> For the complete documentation index, see [llms.txt](https://docs.expel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.expel.io/workbench-reference/organization-settings/expel-licensing-and-usage-overview.md).

# Expel Licensing and Usage Overview

Expel licensing usage measures counts of endpoints, resources, users, and emails submitted. This page explains what is included in those counts for each type of MDR product.

{% hint style="info" %}
The MDR product types listed on this page are the primary ones where we find counts for determining your usage. There are many [more integrations we support](/connect-your-technology/about-integrations/expel-integrations.md).
{% endhint %}

## Endpoints

Expel counts the on-prem endpoints in your environment that have been seen within the past 30 days.

* If you have multiple endpoint security products, we use the one with the highest count (this is because we assume you've installed all of your endpoint products on the same hosts).
* If your environment has one endpoint security product covering some hosts and a different endpoint security product covering other hosts, we work with you to manually arrive at the correct quantity for your environment.

**What's Not Counted**

We do not count cloud-hosted endpoints (see [Cloud Security](#cloud-security) below), mobile devices, or devices like printers, thermostats, or other things (IoT / OT) with an IP address in the usage data.

**More Details**

For these products, we count the following (all the **endpoint** resource type):

<table data-header-hidden><thead><tr><th width="270.296875"></th><th></th></tr></thead><tbody><tr><td>Crowdstrike</td><td>The hosts with a null service provider.</td></tr><tr><td>Microsoft Defender</td><td>The machines with a status of "onboarded."</td></tr><tr><td>Palo Alto Networks Cortex</td><td>The endpoints.</td></tr><tr><td>SentinelOne</td><td>The number of agents that do not have a cloud provider of AWS, GCP, or Azure in SentinelOne.</td></tr><tr><td>VMware Carbon Black Cloud</td><td>The sensors.</td></tr><tr><td>VMware Carbon Black EDR</td><td>The sensors.</td></tr></tbody></table>

## Cloud

### Cloud Workloads

Expel counts the cloud-hosted endpoints in your environment that have been seen within the past 30 days.

* If you have multiple cloud-hosted endpoint security products, we use the one with the highest count (this is because we assume you've installed all of your endpoint products on the same hosts).
* If your environment has one cloud-hosted endpoint security product covering some hosts and a different cloud-hosted endpoint security product covering other hosts, we work with you to manually arrive at the correct quantity for your environment.

**What's Not Counted**

We do not count on-prem total endpoints (see [Endpoints](#endpoints) above), mobile devices, or devices like printers, thermostats, or other things (IoT / OT) with an IP address in the usage data.

### Cloud Security

Expel uses the count of instances, compute resources, storage resources, serverless resources, and any resources being acted upon by API calls. These counts come from devices outlined in [Cloud Infrastructure](#cloud-infrastructure) below.

**What's Not Counted**

We do not count on-prem total endpoints (see [Endpoints](#endpoints) above), mobile devices, or devices like printers, thermostats, or other things (IoT / OT) with an IP address in the usage data.

### Kubernetes

We count the median number of nodes over the past 30 days, across all clusters. Kubernetes services and pods are informational only and are not factored into your usage.

### Cloud Infrastructure

Expel counts instances, compute resources, storage resources, serverless resources, and any resources being acted upon by API calls. We count the median data point from the past 30 days, which prevents the data from being skewed by outliers. Note that cloud-hosted endpoints are counted under [Cloud Workloads](#cloud-workloads).

**What's Not Counted**

We do not count mobile devices or devices like printers, thermostats, or other things (IoT / OT) with an IP address in the usage data.

**More Details**

For detailed information about a particular cloud product, scroll down or use one of the links below to skip to your desired chart:

* [AWS](#aws)
* [Azure](#azure)
* [Google Cloud Platform (GCP)](#google-cloud-platform-gcp)

### AWS

<table><thead><tr><th width="189.28515625">What We're Counting</th><th width="146.73828125">Resource Type</th><th>Description</th></tr></thead><tbody><tr><td>EC2</td><td>Compute</td><td>The number of running AWS EC2 instances on the account, including any EC2 instances created by other AWS services (like the Amazon Elastic Kubernetes Service).</td></tr><tr><td>Lambda</td><td>Compute</td><td>The number of unique lambdas grouped by account, region, and lambda name. Lambdas with the same name but different regions or accounts are considered as separate lambdas, because there can be differences in the security configurations and access to services in each region or account.</td></tr><tr><td>S3</td><td>Storage</td><td>The number of S3 buckets.</td></tr><tr><td>RDS</td><td>Storage</td><td>The number of provisioned RDS instances.</td></tr></tbody></table>

### Azure

<table><thead><tr><th width="189.28515625">What We're Counting</th><th width="146.73828125">Resource Type</th><th>Description</th></tr></thead><tbody><tr><td>Vritual Machines</td><td>Compute</td><td>The number of virtual machines and virtual machine scale sets in the subscription.</td></tr><tr><td>Sites</td><td>Storage</td><td>The number of static sites the subscription.</td></tr><tr><td>Storage Accounts</td><td>Storage</td><td>The number of storage accounts and compute disks in the subscription.</td></tr><tr><td>SQL Servers</td><td>Storage</td><td>The number of SQL virtual machines, SQL servers, and SQL databases in the subscription.</td></tr><tr><td>Functions and App Services</td><td>Compute</td><td>The number of Functions and App Services in the subscription.</td></tr></tbody></table>

### Google Cloud Platform (GCP)

<table><thead><tr><th width="189.28515625">What We're Counting</th><th width="146.73828125">Resource Type</th><th>Description</th></tr></thead><tbody><tr><td>App Engine</td><td>Compute</td><td>The number of App Engine applications in all projects.</td></tr><tr><td>Cloud Function</td><td>Compute</td><td>The number of unique cloud functions grouped by project ID, region, and function name. Functions with the same name but different regions or accounts are considered as separate functions, because there can be differences in the security configurations and access to services in each region or account.</td></tr><tr><td>Compute Instance</td><td>Compute</td><td>The number of compute instances in all projects and regions.</td></tr><tr><td>SQL Admin</td><td>Storage</td><td>The number of cloud SQL instances in all projects.</td></tr><tr><td>Storage</td><td>Storage</td><td>The number of cloud storage buckets in all projects.</td></tr></tbody></table>

## Identity/SaaS Applications

Expel looks at the Identity Provider (IdP) SaaS application with the highest number of users and uses that user total as the count. If there is no IdP currently connected, we look at the most recent SaaS app with the highest number of users and get our count from there.

Anything that can log in to the SaaS app and leverage its full functionality is considered a user. So your count may include:

* Normal human users
* Shared accounts intended to be used by multiple humans
* Service accounts intended to be used by software

**What's Not Counted**

We do not count suspended, archived, or administratively disabled users who can't log in.

**More Details**

For these products, this is how a "user" is defined and counted:

<table data-header-hidden><thead><tr><th width="182.89453125"></th><th></th></tr></thead><tbody><tr><td>Duo</td><td>The user count is the number of users that are not disabled or pending deletion in the organization's Duo account, which we obtain <a href="https://duo.com/docs/adminapi#users">via Duo's API</a>.</td></tr><tr><td>Google Workspace</td><td>The user count is the number of users that are not suspended, archived, or deleted in the organization’s Google Workspace account, which we obtain via <a href="https://developers.google.com/admin-sdk/directory/reference/rest/v1/users/list">Google's API</a>.</td></tr><tr><td>Microsoft 365</td><td>The user count is the number of users that can sign in and are categorized as "Members," which we obtain via <a href="https://docs.microsoft.com/en-us/graph/api/resources/user?view=graph-rest-1.0#properties">Microsoft's API</a>.</td></tr><tr><td>Okta</td><td>The user count is the number of active users in the organization's Okta account that are not suspended or deprovisioned, which we obtain via <a href="https://developer.okta.com/docs/reference/api/users/#user-status">Okta's API.</a></td></tr><tr><td>OneLogin</td><td>The user count is the number of active users in the organization's OneLogin account and does not include unactivated or suspended users. We obtain this information via <a href="https://developers.onelogin.com/api-docs/1/users/user-resource">OneLogin's API</a>.</td></tr></tbody></table>

## Managed Phishing

Expel counts using two different methods:

* **Counting by Users** - We count each user in the customer organization as a unique user toward phishing coverage. The count includes anyone who is able to report suspected phishing emails that then go to Expel for analysis, and may be employees or contractors. If there are too many users in an organization, there may be a monthly threshold limit set on email submissions.
* **Number of Email Submissions** - We count each individual email that is sent to Expel for analysis by each individual user on a monthly basis. Similar or identical emails that are sent multiple times are counted as separate emails, regardless of whether they are sent by one authorized user or by multiple.

**What's Not Counted**

We do not count email aliases as separate users.

## Vulnerability Prioritization

Expel counts the on-prem total endpoints in your environment as reported by your vulnerability prioritization vendor. We take the most recent number of endpoints, and only count endpoints that have been seen within 30 days.

* If you have multiple vulnerability prioritization security products, we use the one with the highest count (this is because we assume you've installed all of your products on the same hosts).
* If your environment has one vulnerability prioritization security product covering some hosts and a different vulnerability prioritization security product covering other hosts, we work with you to manually arrive at the correct quantity for your environment.

**What's Not Counted**

We do not count cloud-hosted endpoints, mobile devices or devices like printers, thermostats, or other things (IoT / OT) with an IP address in the usage data.

## MDR for Email

Expel counts users based on your email security service provider. The definition of "users" is determined by the specific email security service provider you are using:

* **Proofpoint TAP** - The user count is the number of users licensed for Proofpoint TAP. This count can be found in the TAP Dashboard by going to Account Management > Profile > Products Overview Panel > Number of Licensed Users.
* **Abnormal AI** - The user count must be obtained by reaching out to your Abnormal account executive.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.expel.io/workbench-reference/organization-settings/expel-licensing-and-usage-overview.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
