Join our Newsletter — 33% off our NHI Course

Per-User Subscription

A licensing or service model in which access to a security capability is assigned to an individual user rather than a single device. This approach can simplify workforce scaling, replacement of lost hardware, and budgeting. It is commonly used when organisations need predictable operating expense and easier lifecycle management for authentication controls.

What Per-User Subscription Means in Security Operations

A per-user subscription ties entitlement to an individual person, which matters because access can follow the user across devices, replacements, and workspace changes. That makes the model useful for authentication services where the operational unit is the employee, not the endpoint.

In practice, this model supports predictable budgeting and simpler administration, but it also means the organisation must think in terms of account lifecycle rather than hardware lifecycle. For security teams, that shifts attention to enrolment, revocation, and how quickly access changes when people join, move, or leave.

Why Organisations Choose This Licensing Model

The main attraction is operational simplicity. When a capability is licensed per user, the organisation can standardise access across laptops, desktops, or temporary devices without reassigning a device-bound licence each time hardware changes. That is especially useful for distributed workforces and helpdesk-managed authentication tools.

It also reduces friction in replacement scenarios. If a device is lost, retired, or reimaged, the user’s subscription can usually remain intact, which avoids service interruptions and repetitive procurement steps. Where the service supports security controls such as MFA or passwordless access, this can make adoption easier because the licence follows the user’s identity rather than the machine.

Operational and Security Implications

Per-user licensing sounds administrative, but it has security consequences because the billing unit becomes the access unit. If user accounts are not disabled promptly, the subscription can continue to fund access for accounts that should no longer exist. If shared accounts are used to save cost, the model can also blur accountability and weaken auditability.

The approach is strongest when paired with clear ownership of account creation, review, and revocation. It works best when the organisation can answer which individual owns the entitlement, how usage is measured, and what happens when a user changes role or exits the business. Those questions are more important here than the device count itself.

For identity-heavy environments, the subscription model fits neatly with a broader lifecycle view of access management, especially where access is granted to the person and then inherited across endpoints. NHIMG’s Ultimate Guide to NHIs is useful background for understanding why lifecycle discipline and entitlement visibility matter when access is tied to an identity rather than a machine. For a concrete attack-path example of why entitlement mistakes matter, see the Replit AI Tool Database Deletion incident analysis.

When Per-User Subscription Becomes a Governance Decision

Governance implication: This model is not just a procurement choice, it is an access governance choice. Teams should decide whether the subscription is meant to represent one named worker, one operational function, or one security-relevant account, because that determines how ownership, offboarding, and reporting are handled.

What to watch for: Problems usually appear when organisations treat the subscription as “just a licence” and stop tracking who actually benefits from the access. If the user can shift devices freely, the entitlement still needs periodic review so that dormant accounts, duplicated subscriptions, and forgotten administrative access do not accumulate.

For broader control design, NIST’s Security and Privacy Controls provide a strong reference point for access control and account management, while NIST SP 800-63 Digital Identity Guidelines helps frame how the user’s authenticated identity should anchor access decisions. Organisations that want a service model view can also map the choice to the NIST Cybersecurity Framework 2.0 under governance and protect functions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organisational Context Per-user subscriptions reflect how the organisation structures and owns access capabilities.
PR.AA-01 — Identity Management, Authentication and Access Control The model ties access to named users, so entitlement and authentication governance are central.
PR.PS-03 — Configuration Management Device changes should not disrupt user access when the licence follows the user.
Recommendation — Define who owns per-user entitlements and how they support business operations. Bind subscriptions to named identities and enforce access lifecycle controls. Maintain configurations that preserve user access across device replacement and refresh.
NIST SP 800-63 IAL — Identity Assurance Level User-bound access depends on confidence in the identity being licensed and authenticated.
AAL — Authenticator Assurance Level Per-user subscriptions often support authentication controls that must be matched to the user’s access.
Recommendation — Use identity assurance appropriate to the sensitivity of user-bound access. Choose authenticators that match the assurance needs of the subscribed user.
CIS Controls v8 5 — Account Management Named-user licensing depends on managing user accounts, enrolment, and deprovisioning.
Recommendation — Track, review, and remove user accounts that no longer need the subscription.

Practitioner Guidance

Why practitioners should care: Per-user subscription is easiest to defend when the entitlement is tied to a named owner and a real access lifecycle. That keeps budgeting, audit trails, and revocation aligned, and it reduces the temptation to use shared accounts or unmanaged workarounds.

Common misunderstanding: Teams often assume that because the licence follows the person, the control is automatically well managed. In reality, the subscription model only remains safe when joiner-mover-leaver processes, periodic access review, and licence reclamation are operationally disciplined.

Practitioner takeaway: Treat the subscription as an ownership model, not just a billing model, and make sure the person who receives the entitlement is also the person who can be reviewed, offboarded, and held accountable for it.