LICENSEWARE

BeyondTrust Password Safe and Endpoint Privilege Management licensing

This article is about licensing BeyondTrust Password Safe (with BeyondInsight and Secrets Safe) and Endpoint Privilege Management for Windows and Mac, Unix and Linux, and Linux. For remote access products see BeyondTrust Remote Support and Privileged Remote Access licensing. It is not legal advice.

On This Page

BeyondTrust Password Safe and BeyondTrust Endpoint Privilege Management (EPM) are BeyondTrust’s credential management and least-privilege product lines. Password Safe manages privileged accounts, credentials, secrets and sessions from the BeyondInsight management console. Its on-premises licence carries a purchased asset count.[2] EPM comes in three variants: EPM for Windows and Mac, EPM for Unix and Linux (EPM-UL) and EPM for Linux (EPM-L). Each is licensed by the endpoints it governs. In the contract, that unit is the Managed User and/or Managed Computer Object, and the product documentation adds its own client and endpoint counters.[1][10][11] All of these products are sold as Cloud or On-Premise Software Subscriptions under the Software License and Subscription Agreement. Password Safe, EPM for Windows & Mac and EPM for Unix & Linux were among the products whose perpetual licences were retired.[12]

Editions

  • Password Safe is sold as Password Safe Cloud or as on-premises software, installed on Windows Server or on a U-Series appliance. BeyondTrust describes Secrets Safe, its secrets management capability, as included with Password Safe at no extra cost.[3][5] Password Safe also replaced Privileged Identity, the former Lieberman product, which reached end of life on 2025-03-31.[5]
  • EPM for Windows and Mac is delivered mainly as a SaaS console that deploys policies to agents on each computer. Two older editions are listed as end of sale or end of life: the Windows Group Policy Edition (GPO) and the Trellix ePolicy Orchestrator Edition (ePO). The same list includes PowerBroker for Windows.[13]
  • EPM for Unix and Linux is installed software with its own licence server and a JSON licence string.[10]
  • EPM for Linux is the SaaS variant, managed at app.beyondtrust.io.[11]

All of these products except AD Bridge have both SaaS and on-premises subscription offerings. AD Bridge is sold only as an on-premises subscription.[12]

Metrics

BeyondTrust unit Catalog row Product 
Asset Asset Password Safe / BeyondInsight 
Managed Servers Managed Servers Password Safe, EPM (server targets) 
Managed Devices Managed Devices Password Safe, EPM (non-server devices) 
Managed User and/or Managed Computer Object Managed Computer Object EPM for Windows and Mac 
Client (EPM-UL licence) EPM-UL Client EPM for Unix and Linux 
Endpoint (EPM for Linux licence) EPM-L Endpoint EPM for Linux 
Managed system (licence key) Privileged Identity managed system Privileged Identity (legacy) 

The contract defines the first four units in Exhibit A. The EPM-UL and EPM-L counters, and the legacy Privileged Identity licence key, come from product documentation.[1][6][10][11]

Counting / floors

Password Safe and BeyondInsight

In the agreement, an Asset is a physical or virtual device that meets one of the descriptions for the other units. The grant is limited to the Assets, Instances, machines and locations in the Order.[1] For on-premises deployments, the BeyondInsight documentation states that the licence must be upgraded, through the Manage License function of the BeyondInsight Configuration Tool, both to extend maintenance and to apply a purchased asset count. Its example is moving from 500 assets to 1,000 assets.[2] Licence keys are generated from the customer’s serial number at licensing.beyondtrust.com. U-Series appliances show the licence on their Product Licensing card.[2][3] Once the licence key expires, administrators can still log in to the console, but product updates stop.[2]

Exhibit A separates servers from other devices. A Managed Server is a managed device that acts as a server, runs a server operating system (physical or virtual) or serves applications, websites, DNS, directory services, DHCP, files, storage arrays or databases. A Managed Device is a non-server device such as a desktop PC, router or switch.[1] BeyondTrust’s public documents do not say which of these units a given Password Safe Order uses. The Order therefore decides whether assets are counted as one pool or split into servers and devices.

When Password Safe is integrated with Privileged Remote Access, external Jump items do not count toward the PRA endpoint licence count.[4]

EPM for Windows and Mac

The contract unit is the Managed User and/or Managed Computer Object: any physical, virtual, Container or computing device, whatever the number of IP addresses assigned, that interacts with software rules, has an agent installed or is targeted for an assessment.[1] In technical terms, the product needs a valid licence code in the Policy Editor. When more than one policy applies to a computer, at least one of them must contain a valid licence code. The documentation suggests adding the licence to a policy that applies to all managed endpoints.[7] The client installer carries no licence, because the licence is deployed with the EPM Workstyles.[8]

The cloud console’s default management rules affect how many computers stay on record:

Rule Default behaviour 
Archive Rule Archives computers disconnected for 90 days 
Deletion Rule Soft-deletes computers archived for 90 days (still in the database) 
System Purge Computer Rule Deactivates computers 7 days after deletion (adjustable); purges them 14 days after deactivation 

The documentation does not say whether archived or deleted computers stop counting against the licence. The table records only the lifecycle BeyondTrust documents.[9]

EPM for Unix and Linux

EPM-UL checks for a valid licence every time a user submits a request through pbrun, and refuses requests without one. The licence is a JSON string that sets the maximum number of clients for each service, including role-based policy (RBPClnts), Advanced Keystroke Action (AKAClnts) and File Integrity Monitor (FIMClnts). A value of 0 means no entitlement and -1 means unlimited.[10] Any machine that runs a client component consumes a licence, even if it is also a policy server host or log host. Since version 8.5, clients have been identified by UUID rather than IP address. Since version 10.0, licences have been synchronized across all servers as one pool.[10]

Since version 8.5, EPM-UL has enforced its limit softly:

Clients over the licensed limit Behaviour 
Up to 10% Connect without any error 
11% to 20% Warning in syslog and the policy server diagnostic log 
21% to 50% Warning also shown to the initiating client program 
More than 50% Error; new connection requests are rejected 

The licence also sets AutoRetire, the minimum number of inactive days after which a client’s licence is freed automatically, and Recycle, the minimum number of days before a manually retired client can be used again. Administrators retire clients by UUID or FQDN with pbadmin --lic -r.[10] If no standard licence is provided at installation, a temporary licence is installed automatically. It enables 20 client seats for all services for 60 days. A standard licence is bound to the host UUID of the primary licence server.[10]

EPM for Linux

In EPM for Linux, an endpoint appears on the Endpoints page once a user has run pbrun on it at least once. The page shows the subscription details and the number of licences used. Retiring an endpoint cannot be undone and updates the endpoint licence count immediately. A “Reusable after” column shows when the licence can be used on another endpoint.[11]

Virtualization & partitioning

Neither Password Safe nor EPM uses processor or core metrics. Exhibit A counts virtual machines and containers as devices in their own right. It names VMware Server, Hyper-V, Azure VMs, Amazon AWS VMs and zOS LPARs as virtual environments, and it describes containers as emulation at the operating system level.[1] An EPM agent in each virtual machine or container therefore counts as one Managed Computer Object, and a virtual server managed by Password Safe counts as a Managed Server.[1] In EPM-UL, each client host is identified by a UUID derived from operating system calls, so every virtual or cloud host running a client consumes a licence.[10]

Cloud / BYOL

Password Safe Cloud, EPM for Windows and Mac and EPM for Linux are BeyondTrust SaaS services sold as Cloud Services Subscriptions.[11][12] On-premises Password Safe can run on U-Series virtual appliances. BeyondTrust publishes no bring-your-own-licence rule or vCPU mapping for running on-premises Password Safe or EPM-UL on public cloud infrastructure.

Programs

  • Perpetual retirement. Password Safe, EPM for Windows & Mac and EPM for Unix & Linux perpetual licences could not be extended after 2025-12-31. Maintenance for them ends on 2026-12-31.[12]
  • Privileged Identity migration. Maintenance and support for Privileged Identity, Bomgar Privileged Identity, Lieberman RED Identity Management and Lieberman ERPM ended on 2025-03-31. Password Safe is the named replacement, with cloud deployment preferred.[5] Privileged Identity licences were assigned to machine names and consumed on the first management action. Releasing and reassigning them was limited by an allowed number of re-keys.[6]

Out of scope

This article does not cover AD Bridge counting rules, Identity Security Insights, BeyondInsight vulnerability-management licensing or Workforce Passwords, because BeyondTrust publishes no licensing rule for them in the documents cited here. Contract-wide terms are covered in BeyondTrust licensing.

References

  1. BeyondTrust Software License and Subscription AgreementExhibit A: Asset, Managed User and/or Managed Computer Object, Managed Devices, Managed Servers, Instance.Retrieved 2026-09-26.
  2. Install BeyondInsight | BI On-premdocs.beyondtrust.com; Manage Your BeyondInsight License.Retrieved 2026-09-26.
  3. Software and licensing | U-SeriesProduct Licensing card; licensing.beyondtrust.com key generation.Retrieved 2026-09-26.
  4. Secure Remote Access Appliance | PSExternal Jump items and the PRA endpoint licence count.Retrieved 2026-09-26.
  5. Privileged Identity End of Life Announcement & FAQDated March 31, 2023; hosted on assets.beyondtrust.com.Effective 2023-03-31. Retrieved 2026-09-26.
  6. Assignment of Licenses in Privileged IdentityLegacy licence key assignment FAQ.Retrieved 2026-09-26.
  7. Policy Editor utilities | EPM-WM CloudLicensing node in the Policy Editor.Retrieved 2026-09-26.
  8. Client installation | EPM-WM CloudNo licence at client install.Retrieved 2026-09-26.
  9. Management rules | EPM-WM CloudArchive, deletion and system purge rules for computers.Retrieved 2026-09-26.
  10. License management | EPM-ULLicence string attributes, client counting, enforcement, retirement.Retrieved 2026-09-26.
  11. Endpoint management | EPM-LEndpoint licence count and retirement in EPM for Linux.Retrieved 2026-09-26.
  12. Perpetual Licensing End of Sale & End of Life FAQDated August 30, 2024; hosted on assets.beyondtrust.com.Effective 2024-08-30. Retrieved 2026-09-26.
  13. End of Sale (EoS) & End of Life (EoL)EoS/EoL product list including EPM GPO and ePO editions.Retrieved 2026-09-26.

See also

Catalog Rows Cited

7Metrics

Esc