Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Client Access License
Governance, Ownership & Risk

Client Access License

← Back to Glossary
By NHI Mgmt Group Updated September 26, 2026 Domain: Governance, Ownership & Risk

A Client Access License is a permission to connect users or devices to a server product. In Active Directory budgeting, CALs are the visible licensing cost, but they do not capture the full expense of running directory services. Teams still need to fund servers, redundancy, hosting, administration, and security controls.

What a Client Access License Represents

A client access license, or CAL, is a commercial permission to connect a user or device to a server product. It is not the server itself, nor is it a security control, but it often determines whether access is contractually permitted and budgeted.

In practice, CALs matter because they sit at the boundary between licensing, user access planning, and operational cost. A directory service or other server platform may be technically reachable, but the organisation still needs the right license model to use it legally and at scale.

Why CALs Show Up in Server and Directory Planning

CALs become visible whenever a server product is sold on a per-user or per-device basis. That makes them common in enterprise infrastructure discussions, especially where teams are sizing directory services, remote access, collaboration platforms, or other systems that serve many internal consumers.

For budget owners, the key point is that the license line item is only part of the total cost. The real planning exercise includes server infrastructure, redundancy, hosting, administration, patching, monitoring, and security controls, all of which continue whether the CAL is user-based or device-based.

Because the licensing model can affect how access is counted and assigned, organisations should be clear on who or what is consuming the service. That clarity helps avoid surprise spend, under-licensing, and procurement friction when environments grow or change.

User-Based and Device-Based Licensing

CALs are usually sold in two broad models: user CALs and device CALs. A user CAL generally allows one person to access the server from multiple endpoints, while a device CAL generally allows multiple people to access through one licensed device.

The distinction is operational, not merely contractual. A mobile workforce, shared terminals, call centres, and remote desktop estates can produce very different license outcomes depending on which model is chosen. The wrong choice can make access more expensive than expected even when the technical architecture does not change.

This is why CAL planning should follow actual access patterns rather than assumptions about headcount alone. The best model depends on how users and endpoints interact with the service, not just on the number of employees in the organisation.

What CALs Do Not Cover

A CAL gives permission to connect, but it does not pay for resilience, security, or the broader operating burden of the service. Organisations still need to fund the server platform itself, directory design, backups, availability engineering, logging, endpoint hardening, and administrative overhead.

That distinction matters in identity-heavy environments because a license shortage can hide the real resource picture. Teams may think the platform is “covered” when only the right to connect has been purchased, leaving budget gaps in the controls that actually protect the service.

CALs also do not define access policy. A user may be licensed but still need authentication, authorization, least privilege, and governance controls before any meaningful access is granted.

Risk and Threat Considerations

Misunderstanding CALs creates operational and financial exposure more than direct cyber risk. The common failure mode is budgeting for access rights while underfunding the infrastructure and controls required to run the service securely and reliably.

Failure mechanism: Organisations treat the CAL as the total cost of access, then defer spending on redundancy, administration, and security controls until the environment is already in use.

Impact: The result can be service fragility, audit and procurement friction, unexpected renewal pressure, and weaker operational security because the supporting platform was never funded as part of the full lifecycle.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementCALs tie access eligibility to controlled account and license assignment.
IA-2 — Identification and Authentication (Organizational Users)CAL-funded access still depends on authenticated user access to the server product.
SC-28 — Protection of Information at RestServer products that use CALs still require protected data storage as part of the operating cost.
Recommendation — Align license assignment with account governance so only approved users or devices are enabled. Require authenticated access before a licensed user can connect to the service. Apply storage protection controls when budgeting for the licensed server environment.
CIS Controls v8CIS-6 — Access Control ManagementCAL planning intersects with who is permitted to connect and how access is governed.
Recommendation — Control access pathways so license assignment reflects actual authorised use.
ISO/IEC 27001:2022A.5.15 — Access controlCALs sit alongside access control because they permit connection to the server product.
Recommendation — Document access control requirements separately from licensing entitlement.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org