BeyondTrust Privileged Remote Access and Check Point Remote Access VPN compete in the remote access security category. BeyondTrust seems to have the upper hand in direct remote access without a VPN while Check Point offers deep firewall system integration for remote network access.
Features: BeyondTrust Privileged Remote Access offers cross-platform compatibility, encryption enforcement, and rapid VM deployment. It doesn't require a VPN and has flexible deployment formats with a robust API for automation. SSO authentication enhances its adaptability. Check Point Remote Access VPN excels in integration with Check Point firewalls, providing seamless access through MFA and comprehensive user event logs across various operating systems.
Room for Improvement: BeyondTrust could benefit from an enterprise vault, improved automation APIs, and a streamlined management interface. Multi-factor authentication limitations and integration complexities with customized environments are also concerns. Check Point needs to improve compatibility with Linux systems and simplify integration processes. Enhancing the user interface and addressing VPN client updates would be beneficial, as would increased flexibility in licensing.
Ease of Deployment and Customer Service: BeyondTrust supports on-premises and cloud solutions but requires knowledgeable staff for implementation. Its customer service is responsive and expert, though direct support communication could improve. Check Point offers similar deployment versatility, especially for integrating with Check Point products, but could use more user-friendly configurations. Both companies receive positive customer service feedback, with BeyondTrust noted for a more immediate support approach.
Pricing and ROI: BeyondTrust is seen as expensive upfront but offers robust features and quick ROI through operational efficiencies. Despite complicated cost structures, it provides substantial time and effort savings. Check Point presents a competitive pricing structure; leveraging existing infrastructure keeps additional costs low. Users report satisfaction with its value, noting affordability in securing remote work environments. Both solutions deliver solid ROI, but BeyondTrust stands out for achieving compliance and cost-effective remote support quickly.
Everything we've gained from it makes my job easier day after day, and I see value in it as an engineer.
Importantly, when someone leaves the company, it helps protect document access on their devices.
Applications are deployed through Intune, and we see fewer tickets for common issues because we can resolve them through the solution.
When a support ticket is submitted, it directly reaches someone with Intune support expertise.
When I contacted Microsoft, they had the same expertise, if not more, which is phenomenal because I felt heard and my problem was solved.
Sometimes, the support provided is excellent, and the representative is knowledgeable, while other times, the service needs improvement.
Support now requires opening a ServiceNow ticket, which can be time-consuming.
The scalability of Microsoft Intune is ten out of ten.
Ideally, we want to automatically segregate devices based on user properties like primary use, but currently, dynamic groups seem limited to device properties.
It supports organizations with 200 endpoints and those with more than 15,000 endpoints.
I would give it an eight or nine out of ten for scalability, possibly even a ten, as I do not see a limitation in scaling.
Microsoft Intune has been very stable.
A couple of years ago, the performance was not as good as it is now, but there are noticeable backend improvements.
We've encountered problems with other services like Exchange, Intune has remained unaffected.
Updates sometimes introduce bugs or issues, especially with non-English versions.
There are communication issues, so you might start working with a feature without knowing if it will be deprecated six months from now.
Many third-party companies offer single-pane-of-glass reporting that shows you what your update environment looks like, how your patch is doing, application status, etc., but Intune's reporting is not intuitive.
Workspace ONE operates in real-time, whereas Intune has a noticeable delay when deploying policies or apps.
BeyondTrust should focus on automating the update process to reduce unnecessary ticket creation.
Introductory professional services, like a fast-track service, were included with our E5 membership, and there have been no additional costs.
The Intune suite and add-ons, such as batch management and remote help, are costly.
Microsoft Intune's costliness stems from licensing fees and the overhead associated with its management, user experience, and device remediation.
My experience with pricing, setup cost, and licensing is that it is expensive, yet not the most expensive in the market, so the price can be considered justifiable.
Intune excels in configuration and compliance management for Windows 10, ensuring devices receive timely updates and adhere to organizational standards.
Dynamic groups allow us to set conditions for automatic membership, eliminating the need for user intervention or manual review and ensuring a seamless workflow.
Windows Autopatch is the most valuable because it removes the burden of patch management.
The secure access must be audited live, ensuring patient data protection.
Microsoft Intune is a comprehensive cloud-based service that allows you to remotely manage mobile devices and mobile applications without worrying about the security of your organization’s data. Device and app management can be used on company-owned devices as well as personal devices.
In an increasingly mobile workforce, Microsoft Intune keeps your sensitive data safe while on the move. Microsoft Intune makes it possible for your team members to work anywhere using their mobile devices. Microsoft Intune provides both the flexibility and the control needed for securing all your data on the cloud, no matter where the device with the data is located.
Microsoft Intune Device Management Key Features
With Microsoft Intune Device Management you can:
Mobile Application Management
Mobile application management in Intune is designed to protect your organization’s data at the application level.
With Microsoft Intune Application Management you can:
As part of Microsoft's Enterprise Mobility + Security (EMS) suite, Intune integrates with Microsoft Entra ID for access control and with Azure Information Protection for data protection. It also integrates with Microsoft 365 Applications.
Reviews from Real Users
Microsoft Intune stands out among its competitors for a number of reasons. Two major ones are its ability to secure all devices under its management and the flexibility that the solution offers its users.
A computing services manager notes, "Its security is most valuable. It gives us a way to secure devices, not only those that are steady. We do have a few tablets and other devices, and it is a way for us to secure these devices and manage them. We know they're out there and what's their status. We can manage their life cycle and verify that they're updated properly."
The head of IT engineering at a financial services company writes, "The one feature we find most useful is the Mobile Application Manager. There are two types: we have the complete MDM and the Mobile Application Manager (MAM). We don't give our users phones, it is their own personal phone, and we need to allow them to have access to the company details on their phone. We need to create a balance between their own personal data and the company data. We deploy the Mobile Application Manager for them so that we won't be able to interfere with their own personal data."
BeyondTrust Privileged Remote Access (formerly Bomgar Privileged Access) lets you secure, manage, and audit vendor and internal remote privileged access without a VPN.
Privileged Remote Access provides visibility and control over third-party vendor access, as well as internal remote access, enabling your organization to extend access to important assets, but without compromising security.
Features include:
- Privileged Access Control: Enforce least privilege by giving users the right level of access.
- Monitor Sessions: Control and monitor sessions using standard protocols for RDP, VNC, HTTP/S, and SSH connections.
- Reduce the Attack Surface: Reduce attacks by consolidating the tracking, approval, and auditing of privileged accounts in one place and by creating a single access pathway.
- Integrate with Password Management: Inject credentials directly into servers and systems with just one click, so users never need to know or see plain text credentials.
- Mobile & Web Consoles: Use mobile apps or web-based consoles anytime, anywhere.
- Audit & Compliance: Create audit trails, session forensics, and other reporting features by capturing detailed session data in real-time or post- session review, and provide attestation reports to prove compliance.
Remote secure access VPN is a solution that provides users with remote access to an organization’s network. The host may have VPN client software loaded or use a web-based client. The solution leverages security features like multi-factor authentication, endpoint scanning, and encryption of all data in motion.
Check Point Remote Access VPN provides individuals with protected and efficient access to a company network from anywhere. This strategy fosters collaboration and connectivity between distributed teams and offices.
Features of Check Point Remote Access VPN
Key features of the secure remote access VPN include:
The system enforces endpoint security with endpoint compliance. It monitors and verifies the security status of each endpoint and reports back to the Security Gateway. The gateway, in turn, checks the compliance level and directs the connectivity to the right resources.
Users can deploy the Remote Access VPN in one of three ways:
Remote Access VPN is centrally managed. The centralized console enables management and enforcement of policies with a single log-in.
The Remote Access VPN has a web portal that users can use to connect securely to corporate applications, such as web-based resources, file-sharing, and email. Administrators can customize the web portal to match the brand identity.
Remote Access VPN offers two choices for remote access:
The authentication features include password management, RADIUS challenge/response, CAPI software, and hardware tokens. P12 certificates, and SecurID.
The system establishes a VPN tunnel on demand. It also re-arranges connections when roaming. The tunnel can automatically tear down when the user is on the corporate LAN.
There are several connection features, such as Hotspot detection, office mode IP, split tunneling, and automatic fallback to HTTPS.
Benefits of Check Point Remote Access VPN
One of the key advantages of Remote Access VPN is that it provides remote workers with a secure way to connect to a corporate network from any device, including their personal devices. The data encryption in transit enables them to securely access the resources they need for their tasks.
It also provides IT support and technicians with a faster way to troubleshoot software issues. In the case of a ticket, IT doesn’t need to go to the server location to fix the problem but can troubleshoot it remotely.
A remote secure access VPN is also an affordable alternative for small and medium-sized businesses, without requiring expensive infrastructure.
Reviews from Real Users
A Global IT Network and Security Service Senior Specialist at a manufacturing company who uses Check Point Remote Access VPN says, "I found the MEP feature the most valuable. This has improved users' latency allowing the users to connect to the nearest Azure Check Point VM."
"Organizations that already use the Check Point NGFW Solution do not require any additional hardware, which makes the implementation straightforward and reduces the time to go live," explains Basil D., Senior Manager at a financial services firm.
Manuel B., a Voice and data infrastructure specialist at a tech services company, says that "The IPSec VPN, Mobile Access, and Identity Awareness are three of the blades with which we have been working with since the pandemic. This has given us great mobility, making our network more dynamic."
We monitor all Remote Access reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.