We just raised a $30M Series A: Read our story

BeyondTrust Endpoint Privilege Management OverviewUNIXBusinessApplication

BeyondTrust Endpoint Privilege Management is the #4 ranked solution in our list of top Privileged Access Management (PAM) tools. It is most often compared to CyberArk Privileged Access Manager: BeyondTrust Endpoint Privilege Management vs CyberArk Privileged Access Manager

What is BeyondTrust Endpoint Privilege Management?

BeyondTrust Endpoint Privilege Management enables organizations to mitigate attacks by removing excess privileges on Windows, Mac, Unix/Linux and networked devices. Remove excessive end user privileges and control applications on Windows, Mac, Unix, Linux, and networked devices without hindering end-user productivity.

Key Solutions Include:

-ENTERPRISE PASSWORD SECURITY

Discover, manage and monitor all privileged accounts and SSH keys, secure privileged assets, and report on all privileged account activity in a single solution.

-ENDPOINT LEAST PRIVILEGE

Enforce least privilege across all Windows and Mac endpoints, gain visibility into target system vulnerabilities, and control access to privileged applications without disrupting user productivity or compromising security.

-SERVER PRIVILEGE MANAGEMENT

Gain control and visibility over Unix, Linux and Windows server user activity without sharing the root or administrator account.

-A SINGLE PLATFORM FOR MANAGEMENT, POLICY, REPORTING AND THREAT ANALYTICS

Utilize a single solution to manage PAM policies and deployment, understand vulnerability and threat analytics, and provide reporting to multiple stakeholders and complementary security systems.

Learn more at https://www.beyondtrust.com/privilege-management

BeyondTrust Endpoint Privilege Management is also known as BeyondTrust PowerBroker, PowerBroker, BeyondTrust Endpoint Privilege Management for Windows, BeyondTrust Endpoint Privilege Management for Mac, BeyondTrust Endpoint Privilege Management for Linux, BeyondTrust Endpoint Privilege Management for Unix.

BeyondTrust Endpoint Privilege Management Buyer's Guide

Download the BeyondTrust Endpoint Privilege Management Buyer's Guide including reviews and more. Updated: October 2021

BeyondTrust Endpoint Privilege Management Customers

Aera Energy LLC, Care New England, James Madison University

BeyondTrust Endpoint Privilege Management Video

Archived BeyondTrust Endpoint Privilege Management Reviews (more than two years old)

Filter by:
Filter Reviews
Industry
Loading...
Filter Unavailable
Company Size
Loading...
Filter Unavailable
Job Level
Loading...
Filter Unavailable
Rating
Loading...
Filter Unavailable
Considered
Loading...
Filter Unavailable
Order by:
Loading...
  • Date
  • Highest Rating
  • Lowest Rating
  • Review Length
Search:
Showingreviews based on the current filters. Reset all filters
Faraz Abbasi
Security Engineer at Dig8Labs
Real User
Provides our clients with Session Management and state-of-the-art Password Management

Pros and Cons

  • "I'm a BeyondTrust partner and I have multiple deployments, four or five banks right now. The features that give us quite an edge compared to what our competitors are offering - like IBM or Thycotic - are the Session Management, that is quite a big one; also the recording of keystrokes. In addition, there is the password vaulting and state-of-the-art Password Management, which I haven't seen in other products."

    What is our primary use case?

    There are multiple use cases for this solution. There is the auto-discovery option for PowerBroker Password Safe, which can discover all the local accounts on any of Windows, Linux, or Unix. It can work with Active Directory and onboard Active Directory accounts automatically, if the correct credentials have been provided for AD. When it comes to databases, it also governs and controls all of them. It can integrate with Oracle Database, SQL, Oracle Linux, or other database environments.

    What is most valuable?

    I'm a BeyondTrust partner and I have multiple deployments, four or five banks right now. The features that give us quite an edge compared to what our competitors are offering - like IBM or Thycotic - are the Session Management, that is quite a big one; also the recording of keystrokes. In addition, there is the password vaulting and state-of-the-art Password Management, which I haven't seen in other products.

    It also provides a granular approach through the Management Console and manages all the operations "from the inside out". It is easy to explain and easy to manage.

    What needs improvement?

    If you are specifically dedicated to Privileged Access Management, the definitions are a bit unclear throughout the world. I have been in contact with engineers around the world, in Canada, the U.S, and the U.K as well. Everyone has quite a different definition for Privileged Access Management or Identity Access Management or Identity Management.

    Because of the definition of PAM, I don't think they can provide anything in addition to what has been defined. If you want to include anything else in this product, it will deviate from the boundaries of PAM.

    For how long have I used the solution?

    Three to five years.

    What do I think about the stability of the solution?

    I have not encountered issues with the stability.

    There are slight hiccups but they are based on the configuration details of the appliances, as done by the clients. If you are talking about the application or the features it provides, I don't think there are any hiccups with BeyondTrust.

    I have worked on competitive products as well. IBM and Thycotic are lightweight applications utilizing limited resources and providing proportionate results. I don't think anyone can compete with BeyondTrust.

    How are customer service and technical support?

    The response time and the responsiveness, the level of support that they provide, is tremendous.

    I have worked on the scene, I have worked on firewalls as well as on multiple security products, but the support from BeyondTrust is highly efficient, from a highly experienced technical staff. The level at which they provide support, the dedication as well as the expertise they have, is among the best I have seen.

    Which solution did I use previously and why did I switch?

    I have utilized OpenAM SSO, as a single sign-on. That was a Canadian product. It was an open-source solution. But I am happier with BeyondTrust. About 95 percent of use cases are handled by BeyondTrust. Whether you're talking about a bank or a telco, whatever their requirements are, they can be met by the PAM. When it comes to the PAM, I don't think that any application can compete with BeyondTrust, except for the financial issue that has been recently affected by the change in the licensing model.

    How was the initial setup?

    The initial setup is straightforward; the way that they provide the UVMs, and the whole package when it comes to deployment. What they do is provide you a complete setup package. Everything in there is preconfigured, so all you have to do is to provide the basic IP addresses and other stuff and that's it.

    What's my experience with pricing, setup cost, and licensing?

    What BeyondTrust was providing was user-based licensing which was a great benefit from the client point of view. Recently, I don't know why, the licensing model has been changed, and that is the reason that they have lost a bit of their edge when it comes to the PAM, against our competition.

    The asset-based licensing, from the user's point of view, is not beneficial. The licensing should be based on the users. The greater the number of users, the greater will be the load and the greater the scalability problems. I presume that is why the licensing model has changed.

    Which other solutions did I evaluate?

    My company first chose the IBM Identity Manager suite. Later on, we surveyed the market and the needs and requirements of the clients. We thought the IBM solution was utilizing too many resources to achieve a very limited goal. The requirements are related to PAM, but they were employing IM.

    What other advice do I have?

    I would rate BeyondTrust at eight out of 10. It's not a 10 because the scalability and licensing have impacted us a lot. Of the two points that I have deducted: One is the non-flexibility on the pricing and one is the licensing model. When you launch a product in several markets like the European market, the Asian market, or the Russian market, you have to be very flexible when it comes to the pricing.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
    Star Tseng
    Senior Technical Consultant at a tech services company with 1,001-5,000 employees
    MSP
    It scales easily and the product is stable

    What is our primary use case?

    We use it for the password management (of privileged password management).

    What is most valuable?

    Privileged password management.

    What needs improvement?

    It should support XWindows Remote Desktop Access Protocol for Linux/Unix. I would like more connectors for other security software/systems. A password is needed to access their security systems.

    For how long have I used the solution?

    Less than one year.

    What do I think about the stability of the solution?

    No stability issues.

    What do I think about the scalability of the solution?

    It scales easily.

    How are customer service and technical support?

    I would rate their technical support as a nine out of 10. I have a technical support contact in Singapore.

    Which solution did I use

    What is our primary use case?

    We use it for the password management (of privileged password management).

    What is most valuable?

    Privileged password management.

    What needs improvement?

    It should support XWindows Remote Desktop Access Protocol for Linux/Unix.

    I would like more connectors for other security software/systems. A password is needed to access their security systems.

    For how long have I used the solution?

    Less than one year.

    What do I think about the stability of the solution?

    No stability issues.

    What do I think about the scalability of the solution?

    It scales easily.

    How are customer service and technical support?

    I would rate their technical support as a nine out of 10. I have a technical support contact in Singapore.

    Which solution did I use previously and why did I switch?

    We did not previously use another solution.

    How was the initial setup?

    The initial setup was easy.

    What other advice do I have?

    For a Windows/Linux/Unix mixed environment, it is a good product to management privilege account passwords to prevent security breaches.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor.
    Learn what your peers think about BeyondTrust Endpoint Privilege Management. Get advice and tips from experienced pros sharing their opinions. Updated: October 2021.
    542,823 professionals have used our research since 2012.
    BS
    Security Staff Engineer at a tech vendor with 1,001-5,000 employees
    Real User
    Helps us reduce major vulnerabilities by removing local administrator privileges

    What is our primary use case?

    We use it to limit user privileges.

    How has it helped my organization?

    It reduces major vulnerabilities by removing local administrator privileges.

    What is most valuable?

    I like that I can remove local admin privileges from developers.

    What needs improvement?

    It only has limited support for Mac.

    For how long have I used the solution?

    Less than one year.

    What do I think about the stability of the solution?

    In version 7.3 there were driver compatibility issues with other security applications, but they were resolved very quickly by support.

    What do I think about the scalability of the solution?

    The BeyondInsight appliance environment is not as flexible as it should be in some designs. But overall, it’s a well-designed product.

    How is

    What is our primary use case?

    We use it to limit user privileges.

    How has it helped my organization?

    It reduces major vulnerabilities by removing local administrator privileges.

    What is most valuable?

    I like that I can remove local admin privileges from developers.

    What needs improvement?

    It only has limited support for Mac.

    For how long have I used the solution?

    Less than one year.

    What do I think about the stability of the solution?

    In version 7.3 there were driver compatibility issues with other security applications, but they were resolved very quickly by support.

    What do I think about the scalability of the solution?

    The BeyondInsight appliance environment is not as flexible as it should be in some designs. But overall, it’s a well-designed product.

    How is customer service and technical support?

    I would rate support at six out of 10. They need more people in the Pacific time zone.

    How was the initial setup?

    The setup was straightforward. The appliance build was very simple and was completed with minimal effort.

    What's my experience with pricing, setup cost, and licensing?

    PowerBroker for a Mac client is three times the price of the Windows version.

    Which other solutions did I evaluate?

    • Avecto
    • Thycotic
    • Viewfinity

    What other advice do I have?

    Implementation is simple, but privileged application support may need a lot of testing. Support may not be able to help due to a lack of understanding of your environment.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    StarTseng
    Senior Technical Consultant at a tech services company with 1,001-5,000 employees
    MSP
    Simplifies server access without password distribution

    How has it helped my organization?

    Simplifies server access without password distribution.

    What is most valuable?

    Password management, as it is a core function; passwords are a frequent hacking point.

    What needs improvement?

    All products have room to improve. I would like to see support for many more systems, such as AS400.

    For how long have I used the solution?

    Less than one year.

    What do I think about the stability of the solution?

    No issues with stability.

    What do I think about the scalability of the solution?

    I have not had a chance to scale out.

    How is customer service and technical support?

    My support has come from the sales engineering team, not the support team, and I would rate the support at nine out of 10.

    How was the initial setup?

    For a production…

    How has it helped my organization?

    Simplifies server access without password distribution.

    What is most valuable?

    Password management, as it is a core function; passwords are a frequent hacking point.

    What needs improvement?

    All products have room to improve. I would like to see support for many more systems, such as AS400.

    For how long have I used the solution?

    Less than one year.

    What do I think about the stability of the solution?

    No issues with stability.

    What do I think about the scalability of the solution?

    I have not had a chance to scale out.

    How is customer service and technical support?

    My support has come from the sales engineering team, not the support team, and I would rate the support at nine out of 10.

    How was the initial setup?

    For a production environment, the setup is easy. For a PoC it is a different scenario.

    What other advice do I have?

    Take care regarding the SQL database.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    ITCS user
    Identity and Governance Access Lead
    Real User
    The features related to application elevate is amazing.

    Pros and Cons

    • "The features related to application elevate is amazing. It helped the company to remove almost all admin local users."
    • "Reports to the end user."

    What is most valuable?

    The features related to application elevate is amazing. It helped the company to remove almost all admin local users.

    How has it helped my organization?

    There are severals application that all users needed to have local admin configured to work. After the powerbroker implementation, all users with this privilege were removed, it improved the security and helped to change the IT vision, from Security to SAFETY.

    What needs improvement?

    Reports to the end user.

    For how long have I used the solution?

    1 year

    What was my experience with deployment of the solution?

    Not at all.

    What do I think about the stability of the solution?

    Not at all

    What do I think about the scalability of the solution?

    No.

    How are customer service and technical support?

    Customer Service:

    Very good.

    Technical Support:

    Very good

    Which solution did I use previously and why did I switch?

    No.

    How was the initial setup?

    Easy.

    What about the implementation team?

    Vendor team. Very good.

    What was our ROI?

    N/A

    What's my experience with pricing, setup cost, and licensing?

    I'm sure everyone should have the cluster environment, which means more expensive, anyway, cheaper than the other solutions.

    Which other solutions did I evaluate?

    Yes, CyberArk, CA.

    What other advice do I have?

    No.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    it_user599004
    Sr Platform Engineer at a construction company with 10,001+ employees
    Vendor
    Elevation rules reduce the number of users in administrator groups.

    What is most valuable?

    It elevates the user to perform admin tasks without the user being a part of an administrator group.

    PowerBroker allows elevation of required actions or application and eliminates the need of user having full administrative access. There are immense security and administrative benefits associated with removing users administrative access on the workstation.

    PowerBroker allows the elevation of certain actions based on different whitelisting abilities. This can range from restarting services, installing software and allowing applications that require administrative privileges to run.

    It is very similar to the UAC components built into Windows but gives us a lot more control surrounding the elevation

    How has it helped my organization?

    Previously, all users were in the administrator group of their machines. Since PowerBroker elevates the user, we can remove the users from the administrator group. Thus, the machines become less vulnerable to attacks

    What needs improvement?

    Improve the ActiveX rule for websites.

    For how long have I used the solution?

    I have used this product for almost a year.

    What do I think about the stability of the solution?

    The software sometimes uses a lot of memory.

    What do I think about the scalability of the solution?

    We have not had any scalability issues.

    How are customer service and technical support?

    Technical support is mostly good.

    Which solution did I use previously and why did I switch?

    We didn’t use any previous solutions.

    How was the initial setup?

    It's a straightforward setup.

    What's my experience with pricing, setup cost, and licensing?

    Price seems to be a little on the higher side.

    Which other solutions did I evaluate?

    We evaluated Avecto.

    What other advice do I have?

    Make use of Polmon and Beyondtrust reporting console to create the elevation rules.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    ITCS user
    Information Security & PreSales Officer at a tech services company with 51-200 employees
    Consultant
    It allows implementing a strong workflow in the organization for accessing the most valued resources.

    What is most valuable?

    The main areas of focus of BeyondTrust products is Privileged Access Management. Along with it, they've also bundled the PAM solutions with a Vulnerability Management solution. We all know Retina Network Security Scanner has been around for more than a decade now and anybody would agree with me that it has been a most comprehensive scanner. BeyondTrust bundles these two areas of security - PAM and VM - with an extremely rich reporting & analytics platform – BeyondInsight - which gives actionable intelligence to SMBs as well as large enterprises.

    Along with PAM & VM, PBW allows implementing a strong workflow in the organization, with regards to accessing the most valued resources of the enterprise. The request-approval process along with session monitoring and recording, could prove a very strong deterrent security control for actors with malicious intent.

    With all the other features, such as asset inventory, scanning, jobs scheduling, etc., BeyondInsight offers an intelligent platform for reporting and analysis of the collected information from the customer's environment. It presents the information in the form of heat maps, risk maps, ROI graphs which are very useful for presenting to your senior executives during your budget planning. Overall, it has proven very useful to all individuals from engineer to the 'C' class of the company.

    How has it helped my organization?

    We implemented the BeyondTrust suite of products as part of our initial evaluation and continued to use the product because we liked it very much. We distribute security solutions to our customers, so we can only sell something to our customers that we believe in. And the best way to start to believe in something is to experience it. So, from the initial evaluation environment, we moved a few assets – because it's not a very large organization - and implemented a workflow process for our IT contractors. Developers and network engineers who access our infrastructure devices such as servers, routers, and firewalls have to put forth a request (though we've kept them as auto-approve 24x7, since we trust them :) ), to access the devices. All these activities are monitored, recorded & audited on a periodic basis or in cases of issues. We do not have any external auditing done within our company. However, I can imagine the kind of details provided by the solution to the auditors on almost all of the IT activities required to be monitored and audited.

    Apart from auditing & recording requirements, our sysadmin now has the best control of his work in his tenure with us, in the area of patch management for our networks. RNSS has been scheduled for periodic scan jobs preparing a report. We've configured the Enterprise Update server, which checks the vulnerabilities, suggested remediation, and once they've been reviewed, all the systems are patched directly from the Enterprise Update server.

    These are some of the areas I can think of at this point of time that we have benefited from BeyondTrust so far.

    What needs improvement?

    I'm of the thought that the best products in the market have room for improvement, always, and so is the case with this product as well. I have always submitted the improvements / bugs list to the vendor and am looking forward for them to be implemented in their coming releases.

    These are related to the Flash / Java Web UI, which we know is very vulnerable. I would love to see the Reporting & Analytics console in HTML5 or other technologies which are not as vulnerable as Flash. That's something I don’t promote for the product. However, it being an internal-facing Web application, it doesn't pose a very high risk.

    Other areas for improvement I have suggested in the past were more tight integration with some of the comprehensive ticket management systems. Currently, it does open a ticket in external ticket management system by sending an email. However, I would love to see these tickets being opened and customizable for other activities, such as after a vulnerability scan for high-impact or high-risk vulnerabilities, systems not patched for a certain time duration, and the list can go on. Auto-opening & auto-closing of tickets is something I would love to see implemented in BeyondTrust.

    For how long have I used the solution?

    I've been implementing & using BeyondTrust products for more than a year now.

    What do I think about the stability of the solution?

    I have not encountered any major stability issues so far; just a few minor bugs, such as when you run / schedule jobs, sometimes we could see two of them being run. But this was just in the UI, RNSS in the background would still run as per the configured and scheduled jobs & reporting back is also as expected. Apart from that, the product is pretty much stable.

    What do I think about the scalability of the solution?

    I've seen the product scale with no problems. I've implemented products in customers’ environments as a POC with a few servers / resources under monitoring. And once they decided to go ahead with the solution, they've scaled very well to a few hundred or thousands of users with addition of endpoint software, with virtually no impact on the performance. On the contrary, the more the resources being monitored, the more information being collected, which lights up the platform and provides a very comprehensive list of information of your network.

    How are customer service and technical support?

    Until now, there hasn’t been local direct support in Australia, so any support has to be raised via email and there is a day's lag. To speak directly to the support rep, you have to call a toll-free U.S number. However, I haven't doubted the competitiveness and efficiency of the support. All the cases I have submitted so far, for ourselves as well as our customers, have been resolved to an excellent level of satisfaction.

    Which solution did I use previously and why did I switch?

    I wasn't using any similar solution previously.

    How was the initial setup?

    The product is available in the software as well as virtual appliance form which is a hardened Windows server, shipped securely to the end-user. It does have initial setup and configuration tasks. I would not say it's simple for naive users; however, having said that, it's backed up by very strong, simple and straightforward step-by-step documentation, which is very simple to understand and can be followed by a beginner to mid-level engineer.

    What's my experience with pricing, setup cost, and licensing?

    Compared to its competitors, BeyondTrust software is way too cheap and offers many more features and functionality at the base price point. Licensing is simple and based on either number of users or number of resources, whichever is cheaper for the customer and very easy to calculate. Licenses are not hard-limited on the number of users.

    What other advice do I have?

    Security, as always, should be taken care of in a layered approach. BeyondTrust products take care of the containment of the breach with its PAM suite of solutions, as well as reducing the attack surface with its Vulnerability Management products. Together, they present a very strong, in-depth defense approach for customers. It's not an endpoint protection product, though they have their endpoint agents, which could be installed on the workstations. It has to be implemented in conjunction with other security solutions such as endpoint protection and gateway security solutions such as email & web, as well as firewalls, IDS, IPS and other network security devices.

    Disclosure: My company has a business relationship with this vendor other than being a customer: My organization is a Value Added Distributor for BeyondTrust in the APAC region.
    Buyer's Guide
    Download our free BeyondTrust Endpoint Privilege Management Report and get advice and tips from experienced pros sharing their opinions.