What is most valuable?
Delinea Secret Server is robust, and the solution provides value-added security for sensitive credentials. Automatic rotation is one of the key features I appreciate for this particular functionality. Access control is also one of the key features, particularly role-based access control and checkout workflows, including temporary access logs and detailed session tracking, which simplifies the reporting process. I particularly appreciate the deployment speed, as it is generally faster and less cumbersome to deploy compared to heavier legacy systems such as CyberArk.
Built-in automation features, such as password rotation and check-in, check-out workflows, impact operational efficiency and compliance posture significantly. The core built-in capabilities include Active Directory integration that allows joining Unix, Linux, or Windows systems directly into Active Directory without needing complex third-party LDAP synchronization tools. Privilege elevation is another feature that highlights built-in commands, granting specific users or groups temporary administrative rights without sharing a root password. Centralized auditing records user logins, file access, and privileged command executions to satisfy compliance tracking such as PCI DSS, HIPAA, and SOX. RBAC, the granular role-based access controls, is provided to show individuals only the specific server and command access required for their job duties.
What needs improvement?
I would characterize common frustrations related to Delinea Secret Server rather than using the term dislike. One area is the complexity for the administrative part. While it is straightforward in core values, configuring advanced policies, custom templates, and other areas including discovery scans and detailed reporting have a steep learning curve and may require extra training.
The user interface and terminology present another challenge. Some users feel that the user interface can feel dated or overly complex, with terminology around secrets and folder structures taking time to master. Pricing perception is another point where some costs are mixed, while many others find Delinea Secret Server more affordable and flexible than tier one competitors. However, smaller teams still view enterprise licensing as a significant investment.
I have observed poor technical support, particularly in multiple reviews. The support can be slow, limited, and sometimes unhelpful when troubleshooting complex configurations or stability issues. Aggressive or untransparent sales practices also present a concern. Some customers on G2 have cited frustrations with hidden costs, such as unexpected EC2 instance fees and core features being unbundled or oversold during contract negotiation.
Complex implementation and setup is another significant challenge. The initial configuration, deployment, and managing advanced policies or connectors requires specialized expertise that most organizations do not have, and the steep learning curve compounds this issue. Users transitioning to the cloud-hosted version frequently complain that the updated interface and permissions structure feel slow and problematic compared to the legacy on-premise setup.
Integration and API challenges represent the final area of concern. The platform points out challenges with API tokenization and external system integration, and the lack of documentation is one of the key points I would highlight. This limitation affects the ability to integrate with external systems effectively.
For how long have I used the solution?
I have been using Delinea Secret Server for one to two years.
How are customer service and support?
Delinea Secret Server offers 24/7 IT support available, which addresses hidden security gaps and operational risks when validating backups, recovery, and system health, providing clear recommendations and direct communication. They also provide IT free consultations or services and cover several areas including IT security and server management, cybersecurity, and cloud software. They provide 24/7 on-site and remote technical support, and they also offer email and phone technical support globally.
They have recently started third-party partnerships, such as server Omega network integrations. From my experience, they provide technical support coverage and documentation, though I did not have much time to explore them thoroughly. They allow customers to access upgrades and new releases, revisiting new features and providing feedback.
Regarding technical support, the contact process requires gathering several pieces of information before opening a case, including contact and account information, an email account already associated, company name, technical contact name, phone number, and product name. Relevant details should also include technical content. For problem descriptions, I include a concise explanation, full text or error messages, what users were doing when the problem occurred, and other specifics such as timestamps, the number of users, and various IDs. It is crucial to highlight product and environmental versions, SQL high availability or replication configurations, and server specifications, including CPU and RAM. Issues often relate to authentication, licensing, or environmental complexities.
The first step is to gather the mentioned information and then acquire the mandatory support PIN from the Delinea Secret Server main page. If using the ticketing system for support, leaving the browser tab open while returning to a different one is recommended. In the case of Secret Server Cloud, logging on to the cloud manager dashboard, clicking to generate technical support PIN, and recording it is necessary. The support method is then selected, going through Delinea customer support via phone, email, or ticketing. Phone support is delivered worldwide, and for email, the PIN must be provided.
How was the initial setup?
When discussing the initial deployment of Delinea Secret Server, the first step is to select the type of deployment. Delinea Secret Server on-premise is installed locally on a domain-joined Windows virtual machine using Microsoft IIS or Microsoft SQL database, and it includes automatic installation and advanced manual installation. Secret Server Cloud (SSC) is a multi-tenant platform managed by Delinea, with one portal requiring a lightweight distributed engine for local Active Directory and network communication. The first step for initial deployment is to choose the deployment type, whether Secret Server on-premises (SSOP) or Secret Server Cloud (SSC).
The second step is to prepare the prerequisites, including the server and the OS, whether it is Windows Server 2026 or newer Microsoft IIS. Microsoft SQL Server with an assigned account processing and permissions is also required. The third prerequisite is messaging such as RabbitMQ. The third step is to run setup and configuration. For run setup, I generally run a setup.exe file as an administrator on the host server or provision that cloud tenant via a portal.
The API security note is one of the key points to consider. The latest version 12.1 or later has API authentication enabled by default, which blocks direct script and interactive user username and password calls until reconfiguration. For run setup and configuration, I connect directory and secret by setting up Active Directory sync and configuring a backup called the break the glass admin account and running initial heartbeat test to configure remote password changing (RPC) functionality.
In summary, the first step for initial deployment is to choose the deployment type, whether SSC or SSOP. The second step is to prepare prerequisites such as the server and OS. The third step is to run setup and configuration, executing the setup.exe file means running the installer, then addressing the API with modern version 12.1 or later, and finally connecting the directory and secret components.
Which other solutions did I evaluate?
Alternative solutions to Delinea Secret Server include PAM security solutions. Secure-done is one of the PAM enterprise software options. Other key alternatives include CyberArk Privilege Access Manager, Keeper PAM, Manage Engine PAM 360, and PAM 360.
What other advice do I have?
I have integrated components of Delinea Secret Server, such as local IIS processing. This runs the scan directly onto the web server hosting Delinea Secret Server instead of using a remote engine, though it is generally not recommended for restricted or segmented networks due to port and firewall limitations. Another option is deploying a distributed engine, which is a recommended alternative that scales out and groups into specific sites to handle network isolated segments, balance scanning loads, or perform local password changing and heartbeating.
I also use a custom PowerShell scanner, which is a script written inside Delinea Secret Server and serves as an extensible discovery source for querying non-standard systems or third-party environments not supported by the out-of-the-box scanner. Third-party integration uses external asset discovery platforms such as BMC Helix to map or sync assets directly with Delinea Secret Server environment instead of relying strictly on the native engine. Additionally, Delinea provides a free privilege account discovery tool that uses a standard standalone utility for local network scanning and additional account visibility before importing findings into Delinea Secret Server.
Regarding comprehensive discovery capabilities, Delinea Secret Server is designed to automatically scan the IT environment to find unmanaged privileged accounts, servers, and hidden dependencies. Core capabilities include automated network scanning that searches Active Directory, local Windows systems, Unix, Linux hosts, and VMs within ESX or ESXi environments. Cloud and multi-cloud visibility is also significant, as it tracks access and identities across AWS, Google Cloud Platform (GCP), and Microsoft Entra ID. Dependency mapping identifies linked Windows services, scheduled tasks, and IIS application pools to prevent service outages during password rotations. Extensible discovery is achievable using custom PowerShell scripts to build specialized scans for unique or non-standard infrastructure. Privilege control for the server automatically detects server premises to enforce centralized MFA, session recording, and access policies.
Regarding centralized management of all privileged accounts and credentials within Delinea Secret Server, I do not believe it contributes to reducing blind spots. I would rate this review an eight out of ten overall.