Been evaluating PAM solutions for a project, and we looked hard at BeyondTrust. I'm coming from a background where we've managed a lot with simpler automation and cloud IAM.
Maybe it's because we're a smaller shop, but I felt like a huge chunk of the platform was just... not relevant. The core privilege management for servers and endpoints is solid, but then there's this whole other universe of features for databases, network devices, cloud infra. It feels like they're trying to be the one tool for every possible admin, which makes it complex and expensive.
For our use case, we'd be paying for a ton of modules we'd never turn on. Isn't it better to use specialized tools for things like cloud secrets or database access, and just let a PAM handle the core server access? Or am I missing the benefit of having it all in one place?