What is our primary use case?
When we onboard a privileged user onto the PAM solution, we check their access using the PAM, including password management and monitoring with video logging and command restriction.
We can also restrict certain commands, such as the delete command or protect the activity.
What is most valuable?
The most valuable feature is the risk management. When a Privileged user performs a certain command, such as running a script, the system highlights it in the risk management section as high, critical, or medium risk.
We can trigger an alert to our administrator only if a certain command is run. This allows us to verify if the activity is legitimate or not.
Another valuable feature is video recording. Sectona records all privileged user activity in a compressed format, which can be reviewed and exported to PDF. This allows the organization to track all privileged user activity and identify any suspicious behavior.
Finally, Sectona allows organizations to restrict specific commands. For example, if an organization does not want users to be able to use the delete command, Sectona can be configured to prevent users from using it.
What needs improvement?
There are some areas where the GUI could be improved to make it easier to find and update privileged settings and policies.
For example, when creating a PAM policy for Privileged, some of the scroll boxes are difficult to navigate. It would be easier if there were one-click options for checking and unchecking boxes rather than having to scroll down and select individual items.
This would make the GUI more user-friendly for administrators and SOC teams. So, I would like to see the GUI made more user-friendly, especially for administrators and SOC teams.
In future releases, I would like to be able to manage Sectona PAM by location. For example, I'm the global headquarters lead in India, and we have 200 locations around the world. I would like to be able to create sub-locations, so that when I click on support for a location, the configuration is separate. However, the monitoring should still be at the parent level.
For how long have I used the solution?
I have been using this solution for the last six months.
What do I think about the stability of the solution?
It is a very stable product in the on-premises environment. However, since they are introducing it to the cloud environment, Sectona PAM needs to think about the cross-perspective more in the upper area.
There is a need for some cloud-native tools where we can use privileged users and put the Plantech password. We need a very easy way to manage that password and use the PAM use cases on that part.
What do I think about the scalability of the solution?
It is a scalable product. It is a scalable product for our organization. However, it depends on the organization's requirements and how the product is used.
Currently, we have 2,000 privileged users and two administrators. We are still in the implementation phase and onboarding the privileged users.
Once we have educated the users, we can onboard the servers, web applications, network devices, and other devices.
How are customer service and support?
Sectona provides excellent support. We can raise a ticket on the support portal, and a support person will be assigned to us immediately. We also have dedicated team support.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
There was a specific reason for opting for this solution. Like, any user, including privileged users, could access assets using the local administrator account and get admin access to their domain IDs. This made it difficult to monitor these users and identify any suspicious activity on the servers. We put more time into analysis.
After we implemented Sectona, it became much easier to understand user activity from a performance and audit perspective. It is also very easy to manage, even for users who are not familiar with technical details.
For example, if a local system is connected to the domain after the temporary persona is created, Sectona can apply the password policy to that system.
How was the initial setup?
The initial setup is very easy. Compared to other products, it is the same for implementation, but it is very easy to install quickly.
For the on-premises setup of all the servers, it took 20 to 25 minutes to complete the implementation. Overall, the entire activity would take two and a half hours.
We have deployed it on-premise. The SaaS solution has just been introduced, and it's not very capable yet.
What other advice do I have?
As a security professional, I would definitely recommend using Sectona PAM. It is a very useful product, both from a user perspective and a technical perspective.
For users, Sectona PAM is very easy to use. They simply need to log on to the One Control console and click on the connect button to single sign-on to a server.
This eliminates the need to open third-party tools, enter IP addresses and usernames/passwords, and remember password expiration dates.
I would give it a seven out of ten. It is a very good product for on-premises solutions. However, Sectona needs to think about SaaS solutions and cloud use cases. For example, we need to be able to integrate Sectona PAM with next-generation applications such as Docker and Lambda, as well as ITD pipelines that use privileged user data. Once they address these use cases, it will be a ten out of ten product.
Which deployment model are you using for this solution?
Hybrid Cloud