Menu
  • Downloads
  • Knowledge Base
  • Documentation
  • Reputation
  • Email Security Tester
  • Downloads
  • Knowledge Base
  • Documentation
  • Reputation
  • Email Security Tester
home/Knowledge Base/Libraesva ESG/Libraesva ESG License Accounting
Popular searches:GDPR, ESG 5 migration guide, "How to configure Libraesva ESG for Microsoft 365"

Libraesva ESG License Accounting

1551 views 1 May 24, 2023 Updated on June 15, 2023 giorgio

Table of Contents

  • Licensing Models
    • Email Address accounting model
    • Mailbox accounting model
  • Licensing knowledge base
    • What are license types listed on license usage?
    • How can I configure email aliases as in ESG before 5.2
    • A note on Microsoft Shared Mailboxes on hybrid configuration
    • Maintenance of users when using an external integration
Print to PDF

Licensing Models

Email Address accounting model

The ESG accounting system is based on active recipient (or sender) addresses, which includes all
email address that have successfully received (or sent) a scanned email. Extra automatic measures
have been put in place to avoid paying for invalid email addresses.

The list of active recipients is created by searching for messages that have been successfully
delivered from or to a configured relayed in “Admin > Mail Transport > Relay”. This means that
bounced deliveries or rejected emails are not accounted for.

Once a recipient is accounted for, it will remain accounted for until it naturally expires after 30
days of inactivity or is invalidated due to configuration control. For instance, if a configured
relay use a “valid recipient list” to verify currently enabled email addresses, a license will automatically
expire when its address is removed from the list.

The accounting process occurs every night but can be re-computed at will from the web UI.

Mailbox accounting model

Depending on your commercial agreement with Libraesva, your licensing may be mailbox based.

The mailbox accounting model uses the same rule as recipient accounting to identify actively used
recipient addresses. Once recipients have been collected, the system determines the active mailboxes
by using the information available in ESG user manager (found under “Admin > Authentication >
User Management > User”). The active mailbox appears in the list as “type = mailbox” with
the user’s primary address listed as the accounted address.

Mailbox accounting typically results in a lower license count as distribution lists and user
secondary emails are immediately excluded from the computation. However, there may be exceptions
to this rule, such as when a user receives email only through distribution lists. In this case, the
user is considered active, even if their primary address is never used.

Starting with ESG 5.2, there is a new type of user called a “Functional User” that is not accounted
for in mailbox licensing. These users can only be created automatically by the importer from
Microsoft 365, Google Workspace, or LDAP and represent Shared Mailboxes or Groups that are not
bound to any users. Functional users cannot log into ESG and have limited quarantine capabilities,
just like the account in external environments.

NOTE: mailbox accounting is very precise in identifying active users, but requires administrators
to properly manage users and integration layers. Please refer to the following paragraphs for
additional details.

Licensing knowledge base

What are license types listed on license usage?

When accessing “Admin > Appliance > Licensing > License Usage,” you may notice a “type” column
in addition to the accounted license.

A license of type Recipient identifies a simple active recipient that is accounted for and is
not bound to any user stored on ESG. Since this is an active recipient, it is accounted for in
all licensing models.

A license of type Mailbox identifies an accounted active mailbox, and the email shown is
the primary (and unique) address of the user. If your license model is simply recipient-based, this is
exactly the same as a recipient license for a user’s primary address. For mailbox accounting, this
refers to an active user who has received at least one email to their inbox; to find details about
which email they received, open the detailed view to see user information and quickly search the
mail logs for hints.

A license of type Free identifies an accounted active mailbox or recipient address that has been
discounted by Libraesva ESG, either manually from Accounting support or remotely using code automation.
These are not accounted for in final costs but are listed for transparency.

How can I configure email aliases as in ESG before 5.2

Starting with Libraesva ESG 5.2, users have a primary and globally unique address that is used
for domain attribution and license accounting. The concept of email aliases is no longer used. Instead,
users may have one or more secondary addresses for the same mailbox.

The old email alias concept is similar to the new secondary email address system. However, the previous
implementation had a long list of heuristics to discriminate an address from an alias, that were
imprecise and not clearly visible from the user interface.

Our testing of the new licensing system has shown that it can identify mailboxes much better thanks
to the user integration layer, configured by the administrators. This has resulted in lower average
license accounting.

A note on Microsoft Shared Mailboxes on hybrid configuration

The Microsoft 365 integration layer has the capability to differentiate between real users and shared
mailboxes by analyzing the licenses assigned to external users. Users without licenses are imported
as “Functional users” in Libraesva ESG, ensuring that both software have the same licensing.

However, the hybrid configuration can be more complicated due to the limited API provided
by Microsoft. Even actual mailboxes may not have assigned licenses. To address this limitation,
for synchronized hybrid users without licenses, we utilize the accountEnabled user property
to distinguish between “Users” and “Functional Users”.

As a result, there may be slight differences in accounting between ESG licensing and Microsoft
Exchange licensing. To minimize this disparity, it is recommended that Hybrid Shared Mailboxes
be configured with accountEnabled = $FALSE.

IMPORTANT: according to Microsoft official documentation, Shared Mailboxes are not designed for logon and leaving a Shared Mailbox without Block Sign-in (that is accountEnabled = $FALSE) is considered a security issue. Therefore, blocking sign-in for all your Shared Mailbox is the best configuration for both Microsoft 365 account security and for Libraesva ESG licensing.

Maintenance of users when using an external integration

Mailbox accounting is much more precise when used in conjunction with external user imports, such
as Microsoft 365, Google Workspace, and LDAP. However, these importers do not automatically
remove mailboxes or valid recipients for security and stability reasons. Therefore, periodic
maintenance is crucial, especially a few days before your next licensing cycle.

To make maintenance easier, here are a few helpful tips:

  1. Ensure that all relays listed under “Admin > Mail Transport > Relays > Relays” are using
    the “Valid Recipient List” as the recipient verification method. Other methods may incur higher
    costs if an invalid address is mistakenly accepted by your server.
  2. Access “Admin > Mail Transport > Valid Recipients > Cleanup Old Import” and delete any email
    addresses that are no longer updated by your configured external sets. If you manually import,
    ensure you execute all imports at least once before proceeding.
  3. Access “Admin > Authentication > User Management > Cleanup Old Import” and remove any users
    that are no longer updated by your configured external sets. If you manually import, ensure
    you execute all imports at least once before proceeding.
  4. Starting with ESG 5.2, the LDAP integration layers now support Group management, which allows
    for the assignment of group emails as a user’s secondary address. Ensure your old configuration
    is updated accordingly.
  5. If you come across any licenses that you do not recognize, access the detailed view for that
    license and click on recipient addresses to swiftly search for the accounted email. If you
    find any email that you do not want to receive or scan, take the appropriate action on the Web UI.
    This may include disabling a user’s secondary email or updating your LDAP configuration.

If you have any additional queries or concerns, please contact our Customer Support for further
assistance and information.

Was this helpful?

1 Yes  3 No
Related Articles
  • Troubleshooting Outlook Add-in Authentication with Microsoft 365
  • Libraesva AI usage: technical implementation, governance, privacy and regulatory compliance
  • ESG API
  • Cluster Firewall ports requirements for workers (distributed setup)
  • Encryption at rest
  • Distributed setup

Didn't find your answer? Contact Us

Popular Article
  • Encryption at rest
  • Protocol number
  • Migration process from UkCloud due to liquidation
  • Cluster Firewall ports requirements for workers (distributed setup)
  • Quarantine Reports are not sent after a migration
Tag Cloud
active content blacklist Cluster Alert Cluster Error delisting delivery disk performance email esva file sandbox gdpr hypervisor ip address memory usage monitoring monitring performance privacy production quarantine disk quicksand rbl reputation retention time sandbox sanitize document security snmp template testing tnef uri sandbox url rewrite url sandbox winmail.dat zabbix

  Libraesva ESG License Billing Information Explained

Libraesva ESG hostname change  

Products
  • Email Security Gateway
  • Email Archiving & Compliance
  • Phishing Awareness
Industry
  • SMB Companies
  • Large Companies
  • Education
  • MSP’s
Solutions
  • Microsoft 365
  • General Data Protection Regulation (GDPR)
  • Business Email Compromise
  • Migrate from Symantec
Resources
  • Email Security Tester
  • Company Website
  • Security Blog
  • Case Studies
  • Free Tech Webinars
Partners
  • Partner Portal
  • Become a Partner
  • Technology Alliances
Company
  • About Libraesva
  • Why Libraesva
  • News
  • Careers
  • Contact Us

LIBRAESVA SRL
Piazza Cermenati, 11
23900 Lecco - ITALY
VAT ID: 03442930131


LIBRAESVA LIMITED
Spaces, 83 Baker St
London W1U 6AG - United Kingdom
VAT ID: 274381685


LIBRAESVA INC
2608 2nd Ave, Suite 327
Seattle, WA 98121 - United States

  • (C) Libraesva 2024 - All rights reserved

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie SettingsAccept
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT

WordPress Download Manager

WordPress Download Manager - Best Download Management Plugin

Popular searches:GDPR, ESG 5 migration guide, "How to configure Libraesva ESG for Microsoft 365"