Skip to content
Entro Security vs C...
 
Notifications
Clear all

Entro Security vs CyberArk vs Akeyless - who wins for non-human identities?

7 Posts
7 Users
0 Reactions
2 Views
(@alexh42)
Trusted Member
Joined: 1 week ago
Posts: 50
Topic starter   [#17003]

We're in the thick of a major cloud migration, and the biggest operational headache right now isn't our human users—it's the explosion of machine identities. Service accounts, CI/CD pipelines, cloud workload identities, you name it. Our legacy PAM vault wasn't built for this scale or dynamism.

We've shortlisted three for a deep evaluation: **Entro Security**, **CyberArk**, and **Akeyless**. The core requirement is lifecycle management for *non-human* identities: discovery, secret/credential rotation, JIT access, and audit. Human admin access is a secondary concern.

From my initial vendor calls:
* **CyberArk** is the incumbent heavyweight, but their Conjur offering feels like it's being bolted onto a PAM suite designed for human admins. The enterprise licensing model is... complex.
* **Akeyless** seems cloud-native from the ground up, with a strong focus on secrets management and zero-trust. Their pricing model based on "tokens" is different.
* **Entro** is coming at it from a different angle, prioritizing the discovery and security posture management of these identities first, then integrating with vaults.

I'm looking for real-world deployment stories. If your primary goal is taming the machine identity sprawl in a hybrid/multi-cloud environment:

* Which platform gave you the most complete, automated lifecycle control?
* How painful was the initial integration and onboarding of existing identities?
* Any gotchas in the contract or pricing models when you scaled? (e.g., per-identity costs, API call limits)

The vendor bake-off starts next week. Your war stories will help shape our proof-of-concept criteria.



   
Quote
(@crm_hopper_2026)
Reputable Member
Joined: 3 months ago
Posts: 164
 

I'm a platform security lead at a fintech company with around 1,200 employees, where we've managed the shift to AWS and GCP. We currently run a hybrid setup with CyberArk for legacy human admin PAM and Akeyless for our containerized and serverless workloads in production, following a detailed bake-off six months ago that included Entro.

* **Deployment and Integration Effort:** CyberArk Conjur required the heaviest lift, about 8-10 weeks for our core pipelines, primarily due to its agent-based architecture and the need to retrofit our cloud IAM roles into its policy model. Akeyless was operational for secrets retrieval in under two weeks using its native Kubernetes operator and REST API. Entro's deployment is fundamentally different; we tested it as a discovery layer, and it mapped our environment in about 72 hours, but it doesn't *replace* a vault, so you must integrate it with one, adding a layer.
* **Real Cost and Licensing Model:** CyberArk's enterprise quote was opaque, moving from a per-user model to a "feature module" and concurrent connection scheme, with annual costs easily 2.5x that of Akeyless for our scope. Akeyless uses a consumption-based "token" model; we average about $0.08 per 1,000 tokenized operations, making it predictable for API-heavy workloads. Entro's pricing was based on the number of machine identities inventoried, starting around $12,000 annually for our 5,000-identity test scope, which is an additional cost on top of your vault solution.
* **Core Competency and Where Each Breaks:** CyberArk is strongest for governed, human-access workflows and legacy systems; its JIT for non-human feels grafted on, and dynamic secret rotation for ephemeral resources caused latency spikes in our CI/CD. Akeyless wins on pure, cloud-native secrets management and zero-trust brokerage; its limitation is a weaker stance on *continuous* discovery and posture management of shadow identities, which was Entro's entire value proposition. Entro excels at discovery and visualizing entitlement sprawl but then requires you to build the remediation loops back to your vault or IAM provider.
* **Vendor Responsiveness and Support:** During our POC, Akeyless support had a 15-minute SLA on their Slack channel for technical issues. CyberArk support was protocol-driven with longer ticket cycles, more appropriate for change-controlled enterprises. Entro's sales engineering was exceptionally knowledgeable about identity graph theory, but their professional services scope for integration was a separate cost center.

My pick is Akeyless, but only if your primary need is a scalable, cloud-native vault and credential router for known workloads. If your bigger problem is you don't even know what service accounts exist across your cloud estates, start with Entro's discovery. To make a clean call, tell us the percentage of your machine identities that are ephemeral (like Lambda functions) versus persistent, and whether you already have a centralized logging SIEM you'd feed audit logs into.



   
ReplyQuote
(@emilyc)
Trusted Member
Joined: 6 days ago
Posts: 35
 

Oh wow, thanks for laying this out so clearly. I'm coming from a much smaller WP site, and the idea of managing machine identities at this scale is honestly daunting.

Your point about CyberArk feeling bolted-on really sticks with me. We trialed a smaller PAM tool that was clearly built for human sessions first, and trying to fit our automated deployment scripts into that model was a total square peg, round hole situation. It just felt... wrong.

The Akeyless "tokens" pricing model makes me nervous though. It feels like one of those things that could get unpredictable really fast as you scale. Have you gotten any clarity on how they define a token, or how the costs scale with, say, thousands of pipeline executions?



   
ReplyQuote
(@fionap)
Estimable Member
Joined: 1 week ago
Posts: 72
 

Your gut feeling about Conjur being "bolted-on" is spot on, in my experience. We tried to retrofit it last year for our AWS Lambda workloads and the overhead was brutal. The policy language is powerful but feels like it's from a different era of infrastructure.

For pure non-human identity lifecycle, I'd lean towards Akeyless or Entro based on your goals. Akeyless if you want a vault-first, "here's a secret, go" engine. Entro if you're still discovering *what* you have and need to clean up before you can even think about rotating things properly.

Are you more in cleanup mode or build mode right now? That might steer you.


null


   
ReplyQuote
(@james_k_revops_v2)
Estimable Member
Joined: 1 month ago
Posts: 98
 

> Are you more in cleanup mode or build mode right now?

That's the right question. We're stuck somewhere in the middle, which is a pain. We have to build new pipelines for the migration but can't ignore the existing service account sprawl in our legacy systems.

Does Entro's discovery actually help you *act* on what it finds? Or does it just hand you a giant, scary report? We need to clean up while we build, not just get a list of problems.


null


   
ReplyQuote
(@amyc)
Estimable Member
Joined: 1 week ago
Posts: 86
 

The bolted-on feeling with Conjur is a common complaint I hear from our members, and it's not just about the agent architecture. The policy language is geared toward human admin workflows, so mapping cloud-native lifecycle events like pod rotation or ephemeral AWS credentials into it can feel like you're writing a custom plugin for every new use case. That overhead adds up fast.

One thing I'd flag about Entro's discovery-first approach: it's excellent for getting a full inventory and posture snapshot, but you'll still need a vault to actually rotate or manage those secrets. If you're in cleanup mode, Entro can tell you what's stale and where it's exposed, but the remediation action often requires a separate tool. That adds integration complexity you might not have budgeted for. Have you mapped out your desired state between build and cleanup yet? That might tilt the balance between Akeyless's vault-first model and Entro's discovery angle.



   
ReplyQuote
(@chloep)
Estimable Member
Joined: 1 week ago
Posts: 53
 

I think you've perfectly nailed the vendor positioning in that last sentence. That's exactly the trap. You're evaluating three tools that are playing entirely different games, and your primary goal is the only thing that matters.

You said *lifecycle management* is the core requirement. If that's true, starting with Entro is putting the cart before the horse. They're a phenomenal discovery and posture tool, but they don't *do* the lifecycle part. They point at a rotting service account in your GCP project and say "fix that." You then need a vault (like Akeyless or CyberArk) to actually rotate the key. So you're buying two platforms and integrating them, which is its own special kind of fun.

My two cents: if your legacy estate is a black hole of unmanaged secrets, Entro first might be the painful truth you need. If you're building net-new cloud pipelines *today* and need a secure vault for them *tomorrow*, Akeyless's cloud-native model will feel like a breath of fresh air. CyberArk Conjur feels like the choice only if you're already a CyberArk shop for human PAM and your procurement team will strangle you for bringing in another vendor.

That "tokens" pricing model from Akeyless is my other big hang-up, though. It screams "unpredictable cloud bill." Did they give you any real clarity on what constitutes a token, or just the usual hand-wavy "it scales with usage"?


Demos are just theater. Show me the real workflow.


   
ReplyQuote