BeyondTrust License provides access to enterprise identity security and privileged access management solutions designed to control privileged accounts, credentials, remote access, endpoint privileges, and identity-related risks. BeyondTrust helps organizations apply least-privilege principles, secure administrative access, monitor privileged sessions, and manage access to critical systems across on-premises, cloud, and hybrid environments.
Quick Benefits
- Privileged Access Management (PAM)
- Privileged account and credential protection
- Just-in-time access control
- Least-privilege enforcement
- Privileged session monitoring and recording
- Secure remote access for internal and third-party users
- Endpoint privilege management
- Password and secrets management
- Identity risk visibility
- Application and service-account protection

BeyondTrust License At a Glance
What it is: Enterprise privileged access and identity security licensing portfolio
Primary products: Password Safe, Privileged Remote Access, Endpoint Privilege Management, Remote Support, Identity Security Insights, Entitle, and Active Directory Bridge
Primary role: Secure privileged identities, credentials, endpoints, sessions, and remote access
Security areas: PAM, least privilege, privileged session management, credential security, identity security, and remote access
Core technologies: Privileged Account and Session Management (PASM), Just-in-Time (JIT) access, least privilege, credential vaulting, session monitoring, and identity analytics
Deployment models: Cloud, on-premises, hybrid, and distributed environments
Typical environments: Enterprise IT, government, finance, healthcare, telecommunications, manufacturing, critical infrastructure, and OT networks
License model: Subscription-based licensing, with product-specific metrics
License Overview
A BeyondTrust License defines access to the specific identity security and privileged access capabilities required by an organization. BeyondTrust does not use one universal licensing metric across its entire portfolio. The licensing requirements vary according to the selected product and deployment architecture.
For example, Password Safe focuses on privileged passwords, secrets, accounts, and sessions, while Endpoint Privilege Management focuses on controlling administrative privileges across endpoints. Privileged Remote Access addresses secure privileged access to remote systems, including access by internal users, vendors, and third parties.
Important licensing factors can therefore include:
- Number of users
- Number of endpoints
- Number of managed systems
- Privileged accounts
- Remote access users
- Concurrent sessions
- Required security modules
- Cloud or on-premises deployment
- Integration requirements
- Subscription duration
BeyondTrust is also transitioning away from perpetual licensing. The company has announced that perpetual licensing is being retired across its products, with support for perpetual licenses ending December 31, 2026.
How BeyondTrust Licensing Works
BeyondTrust licensing begins by identifying the privileged access problem that needs to be controlled.
A typical enterprise may require several security functions:
Identity Discovery
→ Identify privileged users, accounts, machines, and access relationships
Privilege Reduction
→ Remove unnecessary standing administrative rights
Credential Protection
→ Secure privileged passwords, secrets, keys, and accounts
Controlled Access
→ Provide privileged access only when required
Session Monitoring
→ Record and audit privileged activity
Risk Analysis
→ Identify excessive privileges and suspicious access paths
This modular approach allows organizations to select the BeyondTrust capabilities that correspond to their environment instead of treating all privileged access requirements as a single security problem.
BeyondTrust Security Portfolio Overview
| BeyondTrust Solution | Primary Purpose |
|---|---|
| Password Safe | Privileged password, account, secret, key, and session management |
| Privileged Remote Access | Secure and controlled remote access to critical systems |
| Endpoint Privilege Management | Enforce least privilege and control application elevation on endpoints |
| Remote Support | Secure remote technical support and troubleshooting |
| Identity Security Insights | Identity visibility, privilege-path analysis, and identity risk insights |
| Entitle | Just-in-time access and entitlement management |
| Active Directory Bridge | Extends centralized identity and access capabilities to Unix and Linux environments |
| Pathfinder Platform | Unifies BeyondTrust identity security capabilities and visibility |
Licensing Options and Models
| Licensing Option | Description | Suitable For |
|---|---|---|
| Password Safe Subscription | Protects privileged credentials, secrets, accounts, and sessions | Organizations implementing PAM |
| Privileged Remote Access Subscription | Controls privileged remote connections and third-party access | Vendor, administrator, and remote privileged access |
| Endpoint Privilege Management Subscription | Removes unnecessary admin privileges and provides controlled elevation | Windows, macOS, and Linux endpoint environments |
| Remote Support Subscription | Provides secure remote support and troubleshooting capabilities | IT service desks and support teams |
| Identity Security Insights | Provides visibility into identities, privilege relationships, and access risks | Enterprise identity security programs |
| Entitle Subscription | Provides entitlement management and just-in-time access capabilities | Cloud and application access governance |
| Active Directory Bridge | Extends centralized identity capabilities to Unix and Linux systems | Mixed Windows, Linux, and Unix environments |
| Bundled PAM Licensing | Combines selected privileged access capabilities under a broader deployment | Organizations requiring multiple PAM functions |
| Multi-Year Subscription | Provides coverage for an extended subscription period | Long-term enterprise deployments |
Features and Benefits
Privileged Credential Management
Password Safe provides centralized management for privileged accounts and credentials.
It can protect:
- Administrator passwords
- Service accounts
- SSH keys
- Application credentials
- API keys
- Tokens
- DevOps secrets
Credentials can be discovered, onboarded, stored, rotated, and accessed according to organizational policies.
This reduces dependence on manually maintained privileged passwords and limits exposure of credentials to administrators.
Privileged Session Management
BeyondTrust provides session management capabilities that allow organizations to monitor and record privileged activity.
Administrators can review:
- Remote sessions
- SSH activity
- RDP sessions
- User actions
- Credential usage
In supported workflows, active sessions can also be paused or terminated when suspicious activity is detected.
This provides an audit trail for security investigations and compliance requirements.
Just-in-Time Access
Standing privileged access increases the potential impact of compromised credentials.
BeyondTrust supports Just-in-Time access models that provide privileges only when required.
Access can be controlled according to:
- User
- Resource
- Time
- Context
- Task
- Security policy
This helps organizations move toward least-privilege and Zero Trust access architectures.
Compatibility and Requirements
Before selecting a BeyondTrust License, organizations should evaluate:
- Number of users
- Number of privileged users
- Number of endpoints
- Number of managed systems
- Privileged account quantity
- Remote access requirements
- Concurrent sessions
- Windows, Linux, and macOS environments
- Cloud and SaaS resources
- Active Directory or LDAP integration
- SIEM integration
- High-availability requirements
Activation and Deployment
A typical BeyondTrust deployment includes:
- Identify privileged identities and systems
- Select the required BeyondTrust products
- Determine the appropriate subscription scope
- Activate the licenses
- Configure identity providers and authentication
- Onboard privileged accounts and systems
- Define least-privilege and access policies
- Configure session monitoring
Pricing and Quote Process
Pricing for BeyondTrust License depends on the selected products and the scope of privileged access that needs to be protected.
Before requesting a quote, prepare:
- Number of privileged users
- Number of standard users requiring privilege management
- Number of endpoints
- Number of managed servers and systems
- Number of privileged accounts
- Remote access users
- Expected session volume
- Required session recording
- JIT access requirements
BeyondTrust pricing depends on your PAM requirements, product edition, number of privileged users and assets, access management capabilities, deployment model, license term, and support needs.
