Your domain admin password is in a spreadsheet three people can open. An auditor will ask who used it last month — Delinea Secret Server finds your privileged accounts, vaults and rotates their passwords, and records the sessions that use them — on your own servers in three editions, or as Secret Server Cloud on the Delinea Platform.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Delinea Secret Server — the on-premises vault and Secret Server Cloud. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A vault holds admin passwords and keys, rotates them, and lets people use them without ever seeing them.
What consolidation actually replaces, dimension by dimension.
| Dimension | Admin passwords in a spreadsheet | Delinea Secret Server |
|---|---|---|
| Where admin passwords live | A shared spreadsheet and people’s heads | Secrets in one vault, each with its own permissions |
| Knowing what exists | A list someone made two audits ago | Discovery scans and inventories privileged accounts |
| Changing passwords | When someone leaves, if anyone remembers | Template-driven rotation on the target systems |
| Seeing what admins did | Server logs pieced together after an incident | Recorded sessions and keystrokes, Platinum edition |
| Where it runs | Wherever the spreadsheet was saved | Your own servers, or Secret Server Cloud |
| What it is NOT | — | A pipeline secrets store, an India-hosted cloud, or list-priced |
The cheapest test is the 30-day trial: discover one domain, vault ten admin accounts, rotate them, and record one session.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The vault holds each privileged password, key or login as a secret with its own permissions; you host it yourself, or Delinea runs it as Secret Server Cloud on its Platform.
Discovery scans for privileged accounts and lists them so they can be brought under management; AWS and Google Cloud discovery start at the Professional edition on-premises.
Out-of-the-box templates change passwords on the target systems, so a credential lifted from a script or a laptop stops working after the next rotation.
Professional adds RDP and SSH proxying; Platinum records sessions and keystrokes for every secret. Connection Manager and Privileged Remote Access inject vault credentials.
One vault on your servers or Delinea’s cloud — discovery feeds it, templates rotate it, and the edition decides what gets recorded.
Delinea Secret Server turns scattered admin passwords into vaulted, rotated, audited secrets.
Secret Server identifies and inventories privileged accounts automatically, so the vault starts from a list rather than from memory.
From the Professional edition, discovery reaches accounts in AWS and Google Cloud as well as the systems in your own data centre.
Delinea sells Secret Server on securing privileged accounts in weeks, not months; hold the partner to a dated plan in the quote.
Ready-made templates rotate credentials on the target systems, so passwords stop living unchanged in spreadsheets and scripts.
In the Platform bundles, MFA on individual credentials comes with Standard, and credential and approval workflows with Enterprise.
Connection Manager and Privileged Remote Access pull credentials straight from the vault, so admins connect without seeing the password.
Platinum records privileged sessions and logs keystrokes for every secret; Professional covers only 50 secrets and Vault none.
Professional and Platinum proxy RDP and SSH connections, so each privileged session passes a point you control and can watch.
Monitoring and audit of privileged accounts give the trail a reviewer asks for; extensions come from the Integration Marketplace.
Delinea’s own demos: Secret Server’s vaulting in a 2026 zero-standing-privilege short, a 2023 vaulting demo, and the 2023 product tour.
How Secret Server’s vaulting fits Delinea’s push to remove always-on privileged access.
A walk through storing, organising and sharing secrets inside the vault.
The broader product tour: discovery, rotation and session features in one pass.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most PAM projects stall because nobody knows how many privileged accounts exist. Secret Server scans for them and builds the inventory first, then rotates passwords with ready templates. Delinea pitches go-live in weeks rather than months; that is its claim, so ask for a dated plan and test discovery on one domain during the 30-day trial.
The same product comes two ways: Secret Server on infrastructure you run, in the Vault, Professional or Platinum edition, or Secret Server Cloud inside the Essentials, Standard or Enterprise bundle. For an Indian bank that wants the vault and its recordings on Indian soil, the on-premises route is the one that keeps them here.
Delinea was a Leader in Gartner’s 2025 Magic Quadrant for PAM, which it counts as the seventh in a row by including its Thycotic and Centrify years, and the Overall Leader in KuppingerCole’s 2026 PAM Leadership Compass. On top of that, Delinea is a Leader in Forrester’s Wave on privileged identity management, Q3 2025 edition.
There is no public price for any edition. Full recording on-premises is Platinum-only. Pipeline secrets are the separate DevOps Secrets Vault. Delinea has no India office or cloud region. And in September 2026 it published four critical on-premises advisories, so anything older than 12.2.7 needs patching before it goes near production.
Run discovery on one domain during the 30-day trial and compare the inventory with the list your team believes is complete.
Choose on-premises in India or a cloud bundle, then decide whether auditors need Platinum’s full recording or Professional is enough.
Move domain and server admin accounts into the vault, turn on template rotation, and check every dependent service still logs in.
Proxy RDP and SSH through Secret Server, connect Connection Manager if you use it, and replay one recorded session for the auditor.
Confirm the build is 12.2.7 or later, set a patch cadence for future advisories, then onboard the remaining accounts in waves.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Discovery turned up three times the service and admin accounts we had on our list. That inventory alone justified the pilot.”
“We bought Professional and then learned recording stops at 50 secrets. Price Platinum on day one if auditors want video.”
“Rotation templates covered our Windows and Linux admin accounts out of the box; two odd appliances needed custom work.”
“We kept Secret Server on our own servers here because the cloud offered no Indian region, and our regulator asked.”
“Admins launch RDP from Connection Manager with the vault filling in the password. Nobody asks for the domain admin login now.”
“The September advisories meant an unplanned upgrade weekend. Budget for patching an on-premises vault every quarter.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the privileged access management market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Gartner PAM Leader 2025; KuppingerCole Overall Leader 2026.
The grid nobody publishes — how openly a vault states its price vs how far its rotation, discovery and session recording reach.
Quote-only; full recording needs the Platinum edition.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against CyberArk (Idira) Privileged Access Manager, BeyondTrust Password Safe, ARCON PAM, Securden Unified PAM and Devolutions PAM — on deployment, coverage, price, recording, secrets, support and India.
| Dimension | Delinea Secret Server | CyberArk (Idira) Privileged Access Manager | BeyondTrust Password Safe | ARCON PAM | Securden Unified PAM | Devolutions PAM |
|---|---|---|---|---|---|---|
| What it is | Delinea’s flagship vault | The best-known vault | Vault plus brokering | Mumbai-built suite | Securden’s flagship | Module inside RDM |
| Deployment | Own servers or SaaS | Self-Hosted or Cloud | Three routes | On-prem, cloud or SaaS | On-prem or PAMaaS | Server or Cloud |
| Targets and discovery | Discovery + templates | Six target types | Discovery to DevOps | Five target types | SaaS admins as well | Three are reset-only |
| Pricing model | Quote; unit unstated | Per user or account | Per managed asset | Users and targets | Per user, nothing else | Per named user |
| Published entry price | None published | ~$1,800–12,000 reported | ~$157/asset/yr (GSA) | INR quote only | Free up to 5 users | $50/user/month |
| Included vs add-on | Editions gate features | Extras sold apart | PRA and EPM extra | Broad suite inside | EPM included | RDM, vault, Gateway |
| Scale and standing | Leader: Gartner, KC | Gartner Leader, F500 | Gartner Leader, 20,000+ | Challenger, 2025 | No analyst rating | No MQ; KC Rated |
| Session recording | Full only in Platinum | Isolated and recorded | Keystrokes, live view | Recorded and monitored | All sessions, no cap | Video, no keystrokes |
| Integrations and secrets | Marketplace; DSV apart | Secrets Manager apart | A2A, ServiceNow, SIEM | Partial for pipelines | Served, not CI/CD | Reads rival vaults |
| Approvals and JIT | Bundle-dependent | Just-in-time | Time-boxed checkout | JIT, MFA and SSO | Granted, then revoked | Approval, ticket, MFA |
| India storage region | No India; self-host | Self-Hosted keeps it | PRA sibling only | Built in Mumbai | India-built vendor | Self-host only |
| Support | No India office | India office | India office | Mumbai engineers | India-built team | 48 h standard |
| Lock-in and exit | Bundle ties | Platform core | Pathfinder pull | ARCON family | Smaller at scale | Yearly, reads rivals |
| Best fit | Rated vault, your choice | Large regulated estates | Few admins, many servers | Indian BFSI | Mid-market, one price | RDM teams, open price |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Delinea Secret Server is one of 29 privileged access management products TechBag carries. The Privileged Access Management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (privileged accounts managed by hand; admin-hour cost). Estimates model staff time spent changing shared admin passwords, chasing who used them and assembling audit evidence at an assumed 1.5 hours per privileged account a year, with 70% of it removed by discovery, template rotation and recorded sessions. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Delinea prices every Secret Server edition (Vault, Professional, Platinum) and every Platform bundle (Essentials, Standard, Enterprise) on quote, and does not state the licensing unit. Per-user figures quoted by third-party sites are not list prices. The edition matters more than usual, because full session recording is Platinum-only on-premises. TechBag sizes your accounts in the 30-day trial first, then quotes in INR with GST.
Best for keeping the vault in India
Best for a broader rollout
Best for teams that want Delinea to run it
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many privileged, service and admin accounts exist today? Run discovery in the trial before you size a quote.
Do auditors need recordings of every privileged session? If so, budget for Platinum, not Professional’s 50 secrets.
Must the vault stay in India? Only on-premises Secret Server does; the cloud’s nearest regions are Singapore and the UAE.
Is any existing on-premises install below 12.2.7? Four critical September 2026 advisories make that an upgrade first.
Do you need AWS or Google Cloud account discovery? It starts at the Professional edition on-premises.
Are secrets hard-coded in CI/CD jobs? Secret Server is not the answer there; price DevOps Secrets Vault separately.
Will admins launch RDP and SSH from the vault? Decide between proxying, Connection Manager and Privileged Remote Access.
What unit does the quote count — users, secrets or both? Ask for INR with GST and the support term itemised.
Count your privileged accounts with discovery in the free trial first, or let a TechBag advisor scope a pilot that vaults and rotates one domain’s admin accounts.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.