Editorial photograph of a security team reviewing Oracle Access Manager identity licensing
Oracle / Identity

Oracle Access Manager licensing. OAM in 2026.

Oracle Access Manager is a Fusion Middleware product licensed on Processor or a user metric, almost always inside a suite. The SKU on your ordering document decides what you may run, and what an audit will find.

Contact Us Oracle Practice
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Oracle Access Manager is a Fusion Middleware product licensed from Oracle's technology price list, on Processor or on a user metric, almost always inside a suite. What you may run is set by the SKU on your ordering document, not by the product you installed.

Key takeaways

  • OAM is a middleware product, not a cloud subscription. It is a perpetual license with annual technical support, so the levers are different from anything in Fusion SaaS.
  • The SKU name on your ordering document is the whole story. A legacy standalone Access Manager entitlement permits less than today's suite, and nothing on the current price list changes that.
  • WebLogic and the schema database that ship with OAM are restricted use. They are licensed for the identity product that shipped them and nothing else.
  • Processor counts on OAM tiers were overstated by 20 to 45 percent where virtualization was not documented to Oracle's partitioning policy.
  • Non production is not free. Development, test, and warm standby identity environments are countable unless your contract says otherwise.
  • You cannot simply drop unused suite components at renewal. These are perpetual licenses, so the only lever is terminating support, and partial termination triggers repricing rules.

What is Oracle Access Manager, and what does it actually do?

Oracle Access Manager is Oracle's on premises access management server: web single sign on, authentication and authorization policy, session management, and federation. It sits in front of applications and decides who gets in.

The parts you will find running

  • The access server tier: the OAM managed servers running on a WebLogic domain. This is where the license attaches.
  • Agents: WebGate modules installed on web servers and proxies that intercept requests and call the access server.
  • A policy and session store: a database schema holding policies, sessions, and configuration.
  • A user store: an LDAP directory holding the identities themselves, which is frequently a separately licensed product.
  • Federation and token services: SAML and OpenID Connect endpoints for outbound and inbound trust.

Where the product ends and the bill begins

The interesting boundary is not technical, it is contractual. The access server tier is clearly OAM; the directory, the governance tooling, and the risk based authentication service usually are not.

Oracle documents the product on its identity management pages, and the component detail sits in the Access Manager documentation. Neither tells you what you bought. Only the ordering document does.

How is Oracle Access Manager licensed in 2026?

OAM is licensed from Oracle's technology price list, on a Processor metric or on a user based metric, and almost always as part of an access or identity suite. It is a perpetual license with annual technical support, not a subscription.

Processor metric

Processor licensing counts cores on the servers running the licensed program, adjusted by the Oracle core factor table. It suits internet facing single sign on where the user population is large, external, or simply unknown.

User metric

User based metrics count the individuals authorized to use the program, whether or not they log in. They suit internal deployments with a bounded, countable population.

Every user based technology metric carries a stated minimum expressed per processor, which puts a floor under the count no matter how few people you have. Oracle sets out the principle in its Software Investment Guide.

The number that applies to your SKU is on the price list section that SKU sits in. Read yours rather than assuming a figure carried over from another Oracle product.

Which OAM metric fits which deployment

DeploymentPopulationMetric that usually winsWhat decides it
Employee single sign onKnown, bounded, internalUser metricHeadcount against the per processor minimum
Customer or citizen portalLarge, external, growingProcessorYou cannot count or cap the users
Partner federation hubThird party, uncontrolledProcessorThe population is not yours to enumerate
Mixed internal and externalBothProcessor on the shared tierOne tier serving both cannot be split by metric

Never buy a user metric for a tier that also serves an external population. A single access tier serving both audiences is counted once, and the uncountable half sets the answer.

Is OAM sold standalone or only inside a suite?

In practice it is bought inside a suite, and that has been true for well over a decade. Older estates still hold narrower legacy entitlements, which is exactly where the arguments start.

Legacy entitlements permit less than people assume

If your contract names an older access product rather than a current suite, your rights are defined by the licensing documentation in force for that release, not by what the equivalent suite includes today.

This is the single most common misunderstanding on OAM. Teams read the current suite description, see federation and adaptive access listed, and deploy them against a license that never covered either.

What a suite migration offer actually does

Oracle will happily convert a legacy entitlement into a current suite license. Before accepting, get four answers in writing.

  1. What quantity and metric do you end up holding, and how does that compare to what you hold now?
  2. What happens to the support base, and does the annual support fee move up as a result?
  3. Are the original licenses terminated, and if so, is that irreversible?
  4. Which components does the new entitlement add that you actually intend to deploy?

A migration that converts a comfortable legacy position into a larger, more expensive current one is a sale, not a remedy. It is only worth doing if you are genuinely going to run the extra components.

What do the Oracle identity suite bundles include?

Oracle packages access, directory, and governance capabilities into suite editions, and the edition you bought defines what you may deploy. Deploying beyond it creates a gap that an audit will price.

Know your bundle scope

Confirm exactly which components your contract covers, by name, against the licensing documentation for the release you run. A directory or governance piece running outside the bundle is a routine compliance finding.

Oracle identity capability areas around OAM

CapabilityFunctionLicensing note
Access managementSingle sign on, session policyCore OAM area
Federation and tokensSAML, OpenID Connect, OAuthIn some editions, an add on in others
Directory servicesUser and credential storeOften a separate entitlement
Identity governanceProvisioning, certificationSeparate suite component
Adaptive accessRisk based and step up authenticationCommonly a separate product
Desktop single sign onCredential injection into thick clientsA distinct product line, never assumed

Treat that table as the shape of the question, not the answer. The full component map across Oracle identity sits on the Oracle IAM licensing page; what matters here is the boundary around OAM itself.

Put your own numbers on this. The free Oracle calculator prices your processor vs Named User Plus position, VMware cluster exposure, Java SE employee tiers, and the 22 percent support line, then hands you a two page executive summary you can forward to your CFO. No account, no sales call. Run the Oracle calculator →

What ships with OAM that you are not fully licensed to use?

WebLogic Server and the database that holds the product schemas both ship with Oracle identity products under restricted use terms. Restricted use means licensed for that product only, and it is one of the most reliable ways estates fall out of compliance.

What restricted use actually means

A restricted use entitlement lets you run the bundled component in support of the product that shipped it. It does not give you a general WebLogic license or a general database license.

  • Allowed: the WebLogic domain that hosts the identity servers, running only the identity product.
  • Allowed: a database schema holding the product's own policy, session, and configuration data.
  • Not allowed: deploying your own applications into that WebLogic domain because the capacity is there.
  • Not allowed: using the same database instance to host unrelated application schemas.
  • Not allowed: switching on database options or management packs against that instance without separate licenses.

How to verify your position in an hour

Open the licensing information documentation for the exact release you run, on the Oracle Fusion Middleware documentation site, and find the entry for your product. It states what the bundled components may be used for.

Then list every application deployed into the identity WebLogic domain, and every schema in the identity database. Anything on those lists that is not the identity product is a finding waiting to happen. The same pattern recurs across Fusion Middleware licensing generally.

Which OAM component traps inflate the bill?

The biggest OAM cost surprises come from adjacent components switched on without a separate entitlement, and from environments nobody counted. Map deployment to entitlement before an audit does it for you.

Directory and federation

Directory services and federation gateways can carry their own licensing. Confirm whether your edition includes them or whether they need separate licenses, in the documentation for your release rather than the marketing page.

Virtualization

Soft partitioning does not reduce Oracle processor counts on its own. Oracle's partitioning policy sets out which technologies it recognizes, and everything else is treated as running on the whole physical estate it could move across.

The practical defense is architectural, not documentary. Pin identity workloads to a named, isolated cluster, keep the evidence, and stop the hypervisor from being able to move them anywhere else.

Non production is not free

Development, test, quality assurance, training, and warm standby identity environments all need licenses unless your contract says otherwise. A four environment OAM landscape licensed for one is a very expensive surprise.

  • Map components: list every identity component running against the bundle, by environment.
  • Check minimums: apply the per processor user minimum before choosing a metric.
  • Document virtualization: evidence the isolation that defends a lower processor count.
  • Count every environment: production, disaster recovery, test, and anything a vendor built and left running.
Cover of the Redress Compliance Oracle white paper

White Paper · Oracle Middleware

Oracle Fusion Middleware Licensing

WebLogic, SOA and Coherence, priced. Read it free.

Read the white paper

What is the audit exposure on Oracle Access Manager?

Oracle identity audits focus on three things: components running beyond the licensed edition, processor counts on virtual platforms, and environments that were never counted. OAM inside a shared identity stack is a common finding area.

Bundle gaps

Auditors compare deployed components against the licensed edition. Components outside the edition drive the findings, and the findings drive the proposal that follows.

Defending the count

A clean map of deployed components to entitlements, with virtualization documented, is the strongest defense. Build it before any audit notice arrives, because after the notice it looks like a reaction.

The OAM evidence pack, and who owns each piece

EvidenceWhat it provesOwner
Ordering documents and amendmentsThe SKU, metric, and quantity you actually holdProcurement
Deployed component inventoryWhat runs, by environmentIdentity architecture
Cluster and host topologyThe processor count you will defendInfrastructure
Domain and schema listingThat restricted use is not breachedMiddleware and database teams
Support renewal quotesThe licenses Oracle believes you holdVendor management

If the entitlement record and the support quote disagree, resolve that before anything else. Oracle's own view of your estate is in the support renewal, and it is often wrong in both directions.

What happens to support if you stop using part of the suite?

Nothing, unless you act, and acting is harder than it sounds. These are perpetual licenses, so unused components do not fall away at a renewal date the way a SaaS module does.

The correction most buyers need

You cannot drop a perpetual license you no longer use. You can only stop paying support on it, and Oracle's technical support policies govern what happens when you do.

Those policies tie support pricing to sets of licenses and require matching service levels across them. Terminating support on a subset can reprice the support you keep, so the saving is routinely smaller than the cancelled line suggests.

The realistic options, in order of difficulty

  • Leave it: keep paying and treat the shelfware as sunk. Cheapest to execute, worst over five years.
  • Terminate a clean license set: works when the unused components sit on their own agreement lines with nothing entangled.
  • Trade it in a larger deal: the most reliable route. Unused entitlement has value to Oracle when you are buying something else.
  • Move to third party support: viable on a stable identity estate you do not intend to upgrade, and a real decision, not a threat.

Check the release lifecycle before you plan anything

Support dates drive the timeline more than budget does. Confirm the premier and extended support dates for your exact release on Oracle's Lifetime Support Policy pages before committing to a roadmap.

Where the common advice on Oracle Access Manager licensing is wrong

The common advice is to buy the broadest Oracle identity suite edition up front so every component is covered and audit risk disappears. We disagree. In roughly half the identity estates Fredrik Filipsson reviewed, the broad edition meant paying support forever on governance and adaptive access components that were never deployed, while the actual gap sat on a single directory piece. Because these are perpetual licenses, that shelfware does not expire at a renewal date; it becomes an annual support line you will still be arguing about in five years. The buyer side move is to map deployed components to entitlements precisely, license only what runs, and isolate Oracle workloads to defend processor counts.

Editorial photograph of an identity architect mapping Oracle Access Manager components to entitlements
On Oracle identity the exposure usually sits in one or two adjacent components running outside the bundle, not in the access tier itself. Precise component mapping is the defense.
20
Oracle identity reviews
20 to 45%
Processor counts overstated
1 in 2
Estates running outside the bundle

Source: Redress Compliance advisory engagement file, 2024 to 2025.

Oracle Access Manager audits rarely turn on the access tier. They turn on the directory or governance piece someone switched on outside the bundle.

Suggested reading

What should a buyer do next?

  1. Retrieve the ordering document and every amendment, and write down the exact SKU, metric, and quantity.
  2. Open the licensing information documentation for the release you run and list what that SKU permits.
  3. List every Oracle identity component running in the estate, by environment, including test and standby.
  4. List every application and schema sharing the identity WebLogic domain and database, and clear the ones that do not belong.
  5. Apply the core factor and the per processor user minimum to both metrics before choosing one.
  6. Isolate and document Oracle identity workloads on virtual platforms, architecturally rather than on paper.
  7. Close any gap by licensing only the components that actually run.
  8. Decide what to do with the shelfware: trade it in the next deal, or terminate a clean license set with the repricing impact quantified first.
  9. Engage independent Oracle advisory before any identity audit response.
Need help? Try our AI agents. Ask the Oracle licensing AI agent → Scoped to one vendor and one problem. Runs in your browser.

Frequently asked questions

How is Oracle Access Manager licensed?

OAM is licensed from Oracle's technology price list, on a Processor metric or on a user based metric, and almost always inside an access or identity suite. It is a perpetual license with annual technical support. The suite edition named on your ordering document defines which components you may deploy.

Is OAM sold as a standalone product?

In practice it is bought inside a suite rather than fully in isolation. Older estates may hold a narrower legacy entitlement, and those rights are defined by the licensing documentation for that release, not by what the current suite includes.

Do I need a WebLogic license to run Oracle Access Manager?

Not a separate one for the identity domain itself. Oracle identity products ship with a restricted use entitlement for the WebLogic Server that hosts them, which covers that product and nothing else. Deploy your own applications into that domain and you need full WebLogic licenses.

Does the database behind OAM need its own license?

For the product's own schemas, a restricted use entitlement normally applies. It stops being restricted use the moment that instance hosts unrelated schemas, or someone enables a database option or management pack against it. Check the licensing documentation for your release and keep the instance clean.

Do development and test OAM environments need licensing?

Yes, unless your contract says otherwise. Oracle technology licensing does not grant a general free non production right, so development, test, training, and warm standby identity environments are countable. A four environment landscape licensed for one is a common and expensive finding.

Does virtualization reduce OAM processor counts?

Not on its own. Oracle's partitioning policy recognizes only specific technologies as reducing the count, and treats most soft partitioning as non binding. Pin identity workloads to a named isolated cluster and keep the evidence if you intend to defend a lower number.

What triggers an Oracle identity audit?

Component usage beyond the licensed edition and processor counts on virtual platforms are the common triggers, often surfaced by a support renewal that does not match the estate. OAM inside a shared identity stack is a frequent finding area.

Can we drop identity suite components we never deployed?

Not the way you drop a SaaS module. Perpetual licenses do not expire, so the only lever is terminating support on them, and Oracle's support policies can reprice the lines you keep when you terminate a subset. Quantify that impact before cancelling anything, or trade the unused entitlement inside your next purchase.

White Paper · Oracle Middleware

Oracle Fusion Middleware: WebLogic, SOA & the Suite trap.

The middleware layer is licensed like the database, per processor with the core factor, but the bundles pull you up to the $120,000 Suite. The edition ladder and how to license to need.

Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.

Get the white paper →
Opens the white paper landing page. We only email you about this download.
Run the Oracle Java license calculator against your estate in under five minutes.
Open the Tool →
Suite
Bundled License
Core Factor
Drives Processor
Component
Where Gaps Live
100%
Buyer Side

The cheapest Oracle identity license is the one mapped to what actually runs. Broad bundles bought for safety mostly fund shelfware.

Fredrik Filipsson
Co Founder and Group CEO, Redress Compliance
Deep Library

More on this topic.

Oracle Practice →
Oracle
Oracle BPM Suite Licensing
User and processor metrics on middleware.
8 min read
Oracle
Oracle Analytics Server Licensing
Processor and user metrics on analytics.
7 min read
Oracle
Oracle Audit Defense
Buyer side defense against Oracle audits.
6 min read
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Buyer side intelligence, every two weeks.

Oracle pricing shifts, audit patterns, and negotiation levers from live engagements. No vendor spin.

Pass it on

Know someone facing this exact decision?

Send this to whoever owns the renewal, the audit response, or the budget. It takes two clicks and it saves them a quarter of guessing.

Share on LinkedInShare by email