Try our new research platform with insights from 80,000+ expert users

Azure Key Vault vs BeyondTrust Password Safe comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 16, 2024
 

Categories and Ranking

Azure Key Vault
Ranking in Enterprise Password Managers
1st
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
45
Ranking in other categories
Certificate Management Software (1st), Microsoft Security Suite (14th)
BeyondTrust Password Safe
Ranking in Enterprise Password Managers
6th
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
22
Ranking in other categories
Privileged Access Management (PAM) (8th)
 

Mindshare comparison

As of December 2024, in the Enterprise Password Managers category, the mindshare of Azure Key Vault is 27.6%, down from 29.4% compared to the previous year. The mindshare of BeyondTrust Password Safe is 3.7%, up from 3.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Enterprise Password Managers
 

Featured Reviews

Mayur B N - PeerSpot reviewer
Offers good integration capabilities to its users
I use the tool to manage encryption keys and secrets in our application. In our company's production environment, we have some secrets and certificates that need to be accessed by the Kubernetes cluster, which is why we store those secrets in Azure Key Vault. In Kubernetes, we have a SecretProviderClass, which helps us access those keys from Azure Key Vault and then give them to our applications. Speaking about how Azure Key Vault plays a crucial role in our company's security strategy, in Kubernetes, you have to define environment variables for the application. In my company, we have around 60 to 70 environment variables, and most of them are sensitive. In Kubernetes, you define YAML files, and you can't directly use any values in YAML files and commit them to the GitHub commit because you will basically see the text values in YAML files. Instead, we store it in Azure Key Vault and then access those keys and values as variables for our company's applications. In terms of the benefits of cryptographic key management features, I would say that my company has used only the secret option in the tool, so we haven't checked out the keys and certificates. In my company, we just store key-value pairs for variables in Azure Key Vault. The product's integration capabilities are good. The tool has a pretty good firewall, which allows my company to access only private networks and certain IP addresses. Everything else is good with the product. My company doesn't use the policies in the product since we rely on roles and role assignments. One person is enough to take care of the maintenance of the solution. The product helps my company comply with the industry regulations since I believe that Azure Key Vault has its own set of SLAs and compliances, which we have gone through. I think Azure has some default compliance for each and every resource, which would be enough considering that I work in a very small organization where we didn't think of going into the details related to it. Azure is a very good platform, but it is a bit expensive. I think the price is justified because of the reduced complexity and the way it handles things, considering that Azure manages certain things better than its competitors. The tool is a bit expensive, but the management and configurations would be less expensive from the user's side. I rate the tool a nine out of ten.
Vinay Dabas - PeerSpot reviewer
Allows us to automatically rotate passwords, set the complexity, and enforce password policies on privileged accounts
The database instance onboarding should be simplified. The problem is that you can scan the assets and databases inside a server, but you cannot onboard them or manage them with the smart tools. It has to be done manually. I think they should try to include more custom platforms. With the databases, there were some issues. The databases are inside the servers, and it was a bit difficult to scan the databases. Apart from that, the rest of the assets were easy to scan and integrate. It's difficult to onboard the database. You can scan and find them, but you have to onboard the databases manually. You cannot onboard databases using Smart Rules databases. Database instances are difficult to onboard and must be done manually. The applications should be more like in the SDK. They have good API support now.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of the solution is the search for secrets feature that we use to store our passwords and connection strings."
"The centralized storage and secure storage are features we like."
"This solution speeds up the product development life cycle. That is, the time from the development of the product to the time to market is drastically reduced because of the CI/CD pipelines. You can have your code deployed within a matter of minutes."
"The most valuable features of Microsoft Azure Key Vault are the security and convenience of changing passwords in multiple places."
"The product’s advantageous feature is integration."
"The product's integration capabilities are good."
"A high level of security."
"I am satisfied with the product overall."
"It provides integrated password and session management in one solution, which is important for us because, from an auditing standpoint, we are accountable for the type of access being used. We need to ensure that accounts are securely stored and there is the right type of accountability around who is gaining the access. After gaining it, how they're using it, where they're using it, etc."
"It simplifies your compliance and tracking to benchmark other credentials and analytics."
"The ability to manage privileged account passwords is the most valuable feature."
"BeyondTrust Password Safe is a good PAM tool."
"Its number one feature is discovery. The discovery engine in BeyondTrust is off the charts. When they perform a discovery, you know everything there is about a server, including what software is installed. For example, if you want to group all of your database servers together, you can do that by using discovery and Smart Rules. If a server has Microsoft SQL installed, it gets put into a group based on a Smart Rule. It makes it very easy to determine what is what in your environment. As organizations grow or acquire other companies and merge, they lose track of what they have. BeyondTrust can help you throw a rope around it very rapidly."
"Session recording, password rotation, and password vaulting are the most valuable features."
"BeyondTrust Password Safe has good reporting and Smart Rules which makes it convenient. Though Smart Rules are convenient, those who do not have much experience with such things may find it difficult to understand how these things work. Otherwise, I find Smart Rules very convenient to work with."
"The actual innovations offered by the vendor stand out to me. They are quick to respond to market demands and the changing environment of privileged access management."
 

Cons

"The big problem with Azure Key Vault is key rotation. We haven't found a good way to synchronize the credentials between the databases and Key Vault."
"The voucher access policy can be improved by configuring it based on groups, rather than just applications or users."
"Currently, our company has to add the secrets manually, one by one, in Azure Key Vault, which is a tedious process."
"One of my previous clients was one of the big banks here in the Netherlands and the EU courts have stated that Microsoft Azure Key Vault is not, according to their perspective, secure due to the fact that Microsoft has access to Key Vault."
"If you check the capabilities of other key management services across Amazon, HashiCorp, and Google, there are features that Key Vault doesn't have. It could be the case that when you use Key Vault, you might be forced to use a third-party solution to get certain services. If those services could be included in Key Vault, there would be diminished reasons to go for a third-party key management system."
"The solution needs to improve its cost."
"We've experienced issues with configuration."
"The solution needs to improve reliability and protection."
"Its documentation can be improved. Its documentation is currently complicated, and it is not good. It needs to be better. Their technical support can also be improved. It is not bad, but it can be better."
"There are multiple features that have issues, although they could be specific to our environment. What we have seen is that whenever a user gets added to the authentication store, the sync between Password Safe and the authentication store, which is generally easy, takes a lot of time. It does not occur immediately."
"The only feature they could improve is the banners because they aren't informative. For example, if something is not correct and I open the error notification, the dialogue box simply says, "This is an error." It would be great if they could provide some valuable comments about how to fix the errors."
"We'd like to have incremental backups to ensure the solution's information is protected regularly."
"The initial server implementation tasks could be easier to process."
"If there was one thing, it would be having the documentation standardized. They should keep the documentation consistent. For example, when BeyondTrust updated one of their admin guides, they left out the information on the discovery account requirements, and then over a period of time, we ended up having to search multiple different documents to put together a string of information for a specific topic, which was problematic. It was minor, but it was problematic. Standardized documentation would be the one thing I would suggest."
"Documentation is the primary area of improvement."
"Named accounts don't work well in this solution. If you use named accounts for your administrative access, the way Smart Rules work is that it takes your SAM account name and matches it to the account name of your privileged ID, which creates limitations on size and how big those names can be because the directory has a 20-character limit."
 

Pricing and Cost Advice

"I find the pricing of Azure Key Vault to be reasonable."
"Azure is cheaper than CyberArk... CyberArk is good, but it's quite expensive."
"There are no extra costs beyond the standard fees, beyond maybe data transfer charges. It's $0.025 per 10,000 data transactions, so it is quite cheap."
"The cost of the Azure Key Vault is very high and the pricing model is based on the number of keys that you store and retrieve."
"The product is neither cheap nor expensive."
"We use a pay-as-you-go license for the solution, which is not very expensive."
"The product costs much less compared to other vendors."
"Azure Key Vault is an affordable solution."
"The pricing of BeyondTrust is very good as compared to other products. That was the main reason we decided to go with BeyondTrust at first."
"It has subscription-based licensing. BeyondTrust is three times less expensive than CyberArk."
"The pricing structure is better than the competitors. It's much cheaper than CyberArk. They do the licensing on the basis of assets, not on the number of users. For CyberArk, they base the licensing on the number of users, and they have an expensive model of pricing. BeyondTrust has a cheaper model."
"The product is quite affordable."
"At the time, BeyondTrust was significantly cheaper than CyberArk. Pricing-wise, if I remember correctly, it goes by assets. The pricing was negotiated for our instances based on the number of assets that we onboard into the system. It is a little different from CyberArk, where the pricing is by users. So, it depends. If you have a lot of assets, it can get very expensive."
"I would rate the pricing a seven out of ten, where one is cheap and ten is expensive."
"This solution is not cheap—it's a very expensive solution. Very, very expensive compared to the features and functions that they offer."
"When you buy Password Safe and perform your initial Discovery, you have all these servers that are added to your assets in BeyondTrust, but you're not using a license until you actually start managing the systems. BeyondTrust's licensing is based on the systems when they're managed, which means when an administrator is able to connect to the server through BeyondTrust with a managed account. There would be a privileged account on the endpoint when the licensing starts. A significant advantage to that is that there are many organizations that want to evaluate their environment prior to automatic management."
report
Use our free recommendation engine to learn which Enterprise Password Managers solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
13%
Manufacturing Company
9%
Government
7%
Computer Software Company
16%
Financial Services Firm
15%
Government
8%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is better - Azure Key Vault or AWS Secrets Manager?
Azure Key Vault is a SaaS solution. You can easily store passwords and secrets securely and encrypt them. Azure Key Vault is a great solution to ensure you are compliant with security and governanc...
What do you like most about Microsoft Azure Key Vault?
With Azure Key Vault, we can generate our own keys and then import them inside the system, which provides a higher level of security than provider-managed keys.
What is your experience regarding pricing and costs for Microsoft Azure Key Vault?
Azure Key Vault is a very, very expensive solution. Currently, the solution's pricing is based on the number of transactions, which is very high in some cases.
What is your experience regarding pricing and costs for BeyondTrust Password Safe?
The pricing model is more affordable with the option of going for either unlimited devices or users. It is cost-effective compared to other solutions.
What needs improvement with BeyondTrust Password Safe?
As of today, I haven't found any issues. Adding user behavior analysis to the server or messaging would be beneficial. This would help in identifying suspicious activities immediately when users lo...
What is your primary use case for BeyondTrust Password Safe?
Our customers are looking for a product that offers provisioning in their network, and for that reason, they choose BeyondTrust Password Safe.
 

Also Known As

Microsoft Azure Key Vault, MS Azure Key Vault
BeyondTrust PowerBroker Password Safe
 

Overview

 

Sample Customers

Adobe, DriveTime, Johnson Controls, HP, InterContinental Hotels Group, ASOS
Aera Energy LLC, Care New England, James Madison University
Find out what your peers are saying about Azure Key Vault vs. BeyondTrust Password Safe and other solutions. Updated: December 2024.
824,053 professionals have used our research since 2012.