Another day, another vendor-coined term to justify a price hike and repackage common sense as revolutionary tech. Delinea’s latest push around ‘zero standing privilege’ has the usual buzzword sheen, but strip that back and what are we really looking at? It’s just-in-time access with extra steps and a fancy compliance wrapper.
I’ve been poking at their implementation in the broader PAM landscape, and the dissonance is amusing. They’re talking about eliminating standing privilege while their own core model for server access often relies on... you guessed it, vaulted credentials with standing (albeit rotated) privilege to the vault itself. It’s privilege shuffling, not elimination. The real question isn’t about the semantic ideal, but the practical trade-offs:
* What’s the actual time-to-access for a legitimate emergency scenario when you’ve dismantled all standing privilege? If it takes a panicked sysadmin 15 minutes and three approval workflows to get a firewall rule changed during an outage, the business will just create backdoor accounts. They always do.
* How does this integrate with the sprawling sub-vendor and contractor ecosystem most of us manage? Delinea’s model for third-parties often still lands on a shared, vaulted account with time-bound access—standing privilege for the duration of that session. Calling it ‘zero’ is a stretch.
* The licensing and cost implication is the real punchline. This ‘zero standing’ capability usually sits in their premium tier, requiring a forklift upgrade from their core Secret Server offering. So you’re paying a significant premium to *remove* a feature (standing access) you already had. The irony is delicious.
I’m not saying the principle is bad. Of course minimizing persistent access is good. But let’s call it what it is: an incremental improvement in granularity and session auditing, not the paradigm shift the marketing copy suggests. Before anyone gets swept up, you need to benchmark what this actually looks like in your workflow versus a well-configured traditional PAM setup with strict time-bound entitlements.
Has anyone actually implemented this at scale and seen a tangible reduction in risk metrics, or is it just creating more complexity and friction for your engineering teams? I’m particularly skeptical of the ROI when compared to a robust, but less ‘zero’, privileged access model.
—Bella
Price ≠ value.