Alright, let's cut through the marketing cloud. I just spent the last six weeks navigating an "enterprise-wide deployment" evaluation for Absolute Secure Access, and the pricing journey was… an experience. The public-facing quotes and the final negotiated structure are galaxies apart, and not in a fun, exploratory way.
The sales team loves to lead with the per-user, per-month cost for their core secure access service. It looks clean. But the moment you mention "enterprise," the conversation immediately pivots to tiers based on "capabilities" and "scale," which is really just a gateway to the module add-on parade. Want detailed device posture checks before granting access? That's a module. More granular reporting on application usage within the tunnel? Module. Advanced data loss prevention filters for the tunneled traffic? You guessed it. The base fee becomes basically an entry ticket.
Here’s what our final quote breakdown looked like, which took three calls and an implied "we're looking at competitors" to get:
* **Base Secure Access fee:** The advertised starting point. Fine.
* **"Advanced Endpoint Context" module:** Essentially mandatory for any real zero-trust policy. Adds ~40% to the effective per-user cost.
* **Enterprise SSO integration beyond basic SAML:** They charge for the "privilege" of deeper Okta/Entra ID group sync and conditional access hooks. A fixed annual "connector" fee.
* **Data egress fees:** This was the sneaky one. A certain amount of tunneled data is included per user. Exceed that (and with remote devs/cloud backups, you will), and you're into a murky per-GB overage structure. Our quote had this buried in an appendix.
The real kicker? The "enterprise deployment" fee itself. It wasn't a line item for professional services (which were also extra), but a one-time "platform activation and configuration" charge that scaled with our user count. It felt like paying a cover charge to then buy drinks at full price.
So, my question to this forum: did anyone else go through this labyrinth? Specifically:
* Were you able to bundle the "mandatory" modules into the base price effectively?
* How did you model or cap the data egress risk? Any gotchas post-deployment?
* Did the "deployment fee" magically vanish for anyone during negotiations?
I need the unvarnished truth. The product demo was slick, but I'm not buying a demo; I'm buying a bill, and that bill needs to make sense.
chloe
Demos are just theater. Show me the real workflow.
Your breakdown of the module parade is spot on. In my last architecture review, we found the "Advanced Endpoint Context" module wasn't just mandatory for policy, but its data schema was fundamentally required for the reporting APIs to function with any granularity. Without it, you're blind.
The more troubling pattern is how the "scale" tiers obscure the real cost driver: egress and session persistence. They quote per user, but your actual bill becomes a function of concurrent connections and traffic volume, which those modules inevitably increase. Did your final quote include any throughput caps or was that a separate conversation after the fact?
Trust but verify.