Try our new research platform with insights from 80,000+ expert users

BeyondTrust Password Safe vs WALLIX Bastion comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

BeyondTrust Password Safe
Ranking in Privileged Access Management (PAM)
7th
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
22
Ranking in other categories
Enterprise Password Managers (6th)
WALLIX Bastion
Ranking in Privileged Access Management (PAM)
8th
Average Rating
7.6
Reviews Sentiment
7.3
Number of Reviews
10
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2025, in the Privileged Access Management (PAM) category, the mindshare of BeyondTrust Password Safe is 3.3%, up from 2.9% compared to the previous year. The mindshare of WALLIX Bastion is 9.9%, up from 8.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Privileged Access Management (PAM)
 

Featured Reviews

Gary Jolley - PeerSpot reviewer
Their discovery engine is off the charts, and the ease of administration and implementation they talk about is for real
It starts with discovery. Its number one feature is discovery. The discovery engine in BeyondTrust is off the charts. When they perform a discovery, you know everything there is about a server, including what software is installed. For example, if you want to group all of your database servers together, you can do that by using discovery and Smart Rules. If a server has Microsoft SQL installed, it gets put into a group based on a Smart Rule. It makes it very easy to determine what is what in your environment. As organizations grow or acquire other companies and merge, they lose track of what they have. BeyondTrust can help you throw a rope around it very rapidly. Its user interface is really nice. It is very visual. When you first log in, based on your job role, you see what you have access to when you look at the screen. As an administrator, I see the configuration screen where I can go in and modify Active Directory and authentication connections. I can set up SAML, or I also have access to create Smart Rules. The access is based on the role that you have when you log in. I have six boxes or six categories of administration items, whereas when an admin user connects, he would only have one or two. So, based on your role, you see what you have access to. It is not like you click something and then it fails because you're not an administrator at that level. You actually see what you have access to, and BeyondTrust is very good at that. BeyondTrust provides the ability to connect by using not just the web interface but also the admin tools such as MobaXterm, PuTTY, or a lengthy list of other types of tools. You can use the connection string and connect through BeyondTrust, and it will be session recorded, keystroke logged, and highly available. When you bring up MobaXterm, you probably bring up one of the most complex ones because MobaXterm has the ability to have two, three, or four concurrent connections, which makes BeyondTrust Password Safe ideal. It is very easy to integrate session management into existing business processes. To make it easy for the engineers, we created templates of the connection strings and then used, believe it or not, Microsoft Excel to create custom strings for each of the engineers. We exported them to a text file that they could then import. In the case of PuTTY, because PuTTY stores the connections and the credentials in the registry, we had to do something different there, but the connection string is customizable enough to make the job fast and easily repeatable for all the other engineers. You don't have 20 or 30 engineers spending two or three days creating all these connection strings. I can create them in a matter of minutes with a Microsoft Excel spreadsheet and then save them to a text file or a CSV file. It is awesome. We are able to integrate session management without disrupting business processes. One of the niceties about BeyondTrust is the ability to integrate it with ticketing systems. For example, as per Sarbanes-Oxley, we have to have a reason for why an administrator is performing something. The integration with a ticketing system is ideal rather than manually typing the reason in the reason field through the GUI where most engineers, after a while, end up just typing in Work. They don't put in enough data to make it clearly visible why they connected. The integration with the ticketing system is ideal for that. Ticket-driven access makes the work very quantifiable.
Herve Choupot - PeerSpot reviewer
Enhancing administration security with critical feature improvements needed
My primary use case is to make a training about Active Directory security. In my experience, I work with Bastion. I emphasize the importance of having a good knowledge of Bastion to avoid vulnerabilities It helps by providing some security features for administration, although it's crucial to be…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is the architecture capabilities, which allow designated server components for high availability and failover. It works well with identity and access management solutions, allowing users to be automatically onboarded and offboarded. The account mapping feature makes rollout seamless. The session monitoring capabilities are excellent, with keystroke and graphical monitoring. This enhanced our security posture by providing detailed accounts of user actions. It helped us pass our SOX audits."
"The performance is good."
"The product has improved security and login due to the system recordings. In case, there is a doubt that someone has done something which they shouldn't have been doing, we can just go back and check what the user actually did."
"Overall, I rate the solution ten out of ten."
"The best aspect of the product is the ability to onboard devices. You can scan the IP subnets and onboard all the devices. You can then segregate them if it's a network device or a firewall. If it's a Windows server or a UNIX, you can basically scan your IT infrastructure and onboard the efforts, which should be managed. Once they have been onboarded, then the session management and password management are easy and nicely configurable."
"Its number one feature is discovery. The discovery engine in BeyondTrust is off the charts. When they perform a discovery, you know everything there is about a server, including what software is installed. For example, if you want to group all of your database servers together, you can do that by using discovery and Smart Rules. If a server has Microsoft SQL installed, it gets put into a group based on a Smart Rule. It makes it very easy to determine what is what in your environment. As organizations grow or acquire other companies and merge, they lose track of what they have. BeyondTrust can help you throw a rope around it very rapidly."
"BeyondTrust Password Safe is a good PAM tool."
"It is very easy to deploy. It's easy to use. That's the major thing I like about it."
"We use WALLIX Bastion to provide access and to monitor sessions."
"WALLIX Bastion's most valuable feature is the Access Manager because you can use it and access the data center without any client VPN."
"The solution's technical support team is helpful."
"Its video recording capabilities have definitely been key for us."
"The interface is very simple. It doesn't need any plug-ins, just browsers that are installed at the beginning."
"Bastion provides a kind of isolation between the administration laptop and the server you want to administer."
"I like that it's Linux-based, and you don't need to have separate implementations, extra database licenses, or enterprise licenses. I think because it's Linux-based, it's more seamless than Windows. I also like the access manager, which I think is a super tool. Everything is browser-based, and you don't need a VPN. So, that's a great thing."
"Bastion provides a kind of isolation between the administration laptop and the server you want to administer."
 

Cons

"There is a limited capacity on the appliance, which I wasn't informed about when I purchased the product. I can have a maximum of 150 rules per appliance; any more than that and rule processing becomes very complex, especially regarding password revision. Hitting a capacity limit you don't know about can be problematic. Ideally, we would not have a limited capacity, allowing us to be in a completely managed state with password rotation for every service account, not just the highly privileged ones."
"If there was one thing, it would be having the documentation standardized. They should keep the documentation consistent. For example, when BeyondTrust updated one of their admin guides, they left out the information on the discovery account requirements, and then over a period of time, we ended up having to search multiple different documents to put together a string of information for a specific topic, which was problematic. It was minor, but it was problematic. Standardized documentation would be the one thing I would suggest."
"Named accounts don't work well in this solution. If you use named accounts for your administrative access, the way Smart Rules work is that it takes your SAM account name and matches it to the account name of your privileged ID, which creates limitations on size and how big those names can be because the directory has a 20-character limit."
"The only feature they could improve is the banners because they aren't informative. For example, if something is not correct and I open the error notification, the dialogue box simply says, "This is an error." It would be great if they could provide some valuable comments about how to fix the errors."
"The initial server implementation tasks could be easier to process."
"Adding user behavior analysis to the server or messaging would be beneficial."
"It has crashed on us in the past."
"I think that BeyondTrust Password Safe could be improved with more testing. In the beginning, they were practically using customers as beta testers. Maybe the product has evolved since I last used it, but if you look at PAM, privileged access management, whatever's out there has already been done. I don't see there being any other enhancements that are being made regarding PAM, except to support more cloud-based applications."
"The performance of WALLIX Bastion's password manager is very low."
"There could be more automation features for the solution."
"It would be better if I could manage multiple accounts in one place, like CyberArk. With WALLIX, you can only manage one account, and you are given a separate category. You have to click on each connection to do anything. For example, CyberArk might give three options for one connection if you want to have an interactive user-level experience. But with WALLIX, you have to click three times to get that access. Also, the biggest disadvantage of WALLIX is the reporting. I feel like it's very weak in reporting when compared to the other solutions. As a solution, they're good and stable. But they need to make their reports neater and better. Right now, we're going to the console and then pressing buttons every single time."
"Based on my experience as a sales tech person, one area of improvement could be a more unified licensing model."
"There should be more effort to increase the level of security."
"The product doesn't have behavior analytics. They promised to develop this, but only for the cloud, not for on-premise versions."
"The password management needs improvement. Management of Access Manager should be improved as well."
"The main problem of Bastion, CyberArk, and WALLIX is that they have the same interface for both administration and users, which is not a good idea from a security perspective."
 

Pricing and Cost Advice

"I would rate the pricing a seven out of ten, where one is cheap and ten is expensive."
"We just pay for Password Safe. Session management is included, but we don't use it. There aren't any additional costs besides the standard licensing fees. We pay for an annual license."
"At the time, BeyondTrust was significantly cheaper than CyberArk. Pricing-wise, if I remember correctly, it goes by assets. The pricing was negotiated for our instances based on the number of assets that we onboard into the system. It is a little different from CyberArk, where the pricing is by users. So, it depends. If you have a lot of assets, it can get very expensive."
"It has subscription-based licensing. BeyondTrust is three times less expensive than CyberArk."
"When you buy Password Safe and perform your initial Discovery, you have all these servers that are added to your assets in BeyondTrust, but you're not using a license until you actually start managing the systems. BeyondTrust's licensing is based on the systems when they're managed, which means when an administrator is able to connect to the server through BeyondTrust with a managed account. There would be a privileged account on the endpoint when the licensing starts. A significant advantage to that is that there are many organizations that want to evaluate their environment prior to automatic management."
"The product is quite affordable."
"This solution is not cheap—it's a very expensive solution. Very, very expensive compared to the features and functions that they offer."
"The pricing of BeyondTrust is very good as compared to other products. That was the main reason we decided to go with BeyondTrust at first."
"The solution's price is mid-ranged."
"The solution's pricing is comparable to that of other products."
"Some extra price needs to be paid for license."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
15%
Government
9%
Manufacturing Company
8%
Computer Software Company
20%
Financial Services Firm
9%
Government
9%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for BeyondTrust Password Safe?
The pricing model is more affordable with the option of going for either unlimited devices or users. It is cost-effective compared to other solutions.
What needs improvement with BeyondTrust Password Safe?
As of today, I haven't found any issues. Adding user behavior analysis to the server or messaging would be beneficial. This would help in identifying suspicious activities immediately when users lo...
What is your primary use case for BeyondTrust Password Safe?
Our customers are looking for a product that offers provisioning in their network, and for that reason, they choose BeyondTrust Password Safe.
What do you like most about WALLIX Bastion?
The support is great. They offer 24/7 support, but the specific level of support depends on your subscription. There's a weekday-only option, and a 24/7 option that covers all days of the week. The...
What is your experience regarding pricing and costs for WALLIX Bastion?
I do not know the pricing, setup cost, or licensing. It's difficult to compare without an identical infrastructure.
What needs improvement with WALLIX Bastion?
The main problem of Bastion, CyberArk, and WALLIX is that they have the same interface for both administration and users, which is not a good idea from a security perspective. Also, there should be...
 

Also Known As

BeyondTrust PowerBroker Password Safe
Bastion
 

Overview

 

Sample Customers

Aera Energy LLC, Care New England, James Madison University
RTBF, Pharmagest, Michelin Group, Niort Hospital
Find out what your peers are saying about BeyondTrust Password Safe vs. WALLIX Bastion and other solutions. Updated: January 2025.
831,158 professionals have used our research since 2012.