
StrongDM: The Dynamic Access Management Platform
Centralized access has improved incident response and provides secure, credential-less logins
What is our primary use case?
In our environment, we have managed Linux servers, cloud resources, and production systems, and we use StrongDM as a privileged access management solution. StrongDM authenticates users through the identity provider, authorizes access based on RBAC, and establishes secure SSH connections. We also maintain complete audit logs of all user activities.
For example, if our team needs to access an app server, DB server, or a Kubernetes cluster, instead of using SSH user@server, we first authenticate them through StrongDM. Then, StrongDM checks if the user is active and belongs to the cloud operations team, and if they have production access. If the criteria are met, StrongDM creates the security connection for them. Once the security connection is established, the cloud engineer logs in to the StrongDM portal, it performs SSO authentication, and the role is verified. Then, they are redirected to the StrongDM gateway, and the person can connect. No passwords need to be shared.
Regarding the workflow, suppose there is an incident. Without StrongDM, we would have to find the key and then SSH to the production VM, which would take several minutes. With StrongDM, we go to the StrongDM portal, select the production VM, connect, and start troubleshooting. This saves time. The focus shifts from managing access to solving the incident within a few minutes.
Regarding the audit process, everything will be recorded in StrongDM. The administrator knows who connected, which resource was accessed, and for how long they were active. We can get all of this information from the complete audit logs.
What is most valuable?
The best feature of StrongDM is that it is a time-saving tool for us, and it also provides centralized access management, which is the biggest advantage of StrongDM. Another feature is single sign-on (SSO). Instead of entering passwords, we can use the single sign-on option. Apart from that, role-based access control is also a great feature.
StrongDM has had a positive impact on my organization by providing faster access to production servers. Instead of remembering SSH keys and multiple passwords, the positive impact is an easier login process, which reduces login issues.
When it comes to periodic checks, one is periodic authorization, and the other one is continuous authorization. In periodic authorization, access is checked only at specific intervals. However, when it comes to continuous authorization, StrongDM continuously validates the session instead of checking only once, so the access is constantly re-evaluated.
From my experience with StrongDM, the biggest advantage was its credential-less access model. As an engineer, we did not have to store or handle SSH keys, database passwords, or any other privileged credentials on our laptops. We authenticated using our corporate SSO account, and StrongDM established a secure connection to the target resource based on our role permissions. I understand that StrongDM can integrate with secret managers like HashiCorp Vault or cloud KMS services, so credentials can be centrally managed and not exposed to end-users. That is a significant advantage.
What needs improvement?
StrongDM can be improved in many ways. For example, the access approval workflow could be faster. We face a challenge where we sometimes need temporary access to production but have to wait for an administrator to grant permission. This could be improved and streamlined. If they could provide a just-in-time access approval workflow with integrations to Slack or Microsoft Teams, that would greatly help, especially during production incidents. A faster approval workflow would be beneficial. Additionally, for large environments with many servers, features such as smart automations and resource tagging would be helpful and save time.
One more feature I would like to add is more built-in operational dashboards. Although StrongDM has some dashboards, if they added more comprehensive dashboards, it would be easier to see who has access to what.
For how long have I used the solution?
I have been using StrongDM for five years.
What do I think about the stability of the solution?
StrongDM is very stable, and we have not experienced any downtime or faced any issues with StrongDM. From my experience, it was reliable and generally stable. We used it to access our production Linux machines for troubleshooting, OS patching, and maintenance. I do not recall any major outages that significantly impacted my work.
What do I think about the scalability of the solution?
StrongDM can easily handle growth because it is very scalable and very reliable as well. From the past few months, we have been using it continuously. We access the resources through the same platform without any visible changes in performance. I was not responsible for the deployment, but I can tell you that my user experience remained consistent.
How are customer service and support?
The customer support was good, and we had a positive experience with StrongDM's support team, as they have been assisting us in a prompt and professional manner.
Which solution did I use previously and why did I switch?
In my company, we have been using StrongDM exclusively.
What about the implementation team?
The implementation was straightforward, as we have a separate team that handled it.
What was our ROI?
I was not involved in calculating the formal return on investment, and I do not have exact financial metrics on that. However, from an operational perspective, we have been seeing improvements in efficiency. While I cannot quantify the savings, it definitely reduced operational overhead and improved security.
What other advice do I have?
StrongDM is very effective in closing initial breach paths because it follows a zero-trust platform and centralized privileged access management. Instead of allowing users to directly connect to production resources using shared credentials, StrongDM authenticates the user through SSO, enforces role-based access control, and logs every access attempt. This significantly reduces the chances of unauthorized access, which is often one of the primary breach paths in enterprise environments. I give this solution a rating of nine out of ten.
Just-in-time access has strengthened zero trust and reduces long-standing privileged accounts
What is our primary use case?
My main use case for StrongDM is Just-In-Time access for connecting to Windows or Linux machines through RDP or SSH.
A specific example of how I use StrongDM for Just-In-Time access is that we have implemented StrongDM as a PAM tool which enhanced the Just-In-Time access for a customer. We did a one-to-one resource mapping with respect to the target systems in each data center. Once we added the resource into StrongDM, with the help of dynamic rules, we can provide access to the relevant users or groups. The users can access StrongDM using the Just-In-Time access and establish a connection via the StrongDM client.
What is most valuable?
The best features that StrongDM offers include a proxy-based system that aids in Just-In-Time access, ultimately helping to remove long-standing access, which every organization looks for to reduce high privilege accounts. Every user gets access based on their required need.
StrongDM has impacted my organization positively by being user-friendly with automation and command-line utilities, which have reduced effort. Customers can access it via browser or client, offering many options for utilization.
StrongDM's ability to unify access across different systems is significant; it allows for individual resource mapping and ensures users can connect through appropriate proxy clusters for target machines.
I see the importance of StrongDM's continuous authorization as having periodic checks enabled by identity governance tools, ensuring that access is necessary for a certain period according to access review processes.
What needs improvement?
StrongDM lacks the capability for web application injections or password injections, so we need to rely on other tools such as HashiCorp for non-human accounts or DevOps scenarios. This is a limitation that hopefully will be addressed in the future.
Improvements are needed for StrongDM, particularly in web session handling and service account management, similar to HashiCorp or DevOps pipeline requirements.
People using StrongDM may have to rely on Terraform or Bash scripts for command-line utilization. It is user-friendly if a user is knowledgeable; otherwise, they may need to use the UI.
For how long have I used the solution?
I have been using StrongDM for more than one year, specifically for Just-In-Time access.
What do I think about the stability of the solution?
StrongDM is stable.
What do I think about the scalability of the solution?
StrongDM's scalability requires some configuration tweaks on our part.
How are customer service and support?
The customer support for StrongDM is really good. They help a lot with any issues we face.
Which solution did I use previously and why did I switch?
Previously, we used Centrify but switched to StrongDM due to its advancements and capabilities.
How was the initial setup?
We did not purchase StrongDM through the AWS Marketplace; we had a direct contact with StrongDM for this configuration.
What was our ROI?
I have seen a return on investment; whatever amount we spend saves us time and ensures a high level of security with zero trust.
What's my experience with pricing, setup cost, and licensing?
I cannot disclose the pricing details, but I find it competitive compared to other solutions.
Which other solutions did I evaluate?
Before choosing StrongDM, I evaluated it alongside other options such as HashiCorp. StrongDM has proven to be comparatively better, despite some feature gaps.
What other advice do I have?
StrongDM integrates with Dell Secret Server, and we can also integrate it with other PAM solutions. It fetches credentials from the other vaulting tool and establishes connections. It also manages non-human accounts and can establish connections through direct or proxied connections. Credential rotation is handled by the other vaulting tool, so StrongDM acts as a proxy tool over it.
Removing long-standing access has significantly impacted my security posture by ensuring that no user has high privilege accounts or long-standing access without necessity. Access is only provided for a certain stipulated period when needed, which helps prevent hacking.
Since using StrongDM, I estimate around a 60% reduction in effort compared to other PAM tools. The integration allows for user-friendly mapping, even in disaster recovery scenarios, making it straightforward to configure and highly useful for those needing strong disaster recovery solutions.
StrongDM's approach to credential-less access control aligns with zero trust principles based on Just-In-Time access, ensuring no long-standing privilege exists without necessity, reducing the risk of credential leaks.
StrongDM's AI capabilities increase security posture effectively.
The accuracy and reliability of StrongDM's output are very good. I can fully rely on the output without needing to validate it.
We use AWS for our private cloud.
We assess the effectiveness of StrongDM in closing breach paths in real time through proof of concept and analyzing the use case with respect to requirement and capability mapping.
I would rate this solution an 8 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
User-friendly access controls have streamlined audits and saved significant review time
What is our primary use case?
My main use case for StrongDM is to assess identity and authentication and authorization access control reviews. When I conduct internal audits or assessments to check the presence of security controls, I use StrongDM to navigate to the configuration settings panel to check what flags and features are enabled or disabled. I appreciate the UI of the overall tool and its functionality.
There was a situation where I had to check whether the privileged account credentials maintained in StrongDM PAM tool are actually encrypted. I configured and opened StrongDM and checked the settings in the configuration window where I was able to verify that StrongDM contains controls and features which enable it to encrypt privileged account credentials. Additionally, it has features for auditing, generating audit trails, and log trails for all activities conducted by any user who is using privileged accounts. Apart from that, there is a database active monitoring tool embedded within StrongDM. These are certain cases where I have navigated this tool and found the UI to be very user-friendly.
What is most valuable?
The best features StrongDM offers include the JIT access and workflows, which is the Just-in-Time access provided by StrongDM. Apart from that, there are features like the context-aware policy engine, which helps this tool integrate with endpoint security providers like CrowdStrike and SentinelOne. It also offers comprehensive session visibility and auditing, which helps in session recording and captures all the SSH and RDP terminal sessions as replayable video files. Additionally, it has the ability to navigate with SIEM tools, such as Splunk or DataDog, used to capture all the logs of the servers or cloud storage tools such as Amazon S3 bucket or EC2 instances. Those features are very handy and can integrate very easily with StrongDM. It also offers infrastructure-wide protocol support, whether it talks about PostgreSQL, MySQL, or any database tool. It has secrets management and offers a secret vault agnostic feature through which it can be integrated with any encryption key management tool such as HashiCorp or AWS Secrets Manager. The best thing about it is that it offers a developer-friendly deployment, which is very straightforward and simple with StrongDM PAM tool.
StrongDM has positively impacted my organization by saving me a lot of time as a security auditor, because I have to navigate settings and configurations to check the presence of certain security controls in place. When I am auditing StrongDM, it obviously helps me. It has a very user-friendly UI, with which any auditor or any security professional will find it easier to navigate different options to check the presence of security controls. Apart from that, it also offers dynamic access control, enforcing restrictions based on user role, time of the day, location, and device context. These features help auditors significantly.
What needs improvement?
I think StrongDM could improve by focusing more on network device management by allowing the addition of PAM for network devices, managing legacy network equipment, or helping to initiate enterprise onboarding where a lot of complex environments and initial setup are required. I think that would be a good area for StrongDM to work on.
Apart from that, integration with SIEM and SOAR tools, regarding the logs generated by any privileged user account in these SIEM or SOAR tools, and how to ensure these logs are encrypted, are areas that if StrongDM focuses on, will help it gain advantage over other products in the market right now because they do not have it.
Another area for improvement is the client-side footprint. If StrongDM can provide an installation for user workstations in strict or heavily lockdown environments, maintaining and deploying these desktop clients across thousands of machines can pose a logistical challenge for IT teams. If StrongDM can work on that area as well, it will be a great product.
For how long have I used the solution?
I have been using StrongDM for approximately three or four months.
What do I think about the stability of the solution?
I have not noticed any issues with StrongDM's stability or reliability.
What do I think about the scalability of the solution?
StrongDM's continuous authorization is advanced, and using credential-less accounts offers a lot of flexibility to the users within the company. I believe it is a great initiative.
StrongDM works best to unify access across different systems.
How are customer service and support?
I have not personally interacted with StrongDM's customer support, but I have not heard any complaints from any vendors who are using StrongDM.
What other advice do I have?
I can share that in terms of the number of hours, as an auditor, if I require 30 hours to audit a PAM tool, with the help of StrongDM, when I am auditing the tool, it will help me to audit the whole thing within 10 hours or maybe 15 hours. This amounts to approximately 50% of the time saved for me as an auditor.
My advice for others looking into using StrongDM includes its user flexibility, good scalability, and providing advanced features. If they are looking for these things, they should proceed with StrongDM. My overall rating for this product is 9 out of 10.
Centralized access has strengthened compliance and audits but integration and AI still need work
What is our primary use case?
How has it helped my organization?
StrongDM positively impacts my organization by helping with compliance and audit functions. Audits and compliance are areas where this tool helps significantly because it maintains records in such a way that whenever an investigation is needed on something particular or an incident occurs in the organization, it helps in obtaining information regarding the access given to users. This is one of the positive things, and the outcome it brings could lead to better usage of the product and a better running of the organization in giving access and managing licenses.
If something goes wrong, such as when a user performs an action on a server they have been given access to that should not have been done, checking is easier because the session will be recorded by StrongDM. The session recording feature is useful for the audit and compliance team to investigate issues and rectify them in time so that they will not affect other users.
What is most valuable?
The best features that StrongDM offers include centralized access management, which I would say is the best feature provided.
Centralized access management helps me by giving users access all in one place where they can easily access resources such as databases, internal applications, and VPN access. All of these resources can be managed at one centralized platform, giving unified access to users. Centralized access management is something I appreciate about StrongDM.
What needs improvement?
I would not say ease of use and integration are features to criticize because ease of use is something taken on by the user, so it is actually considerable. Integration, however, is something which admins configure with StrongDM, and in that area, it can be improved. Sometimes, if there is an architecture or infrastructure that is more complex, it would take extra time for integrations.
I think something can be improved in AI, such as using AI for certain functions within StrongDM. Enhancing features with AI can help StrongDM grow significantly in its domain.
I would say that reports can now be generated from the data StrongDM stores. For instance, if one user accessed a database or Kubernetes cluster a long time ago and is not using it now, applying intelligence to that data can better inform the admin. The system could indicate that a particular user has accessed that resource in the past but is not using it currently. Better addressing least privilege access by removing unnecessary access would be valuable. Those AI capabilities that provide insights to admins regarding access could be very helpful.
I have already mentioned that AI capabilities can be improved, and the remaining aspects such as recording queries, sessions, and SSH keys are already being managed well by StrongDM. I believe AI capabilities could be enhanced, and I would also suggest improvement in reporting and dashboard generation with the data available in StrongDM.
Which solution did I use previously and why did I switch?
There are no challenges because I already had knowledge in this area from using similar types of products other than StrongDM. The unique approach that StrongDM offers is centralized access where I can provide user access to all types of resources such as internal applications, which could be databases or Kubernetes clusters. This is one of the features that StrongDM has, and it represents the unique value and the approach I have experienced while using StrongDM.
What other advice do I have?
I would assess StrongDM's effectiveness in closing breach paths in real-time as easy and effective, although I have not encountered this type of situation in my test case.
Continuous authorization is more valuable than periodic checks from my perspective because if something goes wrong during the period of a periodic check, it could be a loss for the organization. Continuous authorization is better.
My advice for others looking into using StrongDM is to plan everything before integrating it into their organization. It is not suitable for very small startups with fewer resources. It is more useful for organizations that have adopted Kubernetes, VPN access, databases, and manual applications for granting access. These resources can better benefit from StrongDM based on my experience.
I have rated this review with a score of seven.
Secure access has transformed our audits and weekend operations run smoothly
What is our primary use case?
StrongDM offers just-in-time access by automatically granting users temporary or time-bound access to privileged systems and revoking it when the task is complete, enforcing the principle of least privilege. StrongDM replaces our legacy PAM solution with a modern, lightweight platform that simplifies access management, enhances the user experience, and ensures robust security. It enables role-based access control, automates our workflows, eliminates the need for old license rotations, captures every query and keystroke, and ensures compliance following standard frameworks like SOC 2 and ISO 27001. Furthermore, it features an agentless architecture that supports users' preferred tools, reduces friction, and boosts productivity. It also enables centralized multi-cloud access, accelerates growth, eliminates VPN pain with zero-trust security, and secures and streamlines our database access.
StrongDM provides just-in-time access by automatically granting users temporary or time-bound access; for example, if someone wants to use it for four hours or eight hours, it will specify that to the privileged system and revoke access when the task is complete. Another great feature is total session visibility, as StrongDM acts as a protocol-aware proxy that captures every query, keystroke, and server interaction, creating a comprehensive audit trail required for standard frameworks like SOC 2 and HIPAA. StrongDM eliminates credential sprawl by separating end-user authentication, typically via SSO, from the database's native credentials, so users never need to know or manage raw passwords.
By adopting StrongDM, we have achieved benefits such as eliminating our weekend outages, streamlining ongoing on-call workflows, enabling seamless migration with POC transitions directly into production with minimal effort, allowing our engineers to use their preferred SQL clients like MySQL, PostgreSQL, and Workbench, and facilitating compliance through detailed session logs and query capture for SOC 2 and ISO audits.
StrongDM connects a user to a database or server, but once the session is established, it treats the runtime as a black box and cannot natively enforce fine-grained or attribute-based access control, such as restricting raw column visibility. For a generic TCP resource, StrongDM only records metadata — who, when, and what — instead of capturing the actual commands or payloads executed within the session.
What is most valuable?
StrongDM's continuous authorization is important for our organization; its scalability, role-based access management, and robust audit capabilities enable us to automate access workflows, retire shared SSH keys, and enhance security. Developers gain self-service access to scrubbed, production-like databases, simplifying testing and development. This is a great feature.
Our impression of StrongDM's credential-less access control and its integration with existing vaults and secret managers is positive. We are integrated with AWS, have an integration team that captures all the configuration, and have added their process, exposing sensitive data while our AI agents help configure these things automatically, making it very easy to deploy.
StrongDM unifies access across different systems in our organization by providing various policies that can trigger step-up multi-factor authentications or automated manager approvals when a user attempts to execute a risky operation. It builds and handles non-deterministic AI agents, logging every query, keystroke, and response to provide complete, searchable records satisfying compliance and governance. Whenever our engineers need access, administrators or our team admin can remove their standing access entirely, and users can request temporary access for a defined period via the StrongDM portal or apps like Slack, which automatically expires once the time limit is reached.
What needs improvement?
Additionally, StrongDM has limited MFA and passwordless options, relying heavily on time-based one-time passwords (OTP) or Duo, lacking support for true passwordless setups like biometrics or hardware YubiKeys, and it does not support per-session MFA. These are the drawbacks that need improvement for StrongDM.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
I would recommend using StrongDM when comparing it to Teleport because it provides features including completeness of offering, lifecycle management, and context-based policies, along with great ease of use in installation and multiple vault support. I encourage other clients to choose StrongDM over Teleport.
What other advice do I have?
The accuracy of StrongDM's output is good, and for reliability, it allows attempts to read files, connect to services, or make network calls based on human-readable policies, which makes the reliability very good.
I have provided a review rating of eight out of ten for StrongDM.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized access has improved privileged control and now provides strong audit visibility
What is our primary use case?
My main use case for StrongDM is privileged access management and infrastructure access that we cater to, as we were looking for alternatives and solutions to securely control and monitor our access to servers. We have been using different kinds of Kubernetes clusters, databases, cloud infrastructure, and internal applications. Instead of giving direct access to our employees, the idea was a VPN-heavy access with shared keys for better usage. This is how I used it during my Kafka experience about three years ago, and also in my current team at GitLab.
In one of those scenarios, my experience with StrongDM while working with Kubernetes in the Kafka team illustrates how we were initially looking for a better way to manage secure access to our infrastructure. Our teams scaled across different environments and regions, primarily Europe, including Sweden and India. Before using StrongDM, we relied on VPN access and manual permission handling, which became difficult to audit and maintain over time as our team grew. Our main use case was centralized privileged access management for Kubernetes clusters. We also considered using it for Linux servers on-premises for the same application but opted out at that time due to limited usage and some internal platforms running on AWS. We aimed for developers and operations teams to get the access they needed without exposing long-lived credentials.
StrongDM is instrumental in unifying access across different systems in our organization, alleviating the complications from separate tools. In the Kafka team, we had AWS infrastructure with Kubernetes clusters managing EC2 machines and internal services for different customers referring to our Kafka topics. StrongDM facilitated a centralized approach to access control, audit logging, and temporary authorization. For example, while working on the Kafka platform on EKS, developers and operations teams could utilize a unified access process across various environments, thus streamlining their work.
What is most valuable?
I find several best features in StrongDM, but our primary use case focuses on ensuring that we do not have long-lived credentials. The best features for us are the centralized access control and the detailed audit logging, which allow us to provide temporary privileged access without managing VPNs ourselves. I appreciate how well it integrates with Kubernetes and cloud environments on AWS. A significant advantage was simplifying onboarding and offboarding processes, taking away a lot of time and minimizing the risk of overlooking these tasks.
The audit logging feature significantly helps my team during troubleshooting and internal security reviews. With multiple teams accessing Kubernetes clusters in our production environments, it provides clear visibility into who accessed what and when. While we could use CloudTrail, fetching details from it requires complex SQL queries, making it challenging. StrongDM simplifies this, reducing manual tracking efforts and improving accountability, especially important for compliance with specific regulations we need to follow.
StrongDM positively impacts our organization in many ways, mainly in cost savings from the time saved. It has significantly improved both security and operational efficiency for us. Previously, access management across AWS and Kubernetes was manual and highly coordinated, relying on VPNs. With StrongDM, onboarding and temporary privileged access processes became much faster and more standardized, enhancing our security posture while maintaining necessary compliance.
What needs improvement?
I believe StrongDM can improve its initial setup and onboarding experience for larger enterprise environments like Scania, where we have a lot of processes. Integrating different teams, access policies, and existing identity workflows requires substantial planning. Additionally, I think the dashboard customization and reporting could be more flexible for operational teams, though new teams find it manageable. Once the platform is fully integrated, it provides significant value.
Apart from the onboarding experience, I would also mention that the templates for enterprise onboarding and policy setup could benefit from innovative thinking tailored to organizations managing large AWS and Kubernetes workloads. Enhanced customization in dashboards and reporting would further ease operations and provide better insights.
For how long have I used the solution?
I have been using StrongDM for about five years.
What do I think about the stability of the solution?
StrongDM is very stable; I cannot recall experiencing a glitch. It has consistently performed well for us.
What do I think about the scalability of the solution?
StrongDM's scalability is impressive; it is highly available, and we never perceived any latency issues. It operates almost autonomously without the need for our management.
How are customer service and support?
I would rate customer support at StrongDM nine out of ten because we experienced exceptional support during both pre-sales and post-sales. They responded quickly to issues and were readily available for calls rather than waiting for email confirmations. I rate customer support a solid nine out of ten.
Which solution did I use previously and why did I switch?
Before StrongDM, we explored different options but primarily relied on traditional VPN access and manual SSH key management, along with some AWS native workflows. Those methods worked initially but as our Kubernetes clusters expanded, they proved difficult to maintain consistently across teams, prompting us to seek alternative centralized access solutions.
How was the initial setup?
Concerning pricing, setup cost, and licensing, our experience was very smooth as we chose not to go through the AWS Marketplace but arranged meetings directly with StrongDM. Their team was prompt, and I can say that the pricing and licensing appeared reasonable for complex cloud management. We needed a good product and solid sales service post-purchase, which they provided efficiently and adequately. We compared their offerings with other tools in the market, agreeing on an annual license basis. The setup cost was free, with technical staff aiding our onboarding, requiring us only to cover the license fee.
What was our ROI?
I have definitely observed a return on investment through the operational efficiency gains and streamlined access management. The onboarding of temporary privileged access accelerated significantly, allowing us to release consultants much faster than before, saving considerable money. We also reduced reliance on manual VPN workflows, cutting high network costs linked to repetitive approval processes. While it is challenging to quantify with a single figure, the time savings and reduced operational overhead were certainly impactful.
What's my experience with pricing, setup cost, and licensing?
Concerning pricing, setup cost, and licensing, our experience was very smooth as we chose not to go through the AWS Marketplace but arranged meetings directly with StrongDM. Their team was prompt, and I can say that the pricing and licensing appeared reasonable for complex cloud management. We needed a good product and solid sales service post-purchase, which they provided efficiently and adequately. We compared their offerings with other tools in the market, agreeing on an annual license basis. The setup cost was free, with technical staff aiding our onboarding, requiring us only to cover the license fee.
Which other solutions did I evaluate?
I evaluated other options, including Teleport for centralized access management and AWS native tools like Session Manager and CloudShell using AWS Vaults. However, they were mainly services without the complete product offerings needed at an enterprise level. StrongDM distinguished itself by providing a simpler user experience, robust auditability, and alignment with our enterprise requirements.
What other advice do I have?
Continuous authorization is significantly more important for us; periodic checks alone might not suffice. In AWS and Kubernetes environments, access needs fluctuate rapidly due to various incidents or operational tasks. Periodic checks only offer visibility at specific points in time, while continuous authorization ensures we retain real-time control, diminish unnecessary standing access, and improve overall security posture.
StrongDM's credential-less access control was a primary reason for our choice, as managing credentials for various employees and moving consultants was increasingly challenging. The credential-less approach reduces the need to distribute or manage long-lived credentials, enhancing security and operational simplicity. Its integration with existing secrets managers in AWS was particularly beneficial, aligning securely with our centralized authentication and governance processes, matching our zero-trust practices.
My advice for others considering StrongDM is that it greatly depends on individual use cases; however, for enterprise organizations seeking end-to-end identity solutions, this is an excellent tool. Many options in the market may lack certain features that StrongDM provides as a comprehensive package. StrongDM excels in compliance management and identity management, so I recommend considering them. I would rate this review as an eight point five overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Access management has become intuitive and just-in-time onboarding now saves months of effort
What is our primary use case?
What is most valuable?
The impression of the credential-less access control is positive. It is painless, positive, and fast, but mainly it has reduced our time to onboard developers and to maintain any credentials to a minimum. Previously we had to issue a bunch of tickets and grant access, which was IT work and could take days. Now it is instantaneous.
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
How was the initial setup?
What about the implementation team?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
Efficient Privileged Account Management
Secure access to hybrid servers has improved oversight but now needs simpler setup and better guides
What is our primary use case?
My use case involves a company I'm working in that wants to secure the connectivity between the DevOps team and the backend server in the company.
What is most valuable?
The best features in StrongDM are that it is the easiest product in the market for this situation with easy access. The DevOps team only needs to log in through StrongDM with credentials, and then I can control everything after this, including what they are doing inside our servers, their movements, their actions, and everything I can see. One of the most powerful tools in StrongDM is audit logging. I can handle everything and see all that happened inside their movement on the backend server in our company.
What needs improvement?
In StrongDM, I think the installation was hard, and they want to be more flexible in the initial setup. I think they want to add more features like traditional PAM. It is difficult to find documentation or materials to review how it works, and there is less product material available in the market.
For how long have I used the solution?
I have been using the solution for seven months.
What do I think about the stability of the solution?
I rate the stability of the product five out of ten because crashes sometimes happen when we are working on it.
What do I think about the scalability of the solution?
I rate scalability five as well.
How are customer service and support?
I rate technical support seven out of ten because their response takes much more time than usual. However, at the end, they can help. I think they want to reduce their support staff.
How was the initial setup?
The deployment is neither easy nor complex; I think it is in the middle.
What about the implementation team?
I am not deploying it, as someone deployed it for me, but I think they put it in the default credential access.
Which other solutions did I evaluate?
I compare StrongDM with other vendors like CyberArk or Okta, and I think CyberArk is a heavy PAM. If all my product is on-premises and not cloud and premises, CyberArk will be good for that. However, with StrongDM, I think it is better to work on cloud and on-premises at the same time. I recommend CyberArk if your environment is all on-premises.
What other advice do I have?
I am not using the continuous runtime authorization feature, as I think it is not enabled.
I have my servers on-premises and on AWS.
For now, I think it is about 53 or 54 users who use the solution.
StrongDM requires maintenance. In terms of maintenance, it is easy. I think it is easy to maintain, but it is hard to know how to do it because the materials are less than anything in the market. Other vendors' materials are available in the market, but StrongDM materials are not as readily available.
I rate StrongDM overall six out of ten because I think it is the only product that can mix or be hybrid between on-premises and cloud on the market. I think it is a stable product on the market.