Skip to content
Notifications
Clear all

Comparison: Delinea PAM vs. BeyondTrust for cloud-only

1 Posts
1 Users
0 Reactions
1 Views
(@clairen)
Estimable Member
Joined: 1 week ago
Posts: 93
Topic starter   [#17178]

I've been deep in the data security side of our infrastructure lately, specifically around credential management for our cloud data stores (BigQuery, Snowflake, RDS) and streaming services (Kafka, AWS MSK). We evaluated **Delinea Secret Server** (their core PAM) and **BeyondTrust Password Safe** for a cloud-native, no-on-prem-footprint scenario. Here's my take on the trade-offs.

**Key differentiators that mattered for us:**

* **Cloud-Native "Feel":** Delinea's Secret Server felt more immediately like a cloud service, even when self-hosted in our VPC. The BeyondTrust suite felt heavier, like an on-prem tool adapted for the cloud. The REST APIs for Delinea were cleaner for automation.
* **Discovery & Secret Rotation:** This was the decider. Delinea's discovery and automated rotation for cloud database credentials (especially IAM roles and temporary credentials) was more seamless. BeyondTrust could do it, but required more configuration "glue." For a pipeline, automated rotation without service interruption is everything.
* **Session Management:** BeyondTrust had a clear edge here if you need full RDP/SSH session proxying and recording. We didn't need that for our service accounts and CI/CD tools—we needed API-first secret retrieval. So Delinea's simpler model won.

**Where BeyondTrust stood out:**
Integration with existing IT service management (ticketing) workflows was more polished. If your security team lives in ServiceNow, that's a factor. Their privileged remote access (not just password vaulting) is also more mature.

**Pricing & Operational Overhead:**
Delinea's licensing was simpler for our use case (mostly service accounts). BeyondTrust's model felt more per-feature, which got complex. Operational overhead tipped to Delinea as well—fewer moving parts to manage in our cloud tenant.

**Final thought:** If you need robust **session management** for admin access to cloud VMs, lean BeyondTrust. If you need an **API-driven secret vault** for cloud services and pipelines with strong rotation, Delinea was the better fit. We went with Delinea.

Has anyone else made this comparison? I'm particularly curious about long-term scalability of the rotation engines under high churn of temporary credentials.

—Claire



   
Quote