Team: ITDR
Product: Microsoft 365, Google Workspace
Environment: Huntress Platform
Summary: Learn how Huntress calculates billable and non-billable identities across Microsoft 365 and Google Workspace to keep your costs predictable.
In this Article
Overview
Billing Methodology
Common Billing Classifications
View Your Billable Identity Count
Frequently Asked Questions
Overview
Huntress primarily bills for unique, human-controlled identities. Whether an identity is billable or not, successfully onboarded identities receive active monitoring and protection from the SOC. Under special circumstances, Huntress can exclude student identities from both billing and protection at a partner's request. This methodology ensures you pay only for active human users while maintaining 24/7 protection across your entire identity ecosystem.
Billing Methodology
Huntress calculates billable identities by reviewing all identities in an onboarded Microsoft 365 or Google Workspace environment and determining billing status using license and identity mapping data. We bill identities representing human-controlled users and mark certain identities as Not Billed when they meet exclusion criteria.
Billable Identities
Any unique account assigned to a real person that uses a standard, human-facing license (such as Microsoft 365 Business Premium or Google Workspace Enterprise). If a human operates the account to perform daily work, it is billable.
Non-billable Identities
An identity is marked as Not Billed if it meets this criteria:
It is a linked identity across Microsoft 365 and Google Workspace that maps to the same Huntress email address, or it has a license or account type that Huntress excludes from billing. This typically includes shared mailboxes without an assigned billable license, room or resource mailboxes, unlicensed administrator accounts, device licenses, and specific EDU licenses.
The Huntress SOC actively monitors and protects both account types. You receive comprehensive security coverage across your entire tenant, but you only pay for your actual human footprint.
Student Identity Billing and Protection
Student identities follow the same default coverage rule as other identities: they are monitored and protected when their tenant is onboarded, including when an identity is non-billable under standard license rules. A student's identity is not automatically excluded simply because it belongs to a student.
Educational organizations may request an approved student exclusion. Once approved and implemented, the identities in the exclusion scope are neither billed nor protected by Managed ITDR.
Microsoft 365 exclusions are applied by license SKU. Any identity assigned an excluded SKU is excluded from both billing and protection.
Google Workspace exclusions are applied to student organizational units (OUs) that are specifically identified. Provide the exact OU paths; excluding a parent OU does not automatically exclude its child OUs.
Request the exclusion through your Huntress Account Manager. Approval is required, and the partner must understand that excluded identities will not be protected. Until an exclusion is approved and implemented, the standard coverage and billing rules apply.
Common Billing Classifications
Review this baseline breakdown to see how Huntress classifies common cloud infrastructure accounts:
| Account Type | Billing Status | Security Status |
|---|---|---|
| Standard Employee Account | Billable | Actively Protected |
| Shared Mailbox (Unlicensed) | Non-billable | Actively Protected |
| Shared Mailbox (With Paid License) | Billable | Actively Protected |
| Room or Resource Mailbox | Non-billable | Actively Protected |
| Unlicensed Admin Account | Non-billable | Actively Protected |
| Disabled/Suspended User (With License) | Billable | Actively Protected |
| Student Identity without an approved exclusion | Determined by the applicable provider and license rules |
Actively Protected |
| Student Identity within an approved exclusion | Non-billable | Not Protected |
Important
Microsoft 365 offers approximately 800 unique SKUs, so we might occasionally encounter an unusual license that doesn't align with our default logic. You can find a list of our current excluded licenses here. If you identify an account we billed incorrectly, contact your account manager to initiate a review of the applicable SKU(s). If you need assistance contacting your account manager, reach out to Huntress Support.
View Your Billable Identity Count
You can view or configure your billable identity counts in the Huntress Platform in three ways:
From the Command Center
- Log in to Huntress and view the Command Center dashboard.
- Locate the Billable Identities tile to see your total count.
From the Identities Page
- Log in to Huntress and click the Identities tab in the left-hand navigation menu.
- Use the filter to select Billable or Not Billed to see the breakdown of users in your environment.
Programmatically via API
Billable licensing counts are available programmatically using the billing reports endpoint in our API. For full setup instructions, review our API Billing Reports documentation.
Frequently Asked Questions
Can Huntress prevent specific users from being protected by Managed ITDR?
By default, identities in an onboarded tenant are monitored and protected.
Educational student exclusions are a defined exception: when approved and implemented, the specified Microsoft 365 SKU or Google Workspace student OU scope is excluded from both billing and protection. These exclusions require approval and must be scoped to the applicable SKUs or OUs.
Otherwise, no. You can't selectively exclude identities from protection. Identity providers do not selectively exclude identities from their audit logs; therefore, Huntress monitors all identities within an onboarded environment, regardless of billable status.
How do I request a student identity exclusion?
Contact your Huntress Account Manager to request an educational ITDR exclusion.
Include the Huntress organization and tenant, and specify the student scope: for Microsoft 365, provide the license SKU(s) to exclude; for Google Workspace, provide the exact student OU path(s).
Approval is required, and the exclusion is not active until it has been approved and implemented. Excluded identities will not be billed or protected by Managed ITDR.
Does "Not Billed" mean an identity is not protected?
An identity that is non-billable under standard license rules is still protected by default. Protection is removed only when the identity falls within an approved and implemented exclusion, such as an educational student exclusion.
Do you bill for shared mailboxes, distribution groups, Microsoft 365 groups, mail-enabled public folders, room mailboxes, or resource mailboxes?
No, for Microsoft 365, as long as they do not have a valid billable license applied. Shared mailboxes with an assigned billable license count as a billable identity.
Do you bill for disabled or suspended users?
Yes. Disabled Microsoft 365 identities and suspended Google Workspace identities are still billed if they retain a valid billable license. For Google Workspace, archived identities are not billed.
Do you bill for unlicensed administrative roles or application service accounts?
No, as long as no valid billable license is assigned. These accounts are still actively protected by our SOC.
Do you bill the same user twice if they exist in both Microsoft 365 and Google Workspace?
No. If the same person exists in both Microsoft 365 and Google Workspace, and both identities are mapped to the same Huntress organization by email address, Huntress bills only one identity for that user. For example, bob@company.co (MSFT) and bob@company.co (GWS) will count as a single billable identity. In order for this de-duplication to occur, the M365 and GWS tenants must be mapped to the same Huntress organization, and the email addresses must be identical.