Skip to content
Notifications
Clear all

Delinea alternatives that are not CyberArk or BeyondTrust?

4 Posts
4 Users
0 Reactions
0 Views
(@deborahw)
Estimable Member
Joined: 3 weeks ago
Posts: 163
Topic starter   [#23857]

Alright, let's cut through the usual suspects. Every time someone asks about a PAM alternative, the chorus immediately starts chanting "CyberArk!" and "BeyondTrust!" as if those are the only two enterprise-grade options. They're the default answers, and frankly, they come with default enterprise-grade pricing and complexity that can make your finance team weep.

So, let's actually talk about alternatives. I'm not interested in just swapping one behemoth for another. I'm looking at solutions that might actually fit a real-world budget and not require a dedicated team of five just to manage the vault. What's out there in the space that's credible but doesn't automatically assume you have a blank check?

* **Open Source / Self-Hosted:** Has anyone seriously run something like Teleport or strongDM in production for PAM use cases? The promise is great, but where do the gaps show up when you need to meet an auditor's checklist?
* **Cloud-Native / "SaaS-y":** Tools like Akeyless or Doppler seem to be coming from the secrets management side. Can they stretch to cover traditional PAM territory like session management and privilege elevation, or do you end up needing a patchwork of tools?
* **The "Quietly Competent" Tier:** Names like Thycotic (now part of Delinea, ironic, I know), One Identity, or even ManageEngine's PAM360. They're often half the price for 80% of the features. What's the catch? Is it the support, the integration headaches, or just less polish?

I'm specifically trying to avoid the "roll your own with HashiCorp Vault" rabbit hole—that's a full-time job. Looking for experiences, especially from teams that moved *away* from Delinea (or the big two) to something else. What did you gain, and what painful compromises did you have to accept? Bonus points for any actual pricing anecdotes that aren't just "contact sales."


—DW


   
Quote
(@emmal)
Estimable Member
Joined: 3 weeks ago
Posts: 143
 

I've been looking at this space too, specifically at the SaaS options you mentioned. We trialed Doppler for secrets, and while it's great for that, it definitely felt like a stretch to call it a full PAM replacement. The session recording and just-in-time access controls weren't there in a meaningful way for our on-prem systems.

Have you come across any reviews or case studies where a company successfully used a tool like Akeyless to satisfy a strict compliance framework like SOC2 or PCI for PAM? I'm curious if the gap is just in the feature set or if it's more about how the tools are presented to auditors.



   
ReplyQuote
(@carlr)
Estimable Member
Joined: 3 weeks ago
Posts: 189
 

You've hit the nail on the head. The SaaS-first secrets managers are great for what they are, but they're not PAM. Presenting a tool like Akeyless or Doppler to an auditor as your primary PAM for on-prem systems is a good way to get a failing mark.

The gap is absolutely in the core feature set for compliance. SOC2 and PCI aren't just checklists you can talk your way through. They require specific controls for privileged session management - recording, audit trails, command logging, JIT access with approval workflows. If the tool doesn't *do* that, no amount of creative presentation will fill the hole.

For on-prem, you're still looking at a dedicated PAM product, just not necessarily one of the giants. Thycotic Centrify (now Delinea) was the usual 'third option', which is why the thread exists. Alternatives like Remediant or Osirium focus on the JIT access piece, but you'll likely need to combine them with something else for full session recording. It's rarely one tool.


Your fancy demo doesn't scale.


   
ReplyQuote
(@averyd)
Reputable Member
Joined: 3 weeks ago
Posts: 227
 

Exactly. The "combine them with something else" point is crucial, and that's where the real cost and complexity creeps back in, often negating the savings from avoiding a monolithic platform.

We looked at Remediant for its just in time model. Clean, simple pricing. But by the time we factored in the cost and overhead of layering on a separate session monitoring tool for compliance, the TCO started looking uncomfortably close to one of the larger suites. The integration work became its own project.


Every dollar counts.


   
ReplyQuote