Licensing
Axidian Privilege supports the following licensing models:
Per privileged user — the license grants the right to use Axidian Privilege for a specified number of users and an unlimited number of resources.
Per resource — the license grants the right to connect to a specified number of resources: servers, hosts, etc. The number of users connecting via PAM is not limited.
Per privileged session — the license grants the right to open a specified number of simultaneous sessions in Axidian Privilege. All active sessions are counted. The number of PAM users and resources is not limited.
You can select only one licensing model per Axidian Privilege installation.
Regardless of the licensing model, you can also purchase licenses for additional functional modules. Such licenses do not affect users' ability to establish a session via PAM or the administrator's ability to grant permissions. Licenses for functional modules limit the use of additional features. These licenses include:
Licensing per privileged users
When selecting this licensing model, you will need to determine the number of users in your Axidian Privilege installation. The number of sessions (simultaneous connections) is not limited. User licenses can be redistributed between users (revoke licenses from some users and allocate them to others).
Issuance
To issue a user license, add at least one active permission to a user. After this, the license will automatically be considered taken by this user. If all user licenses are taken, you cannot add a permission to a new user.
Revocation
A user license is released when a user has no active permissions left, i.e., as a result of the following actions on a permission:
- Revocation
- Suspension
- Expiration
Validity Period
Types of licenses according to the validity period:
- Not time-limited
- Valid until a specific calendar date
- Trial period
- Subscription
Once the license expires, the following operations will no longer be available:
- Adding a resource
- Adding a user (even if some licenses have not been taken)
- Opening a session (connecting to a resource)
If you do not have unlimited licenses, connections will no longer be available when the licenses expire.
Licensing per resources
When selecting this licensing model, you will need to determine the number of resources in your Axidian Privilege installation. The number of sessions (simultaneous connections) is not limited. Resource licenses can be freed and then taken by other resources.
Issuance
To issue a resource license, create or restore a resource in Axidian Privilege. After this, the license will automatically be considered taken by this resource. If all resource licenses are taken, you cannot create a new resource.
Revocation
A resource license is released when the resource is deleted.
Validity Period
Types of licenses according to the validity period:
- Not time-limited
- Valid until a specific calendar date
- Trial period
- Subscription
Once the license expires, the following operations will no longer be available:
- Adding a resource
- Adding a user (even if some licenses have not been taken)
- Opening a session (connecting to a resource)
If you do not have unlimited licenses, connections will no longer be available when the licenses expire.
Licensing per privileged sessions
When selecting this licensing model, you will need to determine the number of sessions (simultaneous connections that can be opened via Axidian Privilege). The number of users and resources is not limited.
Issuance and Release
A session license is considered taken at the moment the session is opened and is released at the moment the session ends (the reason for termination is not important).
Validity Period
Types of licenses according to the validity period:
- Not time-limited
- Valid until a specific calendar date
- Trial period
- Subscription
Once the license expires, you will no longer be able to open sessions.
The following operations will remain available:
- Editing permissions
- Editing existing resources
- Editing accounts
If you do not have unlimited licenses, connections will no longer be available when the licenses expire.
AAPM License
The AAPM (Application to Application Password Management) license allows third-party applications to retrieve account secrets from Axidian Privilege.
When purchasing licenses of this type, you need to specify the number of accounts that can be accessed using AAPM.
There is no limit on the number of applications, application users, or permissions.
The AAPM license is independent of the selected licensing model.
The AAPM license can be purchased or removed at any time.
Issuance and Release
An AAPM license is considered taken when the first permission for an application is added to an account.
The AAPM license is released when all permissions are revoked from that account.
Suspension of a permission does not release the AAPM license.
Validity Period
Types of licenses according to the validity period:
- Not time-limited
- Valid until a specific calendar date
- Trial period
- Subscription
Once the license expires, the following operations will no longer be available:
- Adding new permissions to applications
- Using scenarios in which third-party applications retrieve account secrets from Axidian Privilege
Ad hoc Resources License
This license allows you to connect to ad hoc resources. The license does not limit the number of permissions or simultaneous connections to ad hoc resources.
The ad hoc resources license is independent of the selected licensing model.
The ad hoc resources license can be purchased or removed at any time.
Validity Period
Types of licenses according to the validity period:
- Not time-limited
- Valid until a specific calendar date
- Trial period
- Subscription
Once the license expires, previously created permissions will be set to the Inactive state, and the following operations will no longer be available:
- Adding or renewing permissions to connect to ad hoc resources
- Opening sessions to ad hoc resource
SQL Proxy License
This license allows you to connect to resources of the PostgreSQL and MSSQL types. This license defines the number of active permissions for resources of the PostgreSQL and MSSQL types.
The SQL Proxy license is independent of the selected licensing model.
The SQL Proxy license can be purchased or removed at any time.
Issuance
To take the SQL Proxy license, grant a user at least one active permission to a resource of the PostgreSQL or MSSQL type. If all SQL Proxy licenses are taken, you cannot add a permission to a resource of the PostgreSQL or MSSQL type to a new user.
Revocation
The SQL Proxy license is released as a result of the following actions on a permission to a resource of the PostgreSQL or MSSQL type:
- Revocation
- Suspension
- Expiration
Validity Period
Types of licenses according to the validity period:
- Not time-limited
- Valid until a specific calendar date
- Trial period
- Subscription
Once the license expires, the following operations will no longer be available:
- Adding or renewing permissions to connect to resources of the PostgreSQL and MSSQL types
- Adding users to a user group that has an active permission to a resource of the PostgreSQL or MSSQL type
- Adding resources to a resource group that has an active permission to a resource of the PostgreSQL or MSSQL type
- Selecting the PostgreSQL or MSSQL type when editing a user connection of a resource that has an active permission
- Opening a session to a resource of the PostgreSQL or MSSQL type