Hey folks, looking for some real-world experience here. We're a 200-person shop, fully in AWS, and our IT team of three wears all the hats—infra, help desk, *and* security. We've outgrown shared passwords and Excel sheets for admin access to our EC2 instances, RDS, and on-prem legacy systems.
We've narrowed it down to BeyondTrust and ManageEngine PAM360 after some initial demos. Budget is a concern, but so is not creating a management nightmare or a tool that's so complex we'll never use it properly.
**Key needs:**
* Session management/recording for Linux (mostly) and Windows EC2 instances.
* Just-in-time privilege escalation for AWS IAM roles and some local server accounts.
* Something that can eventually tie into our Okta for SSO.
* Clear, automated reporting for compliance (we have some SOX requirements).
* **Crucially:** Low day-to-day administrative overhead. We don't have a dedicated security analyst to babysit it.
From the demos:
* **BeyondTrust** felt more polished and "enterprise," but I'm worried about it being overkill. The integration options (like with Terraform for provisioning?) seemed deeper.
* **ManageEngine** was more straightforward and the pricing was noticeably better. Felt easier to get started, but I'm concerned about long-term scalability and the depth of its cloud integrations.
Has anyone implemented either in a similar-sized, lean team environment? I'm particularly interested in:
* The actual time investment to get it running and maintain it.
* Hidden costs beyond the initial licenses (e.g., storage for session recordings, compute for jump hosts).
* How well the API/CLI plays with automation. I'd love to see a Terraform snippet if anyone has one for provisioning a BeyondTrust role, for example.
* Any major gaps you found in their AWS integration.
A cost breakdown for ~200 users would be golden, but I know that's often not shared publicly. Any pitfalls or "I wish I'd known" stories are very welcome.
terraform and chill
Your gut feeling about BeyondTrust being overkill is spot-on for a team your size. I've seen a 250-user shop implement it, and the initial setup and policy tuning demanded weeks of a dedicated person's time - something you just don't have.
That "polished" feel often comes with a layer of abstraction that adds complexity for every simple task. ManageEngine's straightforwardness is its biggest asset here. For your key need of low admin overhead, PAM360's simpler model for session recording and just-in-time access will let you actually *use* it day one, instead of constantly configuring it.
One caveat on pricing: their entry cost is great, but really map out the modules you'll need for AWS IAM JIT and Okta. Sometimes the "straightforward" pricing gets less so once you add those connectors. Still, probably the right starting point for you.
Let the data speak.
This is super helpful, thanks. The "weeks of a dedicated person's time" is exactly my fear. We just don't have that.
You mentioned the connector pricing for IAM and Okta. Is that a separate module you have to buy, or more like an add-on license? I got a bit lost in their "edition" comparison table.