Imprivata Enterprise Access Management (EAM) is Imprivata’s single sign-on and authentication product line for workstations, virtual desktops, mobile devices and clinical applications. The documentation still names its two halves after the older products: “Enterprise Access Management for SSO (Imprivata OneSign)” and “Enterprise Access Management for MFA (Imprivata Confirm ID)”.[1] EAM is On-Premise Software. It runs on Imprivata appliances, with an agent on each endpoint, and is licensed under the Master License and Services Agreement as perpetual or subscription licences, as the Order Form states.[5][6] Its basic unit is the named user. The console counts a user once for each licensed feature turned on in that user’s policy. That makes the user policy, not the directory, the record that decides licence consumption.[1][2]
Editions
Legacy licensed features
The License page in the Imprivata Admin Console lists every licensed feature. Features are shown “in bold if purchased for your environment, grayed out if not yet purchased or if the license has expired”. When an SSO or MFA licence expires, all features under it appear grayed out.[1] The documentation groups the features as follows:
| Group | Licensed features |
|---|---|
| SSO (OneSign) | Authentication Management; Single Sign-On; Self-Service Password Reset; National Access |
| MFA (Confirm ID) | Remote Access; EPCS; Clinical Workflows; Medical Devices; Mobile EPCS; DigiCert Individual Identity Proofing |
| Additional | Fingerprint Identification; Connector for Epic Hyperspace; Connector for Epic Warp Drive; ProveID Web API; Mobile Device Access; OneSpan (VASCO) OTP Token Authentication; Symantec VIP Credential Authentication; Virtual Desktop Access; Hands Free Authentication |
Source: Licensed Features documentation.[1] The archived EULA used older names. “OneSign” meant Single Sign On, Authentication Management, or the combined SSO/AM. “OneSign Options” meant Self Service Password Management, Finger Biometric Identification, Vasco Authentication, Proximity Aware, Virtual Desktop Access and Mobile Device Access. Confirm ID was defined as the secure signing solution for electronic prescribing of controlled substances.[4]
Modular packaging
Imprivata now sells EAM in modules. “Every deployment starts with Core Access”, and optional modules are added “based on user roles, environments, and workflows”.[3] Each module is recorded as a catalog SKU without a part number.
| Module | Prerequisite | Content (summary) |
|---|---|---|
| Core Access | Required for all EAM users | SSO, badge, fingerprint, smart card or password sign-in, identity sync, identity analytics |
| Shared Device Access | Core Access | Shared workstations and kiosks, fast user switching, secure walkaway, pull-printing |
| Advanced and Passwordless Access (APA) | Core Access | Passwordless and risk-based authentication, remote access, self-service password reset |
| Secure Workspace Access | Core Access and Shared Device Access | VDI, secure browsers, thin and zero clients |
| Clinical Workflows Plus | Core Access and Shared Device Access | EHR re-authentication, witness signing, medical devices |
| EPCS Plus | Core Access and APA | Electronic prescribing of controlled substances; includes Clinical Workflows Plus features |
| National Access | Core Access and Shared Device Access | UK NHS Spine and France Pro Santé access |
Source: EAM Packaging.[3] The packaging page names the parts of National Access that are only on the roadmap and says purchases “should be made solely on the features and functionality available today”.[3] For existing customers, “current licenses are mapped to the new Core Access and module-based structure”, in a review led by the Imprivata account team.[3] The 26.2 License page has a “Show EAM new modules” switch between “legacy licensing information and the new EAM modules”.[1] New features can need a module. Risk-Based Access, for example, needs “the Advanced Passwordless Access license”.[9] Catalog proof: Core Access required for every EAM user.
Metrics
- Licensed feature seat. The console shows license usage per feature as “license seats allowed based on purchases, enabled seats, and remaining seats”. A warning appears when all or nearly all seats are used.[1]
- User and Non-Clinical User License. These are the contractual units behind the seats. Both are named and not concurrent.[5]
- Mobile Device Access device. “Imprivata MDA is licensed on a per-device basis.”[1]
- Device (OneSign and Confirm ID). Under the archived EULA, a supported mobile or medical device listed in the Supported Components guide. It needs a separate licence and is not licensed on a concurrent device basis.[4]
- Enterprise licence. Covers the Epic Hyperspace and Warp Drive connectors and the ProveID Web API.[1]
Counting / floors
Which users count
The user account documentation sets three rules. “An enabled user consumes a license for each licensed feature that is enabled in the user policy”. “A disabled user does not count towards your license total”. “Enrollment status does not effect license usage.”[2] A user imported from Active Directory and left enabled therefore counts even if the user never enrolls a badge or fingerprint. Disabling a user takes effect “the next time the user authenticates”.[2] Catalog proof: Enabled users consume a licence per enabled feature.
Per-feature rules
| Feature | What makes a user count |
|---|---|
| Authentication Management | Fingerprint, proximity card, smart card or ID token enabled in the user policy, or desktop authentication with OneSpan OTP tokens |
| Single Sign-On | “Allow users single sign-on access to applications” selected in the policy |
| Self-Service Password Reset | “Allow users to reset their primary authentication password” selected |
| National Access | Spine Combined Workflow enabled; licensed per user |
| Confirm ID features (Remote Access, EPCS, Clinical Workflows, Medical Devices) | The user policy is associated with a Confirm ID workflow |
| Fingerprint Identification, Symantec VIP, Hands Free Authentication, OneSpan OTP | Option selected under Authentication tab, Licensed options |
| Virtual Desktop Access | “Enable virtual desktop automation” selected |
Source: Licensed Features documentation.[1] The Download License Usage button on the User policies page exports the enabled features and the number of licensed users for each. It leaves out the two Epic connectors and the ProveID Web API, “which are licensed once for your enterprise”.[1] Catalog proof: Confirm ID usage follows workflow policies; Epic connectors and ProveID Web API licensed per enterprise.
Bundles and dependencies
Authentication Management and Single Sign-On “may be purchased separately or as a combined license”. With a combined SSO/AM licence, “AM and SSO are counted together and cannot be used separately”. With 100 SSO/AM users, a customer cannot give AM to 100 users and SSO to a different 100.[1] Several features need other licences:
- Mobile Device Access counts each device with the MDA app installed. “Authentication Management and Single Sign-On licenses are also required”, and every user tied to a mobile app profile counts toward those.[1]
- Virtual Desktop Access includes ProveID Embedded. In the typical case it needs an Authentication Management or bundled SSO/AM licence.[1]
- Mobile EPCS needs Confirm ID for EPCS, Mobile EPCS and VASCO OTP Token Authentication. Facial biometrics has no licence of its own but needs Confirm ID for EPCS and Mobile EPCS.[1]
- DigiCert Individual Identity Proofing needs Confirm ID for EPCS and Confirm ID for Clinical Workflows.[1]
Catalog proof: Combined SSO/AM licence counts one population; Mobile Device Access is per device and needs AM and SSO.
Non-clinical users
Staff who never treat patients and never use EAM to access the electronic medical record can be licensed as Non-Clinical Users.[5] The documentation does not describe a separate console counter for them. A licence manager therefore has to keep the evidence of eligibility, such as role data or EMR access records, outside the console. Catalog proof: Non-Clinical User licences exclude clinicians and EMR access.
Virtualization & partitioning
EAM is not counted by processor. Appliance capacity is an infrastructure question. The architecture guide describes appliances as OVF images for VMware ESX, Microsoft Hyper-V and Nutanix, or deployed in the customer’s Microsoft Azure tenant. An enterprise has two database appliances plus service appliances, with standard designs of two, four or six appliances.[6] Licensing reaches the appliance through the licence file. When an enterprise is set up, the administrator uploads “your Imprivata license” on the License Key Configuration page.[8] To add an appliance, an unused serial number from the licence file must be selected. If none is available, “Ensure your license includes the appliance to be added”, and a new licence file must be obtained from an authorized Imprivata reseller. Uploading it overwrites the old file and “takes effect immediately”.[7] Under the archived EULA, OneSign and OneSign Options “are required to be used in conjunction with an Appliance, have a matching level of Support”.[4] Virtual Desktop Access counts each user in a policy with virtual desktop automation enabled; the documentation names no per-virtual-machine count.[1] Catalog proof: Appliances are authorized from the licence file; OneSign must run with an Appliance and matching Support.
Cloud / BYOL
EAM is not a SaaS product, but it uses Imprivata cloud services for some functions. The architecture guide says appliances “communicate with Imprivata cloud services to integrate and support other Imprivata solutions”.[6] The archived EULA gave EAM users access to the Cloud Service, for example the Imprivata ID mobile app, SMS one-time passwords and EPCS identity proofing, only “provided you are active on Support”.[4] The new module view of the License page links to the Access Intelligence dashboard.[1] Access Intelligence is licensed separately; see Imprivata mobile, patient and monitoring licensing.
Programs
EAM is covered by Maintenance and Support. For perpetual licences, Support is the only route to new versions. If Support is bought for any perpetual On-Premise Software, the same level must cover all of it.[5] Support renews only for all Products and Hardware. It covers maintenance releases for the current and two prior versions, and at least 24 months of defect resolution from each release.[10] New application profiles, or changes to existing ones for a new version of third-party software, are outside Maintenance and Support and need Professional Services.[10] Catalog proof: Same Support level for all perpetual On-Premise Software; Maintenance releases for current and two prior versions.
Out of scope
This article does not cover Imprivata hardware readers and badges (see the Hardware terms in the MLSA article), third-party token licences such as OneSpan or Symantec VIP credentials, or EHR vendor licences. Prices are not published. The documentation describes how to count licence usage, but the quantities bought are set only by the Order Form and licence file.