Forescout Flexx, Per-Appliance and legacy licensing covers two things. The first is how licences for the on-premises Forescout platform (eyeSight, formerly CounterACT) are activated, pooled and enforced. The second is the module licences sold before the 2025 and 2026 Product License Guides moved to Solution Bundles. The June 2024 guide listed “two licensing paths”. In Flexx Licensing, “Licenses are independent of hardware appliances”. In Per-Appliance Licensing, “Licenses have a fixed device count per appliance”.[1] Forescout calls Flexx “a software-centric licensing model”.[2]
Editions
Licence types in the June 2024 guide
The 2024 guide named “three primary types of licenses”:[1]
| Type | Definition (2024 guide) | Products |
|---|---|---|
| Perpetual | “Software license with a right to use for an indefinite period of time” | eyeSight, eyeControl, eyeRecover, eyeExtend, eyeInspect 4.x and later |
| Term Based | “Software license with a right to use for the length of the term” | eyeSight, eyeControl, eyeRecover, eyeExtend; requires Forescout 8.1 or eyeInspect 4.x or later |
| Subscription Based | right to use for the subscription, “which includes maintenance and support” | eyeSegment, Forescout REM, Medical Security Platform, Forescout XDR, Forescout Assist |
Perpetual SKUs were paired with separate support SKUs. The perpetual eyeSight licence FS-LIC-SIGHT-100-1, for example, came with FS-AC-A-SIGHT-100-1 or FS-AC-B-SIGHT-100-1. The term-based equivalent was FS-LIC-TERM-A-SIGHT-100-1.[1] The April 2026 guide no longer lists perpetual licences. It lists only Term-Based Licenses and Subscriptions.[12] The EULA still covers perpetual Software: liability for claims about Software “licensed on a perpetual basis” is capped at the fees received for it.[13] Catalog proof: Perpetual licences were available for core modules (legacy).
Licensed products under Flexx
In Flexx mode the eyeSight licence is “the base licensed product and must be installed on each deployment”. eyeControl, eyeRecover, eyeSegment and eyeExtend licences add capabilities on top of it.[14] The documentation notes the older names. eyeSight was “Forescout CounterACT”.[14] eyeControl was “Forescout CounterACT Control”.[15] eyeRecover was “Forescout CounterACT Resiliency”.[16] eyeExtend licences were “previously known as Forescout CounterACT Extended Module licenses”.[9]
Metrics
The 2024 guide meters module licences by Device Count, “the maximum number of devices known to the respective Licensed Product by either their MAC addresses and/or their IP addresses”. SKUs end in -100-1, a block of 100.[1] eyeInspect had two options:[1]
- Option 1, Endpoint. An eyeInspect Base Flat Fee licence gives unlimited Enterprise Command Centers, Command Centers and Sensors. It requires an associated eyeInspect Endpoint licence.
- Option 2, Sensor. A Command Center or Enterprise Command Center licence plus eyeInspect Sensor licences sized by assets. “An extra-large Sensor license can handle up to 10,000 assets”, a large one 2,500, a medium one 500 and a small one 200. Command Centers come in sizes for up to 5, up to 15 or unlimited Sensors.
An active and a passive sensor co-located in one software instance “will be considered distinct sensors”.[1] Catalog proof: eyeInspect Sensor licences are sized by asset count (legacy); extra-large Sensor SKU.
Counting / floors
Add-on counts follow eyeSight (2024 guide). “Endpoint Count for eyeControl must match the Endpoint Count for eyeSight.” The same rule applies to eyeRecover, eyeExtend Connect, eyeExtend Ecosystem and eyeSegment. Individual eyeExtend Module licences may cover fewer endpoints but “cannot exceed the Endpoint Count of the eyeSight license”.[1] In an effective licence position for a legacy estate, eyeSight is the reference count and most add-ons must equal it. Catalog proof: Add-on Endpoint Counts must match the eyeSight count (legacy).
Subscoping (2024 guide). Subscoping was “only available with Flexx licensing” on version 8.1 or higher, with EMM as an exception. It was not available for eyeSight, eyeControl, eyeRecover, eyeSegment, eyeExtend Connect, eyeExtend Ecosystem, Assist, REM or XDR.[1]
Flexx capacity is per deployment. Under Flexx, licences “are activated centrally on the Enterprise Manager or Standalone Appliance”, and endpoint capacity “is calculated per-deployment”. The capacity can be distributed across Appliances.[3] Licence alerts cover licences that are about to expire and cases where “you have added endpoints and exceed your license capacity”. Oversubscription reminders are sent “Once a day”.[7] Catalog proof: Flexx capacity is per deployment and can be distributed; Oversubscription alerts are sent daily.
Per-Appliance counts are fixed. In Per-Appliance mode, “License counts cannot be reallocated or shared across appliances”. The mode is “only available on Forescout CT appliance” (with the CEM, VCT and VCEM variants). “The Forescout 5100 Series appliances only support Flexx”, and 4100 Series appliances run Flexx from version 8.2.2.[1] Catalog proof: Per-Appliance licence counts cannot be pooled (legacy).
Virtualization & partitioning
Under Flexx, Forescout’s licensing page says customers can “Spin-up unlimited virtual appliance instances as needed” and run virtual appliances on KVM, Hyper-V or VMware.[2] The 2024 guide offered virtual appliances in Flexx mode in five sizes, and VCT and VCEM virtual appliances in Per-Appliance mode.[1] Running Software outside Forescout hardware needed Flexible Deployment, sold in 2024 as FS-SUB-FLEX-DEPLOY-100-1. That subscription enabled “Customers who have elected to deploy as virtual appliances, docker container-based sensors, or on approved third-party hardware to receive Support Services”.[1]
Virtual systems in Per-Appliance mode start on a demo licence that is valid for 30 days. Their licences “are authenticated daily by the Forescout License Server”. “Licenses that cannot be authenticated for a month are revoked and significant Forescout functionality stops.” Using the same licence file on more than one device may also lead to revocation.[10] Catalog proof: Per-Appliance virtual licences are authenticated daily.
Cloud / BYOL
The 2024 guide states that Forescout virtual appliances “can be deployed on premises or in AWS or Azure”. For eyeInspect, support covered VMware, AWS and Azure.[1] These deployments use the same Flexx or Per-Appliance licences as on-premises appliances. Forescout publishes no separate bring-your-own-licence terms for them.
Programs
Flexx licence file lifecycle.
flowchart LR A["Order"] --> B["Allocate endpoints to a deployment in the Customer Support Portal"] B --> C["Activate licence file with Deployment ID"] C --> D["Update licence file for added products or capacity"] C --> E["Deactivate: licences invalid after 14 days"] E --> B
- Activation. “All licenses are activated and updated via a single license file.” “Once you activate the license using a specific Deployment ID, that ID is locked to the machine.” Activation on another machine fails until the file is deactivated.[4] Catalog proof: The Deployment ID locks the licence file to one machine.
- Updates. Adding products or capacity requires a request to Forescout. The Entitlement administrator then allocates the new quantity to a deployment in the Customer Support Portal, and a Deployment administrator updates the licence in the Console.[8] Catalog proof: Capacity changes come through an updated licence file.
- Deactivation and reallocation. Customers deactivate a licence file to replace an Enterprise Manager or “reallocate license capacity to a different deployment”. Licences then “become invalid in 14 days from the time of deactivation”, and “License deactivation cannot be reverted”.[5] Catalog proof: Deactivated licence files become invalid after 14 days.
- Enforcement. After a term licence expires, an alert appears. After 15 days, policies can no longer be created or modified. “30 days after expiration: Functionality stops completely.” An invalid eyeSight licence makes all other licensed products invalid “even if their term has not yet expired”.[6] Catalog proof: Expired term licences degrade at 15 days and stop at 30 days; An invalid eyeSight licence invalidates all other licensed products.
- Integration Modules. Integration Modules that bundle several licensed plugins “are not supported when operating in Flexx licensing mode”. Only eyeExtend modules that each package a single licensed module are supported, plus eyeExtend Connect.[9] Catalog proof: Integration Modules are not supported under Flexx.
Centralized Licensing and Deployment Rights (CL&D). The CL&D Supplement is an older enterprise arrangement that supplements the ForeScout EULA. Forescout delivers one master copy of each Software category, and the customer and its Affiliates may deploy instances “up to the Estimated Licensing Units”. The supplement has four main terms:[11]
- Each year, within the 30 days before the anniversary, the customer files a Deployment Report. Units above the estimate are paid “at the same rates as set forth in the most recent and applicable Order”, plus pro-rated ActiveCare support. This is the Licensing Units True-Up.
- Licences under the supplement “are perpetual licenses” unless stated otherwise. If the deployment right ends, the customer keeps a perpetual licence to Deployed Licenses that are in production, fully paid and reported.
- A See Feature licence covers visibility only. Using Control Features under it is a material breach. A customer “may not simultaneously hold a See Feature License for certain Products and a Control Feature License for other Products” without written agreement.
- Forescout may audit at the end of each term.
Catalog proof: CL&D requires an annual Deployment Report and true-up; CL&D customers keep perpetual Deployed Licenses on termination; See and Control Feature licences must be uniform across Products.
Out of scope
This article does not cover the current Solution Bundle SKUs (Forescout Solution Bundles and Cloud Services licensing) or support, verification and end-of-life terms (Forescout EULA, support and end of life). It also does not cover the Medical Security Platform and MDX600S sensor licences, which the 2024 guide mentions only briefly, or the Forescout License Server protocol.[1]