BeyondTrust Password Safe and BeyondTrust Endpoint Privilege Management (EPM) are BeyondTrust’s credential management and least-privilege product lines. Password Safe manages privileged accounts, credentials, secrets and sessions from the BeyondInsight management console. Its on-premises licence carries a purchased asset count.[2] EPM comes in three variants: EPM for Windows and Mac, EPM for Unix and Linux (EPM-UL) and EPM for Linux (EPM-L). Each is licensed by the endpoints it governs. In the contract, that unit is the Managed User and/or Managed Computer Object, and the product documentation adds its own client and endpoint counters.[1][10][11] All of these products are sold as Cloud or On-Premise Software Subscriptions under the Software License and Subscription Agreement. Password Safe, EPM for Windows & Mac and EPM for Unix & Linux were among the products whose perpetual licences were retired.[12]
Editions
- Password Safe is sold as Password Safe Cloud or as on-premises software, installed on Windows Server or on a U-Series appliance. BeyondTrust describes Secrets Safe, its secrets management capability, as included with Password Safe at no extra cost.[3][5] Password Safe also replaced Privileged Identity, the former Lieberman product, which reached end of life on 2025-03-31.[5]
- EPM for Windows and Mac is delivered mainly as a SaaS console that deploys policies to agents on each computer. Two older editions are listed as end of sale or end of life: the Windows Group Policy Edition (GPO) and the Trellix ePolicy Orchestrator Edition (ePO). The same list includes PowerBroker for Windows.[13]
- EPM for Unix and Linux is installed software with its own licence server and a JSON licence string.[10]
- EPM for Linux is the SaaS variant, managed at app.beyondtrust.io.[11]
All of these products except AD Bridge have both SaaS and on-premises subscription offerings. AD Bridge is sold only as an on-premises subscription.[12]
Metrics
| BeyondTrust unit | Catalog row | Product |
|---|---|---|
| Asset | Asset | Password Safe / BeyondInsight |
| Managed Servers | Managed Servers | Password Safe, EPM (server targets) |
| Managed Devices | Managed Devices | Password Safe, EPM (non-server devices) |
| Managed User and/or Managed Computer Object | Managed Computer Object | EPM for Windows and Mac |
| Client (EPM-UL licence) | EPM-UL Client | EPM for Unix and Linux |
| Endpoint (EPM for Linux licence) | EPM-L Endpoint | EPM for Linux |
| Managed system (licence key) | Privileged Identity managed system | Privileged Identity (legacy) |
The contract defines the first four units in Exhibit A. The EPM-UL and EPM-L counters, and the legacy Privileged Identity licence key, come from product documentation.[1][6][10][11]
Counting / floors
Password Safe and BeyondInsight
In the agreement, an Asset is a physical or virtual device that meets one of the descriptions for the other units. The grant is limited to the Assets, Instances, machines and locations in the Order.[1] For on-premises deployments, the BeyondInsight documentation states that the licence must be upgraded, through the Manage License function of the BeyondInsight Configuration Tool, both to extend maintenance and to apply a purchased asset count. Its example is moving from 500 assets to 1,000 assets.[2] Licence keys are generated from the customer’s serial number at licensing.beyondtrust.com. U-Series appliances show the licence on their Product Licensing card.[2][3] Once the licence key expires, administrators can still log in to the console, but product updates stop.[2]
Exhibit A separates servers from other devices. A Managed Server is a managed device that acts as a server, runs a server operating system (physical or virtual) or serves applications, websites, DNS, directory services, DHCP, files, storage arrays or databases. A Managed Device is a non-server device such as a desktop PC, router or switch.[1] BeyondTrust’s public documents do not say which of these units a given Password Safe Order uses. The Order therefore decides whether assets are counted as one pool or split into servers and devices.
When Password Safe is integrated with Privileged Remote Access, external Jump items do not count toward the PRA endpoint licence count.[4]
EPM for Windows and Mac
The contract unit is the Managed User and/or Managed Computer Object: any physical, virtual, Container or computing device, whatever the number of IP addresses assigned, that interacts with software rules, has an agent installed or is targeted for an assessment.[1] In technical terms, the product needs a valid licence code in the Policy Editor. When more than one policy applies to a computer, at least one of them must contain a valid licence code. The documentation suggests adding the licence to a policy that applies to all managed endpoints.[7] The client installer carries no licence, because the licence is deployed with the EPM Workstyles.[8]
The cloud console’s default management rules affect how many computers stay on record:
| Rule | Default behaviour |
|---|---|
| Archive Rule | Archives computers disconnected for 90 days |
| Deletion Rule | Soft-deletes computers archived for 90 days (still in the database) |
| System Purge Computer Rule | Deactivates computers 7 days after deletion (adjustable); purges them 14 days after deactivation |
The documentation does not say whether archived or deleted computers stop counting against the licence. The table records only the lifecycle BeyondTrust documents.[9]
EPM for Unix and Linux
EPM-UL checks for a valid licence every time a user submits a request through pbrun, and refuses requests without one. The licence is a JSON string that sets the maximum number of clients for each service, including role-based policy (RBPClnts), Advanced Keystroke Action (AKAClnts) and File Integrity Monitor (FIMClnts). A value of 0 means no entitlement and -1 means unlimited.[10] Any machine that runs a client component consumes a licence, even if it is also a policy server host or log host. Since version 8.5, clients have been identified by UUID rather than IP address. Since version 10.0, licences have been synchronized across all servers as one pool.[10]
Since version 8.5, EPM-UL has enforced its limit softly:
| Clients over the licensed limit | Behaviour |
|---|---|
| Up to 10% | Connect without any error |
| 11% to 20% | Warning in syslog and the policy server diagnostic log |
| 21% to 50% | Warning also shown to the initiating client program |
| More than 50% | Error; new connection requests are rejected |
The licence also sets AutoRetire, the minimum number of inactive days after which a client’s licence is freed automatically, and Recycle, the minimum number of days before a manually retired client can be used again. Administrators retire clients by UUID or FQDN with pbadmin --lic -r.[10] If no standard licence is provided at installation, a temporary licence is installed automatically. It enables 20 client seats for all services for 60 days. A standard licence is bound to the host UUID of the primary licence server.[10]
EPM for Linux
In EPM for Linux, an endpoint appears on the Endpoints page once a user has run pbrun on it at least once. The page shows the subscription details and the number of licences used. Retiring an endpoint cannot be undone and updates the endpoint licence count immediately. A “Reusable after” column shows when the licence can be used on another endpoint.[11]
Virtualization & partitioning
Neither Password Safe nor EPM uses processor or core metrics. Exhibit A counts virtual machines and containers as devices in their own right. It names VMware Server, Hyper-V, Azure VMs, Amazon AWS VMs and zOS LPARs as virtual environments, and it describes containers as emulation at the operating system level.[1] An EPM agent in each virtual machine or container therefore counts as one Managed Computer Object, and a virtual server managed by Password Safe counts as a Managed Server.[1] In EPM-UL, each client host is identified by a UUID derived from operating system calls, so every virtual or cloud host running a client consumes a licence.[10]
Cloud / BYOL
Password Safe Cloud, EPM for Windows and Mac and EPM for Linux are BeyondTrust SaaS services sold as Cloud Services Subscriptions.[11][12] On-premises Password Safe can run on U-Series virtual appliances. BeyondTrust publishes no bring-your-own-licence rule or vCPU mapping for running on-premises Password Safe or EPM-UL on public cloud infrastructure.
Programs
- Perpetual retirement. Password Safe, EPM for Windows & Mac and EPM for Unix & Linux perpetual licences could not be extended after 2025-12-31. Maintenance for them ends on 2026-12-31.[12]
- Privileged Identity migration. Maintenance and support for Privileged Identity, Bomgar Privileged Identity, Lieberman RED Identity Management and Lieberman ERPM ended on 2025-03-31. Password Safe is the named replacement, with cloud deployment preferred.[5] Privileged Identity licences were assigned to machine names and consumed on the first management action. Releasing and reassigning them was limited by an allowed number of re-keys.[6]
Out of scope
This article does not cover AD Bridge counting rules, Identity Security Insights, BeyondInsight vulnerability-management licensing or Workforce Passwords, because BeyondTrust publishes no licensing rule for them in the documents cited here. Contract-wide terms are covered in BeyondTrust licensing.