CyberArk privileged access management licensing covers three related products: Privilege Cloud, the hosted privileged access service; PAM - Self-Hosted, the Vault, web portal, password manager and session manager that the customer installs; and Remote Access, the service through which external vendors reach privileged accounts. The three share a vocabulary of licence types but count them differently, and Remote Access can consume licences in two products at once. CyberArk’s documents now use the Idira name, so the same page may be titled “Manage the Idira License” while earlier versions say CyberArk.[1]
Editions
Privilege Cloud
The Privilege Cloud user licences report lists the following lines: Privileged Basic User, Privileged Standard Lite User, Privileged Standard User, Privileged External User, Credential Providers (CPs/CCPs) and Total Applications.[2] The number of licences of each type is configured in the tenant at set-up, and the system package may be expanded later with new licence types.[2][3] The Standard Lite licence is discontinued as of 2025, and licences bought before 2025 remain valid.[3]
Another Privilege Cloud documentation page names the licence types as EPVUser, BasicUser and EPVUserLite, and says the initial package may have been expanded with new types.[4] The documentation does not map those legacy names to the current Standard, Basic and Standard Lite names, so an entitlement that uses the legacy names should be reconciled against the Order.
PAM - Self-Hosted
In PAM - Self-Hosted the licence received before the Vault server is installed determines how many users, passwords and files the Vault can store, and it defines groups of user types and the interfaces that each type can use.[1] The licence is delivered as a licence file, License.xml, which is installed in the System Safe or in the Vault’s configuration folder.[1] The Privileged Session Manager service may need a restart after a licence change because it does not recognise a changed number of concurrent sessions until restarted.[1]
Remote Access
The Remote Access tenant licence states the total number of licences usable during the validity period, a breakdown of users and Vendors with limits for each, the number of monthly active Vendors that can log in during the calendar month, the Remote Access sessions permitted during the month, and the expiration date. Fields set to unlimited are not shown.[5]
Metrics
| Metric | Product | Definition in the documentation |
|---|---|---|
| Privileged Standard User | Privilege Cloud | Consumed by roles such as Privilege Cloud Administrators.[3] |
| Privileged Basic User | Privilege Cloud | Consumed by roles with the Basic suffix; not licensed for PSM connections.[3] |
| Privileged Standard Lite User | Privilege Cloud | Discontinued in 2025; existing licences remain valid.[3] |
| Privileged External User | Privilege Cloud | Default licence of vendors invited through Remote Access.[3] |
| Credential Providers (CPs/CCPs), Total Applications | Privilege Cloud | Report lines for providers and applications; the counting unit is not defined on the page.[2] |
| Vault user type | PAM - Self-Hosted | EPVUser, BizUser, PSMUser, AIMAccount, OPMUser and component types, each with allowed interfaces.[6] |
| Concurrent PSM sessions | PAM - Self-Hosted | Concurrent PSM sessions carried by the licence.[1] |
| Remote Access subscription licence, Remote Access monthly active Vendor, Remote Access sessions per month | Remote Access | Licences for users and Vendors, monthly active Vendors and monthly sessions.[5] |
Counting and floors
Privilege Cloud: roles select licences
Each user licence type is mapped to a Privilege Cloud role in Identity Administration, so the role defines the permissions and also maps the user to the licence consumed. The role name reflects the licence: if several types were purchased, each role appears once per type. The Privilege Cloud Administrators role consumes the Privileged Standard User licence while Privilege Cloud Administrators Basic consumes the Privileged Basic User licence.[3] A licence is in use when a user is connected using it or is added to a Safe using it.[2]
When a user is deleted, a role is revoked or a user’s role is changed, the service-specific licences are updated according to the Privilege Cloud licence management policy.[3] For users from Active Directory the documentation advises separate groups per user type and licence and asking technical support to map each group to the right user licence.[4]
The Basic licence restriction
The Privileged Basic User licence is not licensed to perform Privileged Session Manager connections in any role type. A group or user in a role that uses the licence must not be allowed PSM connections, and the documentation advises removing the Use accounts permission the user has on Safes to avoid a licence violation.[3] For a licence position this means that Safe permissions, not only role assignment, are part of the evidence for a Basic user.
External vendors
Vendors invited from Remote Access are assigned to the Privilege Cloud External Vendors role by default and consume Privileged External User licences. The system can be configured to assign vendors to the Privilege Cloud User role, which consumes Privileged Standard User licences.[3] A Remote Access vendor consumes a Privilege Cloud licence only when a corresponding user exists in the Vault. In the worked sequence in the documentation, a vendor user created in Remote Access consumes only a Remote Access licence; immediately after the first connection to Privilege Cloud the system creates the VendorLDAP and Vault users and a Privilege Cloud licence is consumed.[5]
Remote Access users do not consume a Privilege Cloud licence while their status is Before timeframe, Awaiting confirmation, Deactivated or Expired. Deleting a Remote Access user deletes the corresponding Vault and VendorLDAP users; deactivating a user removes it from VendorLDAP at once and from the Vault 24 hours later.[5]
Where a vendors monthly access licence applies, an administrator sets how many of the total Vendor users may access Privilege Cloud in a calendar month. A Remote Access licence is consumed when the Vendor user is created; a monthly licence is consumed only when the Vendor accesses Privilege Cloud.[5]
PAM - Self-Hosted: user types and the capacity report
The licence defines user types, and every user, including predefined users, users added through LDAP and component users, is assigned one. The default types and their interfaces include EPVUser (PVWA, PrivateArk Client, PrivateArk Webclient, PACLI, PIMSU), PSMUser (PSM and PVWA) and AIMAccount (Application Provider and PVToolkit).[6] The License Capacity report in the PrivateArk Client shows the maximum number of licences for each user type or object and the number used. Only types and objects limited by the licence are shown, and predefined Vault users and groups are not included in licence usage.[1]
By default the Vault warns one week before the licence expires and daily thereafter. The LicenseUsageAlertLevel parameter in DBParm.ini sets three percentage thresholds based on the number of users of each type; the default is 85, 90 and 99, with a notification on every new user once the third threshold is exceeded.[1]
Remote Access warnings
An orange warning triangle appears in the licence details when 90 percent of the licensed access is used and a red one after 100 percent. Monthly session use is updated hourly from the first sign-in.[5]
Virtualization and partitioning
The retrieved documents contain no virtualization or partitioning rules for these products. The units they name are user licence types, Vault user types, concurrent PSM sessions, Vendors and sessions, not processors, cores or hosts.[1][2][5]
Cloud and self-hosted
A Privilege Cloud tenant runs on the shared services platform, where every service needs a valid active entitlement. When the entitlement period ends without renewal the service is suspended and then permanently discontinued, and the service and its data are kept for at least seven days after suspension.[7] The Setup space shows licence usage per service and licence type, currently for Privilege Cloud and Idira Identity.[7]
For PAM - Self-Hosted, supported versions are set by the end-of-life policy. LTS versions have a longer development period, and their support period can be extended for additional fees; the development period cannot be extended. Fixes for LTS versions require all components on the same LTS version, and upgrades are supported from one LTS version to another or to the latest release. For example, version 15.2 (LTS) is listed as released July 2026 with end of development July 2029 and extended end of support July 2031.[8]
Programs
- Support options. Production, Premium, Platinum and Trusted (US only) set response times; a subscription customer that does not renew an enhanced level reverts to Production Support.[9]
- Perpetual conversion. Converting perpetual self-hosted licences to SaaS terminates the perpetual licences and their support under the Order.[10]
- MSP licence. A managed service provider operating these products for a Tenant licenses them under the MSP agreement.[11]
Audits and compliance
For self-hosted software CyberArk may review use against licensing metrics, request usage reports not more than once per year on reasonable notice, and invoice use above the purchased number or type of licences.[12] For SaaS, exceeding the quantities in the Order obliges the customer to cooperate and may mean paying overages at then-current rates.[10] Useful evidence sets are the Privilege Cloud user licences report, the Vault License Capacity report, role assignments in Identity Administration and the Safe permissions of Basic-licence users.[2][1][3]
Out of scope
Secure Infrastructure Access and the Privileged Threat Analytics component are not covered here because the licensing pages retrieved do not state their metrics. Privilege Cloud and Remote Access prices are not published.