TL;DR: Traditional PAM tools can manage privileged access, but cloud, Kubernetes, and distributed admin workflows expose limits in deployment, integration, and auditability, according to StrongDM’s comparison of BeyondTrust and Delinea. The practical question is no longer which tool has more features, but which access model can govern modern infrastructure without reintroducing credential sprawl.
Editorial analysis by NHI Mgmt Group, based on content published by StrongDM: “BeyondTrust vs. Delinea (Thycotic): Which Solution Is Better?”.
Key questions
Q: What breaks when traditional PAM is used for cloud workloads?
A: Traditional PAM often breaks down in cloud workloads because it was built around discovery, onboarding, and event capture on stable systems, not ephemeral resources.
Q: Why do cloud and Kubernetes environments change privileged access risk?
A: They increase risk because privileges are exercised across many systems, often by multiple teams and tools, which expands the number of places where credentials, logs and approvals must stay aligned.
Q: How do security teams know if PAM is actually working?
A: Look for evidence that elevated rights are short-lived, session activity is logged, and access reviews result in real removals rather than paperwork.
Practitioner guidance
- Map privileged access by environment type Separate server, cloud, database and Kubernetes access paths so you can see where legacy PAM assumptions still fit and where they break down.
- Test for standing secret dependencies Identify whether users still need exposed SSH keys, local passwords or shared vault workflows to complete admin tasks, then measure how much of the environment depends on them.
- Validate audit continuity across tools Check whether session logs, authentication records and approval data remain correlated when access moves through SSO, third-party tools and cross-platform admin flows.
Bottom line: Legacy PAM still matters, but cloud and Kubernetes expose where server-era access assumptions stop being reliable.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Cloud and Kubernetes access is exposing a PAM model that was designed for steadier infrastructure. The article’s real signal is not vendor feature comparison, but that privileged access governance is colliding with distributed admin patterns, local-install dependencies and environment-specific exceptions. In NHI terms, the access model has to follow the workload and the operator path, not force both back into a server-era pattern. The practitioner conclusion is to judge PAM by how well it governs modern operational topology, not by how closely it resembles legacy privileged login workflows.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What should teams do when their PAM stack cannot support Kubernetes or cloud workflows?
A: They should redesign the access path around the environment, not around the old administrative model. That means choosing controls that can broker access across databases, servers and clusters without forcing local installation, credential sharing or disconnected logs. The goal is to remove exception handling from the operating model, not just document it.
👉 Read our full editorial: PAM controls for cloud and Kubernetes access: BeyondTrust vs Delinea