Hey everyone, I've been living in the PAM space for a while, managing access for our marketing tech stack (all those sensitive CRM and automation platform logins!), and we recently completed a full migration from Delinea (Secret Server) to OneIdentity (Safeguard). It was a big project, and I wanted to share a really granular, hands-on breakdown of the trade-offs from an admin/user perspective—especially for those of us who have to think about non-technical end-users like marketing ops folks.
**What We've Gained (The Good Stuff):**
* **Tighter, More Granular Role-Based Access Control (RBAC):** OneIdentity's model feels more structured. We can create roles that very precisely mirror our team functions. For example, I built a "Marketing Automation Auditor" role that can view but not touch our Marketo and HubSpot service accounts, which is something we could only approximate with Delinea's folders and permissions.
* **Native Session Recording & Audit Trail Depth:** The out-of-the-box session recording for SSH and RDP feels more integrated and easier to search. The audit logs are incredibly detailed, which our compliance team loves. It's easier to trace a "who did what and when" for a specific asset, which is huge for us.
* **The Unified Credential Injection ("Application to Application") is slicker.** Setting up automated processes (like our data sync scripts) to pull credentials felt more straightforward. The API design for this particular use case seemed more intuitive to our devops team.
**What We've Lost (The Not-So-Good Stuff):**
* **User Experience & Onboarding Friction:** This is the big one. Delinea's web interface, especially for everyday secret retrieval, was significantly more intuitive for our non-technical marketing users. OneIdentity's UI feels more "engineer-centric." We've had to create more training docs and hand-hold our team more during the transition. The browser plugin experience also isn't as polished.
* **Discovery and Automated Password Changing:** Our Delinea setup did a fantastic job of auto-discovering service accounts across our network and managing their password changes. Replicating this in OneIdentity required more manual configuration and scripting. We lost some of that "set-it-and-forget-it" automation for a chunk of our assets.
* **The "Secret Template" Flexibility:** In Delinea, we used custom secret templates heavily to standardize how we stored different types of assets (e.g., a "CRM Integration User" template vs. a "Database Connection" template). OneIdentity's equivalent concept ("Asset Types") is less flexible out-of-the-box, forcing us into a more generic model or requiring custom development.
**Overall Verdict:**
The move was driven by a need for stricter compliance controls and deeper audit trails, which OneIdentity delivers on without a doubt. The platform feels more powerful under the hood. However, that power came at the cost of user-friendliness and some automation elegance. It's been a net positive for security posture, but a net negative for day-to-day user satisfaction and admin overhead for certain tasks. If your primary concern is iron-clad governance, OneIdentity is a strong contender. If ease of use and minimizing support tickets from your user base is top priority, Delinea has a real edge.
Would love to hear if others have made a similar switch and how you addressed the UI/UX gap! Did you build any custom front-ends or use specific training tricks?
If it's not measurable, it's not marketing.