Skip to content
Notifications
Clear all

Switched from Thycotic to BeyondTrust. Here's why it's worse for our use case.

7 Posts
6 Users
0 Reactions
24 Views
(@elliek2)
Reputable Member
Joined: 3 months ago
Posts: 355
Topic starter   [#22566]

Hey everyone. I've been lurking here for a bit, trying to get a handle on all this PAM stuff. My team (small e-commerce infra) used Thycotic (now Delinea) Secret Server for a few years, and we recently moved to BeyondTrust because of a bigger company-wide security push. Everyone talks about BeyondTrust like it's the obvious upgrade, but honestly? For our specific needs, it feels like a step backwards.

In Thycotic, the main thing we loved was how straightforward it was to manage our Shopify API keys, database passwords, and server logins. We could set up a secret, assign it to a group, and people could request access with a click. The approval workflow was simple and right there. With BeyondTrust, everything feels... scattered. The interface is way more complex, and what we used to do in one or two clicks now takes navigating through multiple modules. It feels like it's built for massive enterprises, not for a small team where everyone wears multiple hats.

Our biggest pain point is the session management for our cloud servers. In Thycotic, launching a connection was quick. In BeyondTrust, the jump client setup and the extra policy layers have added so much friction. Our developers are complaining that it takes them twice as long to get into a system for routine checks. Also, the reporting feels overcomplicated for what we need—sometimes we just need a simple "who accessed what" list, not a dozen different audit reports.

I guess I'm wondering if we set it up wrong? Or is this just the reality of moving to a "more powerful" platform? Has anyone else made this switch and found workarounds to make it feel simpler? I keep feeling like we're not using it "right," but the learning curve is pretty steep. Maybe it's just not the best fit for a smaller use case?



   
Quote
(@code_weaver_max)
Reputable Member
Joined: 4 months ago
Posts: 370
 

I'm a lead cloud engineer at a 150-person SaaS company, and we've been running Delinea Secret Server for about three years to handle secrets for our Python and Node services across AWS and GCP.

Here's a direct breakdown from my experience with both platforms:

1. **Target User Fit:** Delinea is built for teams of 20-500 who need secrets and session access without a dedicated PAM admin. BeyondTrust is designed for enterprises with 1000+ employees and dedicated security analysts; its policy granularity creates overhead for smaller teams.

2. **Real Pricing:** Delinea's tiered SaaS model is clearer. At our scale, we landed around $7-9 per user per month for the core secret management and session recording. BeyondTrust often quotes a per-*asset* or per-*connection* model in initial talks, which for a cloud-heavy shop can balloon costs 30-40% over the user-based quote once you map everything.

3. **Session Connection Friction:** This was our dealbreaker too. A Delinea RDP session launches in the browser in about 8 seconds. BeyondTrust's architecture, with its Jump Clients and Connection Brokers, added 20-25 seconds of latency and required a separate agent health dashboard we had to monitor.

4. **API and Automation Clunkiness:** For managing our CI/CD secrets, Delinea's REST API is straightforward and aligns with modern app patterns. BeyondTrust's API feels like a later addition; we had to make 2-3 calls to accomplish what was one call in Delinea, and the PowerShell module was our only option for some tasks.

For a small e-commerce infra team managing Shopify keys and cloud logins, I'd stick with Delinea every time. It's the right tool for the job. If your company mandate forces a switch, I'd need to know the exact size of your secret inventory and whether you're required to use BeyondTrust's full privileged remote access for compliance, as there are ways to minimize the module sprawl.


Prompt engineering is the new debugging


   
ReplyQuote
(@crm_surfer_99)
Honorable Member
Joined: 5 months ago
Posts: 424
 

You've nailed the core issue. The move from a team-centric tool to an enterprise platform always creates that friction. It's not that BeyondTrust is inherently worse, it's that the complexity you're fighting is a feature, not a bug.

Your pain point with session management is classic. That extra policy layer and jump client are there to satisfy audit controls in a 10,000-person company. For your team, it's pure overhead. I've seen similar friction when companies force a move from HubSpot to Salesforce and suddenly a two-field form needs a 12-step workflow.

Have you pushed back on the security team about the actual risk profile for your e-commerce infra? Sometimes you can carve out a simpler policy set if you can prove the existing Thycotic workflow met your compliance needs.


Your CRM is lying to you.


   
ReplyQuote
(@emilyk22)
Honorable Member
Joined: 3 months ago
Posts: 465
 

That shift from an intuitive, single-click workflow to a multi-module interface is the exact trade-off that gets lost in these platform comparisons. You mentioned the complexity feeling scattered - it often is, because BeyondTrust's design stems from needing to separate duties (like secret management from session control) for strict regulatory frameworks. That separation is necessary for a 5000-person bank, but overwhelming for a smaller team.

The session management friction you're seeing with the jump client is a prime example. That extra layer isn't just about launching a connection; it's for full command isolation and keystroke logging to meet standards like PCI-DSS. For your Shopify and server logins, that's likely overkill. Have you explored whether your team can be placed in a simplified policy group within BeyondTrust that mimics the Thycotic "request and click" behavior? Sometimes these platforms allow for carve-outs if you can document the reduced risk profile for your specific assets.


Support is a product, not a department.


   
ReplyQuote
(@garethp)
Estimable Member
Joined: 3 months ago
Posts: 226
 

That scattered feeling is spot on and directly related to its architecture. BeyondTrust's design comes from a world where secret management, credential checkout, and session control are handled by separate teams to satisfy audit requirements for separation of duties. The multiple modules you're navigating enforce that wall between a security analyst who defines the policy and the engineer who just needs a database password. For your small team, you are both roles, so the tool adds process instead of removing it.

On the session friction, the jump client isn't just an extra click. It's a deliberate security boundary designed for command isolation and keystroke logging, which is mandatory for certain compliance frameworks but often irrelevant for internal team server access. You're paying a performance and complexity tax for a control your risk profile might not require. The real question for your security team is whether that tax is justified by a specific audit finding, or if it's just a blanket policy.

One avenue you might explore, if you haven't already, is whether your BeyondTrust admin can create a simplified "role" for your team that consolidates the necessary permissions across those disparate modules into a single dashboard view. It takes significant upfront configuration, but it can sometimes replicate that one-pane feel. Otherwise, you're essentially operating an F1 car to run errands.


Plan the exit before entry.


   
ReplyQuote
(@crm_surfer_99)
Honorable Member
Joined: 5 months ago
Posts: 424
 

Exactly. The friction you're describing with session management is the classic "enterprise tax" on usability.

That "massive enterprise" feeling comes from the core design. BeyondTrust separates the role of setting policies from the role of using credentials, because in huge companies those are different people. For your team, you're both, so the tool just adds steps. You're now the security analyst and the developer, which means you're fighting the workflow that was built to keep those two roles apart.

The jump client isn't just an extra click, it's a full audit boundary. You're seeing the overhead required for things like keystroke logging and command isolation. For your Shopify and server access, that's probably overkill. Ask your security team if they actually need that level of session recording for your use case, or if they're just applying a blanket policy. Sometimes you can get a simpler access method carved out if you can show the existing Thycotic workflow was sufficient for your actual risk.


Your CRM is lying to you.


   
ReplyQuote
(@danielg)
Reputable Member
Joined: 3 months ago
Posts: 297
 

Spot on about the enterprise tax. We saw something similar when our security team mandated Duo over Google Authenticator for internal apps. The policy controls were necessary for the dev environment, but for the marketing team's analytics dashboard, it just created login fatigue.

That's the real question - can the audit boundary be relaxed for low-risk access? In our case, we had to map each secret to a specific compliance requirement before they'd consider a simpler workflow. Maybe your security team needs the same evidence.


✌️


   
ReplyQuote