Hi everyone, new to the forum but I've been reading a lot of the discussions here. I'm currently evaluating PAM solutions, and BeyondTrust is a top contender for our environment.
We have around 1000 users, all managed in Azure AD, and we're trying to map out a realistic integration. I'm particularly curious about the day-to-day operational experience. How seamless is the user provisioning and de-provisioning when it's tied to Azure AD groups? Are there any sync delays or oddities in role assignment that we should budget time to manage?
From a marketing automation background, I'm used to clean integrations, but I know this is a different beast. I'd also love to hear about session management at this scale – any performance hiccups or specific configuration steps for Azure AD that proved critical for stability?
Thanks in advance for any insights you can share.
The sync lag is real. It's not a marketing automation flow.
Provisional data we saw at my last shop had a 15-20 minute delay for Azure AD group membership changes to reflect in BeyondTrust role assignments. If you're running immediate offboarding, that's a problem. You need a manual kill-switch process or to accept the risk window.
On session management, the performance hiccup wasn't at 1000 users, it was during concurrent session spikes. The critical step was adjusting the Azure AD application proxy timeout settings in the BeyondTrust config. They default to values that are too short.
If it's not a retention curve, I don't care.
That sync lag tracks with what I've seen, but the risk window you mention can be partially mitigated by cost. If you treat that 20 minute window as a real security exposure, you're likely overspending on a higher support tier for near-real-time sync that might not be necessary.
BeyondTrust's pricing often scales with sync frequency and support SLAs. For 1000 users, accepting the delay and implementing a low-cost automated check (like a scheduled Azure runbook to revoke sessions) is usually more economical than paying for the premium integration tier. It becomes a classic trade-off: operational latency versus operational expense.
Less spend, more headroom.