GitLab Improved Restricted Access Feature for License Spending Control
GitLab updated the Restricted Access feature for instance administrators, group owners, and billing managers: when all paid seats are filled, the system blocks adding new paid users instead of requiring manual limit control. The update covers automatic provisioning via SAML, SCIM, and LDAP, reactivation of inactive accounts, and login scenarios. The feature is available on GitLab.com and in the Self-Managed version.
AI-processed from GitLab Blog; edited by Hamidun News
GitLab has updated the Restricted Access feature — a mechanism for controlling license expenses, which now more fully covers scenarios with automatic user connection through third-party identity providers, reactivation of inactive accounts, and system login.
How Restricted Access works
Restricted Access is a feature for controlling seats (license seats) available on GitLab.com and in the Self-Managed version. When enabled and all purchased licenses are already occupied, GitLab blocks the addition of new paid users — this prevents unexpected expense growth until the subscription is renewed.
- The feature is available to instance administrators, group owners, and billing managers
- When enabled, it blocks the addition of new paid users after licenses are exhausted
- It does not cancel or downgrade the rights of existing paid members
- Users without access rights to projects can be assigned a free Minimal Access role
- The feature works both on GitLab.com and in GitLab Self-Managed
What changed in integration with identity providers
The key improvement concerns how the feature interacts with automatic user connection through SAML, SCIM, or LDAP. Previously, when licenses ran out, such users could unintentionally fall into paid roles; now with Restricted Access enabled and no free seats available, GitLab automatically assigns them a free Minimal Access role, while synchronization with the identity provider continues without errors.
An important detail: Restricted Access only works going forward. If the feature is enabled in a group or instance where the limit is already exceeded, GitLab does not downgrade or remove the rights of existing paid members — administrators still need to manually bring the number of users in line with the license or purchase additional seats.
What this means
For companies with a large number of users and automatic provisioning through corporate identity systems, the feature reduces the risk of accidental budget overrun on GitLab licenses — but does not solve already accumulated overspending, if it exists, and requires manual cleanup by administrators.
Frequently Asked Questions
What will happen to already hired paid users beyond the limit?
Restricted Access does not downgrade or remove the rights of existing paid members — administrators need to independently bring their number in line with the license or purchase additional seats.
Where is the Restricted Access feature available?
The feature works both in the cloud version GitLab.com and in GitLab Self-Managed.
Want to stop reading about AI and start using it?
AI News is a curated feed of AI/tech news. Hamidun Academy teaches you to use AI systematically in your work.
The AI world, distilled — once a week
Seven stories that actually mattered, hand-picked. No noise, no reposts, no press releases.
Done! Check your inbox for a confirmation.