CyberArk Endpoint Privilege Manager (EPM) removes standing local administrator rights from endpoints and servers and elevates privileges for approved applications and tasks on demand.[1] Its licence is a per-endpoint licence set at account level. The documentation describes the licence in four parts: the two licence types, how usage is counted, what happens on overuse, and what happens when the licence expires.[2]
Editions
The EPM licence page names two licence types.[2]
| Licence | Serves | Redesignation |
|---|---|---|
| EPM for Workstation | A single designated endpoint | The licence of a decommissioned endpoint may be redesignated to a different single endpoint; the designated endpoint may not be changed frequently for other purposes |
| EPM for Server | A single endpoint servicing multiple users | The licence of a decommissioned server may be redesignated to a different server; the designated server may not be changed frequently for other purposes |
The licence is set at account level and applies to all the account’s sets, and the account defines its sets using different types of licences depending on the organisation’s needs.[2] The set types visible in the licence rules are full protection, credentials rotation and non-persistent VDI.[2] EPM can be used within the Identity Security Platform Shared Services (ISPSS) or standalone, and the place where the licence details are viewed differs: in ISPSS through View license details next to the Create set button, and in a standalone console through Administration, Configuration, License.[2]
The product is delivered as SaaS, so the SaaS Terms of Service govern access, with the quantity specified in the Order.[3]
Metrics
| Metric | Unit | Counting rule |
|---|---|---|
| EPM for Workstation licence | One designated endpoint | Agents active or inactive for up to seven days.[2] |
| EPM for Server licence | One server serving multiple users | Same agent rule.[2] |
| EPM non-persistent VDI concurrent active agent | Concurrent active agent | Used for sets of non-persistent virtual desktops.[2] |
Counting and floors
The seven-day rule
Licence usage is based on agents that are active or have been inactive for up to seven days. Endpoints inactive for more than seven days are not counted toward licence usage but still count toward the total endpoint count.[2]
The three-times cap
The account may hold a total of active and inactive endpoints that is up to three times the licensed number of endpoints. If that total is exceeded, new endpoints cannot connect to the server.[2] The documentation’s own example sets the licence limit at 100 endpoints, with 90 active endpoints and 10 endpoints inactive for seven days or less (together 100, which count toward usage) and 200 endpoints inactive for more than seven days (not counted toward usage). The total is 300, three times the limit, so new endpoints cannot connect until the total is reduced.[2]
This produces two different thresholds that a licence position must keep apart.
| Threshold | Measured as | Consequence |
|---|---|---|
| Licence limit | Active agents plus agents inactive up to seven days | No new policies can be created; status shows Overused[2] |
| Three times the licensed number | All active and inactive endpoints | New endpoints cannot connect[2] |
Licence status
The licence is validated whenever a set is accessed and when a policy is created. The status is Valid when the licence is applied to a number of agents within the limits, Expired when it is no longer active (new policies cannot be created and the licence must be renewed before account activities are restricted), and Overused when more agents are registered than the licence permits.[2] When a licence nears expiry or overuse an icon in the user menu shows the status.[2]
Virtualization and partitioning
Virtual machines are counted according to how their set is configured. Overuse is checked on the total consumption across all sets: full protection and credentials rotation by the number of registered agents, and non-persistent VDIs by the number of concurrent active agents.[2] A non-persistent desktop pool is therefore measured by the agents active at the same time, not by every desktop that has ever registered. The page does not define a separate rule for persistent virtual machines, and it does not say whether a virtual server uses the Workstation or Server licence beyond the definition that the Server licence serves a single endpoint servicing multiple users.[2]
Cloud and self-hosted
EPM is licensed as a SaaS subscription. The documentation’s expiry timeline shows what the SaaS service does when the licence ends.
| Time | EPM action |
|---|---|
| 30 days before expiry | Email notification to the account owner |
| 1 day after expiry | Second email notification |
| 14 days after expiry | Administrators in the account are prevented from signing in to the console |
| 30 days after expiry | Permanent deletion of account data begins and agents stop enforcing policies |
| 44 days after expiry | Deletion of account data is finished |
| 58 days after expiry | SaaS backups containing customer data are overwritten |
All rows are from the EPM licence page.[2] The SaaS Terms of Service separately provide that data is deleted within the period stated in the documentation or, if none, within 60 days of termination or expiry.[3] Policy enforcement therefore stops at the 30 day point, before deletion of the data finishes.
Programs
- Support. Support Services are provided as part of an active SaaS subscription.[3] Higher support options are bought for additional fees, and a customer that stops renewing an enhanced option reverts to Production Support.[4]
- Trial Services. Free trials and proofs of concept are for internal evaluation and may lose data at the end of the trial unless a subscription to the same product is bought.[3]
- MSP licence. A managed service provider that runs EPM for a customer’s endpoints licenses it under the MSP agreement, for the designated Tenant only.[5]
- Perpetual conversion. Customers converting earlier perpetual self-hosted licences to SaaS see the perpetual licences terminated under the Order.[3]
Audits and compliance
SaaS use is bounded by the quantity in the Order. If the customer exceeds subscribed quantities it must cooperate to resolve the non-compliance, which may include paying overages at then-current rates.[3] The EPM console licence details view is the primary evidence. The seven-day inactivity rule means a licence position taken on one day can differ from one taken a week later, so a position should record the date and the set types in scope.
Out of scope
Pricing is not published. EPM agents’ operating system support and the on-premises server edition’s documentation are not covered here. The Privilege Cloud and PAM - Self-Hosted products are in CyberArk privileged access management licensing.