Rubrik’s SaaS Application Protection products back up data held in third-party SaaS applications into a Rubrik-hosted environment. They are licensed per user. Two of them, Rubrik for M365 Protection and Rubrik for Google Workspace Protection, combine the user count with a limit on the amount of protected data.[1] Rubrik’s identity recovery products are licensed per enabled user account in the protected directory, and its code repository protection per repository.[1] All are term subscriptions under the Rubrik Service Agreement, which limits use to the quantities in the Order.[2]
Editions
The Licensing Guide has product specific terms for each application:[1]
| Product | Metric | Hosting |
|---|---|---|
| Rubrik for M365 Protection | User plus Data Protection Capacity | Rubrik-hosted by default (Azure region chosen by the customer, multi-geo option); Customer-hosted option |
| Rubrik for Google Workspace Protection | User plus Data Protection Capacity | Rubrik-hosted (GCP region chosen by the customer, multi-geo option) |
| Rubrik for Salesforce Data Protection | User (active Salesforce and Salesforce Platform licences) | Rubrik-hosted |
| Rubrik for Microsoft Dynamics Data Protection | User (unique Dynamics 365 users) | Rubrik-hosted |
| Rubrik for Jira Data Protection | User (active Jira Software users, per site) | Rubrik-hosted |
| Universal SaaS Application License | User on one SaaS offering, up to 100GB | Follows the product |
| Identity Recovery; Identity Resilience | Enabled user account in AD or Entra ID | Not stated |
| Identity Okta Recovery | Enabled user account in Okta | Not stated |
| Codebase Recovery for Azure DevOps and GitHub | Repository | Rubrik-hosted by default; Customer-hosted option |
Customers may move from Customer-hosted to Rubrik-hosted M365 offerings, and from standalone to bundle offerings, at any time. This requires an Order and may cost extra.[1] Catalog: Rubrik for M365 Protection; Universal SaaS Application License; Rubrik Identity Recovery and Identity Resilience; Rubrik Codebase Recovery for Azure DevOps and GitHub Protection.
Metrics
Universal SaaS Application License
The Universal SaaS Application License (USL) “is a single SKU available on a per-user basis that entitles a User to use one Rubrik SaaS Application Protection offering”. A USL may be transferred between Rubrik for Microsoft Dynamics, M365, Salesforce and Jira Protection, and it supports up to 100GB of Data Protection Capacity per User.[1] Customers must not back up more User accounts than they have bought, or exceed the capacity supported per User.[1] A user who is protected in two applications therefore needs two USLs. Catalog: Universal SaaS Application License User; One USL covers one user on one SaaS offering up to 100GB.
Data Protection Capacity
For Microsoft 365, Data Protection Capacity “means all non-expired downloaded Customer Data in the SLA window, including relics, data churn, and the Exchange Archive Mailboxes that are protected by the Rubrik Service”.[1] Microsoft’s own reports measure capacity at a point in time and leave out relics, churn and archive mailboxes, so Rubrik’s capacity reports may show higher usage than native Microsoft 365 reports. The same applies to Google Workspace, where the definition covers relics and churn.[1] Licence planning should use Rubrik’s own figure. Catalog: Data Protection Capacity; Rubrik capacity reports can exceed native M365 reports.
Counting / floors
Microsoft 365
The Rubrik-hosted M365 Service is licensed on a combined per User and Data Protection Capacity basis. The Licensing Guide’s example is a customer with 1,000 Users and 5,000 GB, which is out of compliance if it exceeds either.[1]
- User count. The greater of the number of protected user mailboxes and the number of protected OneDrives.
- Shared and group mailboxes. Not counted as Users, but their data counts toward Data Protection Capacity.
- Managed users. A User is managed while at least one restore point from the past 31 days exists. After a continuous month without a backup of a user, the licence can be applied to another User.
- Growth. Users and capacity can be increased at any time, co-termed with the original Subscription Period.
Catalog: M365 Service User; M365 is licensed per User and Data Protection Capacity together; M365 Users are the greater of mailboxes and OneDrives; A SaaS User is managed if it has a restore point in the past 31 days.
Google Workspace
Google Workspace is also licensed per User plus Data Protection Capacity. Users are the unique count across protected Gmail mailboxes and Google Drives. The Licensing Guide’s example: 200 users on both Gmail and Drive plus 100 users on Drive only need 300 User licences.[1] The 31-day managed user rule applies. Catalog: Google Workspace Service User; Google Workspace Users are unique across Gmail and Drive.
Salesforce
Customers must buy at least enough licences for the licensed user base of each protected Salesforce production environment. That base is the sum of active “Salesforce” and “Salesforce Platform” user licences in the protected production org.[1] Rubrik counts the licences each day, so usage can vary. If usage in one org falls, the spare licences can be applied to another org.[1] Each protected production environment may have one Full Sandbox and unlimited Developer, Developer Pro and Partial Copy sandboxes associated with it. Seeding backed-up data into a sandbox org for test or development requires an active entitlement to Salesforce DevOps. Without it, the service may be used only for backup and recovery.[1] Catalog: Salesforce Service User; Salesforce licences cover active Salesforce and Platform users; Seeding Salesforce sandboxes needs Salesforce DevOps.
Microsoft Dynamics 365
The Dynamics service is licensed per user for the entire licensed user base. Unique users licensed for Dynamics 365, or with full or direct access to one or more Dynamics 365 applications, are counted. Users with access only through a Dynamics Trial licence are excluded.[1] Catalog: Microsoft Dynamics Service User; Dynamics trial-only users are excluded.
Jira
The Jira service counts active users with assigned Jira Software licences that have access to the protected site. If the customer protects several sites, users are counted for each site.[1] A user with access to two protected sites therefore counts twice. Catalog: Jira Service User; Jira Users are counted per protected site.
Identity
Identity Recovery recovers a clean copy of Active Directory or Entra ID. Identity Resilience adds risk identification and monitoring for indicators of compromise.[1] Both are licensed per user. Customers must license their entire licensed user base, which “equals the greater of the number of enabled user accounts in all AD domains or in all EntraID tenants managed by the Rubrik Service (whichever is higher)”.[1] A domain or tenant is managed once it is configured for backup. Groups, computers and roles are not counted. Identity Okta Recovery counts enabled user accounts in managed Okta tenants on the same basis.[1] Because only enabled accounts count, disabling leavers’ accounts reduces the count. The count is the larger of AD and Entra ID, not their sum. Catalog: Identity licensed user; Identity products count the larger of AD or Entra ID enabled users.
DevOps
Codebase Recovery for Azure DevOps and GitHub Protection is licensed per repository. The same licence covers repositories in either Azure DevOps or GitHub, and a repository is managed once it is configured for backup.[1] Rubrik Agentic Coding Resilience bundles DevOps Protection with Rubrik Agent Cloud and includes a monthly repository entitlement. A repository counts as protected when it is enabled for automated backup.[1] Catalog: Repository; DevOps Protection is licensed per managed repository.
Floors and trials
Per-user products must cover the entire licensed user base, which acts as the floor.[1] Free Trials of Rubrik-hosted M365 are limited to 500 Users and 10 TB of Data Protection Capacity. Google Workspace trials are limited to 10 Users and 500 GB.[1] The Service Agreement allows trials only for internal, non-commercial evaluation for 30 days unless Rubrik sets another period.[2]
Virtualization & partitioning
The SaaS metrics count users and data, not infrastructure. The relevant boundaries are tenants, orgs and sites. Salesforce is counted per protected production org, Jira per protected site, and the identity products across all managed domains or tenants.[1]
Cloud / BYOL
The SaaS services are Rubrik-hosted. Rubrik stores the backup data in a Rubrik-managed public cloud, and the customer chooses the region at configuration (Azure for M365, Salesforce, Dynamics and Jira, GCP for Google Workspace).[1] Creating a secondary backup copy, such as frequent exports to a location outside the Rubrik Service, is not permitted with any Rubrik-hosted subscription.[1] At the end of a subscription, data extraction may be subject to a one-time fee.[1] Recovery Licenses, which let customers recover data after expiry, are not available for hosted offerings.[1] Catalog: No secondary backup copies from Rubrik-hosted subscriptions.
Programs
Under the RSC Utility program, Microsoft 365 must be covered either by M365 user and Data Protection Capacity licences or by the USL, not both. A customer may buy both, but the USL then cannot be applied to M365 and is limited to other SaaS applications.[1] Catalog: Under Utility, the USL cannot cover M365. Identity and DevOps licences added during a term are co-termed with the original Subscription Period.[1]
Out of scope
- Prices and the pricing of the USL against product specific user licences.
- Rubrik’s support for other SaaS applications not named in the Licensing Guide.
- The licence terms of Microsoft, Google, Salesforce and Atlassian, which govern the protected applications themselves.