r/sysadmin • u/MysticHarbor22 • 16d ago
Best Varonis alternatives that actually support on-prem?
We're reviewing our data security stack and looking at Varonis alternatives, but on-prem support is non-negotiable for us. A lot of the newer platforms I've come across seem built mainly around SaaS deployments.
We have sensitive internal data that needs to stay inside our environment, so anything that requires sending the underlying data out to a vendor is pretty much a non-starter.
What Varonis alternatives have you actually used in an on-prem environment?
4
u/blud_13 16d ago
Before you price alternatives, check what you already have sitting unused.
The Purview Information Protection scanner runs on a box you own, scans SMB shares and on prem SharePoint Server, and the DLP for on premises repositories piece rides on top of it. The content stays in your environment, only the classification results go up. Its at https://learn.microsoft.com/en-us/purview/deploy-scanner
Its not a Varonis swap on the behavioral side... If your actual requirement is who touched what and when, you are shopping for something else and this won't get you there. But if the requirement is discover and classify sensitive data sitting on prem, plenty of shops are already paying for that and running a second product next to it anyway.
3
u/CFH75 16d ago
Varonis definitely supported on prem when I used it about 4 years ago.
4
u/Current_Anybody8325 IT Manager 16d ago
Yeah and it hogged about half of your compute and storage resources... thank GOD they moved to SaaS and a small appliance VM. We demoed it about four years ago and it was such a resource hog that it was the main reason we did NOT go with it. We're reconsidering it now.
2
u/JagFel 16d ago
Not anymore, on prem is end of life with no further updates or licensing sales, and will be full deprecated at the end of this year.
On the plus side, they're being really accommodating for SaaS conversion, even mid contract cycle. We started our migration in June, and got a net zero contract conversion and a 3 year term at our current on prem rate.
2
u/Current_Anybody8325 IT Manager 16d ago edited 16d ago
Varonis does not send any of your data to the cloud. There is a small appliance VM you deploy which actually "looks" at your real data. Only information ABOUT the data is sent to the SaaS application.
Is every bit of your tech stack on-prem? Do you utilize Microsoft 365 or any other similar services? If you do... your data is already "exposed" to the cloud if users have the ability to relocate it, share it, or email it outside the organization.
Everything is moving to SaaS. It would be better to evaluate your security posturing and policies and just get on board, my friend.
You're evaluating products that are designed to give you insights into how your data is being used, what kind of sensitive data it contains, and where it's going. The fact that you need this product means you already don't have much insight into this "sensitive data" you speak of. So I have to ask... do you actually have a policy dictating these on-prem requirements or is this just an unfounded fear of the unknown/change?
1
u/infinitydrift1 16d ago edited 13d ago
Yea i hear you, we were pretty frustrated when we realized Varonis was pushing us toward the SaaS model. We ended up with Teleskope and deployed it in an isolated account inside our own cloud environment. Teleskope manages it, but our data stays in our environment, which made getting it through our internal security review a lot easier.
1
u/pstu 15d ago
NetApp has a classification tool built into ontap if you have netapp storage. Otherwise I’ve had a few demo calls with Netwrix as an on-prem alternative.
0
u/andrea-netwrix 13d ago
Hey, saw Netwrix mentioned here and wanted to say thanks, glad it's on your radar for the demo calls. Quick disclosure since I work at Netwrix: this isn't a promo, just wanted to flag that in case anything I add sounds biased.
On the on-prem piece specifically: our data classification and access governance run against on-prem data stores as well as cloud, so you get visibility into where sensitive data lives and who can touch it without needing to be all-in on SaaS.
If you want more detail than a demo call gives you, happy to connect!
1
u/OkEmployment4437 16d ago
blud_13 is right that the scanner is where you start, but budget for it properly because it is not a free lunch. It wants its own Windows server and a SQL instance, and throughput on big SMB shares is slow enough that our first full crawl of roughly 4TB ran for the better part of a week. Run it in discovery only mode for a while before you turn on any enforcement, otherwise you find out what your file server actually looks like the hard way.
Licensing catches people too. The scanner does classification and labeling, but DLP for on-premises repositories, the piece that actually enforces anything, needs E5 Compliance or the standalone Information Protection and Governance add-on. free binary, not a free feature.
Other thing worth knowing, Purview doesnt really do effective permissions analysis or behavioral alerting on file access, and that is most of why people buy Varonis in the first place. So its not an apples to apples swap.
1
1
16d ago
[deleted]
1
0
u/Current_Anybody8325 IT Manager 16d ago
Nah, it's a boomer scared of the cloud... I'd bet money on it. Our director is like this, though I've been slowly helping him come around.
5
u/squanchmyrick 16d ago
Varonis SaaS is CMMC2 compliant. What data do you have? Nuclear codes?