What is our primary use case?
I am in the energy sector. The solution is primarily used for something called interactive remote access. We have a secure environment where we manage the energy grid. The BeyondTrust PRA solution helps us meet a compliance requirement since we need to establish a protocol break before we start working on the electrical grid. Therefore, we don't have to walk into the room where the stuff is. It can be remotely accessed for us internally for the most part.
Right now, it is in the NERC system, which is the compliance control. This has an electronic access control system that allows us to get to our stuff. It also allows our vendors to possibly get to our stuff.
How has it helped my organization?
I use the tool everyday. I am logged into it right now. It allows me to do my job. I know that I am using the right thing, looking at who goes into what. If somebody needs help with a secure site, I can usually hop and help them, then it is done. It is very good and flexible. It allows me to do my job quite well.
Having a single point of getting anywhere running through its box is like another firewall. It is controlling all access to our secure network so nothing else can get through. Outside of the firewall, it is our network security.
What is most valuable?
It is a real fortress. Its security is very strong. Multi-factor came as a feature out-of-the-box, which was big for us. That helps us meet another compliance requirement. It enforces encryption. Nobody can see what we are doing in our remote system if they happen to be listening for unencrypted traffic. That is its biggest strength.
Having a VPN just means maintenance. I have worked in the industry for around 10 years and have never enjoyed really working on anything requiring a VPN, either working over it or supporting it. As far as IT is concerned, it is no longer a great technology. We like how this solution uses a protocol that enforces encryption right away, like HTTPS. So, the solution is good to go and takes out one of the moving parts, since VPN can get quite complicated.
PRA is available in multiple formats: as a physical and virtual appliance, or as SaaS. We appreciate the flexibility, though we went with the physical in our deployment. We might go to the cloud or use a virtual appliance later. Therefore, I appreciate the flexibility. However, we went with the reliable physicals.
PRA offers SSO authentication, which adds to the encryption suite. You need to have it in order for the appliance to work. It makes compliance easier.
What needs improvement?
It is too much of a fortress. It is difficult for us to report on compliance when I need to check for that device. For instance, I need to monitor what version that device is on, and it is quite complicated for us to do that. You can't connect to it traditionally and that is by design. While they have made some improvements in their API connectivity, it is just not quite what I would really like. It requires me to kind of apply some aftermarket steps in order to get what I need.
There is no connectivity to the appliance side. There is no API, and it is just difficult for me to capture what version the device is on without going in and doing screenshots. It is a little too secure in that regard, where they don't even trust their product owner. Since a lot of hacks come from the inside, they are probably doing what they need to do out of necessity. It is just that I have to work pretty hard to produce compliance data on the box.
You can usually API into something and get whatever you need. Or, you can have an SSH saying, "Do whatever you need. Just do a Git version command." There is none of that with BeyondTrust. However, this is the least of my concerns compared to whatever it grants us in freedom for all our security compliance requirements that it helps us meet.
For how long have I used the solution?
I have been using it for three years.
What do I think about the stability of the solution?
The physical appliances don't have dual-power supplies. Anytime our power goes out, like even for a second, it has a lot of trouble recovering, even though we have two of them in a cluster. It has trouble recovering after a power-related event on the physical side. We know that we don't really have a redundant BeyondTrust PRA, but they would probably tell me to use a cloud or virtual appliance.
What do I think about the scalability of the solution?
Scaling is pretty simple. We can stretch it to different operating systems, devices, and command lines. We can use it in any way that we want, either on stuff or from stuff. I am confident we can work with it for whatever needs to be done.
How are customer service and support?
The technical support has been okay. There have not been too many inquiries. I have asked questions from a developer on how to connect to it and gather the compliance data and was able to get an answer, which was nice.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Some people working remotely have used TeamViewer. However, we have migrated the privileged remote access since then for our security flexibility.
We looked into this solution for its ability to meet our compliance requirement. It is one of the leaders in Interactive Remote Access. When an auditor or whomever sees the solution, they say, "Okay, you are on BeyondTrust. This should be pretty simple." Out-of-the-box, it meets a lot of requirements. We don't need to go out of our way to prove requirements because they are in the manual of the solution saying, "There is encryption."
When the world went remote, we also looked to get off TeamViewer rather quickly and enforce users getting onto a privileged remote access solution. We wanted more control of who could come into the network as well as not be subject to a hack of TeamViewer. Now, we have everything run through our internal network instead of bouncing off Germany.
How was the initial setup?
The initial setup was pretty straightforward. It is simple and elegant in its design. It is pretty clear how to get things configured. There are a few quirks with getting some policies in force for particular types of workers. Once you get that down and have it working, it is a set-and-forget solution. It is not nearly as complicated as some other implementations that we have done with different apps.
It took two weeks to implement.
What was our ROI?
Instantly, we were compliant with one of the SIP standards.
Which other solutions did I evaluate?
It doesn't allow for multiple monitors without some extra steps. TeamViewer allows you to open a monitor in one tab and another monitor in another, then you can drag that tab to your monitors at home. Therefore, you can have a dual monitor setup at home. BeyondTrust doesn't work like that, and our users hate it. It is possible to do this with RDP technology, but next to email, RDP is one of the least secure protocols in the world. We don't really want to use that, but we have been kind of forced to lately when trying to get away from TeamViewer. That is one thing that TeamViewer has, it can tab to multi-monitor support.
PRA stands on its own as a full solution. We appreciate their presence in that realm. You will get part of what you want from TeamViewer, but you are getting quite a bit more with a PRA. You can roll it out via on-prem, cloud, or virtual. You control a lot more of it, controlling what people do. Whereas, with TeamViewer, that is so much more difficult.
I am considering a cheaper competitor since that is what we moved over from. However, I don't think that we have really looked at many other vendors for this since I have exactly what I need from BeyondTrust.
What other advice do I have?
We are monitoring vendor sessions. We will probably start monitoring our own so we can use it to see what happens in regards to a security incident. We can also go back and use it for troubleshooting or see exactly what somebody did inside of their remote session. At some point, we look forward to turning on the session recording. We just hadn't done it yet, not for internal staff.
There is no unattended remote access for vendors that I am aware of, but we know that we can use the solution to do that. Some have done that in the past. We just don't do it all the time and probably not in the last year.
My usage of the solution is primarily in the secure network. I don't have any kinds of sounds that I really need to listen to.
It is hard for us to roll so much trust into one thing at a time, because what happens when that thing is gone? You need to have an adequate backup plan, and we have not quite gone that far yet.
We have an audit coming up this year, because of that it is hard to really decide to do anything new. We kind of have been told, "Hey, stop getting new stuff. You have to get through the audit first."
I would rate PRA as 10 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.