Understand Cortex XSOAR licenses
Understand licenses for Cortex XSOAR 8 SaaS.
Cortex XSOAR requires a yearly license per user. Multi-year licenses are available.
License usage
This table describes the types of Cortex XSOAR licenses which are used in the following circumstances:
Cortex XSOAR (Enterprise) Edition
Built for customers who need a complete security automation solution.
Includes the SOAR Enterprise and TIM Enterprise licenses.
Cortex XSOAR Threat Intel Management Edition
Built for Threat Intelligence and Security Operations teams who need threat intelligence-based automation.
Includes the TIM Enterprise license only.
Cortex XSOAR Starter Edition
Built for Security Operations and Incident Response customers who need case management with collaboration and playbook-driven automation.
Includes the SOAR Enterprise license only.
Multi-Tenant
Cortex XSOAR Enterprise, Threat Intel Management, and the Starter editions are all available for multi-tenant deployments, with a multi-tenant license. Cortex XSOAR multi-tenant deployments are designed for MSSPs (managed security service providers) and enterprises that require strict data segregation but also need the flexibility to share and manage critical security practices across tenant accounts.
If you have a multi-tenant license (for example PAN-DEMISTO-MSSP), you are entitled to a main and child tenant. If you require additional child tenants you need additional licenses.
Development/Production tenants
In Cortex XSOAR you can use a content management system with a remote repository to develop and test content. If you want a development tenant, you need a development tenant license. The development tenant license allows many users to build, test, and refine automations. It is not limited to your purchased user licenses, and it enables multiple stakeholders to work on these tasks. This supports faster innovation, more reliable workflows, and scalable solutions as your organization grows.
License quota
The following table describes the license quotas of each version in Cortex XSOAR.
Integrations
Unlimited
Unlimited
Unlimited
Incident Management
30-day history
180-day history*
180-day history*
Incident Triggered Automations
166 daily
Unlimited
Unlimited
Job Triggered Automations
Unlimited
Unlimited
Unlimited
Intel Feeds
Unlimited
5 active feeds, 100 indicators/fetch
Unlimited
Threat Intel Library
Unlimited
Intelligence detail view and relationship data are not included
Unlimited
Note
*You can extend incident retention by purchasing an add-on. For more information, see Data retention policy.
Intel feed quotas are based on the selected Fetches Indicators field in the integration instance settings, not the enabled status. Disabling an integration instance does not affect the Intel feed quota. For example, if the AWS Feed is enabled and is fetching indicators and you don't want to include this in your quota, open the integration settings and clear the **Fetches Indicators **checkbox.
Cortex XSOAR users
Cortex XSOAR has the following users:
Audit user
Audit users have read-only permission in Cortex XSOAR, meaning they cannot edit system components and data or run commands, scripts, and playbooks. Audit users can view incidents, dashboards, and reports.
Full user
Full users have read-write permission in Cortex XSOAR, meaning they can view and edit system components and data. They can investigate incidents, run scripts and playbooks, chat in the War Room, and more. Full users’ access to Cortex XSOAR is determined by their assigned role.
Last updated
Was this helpful?
