Skip to content
Cybersecurity Delinea

Delinea Privilege Control for Servers

Delinea Privilege Control for Servers: granular command control on servers. Command filtering, sudo replacement, audit trail.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Key Features

  • Command-level privilege control
  • sudo replacement (dzdo)
  • Granular policy enforcement
  • Real-time audit logging
  • AD/LDAP integration
Available now
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Send inquiry
Table of Contents

Why Delinea Privilege Control for Servers?

sudo grants too broad permissions. ALL=(ALL) ALL is equivalent to root. No granularity in native privilege tools. Command logging in sudo is easy to bypass. Central policy management is impossible.

Delinea Privilege Control for Servers provides granular privilege control on servers. Command-level filtering instead of all-or-nothing. dzdo replaces sudo with central policy and audit. Full command logging without bypass possibility.

How does it work?

Command Control

Granular privilege:

  • Per-command allowlists
  • Parameter restrictions
  • Context-aware policies
  • Blacklists for dangerous commands
  • Least privilege enforcement

dzdo (Delinea sudo)

Enhanced privilege elevation:

  • Drop-in sudo replacement
  • Central policy management
  • Tamper-proof logging
  • MFA support
  • Audit everything

Central Policies

Unified management:

  • Policy zones
  • Role-based assignments
  • Inheritance and exceptions
  • Version control
  • Push deployment

Main features

Privilege Zones

  • Logical server grouping
  • Per-zone policies
  • Role definitions
  • Nested zones
  • Emergency override

Command Filtering

  • Allowlist commands
  • Parameter restrictions
  • Script approval
  • Path restrictions
  • Time-based rules

Audit Trail

  • All command logging
  • Keystroke capture
  • Session recording option
  • Tamper-proof logs
  • Compliance reports

MFA Integration

  • MFA for elevation
  • Per-command MFA
  • Risk-based MFA
  • Multiple methods
  • Grace periods

Policy Examples

RoleAllowed CommandsRestrictions
DBAmysql, pg_dumpNo DROP, TRUNCATE
Web Adminapache, nginxConfig files only
Developerdocker, kubectlNon-prod namespaces
Helpdeskpasswd, usermodSpecific users only
EmergencyAllTime-limited, recorded

Supported Platforms

PlatformVersions
RHEL/CentOS7, 8, 9
Ubuntu18.04, 20.04, 22.04
SUSESLES 12, 15
Debian10, 11, 12
Windows Server2016, 2019, 2022

Who is it for?

  • Enterprise with least privilege requirements
  • Organizations with compliance mandates
  • Security teams controlling server access
  • IT teams managing mixed environments

Benefits

For security: Granular control, least privilege, full audit trail

For IT: Central policy management, reduced sudo abuse, simplified administration

For compliance: Command logging, tamper-proof audit, compliance reports

Specification

ControlCommand-level, parameter-level
Replacementsudo (dzdo)
PlatformsLinux, Unix, Windows
LoggingTamper-proof, searchable

FAQ

How is dzdo different from sudo? dzdo is a sudo replacement with central policy, tamper-proof logging, MFA, parameter filtering.

Can I migrate from sudo? Yes. Compatibility mode allows gradual migration. Existing sudoers can be imported.

How does command filtering work? Policies define allowed commands and parameters. dzdo enforces policy before execution.

Can logging be bypassed? No. Agent enforces logging locally. Tamper-proof, cannot be disabled without privilege.

What about Windows support? Equivalent control for Windows commands and PowerShell. Role-based, audited.

Can I test policies? Yes. Dry-run mode shows what would be allowed/denied without enforcement.

How does emergency access work? Break-glass roles with full access but mandatory logging and time limits.

Does it support containers? Host-level control. Container privilege management via integration.

What about high availability? Agent caches policies locally. Continues operation if central server unavailable.

What about support? Delinea support for software. nFlo offers policy design and deployment assistance.

Inquire about Delinea Privilege Control for Servers

Contact your product specialist and get a custom quote.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free technical consultation
Custom quote and configuration

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist