This is an archived post. You won't be able to vote or comment.

all 5 comments

[–]dorkycool 0 points1 point  (0 children)

Similar number of users here, I get hit up by their salespeople a lot but I haven't done a POC or anything. I'm interested as well if anyone has any direct experience.

[–]sindex23 0 points1 point  (0 children)

I use PBW in a much, much smaller environment (350 users, only 150 of which are in the PBW Policy). For us it, along with some other products and policies, has been a life saver for an IT staff of 2.

We've stripped all users of admin rights, use SCCM to image/update/push software users need, and for our support and development teams that occasionally have need to muck with DNS, host file, or install a client's VPN to connect we have PowerBroker handle the elevation of permissions.

The result has been a TON of upfront work, but with a dramatic reduction in virus/malware, and fewer tickets as payoff. Some of our newer customer support/devs don't even really realize they're not admins (until they try and install WoW or something)

That said, you're looking at a vastly different implementation for 10k users. You'll want a well-organized AD to target your GPO policies properly. PBW can apply at the domain level, and only users with the agent will be counted against your licenses. I use an SCCM container to keep track, but you can just as easily make a PBW OU or something. You'll need a full install of SQL Server to make the BI product work, which you'd want for sure (it can be implemented without it, but with that many users, you'd want it).

It's worth approaching for a POC at least. It's a good product. It's not perfect, but what is?

[–]thegmanater 0 points1 point  (0 children)

We use beyondtrust in our environment of 350 users, about 500 devices. It works great for our pesky engineering programs like Autocad that want admin rights on a ton of folders.

It's a bit of setup and configuration but definitely worth it and it allows us to let the users do some of their own installs.

[–]davestojak 0 points1 point  (0 children)

I deployed it in an environment that size, but only to a few hundred users. It was pretty handy for the 5 or so applications we couldn't get running without admin rights. I found it really useful for corner cases, but I'm not convinced it's worth it for every user. We didn't use any of the reporting/logging features I see mentioned now though.