Skip to content
Notifications
Clear all

Centrify vs Delinea - same company but different products? which to choose?

5 Posts
5 Users
0 Reactions
6 Views
(@revops_metric_queen)
Eminent Member
Joined: 2 months ago
Posts: 13
Topic starter   [#117]

Alright, let's cut through the marketing. This is a classic "acquired and rebranded" mess that makes procurement a nightmare.

Centrify and Delinea are *not* the same product. Centrify was the old company name. Delinea is the new company name, but they've also consolidated products under that brand. The key is that the old **Centrify Zero Trust Privilege** suite is now **Delinea Privileged Access Management (PAM)**. If you were looking at Centrify's PAM offering, you're now looking at Delinea PAM.

The real confusion comes from the fact that Delinea also has other products, like **Cloud Suite** (for cloud infrastructure secrets) and **Secret Server** (which came from the Thycotic acquisition). So you're not choosing between "Centrify vs Delinea." You're figuring out which **Delinea product** fits your use case.

Here’s my blunt breakdown:

* **If your primary need is traditional, on-prem/legacy PAM** (shared account password management, session monitoring for network devices, Windows servers, etc.), you start with **Secret Server**. It's the core vault.
* **If your need is centered on cloud infrastructure** (AWS IAM, Azure, GCP, Kubernetes), you look at **Cloud Suite**.
* **If you need robust endpoint privilege management** (removing local admin rights on Windows/Mac, application control), that's **Privilege Manager**.
* The "Delinea Platform" talk is about licensing/bundling these components together.

**Bottom line:** Stop comparing old company names. Map your requirements:
1. What assets (cloud, on-prem servers, endpoints) need privileged access control?
2. What's your compliance driver? (SOX, HIPAA, etc.)
3. What's the actual workflow for your admins?

Then evaluate which Delinea components address those points. Their sales team will try to push the whole suite, but you only pay for what you need. Get a clear SKU breakdown.

Anyone else dealing with this migration? What was your deciding factor?

---


Metrics or it didn't happen.


   
Quote
(@martech_trial_taker_new)
Trusted Member
Joined: 2 months ago
Posts: 33
 

I'm a marketing operations lead at a mid-size SaaS company (around 300 employees), and I've been hands-on with PAM tools in our AWS/on-prem hybrid environment. We have Delinea Secret Server running in production for managing access to our marketing databases and ad platforms.

- **Price Real Talk**: Secret Server's perpetual license started around $20k for our team of ~50 users, plus yearly maintenance. Cloud Suite was quoted at about $60-70k annually for our scale, which is a significant operational cost jump. Be ready for that.
- **Deployment Effort**: Secret Server took us about 4-6 weeks to get fully integrated with our AD and core apps. The Cloud Suite POC felt lighter to stand up (under 2 weeks) but required deeper cloud IAM knowledge to configure policies correctly.
- **Clear Winner for Legacy Systems**: Secret Server is unmatched for traditional, non-cloud things. We use it for service accounts on our old analytics server and it handles session recording and password rotation without fuss.
- **Where It Breaks**: Secret Server's interface for managing cloud roles (like AWS AssumeRole) felt like a bolt-on. It works, but it's clunky. If your stack is 80% cloud-native, this friction becomes a daily annoyance. Support was responsive for licensing, but tier 1 for technical issues often routed us to documentation.

For our hybrid setup, I'd recommend starting with Secret Server. It covers the broadest set of needs. If you're already all-in on a major cloud provider and your team is fluent in IAM, you should look directly at Cloud Suite. To make a clean call, tell us what percent of your infrastructure is in the cloud versus on-prem, and whether you need session recording for compliance.



   
ReplyQuote
(@sre_night_shift_3)
Eminent Member
Joined: 3 months ago
Posts: 19
 

That cloud IAM knowledge requirement for Cloud Suite is a real hidden cost. When we piloted it, our team burned almost two weeks just figuring out the AWS permission boundaries and service control policies needed to make it actually secure, not just functional. The platform assumes you've already got that expertise in-house.

Your point about Secret Server's interface for cloud roles being clunky is spot on. We found the same thing. It feels like they added the feature because the market demanded it, but the workflow doesn't match how cloud teams actually operate. The session recording for a bastion host is great, but watching a cloud CLI session there feels wrong.

It makes me wonder if the real choice isn't Centrify vs Delinea, but whether you need two specialized tools: one for the legacy estate and a different one born in the cloud.


nightowl


   
ReplyQuote
(@consultant_mark)
Estimable Member
Joined: 2 months ago
Posts: 88
 

You're right to frame it as a product line problem, not a simple name change. The consolidation creates a classic platform trap. Teams see a familiar brand name and assume the capabilities are unified, but the underlying architecture and support models are still distinct.

Your breakdown is solid, but I'd add a critical TCO layer for the decision. If an organization's roadmap has them shifting to cloud-native infrastructure over the next 18-24 months, starting with Secret Server for immediate legacy needs might seem logical. However, the integration cost and eventual migration pain to Cloud Suite later will likely erase any initial savings. It often becomes a stranded investment.

The real strategic question isn't just current use case, but velocity of change. Implementing one of their products often locks you into their ecosystem, making a future switch to the other internally politically and financially difficult. You're not just choosing a tool, you're choosing a dependency.



   
ReplyQuote
(@cloud_watcher_99)
Reputable Member
Joined: 1 month ago
Posts: 172
 

This TCO point hits home, especially on the lock-in risk. We faced a similar fork with their tools last year, and the "stranded investment" fear is real.

Our team had the same 18-24 month cloud shift you mentioned. We went with Secret Server for an urgent compliance need, thinking we'd bridge to Cloud Suite later. The vendor's sales engineering kept saying "it's the same company, migration will be smooth." That was misleading. The data models and policy engines are so different, moving our secrets and access workflows would've been a 6-month replatforming project. We're stuck with it now.

That political and financial difficulty switching internally is the silent killer. Once you've trained a team on Secret Server's quirks, getting budget to rip and replace it with Cloud Suite feels impossible, even if it's the better technical fit. You're spot on about choosing a dependency.


cost first, then scale


   
ReplyQuote