What is our primary use case?
We've used it for auto-discovery, and password management on mainframes, networks, applications, and firewalls. We've also used it for password rotation.
We use it for credential management, including rotation for both human and non-human accounts, as well as session monitoring.
How has it helped my organization?
Delinea Secret Server supports our remote access needs.
For remote access needs, we have implemented MFA (Multi-Factor Authentication) and SSO (Single Sign-On) across various applications. We use third-party tools like Ping and SailPoint to integrate with the PAM tools.
Moreover, password rotation has been effective in our environment. We weren't rotating many application passwords before, but an audit from the OCC (Office of the Comptroller of the Currency) triggered a change.
We now rotate all non-human accounts except for Active Directory and local accounts. It's a best practice, so we set a 30-day rotation for some applications like mainframes and applications that support direct password changes. For others, we set it to 8 hours.
Initially, the application teams struggled to adapt to the PAM culture. It's an organizational-wide change, so it took some time. We guided the application owners and platform teams on setting password rotation policies and initial password guidelines.
This helped minimize the impact of breaches, especially in Linux and Windows environments. We also have continuous monitoring with Splunk. We integrated the Delinea Secret Server logs into Splunk for centralized log management.
What is most valuable?
The "App to App" feature has been most impactful. It allows secure communication between applications without requiring direct user access, which is crucial for several applications.
Additionally, working in the finance department, we are heavily focused on enhancing audit reporting and compliance. So, the GRC (Governance, Risk & Compliance) capabilities of Delinea Secret Server have also been crucial for us.
We implemented a custom reporting system that can automatically send reports to auditors daily, weekly, or according to your organization's needs. We also upgraded the audit role within Secret Server, allowing auditors to access and analyze the reports directly.
Additionally, Secret Server provides comprehensive logging capabilities. Auditors can see what data users access, their access levels, and their activities, including check-in and check-out times.
Furthermore, Secret Server helped us manage privileged, elevated access, which we call "K2K." As the lead for this project, I could identify users with the highest access levels and implement specific policies to monitor their activity on servers.
What needs improvement?
In many PAM tools, when users request a password checkout, they need to provide justification. However, in my experience across four organizations, nobody actually reads the justifications. Users can simply type anything and get the password. This becomes a risk and compliance issue.
There needs to be continuous improvement in this area, focusing on problem identification and mitigation strategies.
For how long have I used the solution?
I've been working with Thycotic Secret Server since 2018. My experience with Delinea Secret Server specifically started around the end of 2022, which is when our organization purchased it.
What do I think about the stability of the solution?
I would rate the stability a nine out of ten. It is a stable product.
What do I think about the scalability of the solution?
I would rate the scalability an eight out of ten. We have 300 applications. And they're spread across various platforms, including many high-risk and complex ones. Over 200 of them are SOX applications, which require high-security compliance.
We have close to 10,000 users currently using the product. We do plan to increase the further usage and shift to the cloud.
How are customer service and support?
Delinea's technical support was excellent. They responded to our tickets on the same day and provided access to their portal for direct communication. Even after our support contract ended, they responded within three days. Compared to other PAM solutions, I'd rate them a nine out of ten.
Which solution did I use previously and why did I switch?
I have more experience with IAM and PAM. I've worked with products like SailPoint, and Ping Identity. In the PAM space, I've used CyberArk, Broadcom, Accellion, and Thycotic Secret Server (now Delinea Secret Server).
One major difference is that CyberArk has several separate modules, while Delinea offers a more unified experience with integrated features like auto-discovery for secret keys and API keys.
CyberArk requires additional integration with other applications to achieve these functionalities. Similarly, based on my knowledge, other tools may also require integrations.
Since Delinea (formerly Thycotic) is a relatively newer solution, it comes with pre-built components and focuses on continuous improvement. In contrast, older vendors might lack some built-in features.
Additionally, Delinea allows us to create custom rules and manage all access (Unix, Linux, Windows) for password management within the same platform. However, with CyberArk, managing passwords might require opening additional ports.
Another key difference is privileged account discovery management. In Delinea, we can directly access the admin console to discover accounts. With CyberArk, this might involve integrating with additional tools. These are just some of the differences, and there might be others.
How was the initial setup?
I would rate my experience with the initial setup an eight out of ten. The Delinea team was very helpful.
The initial deployment in the test phase took around three to four weeks.
For ongoing maintenance, after all applications were migrated to Delinea, only five people are needed to support it. That's for around 300 applications.
So, we have a team of five people for maintenance that includes one architect, one lead, and three analysts.
What about the implementation team?
We took assistance from the Delinea vendors.
We already had a CentOS environment, which offered us a discount when migrating to Delinea (formerly Thycotic). Most accounts were simply migrated from one system to another.
Only accounts outside the platform needed direct migration to Delinea, which took some time. We prioritized SOX applications due to their higher-risk compliance requirements.
Overall, the process wasn't too difficult, as we had vendor documentation to guide us.
The migration process begins by having a server dedicated to storing all the data. From there, we access the configuration administrative menu. If the data contains secrets, we need to decrypt them and use specific APIs to import them into Delinea Secret Server.
We use a master account, also known as the "Server account," to facilitate this. Then, we set up folders within Delinea Secret Server, which they might call "parts" or something similar. There might be some naming differences, but the overall process is the same.
Finally, we configure the Delinea Secret Server, and provide account information, and users can then log in and directly feed data into it.
The vendor primarily assisted us. We did have around ten people internally who helped with the process.
There were two architects involved. The remaining group consisted of one lead, two lead security analysts, and several security analysts.
What was our ROI?
If you are planning it to use for more than five years, then it is worth it.
What's my experience with pricing, setup cost, and licensing?
I would rate the pricing a six out of ten, with ten being a high price.
There are additional costs if you want to move to cloud.
Which other solutions did I evaluate?
We previously used Centrify, which is now part of Delinea. We conducted technology assessments and spoke with various vendors like CyberArk, BeyondTrust, and One Identity. Ultimately, our management decided to go with Delinea for two main reasons.
Firstly, budget played a significant role. Secondly, from a technical standpoint, since we were already using Centrify, Delinea offered a clear and step-by-step migration process with ongoing support. This impressed our leadership team.
What other advice do I have?
Overall, I would rate the solution an eight out of ten.
Delinea offers several deployment options beyond the cloud-based solution. They have CAM and PaaS.
CAM focuses on Identity and Access Management (IAM) features like Active Directory Bridging. This allows users, for example, a Linux or Unix administrator with access to 10,000 servers, to access all servers using a single ID and password. This is achieved by Centrify, one of the products under the Delinea umbrella. Other PAM solutions might not have this functionality.
Additionally, Delinea offers "PAMSight" for PaaS, which integrates with Delinea Secret Server. So, if an organization aims for a combined solution, Delinea can potentially save them money.
However, I would recommend Delinea Secret Server for mid to large-scale organizations, not necessarily for smaller ones. Organizations with less than 5,000 employees likely wouldn't benefit from extensive single sign-on features. They might be better served by simpler IAM tools like Ping or SailPoint.