Use this document to evaluate whether IDaaS EIAM fits your needs, select the right edition, and estimate costs. It covers edition features, billing methods, and add-on pricing for procurement decision makers and technical evaluators.
Overview
IDaaS EIAM 2.0 provides the Free Edition, Standard Edition, and Enterprise Edition. The Free Edition is available at no cost. The Standard and Enterprise editions use a prepaid subscription model, billed based on edition features and account quota.
The total cost is calculated as follows:
Total cost = Edition base fee (includes account quota) + Add-on fees (optional) + Machine Identity Management fees (optional, billed separately)
Edition base fee — Determined by the selected edition (Standard Edition or Enterprise Edition) and the purchased account quota. Required for all paid instances.
Add-on fees — Includes Dedicated Endpoint and Conditional Access. Calculated as a percentage of the Enterprise Edition base fee. Available for the Enterprise Edition only.
Machine Identity Management fees — Covers M2M applications, Agent ID Guard, and static credential hosting. Billed independently from the edition base fee.
Edition overview
Dimension | Free Edition | Standard Edition | Enterprise Edition |
Target use case | Personal trial and small-scale testing | Standard identity management for small and medium-sized enterprises | Full-featured identity governance for large enterprises |
Max accounts per instance | 10 | Determined by purchased quota | Determined by purchased quota |
Max applications per instance | 3 | 10 (including paid applications) | 1,000 |
Audit log retention | View logs from the past 7 days | 7 days | 366 days |
Branding (logo, name, custom domain) | Not supported | Not supported | Supported |
Service availability SLA | Not guaranteed | 99.9% | 99.9% |
Technical support | Ticket | Ticket (response within 24 hours) + 8×5 hours dedicated consultation | Ticket (response within 24 hours) + 8×5 hours dedicated consultation |
How to choose an edition:
Free Edition — Try the product with up to 10 accounts and 3 applications. Suitable for individual testing and proof of concept.
Standard Edition — Small to medium teams (up to 10 applications) that need core identity management features including DingTalk and OIDC integration with 7-day log retention.
Enterprise Edition — Large organizations (up to 1,000 applications) that require advanced capabilities such as WeCom integration, SAML federation, outbound IdP, conditional access, dedicated endpoints, 366-day audit logs, and compliance-grade identity governance.
Identity source and sync capabilities
Feature | Free Edition | Standard Edition | Enterprise Edition |
Identity sources | 1 | 1 | 5 |
DingTalk inbound IdP (scan-to-login, full sync) | Supported | Supported | Supported |
DingTalk inbound IdP (workbench SSO, incremental/sensitive data sync) | Not supported | Supported | Supported |
Feishu inbound IdP | Not supported | Supported | Supported |
AD/LDAP inbound IdP (delegated login, filter, full sync) | Not supported | Not supported | Supported |
AD/LDAP inbound IdP (custom login ID, incremental sync, scheduled validation) | Not supported | Not supported | Supported |
WeCom inbound IdP (scan-to-login, workbench SSO, data sync) | Not supported | Not supported | Supported (requires Dedicated Endpoint) |
OIDC inbound IdP (federated authentication, manual account binding) | Supported | Supported | Supported |
OIDC inbound IdP (auto bind/create/update, Azure AD/Okta federation) | Not supported | Supported | Supported |
SAML inbound IdP | Not supported | Not supported | Supported |
Alibaba Cloud SASE inbound IdP | Not supported | Not supported | Supported |
Outbound IdP (login, data sync, and more) | Not supported | Not supported | Supported (DingTalk supported; more integrations to follow) |
Sync direction | Inbound only | Inbound only | Inbound and outbound |
Application and authentication capabilities
Feature | Free Edition | Standard Edition | Enterprise Edition |
App Marketplace applications (SSO, data sync, open API) | Specific apps only | Supported | Supported |
Standard and custom applications (SAML/OIDC SSO, data sync, open API) | Not supported | Supported | Supported |
Basic login and authentication (password, SMS OTP) | Supported | Supported | Supported |
Secondary authentication (OTP/email MFA) | Not supported | Supported | Supported |
MFA binding at login | Not supported | Supported | Supported |
Groups and extended attribute capabilities | Not supported | Supported | Supported |
Security and management capabilities
Feature | Free Edition | Standard Edition | Enterprise Edition |
Basic security (password complexity, high-risk password detection) | Supported | Supported | Supported |
Advanced password policies (initial password, expiration, history, forgot password) | Not supported | Supported | Supported |
Conditional Access (context-based dynamic access decisions and step-up authentication) | Not supported | Not supported | Supported (add-on) |
Branding (logo, name, custom domain) | Not supported | Not supported | Supported |
Authorize applications to accounts, organizations, and groups | Supported | Supported | Supported |
Dedicated Endpoint (for WeCom integration or private network AD/LDAP connectivity) | Not supported | Not supported | Supported (add-on, purchased separately) |
Billing methods
IDaaS EIAM paid editions support two billing methods: Active Account Billing and Account-Based Billing.
Active account billing (recommended — only option for new purchases)
Active Account Billing applies to new purchases. You are billed based on the number of users who log in or authenticate at least once during the past calendar month. The total number of accounts synced to IDaaS is not capped.
Billing rules:
When purchasing an instance, you must pre-select an active account quota as the base quota.
Active accounts are counted monthly. An active account is a unique user who completes at least one login or authentication action during the billing period.
If the actual number of active accounts exceeds the purchased quota, excess users cannot log in. Upgrade your quota promptly to avoid service disruption.
For specific pricing, refer to the pricing page.
Best for: Enterprises with a large total workforce but a low daily active user ratio (such as retail stores, field workers, or seasonal employees), or enterprises that want to sync all employees to IDaaS but pay only for active usage.
Account-based billing (renewal only — existing customers)
Account-Based Billing applies to customers who purchased IDaaS before Active Account Billing was introduced. You are billed based on the total number of accounts created in the IDaaS instance.
Billing rules:
Billing is based on the total account count in the instance. The per-account price decreases as the account count increases.
When the actual account count reaches or exceeds the paid quota, no new accounts can be created. However, existing users' login and SSO functionality is not affected.
Existing customers can continue using this method upon renewal, or they can switch (one-way) to Active Account Billing. Once switched, you cannot revert to Account-Based Billing.
Best for: Enterprises with a small, stable workforce where nearly all employees use the system on a daily basis.
Billing method comparison
Dimension | Active Account Billing | Account-Based Billing |
Applicable users | New purchases (only option) | Existing customers renewing only |
Billing basis | Monthly active user count | Total account count in instance |
Account sync limit | Unlimited | Determined by purchased quota |
Effect when quota is exceeded | Excess users cannot log in | No new accounts can be created |
Can you switch? | — | Can switch one-way to Active Account Billing (irreversible) |
Add-on billing
Add-ons must be purchased alongside an Enterprise Edition instance. The fees are calculated as a percentage of the Enterprise Edition base fee.
Dedicated endpoint
The Dedicated Endpoint add-on enables AD/LDAP data sync and delegated authentication without exposing public network ports, or provides a dedicated public IP address for WeCom integration. For more information, see Network access endpoints.
Each Dedicated Endpoint costs 30% of the Enterprise Edition base fee. You can purchase up to 1 endpoint per Enterprise Edition instance.
If you downgrade from Enterprise Edition to Free Edition, the Dedicated Endpoint becomes unavailable and is automatically deleted after 1 day. Resources and data cannot be recovered.
Conditional access
Conditional Access lets you define dynamic access decisions and step-up authentication requirements based on access context — for example, different applications, network environments, or devices. For more information, see Conditional access policies.
Conditional Access costs 40% of the Enterprise Edition base fee. You must use an Enterprise Edition instance to purchase this add-on.
If you downgrade from Enterprise Edition to Free Edition, custom Conditional Access policies become invalid. Default policies are not affected.
Machine identity management (billed separately)
Machine Identity Management is an independently billed module of IDaaS EIAM that includes the following capabilities:
M2M Management: Manages permissions between services for non-interactive scenarios. IDaaS issues authorization credentials and works with API Gateway and other components for authentication.
Agent ID Guard
Static Credential Hosting
This module is activated using a prepaid model, and subsequent resource consumption is settled through pay-as-you-go billing.
Upgrades and downgrades
Upgrade
All editions support upgrades at any time, including increasing the account quota, upgrading the edition (Standard Edition → Enterprise Edition), and adding add-on capabilities. Upgrades take effect immediately. You pay the price difference prorated to the remaining subscription period.
Downgrade
Starting May 30, 2026, downgrade capabilities are being progressively enabled:
Downgrade item | Status | Notes |
Active account quota reduction | Supported | Reduce the base active account quota |
Edition downgrade (Enterprise Edition → Standard Edition) | Coming soon | Features that exceed Standard Edition capabilities become unavailable after downgrade |
Dedicated Endpoint removal | Coming soon | The endpoint is automatically deleted 1 day after downgrade |
Conditional Access removal | Coming soon | Custom policies become invalid after downgrade; default policies are retained |
Existing customers who switch from Account-Based Billing to Active Account Billing cannot revert to the original billing method.
Instance expiration
Functional restrictions after expiration
When a paid instance expires and is not renewed, it is automatically downgraded to the Free Edition. The following changes apply:
Item | Behavior after expiration |
Feature scope | Restricted to Free Edition capabilities; features beyond the Free Edition become unavailable |
Account data | Instance data is not deleted |
Account limit | Subject to the Free Edition limit of 10 accounts |
Dedicated Endpoint | Unavailable; automatically deleted 1 day after expiration, and cannot be recovered |
Conditional Access | Custom policies become invalid; default policies are retained |
How to restore | Repurchase a paid instance to restore paid capabilities |
Special notes for existing customers
Starting May 30, 2026, existing customers whose instances expire without renewal will have their instances directly downgraded to Free Edition restrictions. The previous grace period that allowed unlimited account counts is no longer available. We recommend renewing before expiration or evaluating whether you need to adjust your edition.
Billing examples
Example 1: New purchase — Enterprise edition (active account billing)
A company has 500 employees to sync to IDaaS, with an estimated 200 monthly active users. They also need Conditional Access and 1 Dedicated Endpoint.
Item | Calculation |
Enterprise Edition base fee | 200 active accounts × unit price (refer to the pricing page) |
Conditional Access | Enterprise Edition base fee × 40% |
Dedicated Endpoint (×1) | Enterprise Edition base fee × 30% |
Total | Base fee × 1.7 |
Example 2: Existing customer renewal — account-based billing
A company currently uses Account-Based Billing with 100 accounts in the instance and no add-ons.
Item | Calculation |
Enterprise Edition base fee | 100 accounts × unit price (refer to the pricing page) |
Total | Base fee |
If considering switching to Active Account Billing: evaluate your monthly active user count. If fewer than 100 users are active per month, switching may reduce your cost. Note: switching is irreversible.