RSA SecurID is RSA’s on-premises multi-factor authentication product line. It centres on RSA Authentication Manager, the server that verifies one-time passwords and other authenticators, together with authentication agents and hardware and software tokens. The software is licensed under RSA’s End User License Agreement (EULA) or a signed agreement, and measured by the Units of Measure in RSA’s Units of Measure and Software Use document.[4][5] Authentication Manager is also included in the ID Plus E1, M1, E2 and E3 subscription plans. Those plans list a “Server license (Enterprise Edition)” and up to 15 replica servers.[9]
An Authentication Manager licence is a file imported into the deployment. Its header carries a licence identifier (LID), and RSA expects a new licence to be issued “with a serial number that matches your currently installed production serial number”.[2] Under the EULA, use may require product registration “to obtain and input an authorization key or license file”.[5] Catalog proof: EULA licence is for internal business purposes for the duration on the quote.
Editions
Authentication Manager licences come as Base or Enterprise. The two differ in replica limits and in advanced authentication features:
| Licence | Replica instances | Risk Based / On-Demand Authentication | Catalog row |
|---|---|---|---|
| Base | One replica instance[3] | Not available[2] | RSA Authentication Manager Base license |
| Enterprise | Up to fifteen replica instances[3] | Required for RBA and ODA[2] | RSA Authentication Manager Enterprise license |
Authentication Manager 8.9 “can use any version 8.0 or later license or a combination of supported licenses”.[1] Version compatibility runs one way, however. An 8.1 licence could deploy 8.1 to 8.4, but “An RSA Authentication Manager 8.4 license can only be used to deploy Authentication Manager 8.4 or later software”.[2] Catalog proof: An Authentication Manager 8.4 licence cannot deploy earlier versions.
RSA also maintains separate “SecurID Standard Form Agreements”, including an End User License Agreement and a Maintenance Agreement for SecurID Products. These are listed on its legacy agreements page.[10] Customers whose contracts reference those documents should read them in place of the current RSA EULA.
Metrics
The licence limit counts users, not tokens. In RSA’s documentation: “Users with assigned authenticators count against the license limit. Users with assigned authenticators that are disabled or expired also count against the license limit. Users with multiple authenticators only count once.”[1] This is recorded as the catalog metric users with assigned authenticators. It is a product-level application of RSA’s general User unit, which counts the maximum Users that may be managed by or authorized to use the software “regardless of whether such Users are actively using or accessing the RSA Software at any given time”.[4]
The replica instance is a second, deployment-level limit. On the License Status page, the Replication section’s Limit column shows the maximum replicas, and the Actual column “indicates the total number of primary and replica instances in the deployment”.[1] Hardware appliances are counted as Appliances: hardware supplied by RSA and loaded with RSA Software.[4]
Counting / floors
What counts. The Actual value “increases by one when one or more authenticators are assigned to a user”. By default a user may hold up to three authenticators, which can be any mix of hardware tokens, software tokens, RBA/ODA and one fixed passcode. Users without authenticators do not count: “there can be millions of users in the database and millions of token seeds imported” whatever the limit.[2] Disabled and expired assignments still count, so unassigning tokens from leavers is how a deployment frees licences.[1] Catalog proof: Authentication Manager counts users with assigned authenticators, including disabled or expired.
At the limit. The License Status page reports OK, Approaching Limit or Limit Exceeded.[1] A warning appears at 95% of the limit. “Once you reach the Actual number, you cannot assign more tokens to users.”[2] The software therefore enforces the user limit for new assignments. Catalog proof: At the Authentication Manager limit, no more tokens can be assigned.
RBA and ODA. Risk Based Authentication and On-Demand Authentication need an Enterprise licence. Enabling a user who has no token for RBA/ODA adds that user to both the assigned-authenticator count and the RBA/ODA licence count.[2] Catalog proof: Risk Based and On-Demand Authentication need an Enterprise licence.
Tokens are bought separately. RSA stresses that “tokens and licenses are separate purchases”. Raising the user limit does not supply tokens, and importing more tokens does not raise the user limit.[2] Token seed records are themselves treated as licensed software: “token records to RSA authenticators shall be deemed RSA Software and be subject to the restrictions on transferability” of the EULA.[4] Seed media must be installed within 90 days of shipment, and RSA deletes it from its systems after 150 days.[8] Catalog proof: SecurID tokens and Authentication Manager user licences are separate purchases; Token records are RSA Software and may not be transferred; Token seed media must be installed within 90 days.
Authenticators and agents. RSA authenticators may be used only to authenticate to RSA Software, and non-RSA devices only where the product licence explicitly allows them. Customers may install as many RSA authentication agents as their internal use needs, provided the agents are used only with RSA Software they have licensed.[4] Agents are therefore not a separate count; the users behind them are. Catalog proof: RSA authenticators may only authenticate to RSA Software; Authentication agents may be installed as needed for licensed software.
Virtualization & partitioning
Authentication Manager runs as a virtual or hardware appliance. The ID Plus plans that include it list both “Virtual appliance” and “Hardware appliance”.[9] The licence does not count hosts or processors. Scale-out is limited instead by the number of replica instances the licence allows, and attaching a replica beyond that number fails with the message “This replica exceeds the number of instances allowed by the license.”[3] The EULA’s default of “one production copy” applies unless the Product Notice grants more.[5] Software delivered on RSA Equipment may be used only on that Equipment.[5] Catalog proof: Base licences allow one replica, Enterprise licences fifteen; Only one production copy unless the Product Notice grants more.
Cloud / BYOL
SecurID itself is on-premises software. Customers that want cloud authentication buy RSA ID Plus, whose E1, M1, E2 and E3 plans combine the Cloud Authentication Service and Identity Router with an Authentication Manager Enterprise server licence. See ID Plus licensing.[9] No rule allows on-premises Authentication Manager licences to be applied to the cloud service.
Programs
Maintenance and the support lifecycle
Maintenance Services cover hardware and on-premises software and are paid annually in advance. Releases past their end of primary support (EOPS) date are excluded. “Each Software Release will reach its EOPS date after a period of not less than twenty four (24) months” following general availability, unless the lifecycle page sets another date.[6] RSA’s lifecycle table gives Authentication Manager EOPS dates by version. For example, 8.9 reaches EOPS in Feb 2028 with Level 1 Extended Support to Feb 2029, and 8.7 SP2 reaches EOPS in Jan 2027 with Level 1 and Level 2 Extended Support to Jan 2028 and Jan 2029. “All EOPS dates will be reached at the end of the stated month.”[7] Catalog proof: On-premises releases reach end of primary support at least 24 months after GA; Extended Support.
Support on an EOPS release without an Extended Support agreement may be charged per case, in addition to the annual contract.[6] Reinstating lapsed support costs the fees for the lapsed period, the current annual fee and a reinstatement fee.[6] Catalog proof: Reinstating lapsed support costs the lapsed period plus a fee.
Warranty
On-premises software warranty “runs with purchase of a maintenance support option”. SID700 and SID800 hardware tokens carry a lifecycle warranty up to six months before the expiry date printed on the token. SecurID hardware appliances carry a three-year advanced replacement warranty.[8] Catalog proof: On-premises software warranty runs only with a maintenance option.
Evaluation
Evaluations run for 45 calendar days for internal, non-production use only.[11] RSA’s guidance is to uninstall an Authentication Manager trial licence before applying the production licence.[2]
Out of scope
- The SecurID Authentication Engine, Authentication API and legacy ACE/Server licence formats.
- Prices of tokens, user licences and appliances, which RSA does not publish.
- RADIUS, Web Tier and Bulk Administration features, beyond the Enterprise licence rule above.