diff --git a/src/pages/about-netbird/self-hosted-vs-cloud.mdx b/src/pages/about-netbird/self-hosted-vs-cloud.mdx index 69bf856e..d34d5fcf 100644 --- a/src/pages/about-netbird/self-hosted-vs-cloud.mdx +++ b/src/pages/about-netbird/self-hosted-vs-cloud.mdx @@ -50,14 +50,14 @@ some additional features that are targeted at business customers and help with n - **[Users and groups provisioning](/manage/team/idp-sync)** from your identity provider (IdP). - **[Traffic events logging](/manage/activity/traffic-events-logging)** of connections to internal resources for audit and analysis. -- **[Event streaming](/manage/activity/event-streaming)** to 3rd party platforms and SIEM systems (also available in self-hosted deployments with an [enterprise license](/selfhosted/enterprise)). +- **[Event streaming](/manage/activity/event-streaming)** to 3rd party platforms and SIEM systems. - **[Integrations with EDR](/manage/access-control/endpoint-detection-and-response)** like CrowdStrike and others. - **[Peer approval](/manage/peers/approve-peers)** to join the network. - **[User invites](/manage/team/add-users-to-your-network#direct-user-invites)**. - **[MSP functionality](/manage/for-partners/msp-portal)** for managing multiple tenant networks from a single account. -SCIM provisioning and some enterprise features require a [Commercial License](https://netbird.io/pricing#on-prem) for self-hosted deployments. +Users and groups provisioning (including SCIM), traffic events logging, event streaming, EDR integrations, and peer approval are also available in self-hosted deployments with an [Enterprise Commercial License](/selfhosted/enterprise). The MSP functionality is available only in NetBird Cloud. ## Geo Distributed Relay Servers diff --git a/src/pages/manage/access-control/endpoint-detection-and-response/index.mdx b/src/pages/manage/access-control/endpoint-detection-and-response/index.mdx index e8245c7f..2a9a9ac7 100644 --- a/src/pages/manage/access-control/endpoint-detection-and-response/index.mdx +++ b/src/pages/manage/access-control/endpoint-detection-and-response/index.mdx @@ -28,7 +28,7 @@ NetBird doesn't apply the MDM and EDR checks to all devices in the network. Inst the checks to apply. - This feature is only available in the cloud version of NetBird. + This feature is available in NetBird Cloud on the [Business plan](https://netbird.io/pricing) and in self-hosted deployments with an [Enterprise Commercial License](/selfhosted/enterprise). The open source Community Edition does not include it. ## Supported EDR Platforms diff --git a/src/pages/manage/peers/approve-peers.mdx b/src/pages/manage/peers/approve-peers.mdx index dd583403..772e36c5 100644 --- a/src/pages/manage/peers/approve-peers.mdx +++ b/src/pages/manage/peers/approve-peers.mdx @@ -8,7 +8,7 @@ When enabled, devices connect to the management service without network access t Administrators then can assess whether the peer is eligible to join the network. - This feature is only available in the [NetBird cloud](https://app.netbird.io/) version. + This feature is available in [NetBird Cloud](https://app.netbird.io/) on the [Business plan](https://netbird.io/pricing) and in self-hosted deployments with an [Enterprise Commercial License](/selfhosted/enterprise). The open source Community Edition does not include it. ## Related Video Content diff --git a/src/pages/manage/settings/plans-and-billing.mdx b/src/pages/manage/settings/plans-and-billing.mdx index b4976517..eadfb7f5 100644 --- a/src/pages/manage/settings/plans-and-billing.mdx +++ b/src/pages/manage/settings/plans-and-billing.mdx @@ -11,6 +11,10 @@ It features peer-to-peer connections and encryption, access control, routing, an - **Business Plan:** At **€12 per user per month**, the Business Plan offers enhanced network security with a Zero Trust approach. It supports unlimited users and includes features like device approvals and integrations (MDM and EDR) for comprehensive control, device posture checks and activity events streaming, making it an excellent choice for organizations seeking advanced security solutions. + + These plans apply to NetBird Cloud. If you self-host NetBird, the paid features (such as IdP provisioning, device approvals, MDM and EDR integrations, traffic events logging, and event streaming) come from an [Enterprise Commercial License](/selfhosted/enterprise) instead. See the [on-prem pricing page](https://netbird.io/pricing#on-prem). + +

pricing-overview diff --git a/src/pages/manage/team/idp-sync/index.mdx b/src/pages/manage/team/idp-sync/index.mdx index 9d3867b3..7483e958 100644 --- a/src/pages/manage/team/idp-sync/index.mdx +++ b/src/pages/manage/team/idp-sync/index.mdx @@ -20,7 +20,7 @@ or update network configurations like [DNS](/manage/dns#distribution-groups), eliminating the need for manual grouping. - This feature is only available in the cloud version of NetBird in the [Team plan](https://netbird.io/pricing) and above. + This feature is available in NetBird Cloud on the [Team plan](https://netbird.io/pricing) and above, and in self-hosted deployments with an [Enterprise Commercial License](/selfhosted/enterprise). The open source Community Edition does not include it. This video guide walks you through an example integration with Microsoft Entra ID, covering both user onboarding and diff --git a/src/pages/manage/team/single-sign-on/authentik.mdx b/src/pages/manage/team/single-sign-on/authentik.mdx index 0abcc99d..84fbf01e 100644 --- a/src/pages/manage/team/single-sign-on/authentik.mdx +++ b/src/pages/manage/team/single-sign-on/authentik.mdx @@ -7,6 +7,7 @@ You can use Authentik as your Identity Provider with NetBird, but it will requir Support for OIDC-compliant IdPs is available on the Team plan and higher. The Free plan supports Google, Microsoft, and social logins. + Self-hosted deployments support OIDC-compliant IdPs in both the open source Community Edition and the [Enterprise Commercial License](/selfhosted/enterprise). See [self-hosted identity providers](/selfhosted/identity-providers). 1. You need to create a new Application and Provider. diff --git a/src/pages/manage/team/single-sign-on/aws-cognito.mdx b/src/pages/manage/team/single-sign-on/aws-cognito.mdx index d12149e3..ae7a3908 100644 --- a/src/pages/manage/team/single-sign-on/aws-cognito.mdx +++ b/src/pages/manage/team/single-sign-on/aws-cognito.mdx @@ -7,6 +7,7 @@ You can use [AWS Cognito](https://aws.amazon.com/cognito/) as your Identity Prov Support for OIDC-compliant IdPs is available on the Team plan and higher. The Free plan supports Google, Microsoft, and social logins. + Self-hosted deployments support OIDC-compliant IdPs in both the open source Community Edition and the [Enterprise Commercial License](/selfhosted/enterprise). See [self-hosted identity providers](/selfhosted/identity-providers). ## Prerequisites diff --git a/src/pages/manage/team/single-sign-on/cidaas.mdx b/src/pages/manage/team/single-sign-on/cidaas.mdx index dd9dd64c..b2428605 100644 --- a/src/pages/manage/team/single-sign-on/cidaas.mdx +++ b/src/pages/manage/team/single-sign-on/cidaas.mdx @@ -7,6 +7,7 @@ You can use [cidaas](https://www.cidaas.com/) as your Identity Provider with Net Support for OIDC-compliant IdPs is available on the Team plan and higher. The Free plan supports Google, Microsoft, and social logins. + Self-hosted deployments support OIDC-compliant IdPs in both the open source Community Edition and the [Enterprise Commercial License](/selfhosted/enterprise). See [self-hosted identity providers](/selfhosted/identity-providers). ## Step 1: Create a New Application diff --git a/src/pages/manage/team/single-sign-on/duo-security.mdx b/src/pages/manage/team/single-sign-on/duo-security.mdx index 62479f74..1428ed0f 100644 --- a/src/pages/manage/team/single-sign-on/duo-security.mdx +++ b/src/pages/manage/team/single-sign-on/duo-security.mdx @@ -7,6 +7,7 @@ You can use Duo Security as your Identity Provider with NetBird, but it will req Support for OIDC-compliant IdPs is available on the Team plan and higher. The Free plan supports Google, Microsoft, and social logins. + Self-hosted deployments support OIDC-compliant IdPs in both the open source Community Edition and the [Enterprise Commercial License](/selfhosted/enterprise). See [self-hosted identity providers](/selfhosted/identity-providers). ## Prerequisites diff --git a/src/pages/manage/team/single-sign-on/iij-id.mdx b/src/pages/manage/team/single-sign-on/iij-id.mdx index d36a879e..b98931a4 100644 --- a/src/pages/manage/team/single-sign-on/iij-id.mdx +++ b/src/pages/manage/team/single-sign-on/iij-id.mdx @@ -9,6 +9,7 @@ NetBird integrates with IIJ ID as a custom OpenID Connect application. Support for OIDC-compliant IdPs is available on the Team plan and higher. The Free plan supports Google, Microsoft, and social logins. + Self-hosted deployments support OIDC-compliant IdPs in both the open source Community Edition and the [Enterprise Commercial License](/selfhosted/enterprise). See [self-hosted identity providers](/selfhosted/identity-providers). ## Step 1: Create a Custom OpenID Connect Application diff --git a/src/pages/manage/team/single-sign-on/index.mdx b/src/pages/manage/team/single-sign-on/index.mdx index 1af0ae40..4f30e0db 100644 --- a/src/pages/manage/team/single-sign-on/index.mdx +++ b/src/pages/manage/team/single-sign-on/index.mdx @@ -44,6 +44,7 @@ to integrate with NetBird. Below are the steps to set up different OIDC-complian Support for OIDC-compliant IdPs is available on the Team plan and higher. The Free plan supports Google, Microsoft, and social logins. + Self-hosted deployments support OIDC-compliant IdPs in both the open source Community Edition and the [Enterprise Commercial License](/selfhosted/enterprise). See [self-hosted identity providers](/selfhosted/identity-providers). ### Authentik diff --git a/src/pages/manage/team/single-sign-on/zitadel.mdx b/src/pages/manage/team/single-sign-on/zitadel.mdx index 3d8cca3b..262f4106 100644 --- a/src/pages/manage/team/single-sign-on/zitadel.mdx +++ b/src/pages/manage/team/single-sign-on/zitadel.mdx @@ -7,6 +7,7 @@ You can use Zitadel as your Identity Provider with NetBird, but it will require Support for OIDC-compliant IdPs is available on the Team plan and higher. The Free plan supports Google, Microsoft, and social logins. + Self-hosted deployments support OIDC-compliant IdPs in both the open source Community Edition and the [Enterprise Commercial License](/selfhosted/enterprise). See [self-hosted identity providers](/selfhosted/identity-providers). ## Step 1: Create a New Project (Optional) diff --git a/src/pages/manage/team/single-sign-on/zoho.mdx b/src/pages/manage/team/single-sign-on/zoho.mdx index fca619b2..8d023821 100644 --- a/src/pages/manage/team/single-sign-on/zoho.mdx +++ b/src/pages/manage/team/single-sign-on/zoho.mdx @@ -9,6 +9,7 @@ NetBird integrates with Zoho as a custom OIDC application. Support for OIDC-compliant IdPs is available on the Team plan and higher. The Free plan supports Google, Microsoft, and social logins. + Self-hosted deployments support OIDC-compliant IdPs in both the open source Community Edition and the [Enterprise Commercial License](/selfhosted/enterprise). See [self-hosted identity providers](/selfhosted/identity-providers). ## Step 1: Create a Custom OIDC Application diff --git a/src/pages/selfhosted/enterprise/index.mdx b/src/pages/selfhosted/enterprise/index.mdx index 61298ff3..37d4ca20 100644 --- a/src/pages/selfhosted/enterprise/index.mdx +++ b/src/pages/selfhosted/enterprise/index.mdx @@ -33,6 +33,8 @@ The core connectivity, access control, and routing features are the same in the | SCIM user and group provisioning | No | Yes | | EDR and MDM integrations (CrowdStrike, SentinelOne, Intune, and others) | No | Yes | | Traffic-flow event logging and streaming | No | Yes | +| Peer approval | No | Yes | +| Audit event streaming and notifications | No | Yes | | Support | Community (Slack, GitHub) | Standard support included | ## Frequently asked questions @@ -73,7 +75,7 @@ To serve multiple isolated customers you have two options: You can start evaluating today for free: the **open source Community Edition is free to self-host for as long as you like**, with no license and no time limit. That is the right way to try core NetBird (the control plane, peers, policies, and routing) while you decide whether it fits. -To evaluate the commercial-only features (active-active HA, SCIM, traffic-flow logging), contact the sales team through the [on-prem pricing page](https://netbird.io/pricing#on-prem) to run an assisted proof of concept with the commercial license. You install and run the stack; NetBird provides the license and guidance. A commercial proof of concept runs for 30 days by default. +To evaluate the commercial-only features, contact the sales team through the [on-prem pricing page](https://netbird.io/pricing#on-prem) to run an assisted proof of concept with the commercial license. A proof of concept includes every feature of the commercial license, including everything marked commercial in the table above. You install and run the stack; NetBird provides the license and guidance. A commercial proof of concept runs for 30 days by default. ### What does the server share with the NetBird license service? diff --git a/src/pages/use-cases/security/implement-zero-trust.mdx b/src/pages/use-cases/security/implement-zero-trust.mdx index 1b3d804c..bc5abbc4 100644 --- a/src/pages/use-cases/security/implement-zero-trust.mdx +++ b/src/pages/use-cases/security/implement-zero-trust.mdx @@ -15,6 +15,10 @@ Before you start planning or changing policies, confirm the basics. This guide uses features from both the **Team** and **Business** plans. Check that your deployment includes what you need. + + Team and Business are NetBird Cloud plans. On a self-hosted deployment, IdP user and group provisioning, traffic events logging, and event streaming require an [Enterprise Commercial License](/selfhosted/enterprise). Audit event logging and posture checks are included in the open source Community Edition. + + **Team plan** - **[User and group provisioning from IdP (Identity Provider)](/manage/team/idp-sync)** for automatic group sync