Skip to content
Notifications
Clear all

Delinea after 12 months - honest review from a mid-market IT manager

1 Posts
1 Users
0 Reactions
26 Views
(@cloud_cost_hawk_new)
Reputable Member
Joined: 5 months ago
Posts: 333
Topic starter   [#17805]

Alright, let's peel back the marketing veneer. We've been running Delinea (Secret Server, mostly) for a year now, managing secrets across a hybrid AWS/on-prem environment. The pitch sold us on "unified" PAM. The reality feels more like "legacy product duct-taped to a cloud console."

Here's the breakdown from a cost and operations perspective:

**The Good (Because I have to list something)**
* The core secret rotation works. It does the job for service accounts, databases.
* The distributed engine model for on-prem is sane. It's not magic, but it's reliable.
* Compared to a full-blown CyberArk rollout, the initial setup was less painful (a low bar).

**The Bad & The Ugly (Where the real review lives)**
* **The Licensing Maze:** Want to use their "Cloud Suite" for AWS? That's a different SKU. Need a certain number of concurrent web sessions? Another line item. The transition from "user-based" to "entitlement-based" licensing felt like a revenue optimization exercise, not a simplification.
* **Hidden Cost: The Cloud Tax:** Their "cloud" features often just orchestrate native AWS services (Secrets Manager, IAM). You pay for Delinea *and* the underlying AWS consumption. It's a margin stack. Example: Their PAM for DevOps scans your AWS accounts for IAM users/roles and "manages" them. You're paying a premium for a workflow that scripts and AWS Organizations could handle at a fraction of the cost.
* **Vendor Lock-in, Cloud Edition:** Once you start using their cloud integrations, unwinding is non-trivial. Their secret injection for CI/CD pipelines means your builds now depend on their platform's availability. A cloud-agnostic approach (like Vault) starts looking better when you run the TCO over 3 years.
* **API Quirks:** Need to automate? Their REST API has gaps. Certain configurations are only possible through the admin UI. This creates friction for proper Infrastructure-as-Code management.

**Bottom Line for Mid-Market**
If you're heavily invested in Windows on-prem and need a straightforward vault, it's passable. But if you're on a cloud journey, be wary. You're buying a legacy PAM product trying to wear a cloud-native mask, and you'll pay for both.

The real question isn't "is it secure?" – it is. The question is, "Are you okay paying a premium for a wrapper on services you could manage more directly, with a higher initial ops cost but lower long-term lock-in?"

-- cost first


-- cost first


   
Quote