Start with actual usage behaviour, not vendor price cards. MAU is easier to understand but can overcharge bursty applications because it counts any authenticated user once per month. aDAU usually tracks cost more closely to daily consumption, so the better model depends on whether your users are steady, seasonal, or spike-driven.
Why This Matters for Security Teams
MAU and aDAU are not just finance labels. For identity teams, they shape how access, licensing, and governance assumptions are built around real user behaviour. A model that looks efficient on paper can become expensive or risky when the population is bursty, seasonal, or tied to short-lived campaigns. That is especially important where identities also touch privileged workflows, service access, or NHI-adjacent controls.
Practitioners should anchor the discussion in observed usage patterns, then test whether the pricing model matches the control objective. The Ultimate Guide to NHIs shows why this matters: NHIs outnumber human identities by 25x to 50x in modern enterprises, and 97% carry excessive privileges. That same discipline applies when identity platforms meter by month or day, because the wrong commercial model can distort how access is provisioned, reviewed, and retired. Current guidance suggests treating pricing as part of identity governance, not a separate procurement issue.
Identity teams often discover the mismatch only after a seasonal rollout, partner onboarding wave, or product launch has already triggered a spend spike, rather than through intentional capacity planning.
How It Works in Practice
MAU counts a user once if they authenticate at any point during the month. That is simple to explain, but it can overstate value for teams with intermittent usage, because a user who logs in once and one who uses the platform daily are treated the same. aDAU measures active users on a daily basis, so it can track consumption more closely when usage is repetitive, operational, or tied to frequent tool access.
In practice, the choice should be driven by the shape of demand:
- Use MAU when engagement is steady across the month and your goal is predictable budgeting.
- Use aDAU when activity is concentrated into workflows, shifts, or campaigns that vary from day to day.
- Compare both against provisioning and audit overhead, not only headline license cost.
- Validate whether the vendor defines “active” the same way your team defines “useful.”
For identity teams, this is also a governance question. The Top 10 NHI Issues highlights how easily visibility gaps and excessive entitlements accumulate when teams optimise for convenience instead of lifecycle control. A pricing model that encourages dormant accounts to remain “available” can quietly increase risk. NIST SP 800-53 Rev. 5 reinforces the need to align access and monitoring with actual operational need, not just procurement categories, through controls such as account management and access review. See the NIST SP 800-53 Rev 5 Security and Privacy Controls for the broader control context.
These models tend to break down when a single identity pool serves both human users and automation because the usage pattern becomes too mixed to price or govern cleanly.
Common Variations and Edge Cases
Tighter pricing alignment often improves cost accuracy, but it can also increase forecasting overhead, requiring organisations to balance budget precision against operational complexity.
One common edge case is partner or contractor access. A team may see low monthly activity but high daily concentration during onboarding or incident response, which can make MAU look cheaper even when it is not operationally fair. Another edge case is blended environments where human sign-in events trigger downstream automated actions. Best practice is evolving, but current guidance suggests separating human identity metrics from automation metrics whenever possible, then comparing pricing on the same usage boundary.
For NHI-heavy environments, the commercial model should not encourage long-lived access just to amortise license cost. That is where the Ultimate Guide to NHIs and the 52 NHI Breaches Analysis are useful reminders: unused or overexposed identities become security debt fast. In other words, the lowest sticker price is not always the lowest total cost once access review, revocation, and incident response are included.
There is no universal standard for this yet, so the practical answer is to model both MAU and aDAU against real logs, then choose the metric that least distorts behaviour and least weakens governance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity usage metrics affect NHI visibility and governance decisions. |
| NIST CSF 2.0 | GV.1 | Pricing decisions should align with governance and risk ownership. |
| NIST AI RMF | GOVERN | Usage-based AI and identity costs need accountability and monitoring. |
| NIST Zero Trust (SP 800-207) | ID.GV-1 | Identity governance should reflect actual access patterns under Zero Trust. |
| CSA MAESTRO | GOV-03 | Agent and workload access economics must support lifecycle control. |
Measure actual identity activity before selecting pricing that could hide dormant or overused NHIs.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org