categories of recipients, describe what they do, and reference the transfer safeguard. A vague line about "trusted service providers" does not meet the disclosure standard in GDPR Article 13. If you need a starting structure that covers processors, transfers, and retention, a privacy policy generator will produce the required sections, and you then edit them to match your actual stack. Keeping a public subprocessor list alongside the policy is the cleaner pattern if you are a B2B vendor whose own customers ask about your supply chain.
Your cookie disclosures. Microsoft-owned tags such as Clarity, Bing UET, and LinkedIn Insight commonly appear on business websites without anyone recording the decision. These set cookies that require consent under Article 5(3) of the ePrivacy Directive before they load. A compliance scanner such as the one built into TermsBox will detect which Microsoft tags are actually firing on your pages, which is usually a shorter or longer list than the marketing team believes.
The reason to check both together is simple. Licensing tells you what you are entitled to run. Your privacy documents tell your users what you are actually running. Those two pictures should match.
Common Open License Mistakes That Create Real Exposure
- Assuming SA renewed automatically. It never did under Open License, and it cannot now. Check the SA end date on every product line.
- Reusing keys past your entitlement count. MAK keys have activation counts but will not stop you from over-deploying. Microsoft's compliance verification rights let it request an inventory.
- Losing the license confirmation. Without it, proving what you bought from a reseller who has since closed is difficult. Export and store it outside the vendor portal.
- Treating a perpetual license as covering a newer version. A 2016 license does not entitle you to run the 2022 release. Downgrade rights run backward, not forward.
- Deploying licensed software to serve third parties. Standard volume licensing does not permit hosting for external customers. That is what SPLA exists for.
- Confusing the Microsoft license with your own EULA. If you build software on the Microsoft stack and sell it, your customers need your own end user license agreement, which is a separate document with your own terms.
Frequently Asked Questions
Can I still buy a Microsoft Open License?
No. Microsoft stopped accepting new orders, add-ons, and Software Assurance renewals through the Open License program on January 1, 2022. New perpetual software and cloud subscriptions for small and midsize organizations are now sold through the Cloud Solution Provider (CSP) program by Microsoft partners.
Do my existing Microsoft Open License keys still work?
Yes. Perpetual licenses bought under Open License remain valid for the versions you were entitled to, and your MAK and KMS keys continue to activate those products. What ends is the ability to renew Software Assurance, which means no more version upgrade rights, so you stay on the last version you were licensed for.
What is the difference between Microsoft Open License and Open Value?
Open License was a transactional program with a two-year ordering window, perpetual licenses, and optional Software Assurance bought per order. Open Value was a three-year agreement that always included Software Assurance and spread payments across three annual installments, while Open Value Subscription was a non-perpetual subscription with lower upfront cost and annual seat-count adjustments.
Where do I find my Microsoft Open License agreement number and keys?
Historically these lived in the Volume Licensing Service Center (VLSC), under the license confirmation attached to your authorization and license numbers. Microsoft has been migrating volume licensing functions into the Microsoft 365 admin center, so check both, and keep your reseller invoice and license confirmation as your proof of purchase.
Does a Microsoft Open License cover the software my own company sells?
No. A Microsoft Open License governs your use of Microsoft products only. If you distribute your own software or app, you need your own end user license agreement, which you can create with an EULA generator that sets out your license grant, restrictions, and liability limits.
Do I need to mention Microsoft in my privacy policy?
If you use Microsoft online services such as Microsoft 365, Exchange Online, or Azure to store or process personal data, yes. Under GDPR Articles 13 and 14 you must disclose the categories of recipients of personal data, and Microsoft acts as a processor under the Microsoft Products and Services Data Protection Addendum.