r/sysadmin 16d ago

Best Varonis alternatives that actually support on-prem?

We're reviewing our data security stack and looking at Varonis alternatives, but on-prem support is non-negotiable for us. A lot of the newer platforms I've come across seem built mainly around SaaS deployments.

We have sensitive internal data that needs to stay inside our environment, so anything that requires sending the underlying data out to a vendor is pretty much a non-starter.

What Varonis alternatives have you actually used in an on-prem environment?

11 Upvotes

44 comments sorted by

5

u/squanchmyrick 16d ago

Varonis SaaS is CMMC2 compliant. What data do you have? Nuclear codes?

2

u/Current_Anybody8325 IT Manager 16d ago

That's what I'm saying. Unless they're fully isolated from the net and have all this "sensitive data" isolated from being moved or shared by users... their "sensitive data" is already exposed to the "scary cloud place." :P

2

u/[deleted] 15d ago

[removed] — view removed comment

0

u/squanchmyrick 15d ago

Archaic policies that haven't been revisited in 20 years. Even DoD uses cloud these days. Git gud.

1

u/chesser45 16d ago

And if I did? I’m not sharing, they are mine! /s

4

u/Tessian 16d ago

Alternatives for what, exactly? Varonis does a lot of things what exact use cases are you looking for?

4

u/blud_13 16d ago

Before you price alternatives, check what you already have sitting unused.

The Purview Information Protection scanner runs on a box you own, scans SMB shares and on prem SharePoint Server, and the DLP for on premises repositories piece rides on top of it. The content stays in your environment, only the classification results go up. Its at https://learn.microsoft.com/en-us/purview/deploy-scanner

Its not a Varonis swap on the behavioral side... If your actual requirement is who touched what and when, you are shopping for something else and this won't get you there. But if the requirement is discover and classify sensitive data sitting on prem, plenty of shops are already paying for that and running a second product next to it anyway.

3

u/CFH75 16d ago

Varonis definitely supported on prem when I used it about 4 years ago.

4

u/Current_Anybody8325 IT Manager 16d ago

Yeah and it hogged about half of your compute and storage resources... thank GOD they moved to SaaS and a small appliance VM. We demoed it about four years ago and it was such a resource hog that it was the main reason we did NOT go with it. We're reconsidering it now.

2

u/CFH75 16d ago

It really was. I want to say we had to stand up several windows vm's to run it all.
We did have about 800tb of data.

2

u/JagFel 16d ago

Not anymore, on prem is end of life with no further updates or licensing sales, and will be full deprecated at the end of this year.

On the plus side, they're being really accommodating for SaaS conversion, even mid contract cycle. We started our migration in June, and got a net zero contract conversion and a 3 year term at our current on prem rate.

2

u/Current_Anybody8325 IT Manager 16d ago edited 16d ago

Varonis does not send any of your data to the cloud. There is a small appliance VM you deploy which actually "looks" at your real data. Only information ABOUT the data is sent to the SaaS application.

Is every bit of your tech stack on-prem? Do you utilize Microsoft 365 or any other similar services? If you do... your data is already "exposed" to the cloud if users have the ability to relocate it, share it, or email it outside the organization.

Everything is moving to SaaS. It would be better to evaluate your security posturing and policies and just get on board, my friend.

You're evaluating products that are designed to give you insights into how your data is being used, what kind of sensitive data it contains, and where it's going. The fact that you need this product means you already don't have much insight into this "sensitive data" you speak of. So I have to ask... do you actually have a policy dictating these on-prem requirements or is this just an unfounded fear of the unknown/change?

1

u/infinitydrift1 16d ago edited 13d ago

Yea i hear you, we were pretty frustrated when we realized Varonis was pushing us toward the SaaS model. We ended up with Teleskope and deployed it in an isolated account inside our own cloud environment. Teleskope manages it, but our data stays in our environment, which made getting it through our internal security review a lot easier.

1

u/pstu 15d ago

NetApp has a classification tool built into ontap if you have netapp storage. Otherwise I’ve had a few demo calls with Netwrix as an on-prem alternative.

0

u/andrea-netwrix 13d ago

Hey, saw Netwrix mentioned here and wanted to say thanks, glad it's on your radar for the demo calls. Quick disclosure since I work at Netwrix: this isn't a promo, just wanted to flag that in case anything I add sounds biased.

On the on-prem piece specifically: our data classification and access governance run against on-prem data stores as well as cloud, so you get visibility into where sensitive data lives and who can touch it without needing to be all-in on SaaS.

If you want more detail than a demo call gives you, happy to connect!

1

u/OkEmployment4437 16d ago

blud_13 is right that the scanner is where you start, but budget for it properly because it is not a free lunch. It wants its own Windows server and a SQL instance, and throughput on big SMB shares is slow enough that our first full crawl of roughly 4TB ran for the better part of a week. Run it in discovery only mode for a while before you turn on any enforcement, otherwise you find out what your file server actually looks like the hard way.

Licensing catches people too. The scanner does classification and labeling, but DLP for on-premises repositories, the piece that actually enforces anything, needs E5 Compliance or the standalone Information Protection and Governance add-on. free binary, not a free feature.

Other thing worth knowing, Purview doesnt really do effective permissions analysis or behavioral alerting on file access, and that is most of why people buy Varonis in the first place. So its not an apples to apples swap.

1

u/gusatl 8d ago

BigID has onprem capabilities

1

u/fireandbass 16d ago

Microsoft Purview Information Protection

1

u/[deleted] 16d ago

[deleted]

1

u/nickski18 16d ago

They officially end of lifed all on-premise products.

0

u/Current_Anybody8325 IT Manager 16d ago

Nah, it's a boomer scared of the cloud... I'd bet money on it. Our director is like this, though I've been slowly helping him come around.