← All customer stories

How a global industrial manufacturer replaced Delinea in 3 weeks and eliminated standing privilege

The manufacturer's IAM team ran Delinea across 2,000 privileged accounts and 800 servers, writing a custom script for every Google Cloud integration and rebuilding it after each product update. They moved the whole estate to Venice in three weeks, and no administrator holds a standing credential today.

3 weeks
to migrate 2,000 privileged accounts and 800+ servers
Zero
standing privilege. No administrator holds a persistent credential
48,000+
servers and 425,000+ identities discovered automatically
25,000+
Just-in-Time requests a month across 1,300+ users

One of the world's largest industrial manufacturers ran Delinea for privileged access across more than 2,000 privileged accounts, 800 servers, and administrators on every continent. The manufacturer's estate ran on Google Cloud, and Delinea could not manage GCP workspaces or IAM service accounts on its own, so every cloud integration was a custom script, and every script broke when Delinea released an update. Venice manages GCP workspaces and IAM service accounts out of the box, so the manufacturer replaced Delinea in three weeks and moved every administrator to Just-in-Time access.

The problem: An incomplete PAM solution held together by custom code

Delinea had no out-of-the-box support for managing GCP workspaces or IAM service accounts. Every cloud workflow ran on a custom API script.

“Every integration was custom API work, and every custom module was a single point of failure,” the company's VP of Identity and Access Management said. “Our cloud accounts needed scripts the platform couldn't provide out of the box, and each script was one product update away from breaking.”

When an update broke a script, the IAM team was the one who found out. On top of the scripts sat an agent on every managed endpoint that the team had to patch, monitor, and troubleshoot.

“We weren't operating a PAM program anymore. We were maintaining one,” the VP said. “It felt like we were duct-taping it together.”

We weren't operating a PAM program anymore. We were maintaining one. It felt like we were duct-taping it together.
VP of Identity and Access Management

The scripts, the agents, and the update breakages all traced back to the same cause: Delinea had no support for the platform the company runs on. The team decided to replace it rather than keep patching around it.

Migration: three weeks, nothing to install

Migrating off Delinea and onto Venice took three weeks. All 2,000 privileged accounts and over 800 servers moved to Just-in-Time access brokered through Venice.

There were two factors that made the timeline possible. Venice is agentless, so there was nothing to deploy on servers or endpoints. And discovery is automated: during rollout, Venice mapped more than 48,000 servers and 425,000 identities across the environment, giving the team a complete inventory of its privileged access surface for the first time.

“We moved 2,000 privileged accounts and 800 servers off our legacy PAM in three weeks,” the company's CISO said. “I've been through a lot of enterprise security migrations. None of them moved as fast as Venice did.”

I've been through a lot of enterprise security migrations. None of them moved as fast as Venice did.
CISO

The results: Zero standing privilege without slowing anyone down

GCP workspaces, IAM service accounts, and all 800 servers are now governed by Venice. Standing privilege is gone: no administrator holds a password to anything. Access is requested, granted for a fixed window, logged, and revoked when the window closes. For auditors, the answer to “who has standing access to this server” is now: no one.

“Honestly, I expected pushback from admins, but it never came,” the VP said. “We run a thousand Just-in-Time requests a day across four continents, and nobody is telling me we slowed the business down.”

More than 1,300 users across every region the company operates in now go through Just-in-Time requests, and no team has reported that access got slower. The company also spends significantly less than it paid for Delinea, with no custom integration work to maintain.

“Admins stopped noticing the control is there,” the VP said. “That's what good security looks like.”

Ready to move on from legacy PAM? See what a three-week replacement looks like.

Get a demo

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
More information

Allow all

Manage Consent Preferences

Strictly Necessary Cookies

These cookies are essential for the website to function properly and cannot be disabled.

Functional Cookies

These cookies enable enhanced functionality and personalization, such as videos and live chat.

Targeting Cookies

These cookies help us understand how visitors interact with our website by collecting anonymous information.

Marketing Cookies

These cookies are used to track the effectiveness of our marketing campaigns.

We value your privacy

We use cookies to enhance your browsing experience, serve personalised ads or content, and analyse our traffic. By clicking "Accept All", you consent to our use of cookies.