Prisma Access by Palo Alto Networks vs VMware Workspace ONE comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Lookout
Sponsored
Average Rating
7.2
Number of Reviews
5
Ranking in other categories
Secure Web Gateways (SWG) (24th), Mobile Data Protection (7th), Cloud Access Security Brokers (CASB) (12th), Threat Intelligence Platforms (18th), Endpoint Detection and Response (EDR) (43rd), Mobile Threat Defense (2nd), ZTNA as a Service (13th), ZTNA (10th), Secure Access Service Edge (SASE) (18th)
Prisma Access by Palo Alto ...
Average Rating
8.2
Number of Reviews
59
Ranking in other categories
Secure Web Gateways (SWG) (3rd), Cloud Access Security Brokers (CASB) (3rd), Enterprise Infrastructure VPN (4th), ZTNA as a Service (2nd), Secure Access Service Edge (SASE) (1st)
VMware Workspace ONE
Average Rating
8.2
Number of Reviews
82
Ranking in other categories
Enterprise Mobility Management (EMM) (3rd), Unified Endpoint Management (UEM) (2nd)
 

Market share comparison

As of June 2024, in the Secure Access Service Edge (SASE) category, the market share of Lookout is 0.1% and it decreased by 67.6% compared to the previous year. The market share of Prisma Access by Palo Alto Networks is 24.2% and it increased by 5.4% compared to the previous year. The market share of VMware Workspace ONE is 0.1% and it decreased by 83.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Secure Access Service Edge (SASE)
Unique Categories:
Secure Web Gateways (SWG)
0.4%
Mobile Data Protection
7.1%
Cloud Access Security Brokers (CASB)
23.6%
Enterprise Mobility Management (EMM)
9.9%
Unified Endpoint Management (UEM)
19.2%
 

Featured Reviews

ML
Dec 22, 2022
Allows users to self-remediate security issues, maintaining their privacy and providing excellent vulnerability detection
We just submitted an enhancement request reflecting the main area we want to see improvement in; the APIs. Currently, we're able to build dashboards, but it's somewhat backward because we use our MDM API to create them. Lookout should provide APIs to customers so we can query our data and use it in the cloud, and this is the only outstanding area for improvement with the product right now. Another improvement could be a more streamlined activation process for Android and iOS; there are several prompts when activating the application on a new device, and if that could be adapted to one click, that would be beneficial.
IE
Dec 4, 2022
Saves costs, helps to identify shadow IT apps, and provides better VPN user experience
It helps to identify and control shadow IT apps. In terms of its impact on our organization's security, it has been like a sword with two edges. Sometimes, it has proved to be helpful in securing workloads, and sometimes, especially when there are modifications to App-IDs pushed through the content database, we find some things messed up. We've come to a point where we have our ways of managing these things, but all in all, App-ID has been very helpful, especially in detecting tunneled applications. At the end of the day, it's simply an operational thing. Sometimes, you have these notifications sent out about changes in App-IDs, modifications in App-IDs, or even the introduction of entirely new App-IDs to replace. Sometimes, the recommendations are followed, but even then, when the package is installed on the firewall, it gets messed up. I remember a particular one was with Tableau, and suddenly, people weren't able to use Tableau, which is an analytics tool for business. So, it can get messed up, but it doesn't happen often.
Mitul Rajput - PeerSpot reviewer
Jan 31, 2024
Enhances user productivity and offers conditional-based authentication with micro VPN channels for internal applications
There are multiple features. It depends on the customer's use case, but for customers using VMware, we've seen that conditional-based authentication establishing a micro VPN channel to internal applications is most valuable. They know these are the only devices accessing their internal applications, and no outside devices can access any applications. That's the overall security posture organizations are looking for, and that's what we're delivering right now. Moreover, the integration capability of Workspace ONE enhances the IT infrastructure. Good integrations are available. There are a few limitations, but both Citrix and VMware are working on enhancements. But the integrations are pretty much similar.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The protection offered by the product is the most valuable feature. It detects vulnerabilities or traps on our users' phones and then prompts them to clean up their devices. Tools we used previously would only discover, which required us to gather information on the backend, so Lookout is a welcome upgrade."
"The solution is stable."
"On the outside, the main differentiation is because Lookout ingest. They have ingested basically all of the apps for the last ten years and all the versions of all the apps, and we have that in a corporate database that allows us to do very large-scale machine learning and analysis on that data set. That's not something that any of the competitors really have the capability to do because they don't have access to the data set. A lot of the apps you can no longer get them because that version of the app is five or six years old, and it just doesn't exist anywhere anymore, except within our infrastructure. So, the ability to have that very rich dataset and learn from that dataset is a real differentiator."
"The most valuable features are the antivirus as a whole, the anti-malware, and all of the protection features that scan our enterprise devices."
"Prisma integrates well with Cortex XDR and Cortex Data Lake. My company has been also using Prisma Access in-house for nearly a year, and it integrates seamlessly."
"The remediation process is easy compared to other platforms."
"It protects all app traffic so that users can gain access to all apps. Unlike other solutions that only work from ports 80 and 443, which are predominantly for web traffic, Prisma Access covers all protocols and works on all traffic patterns... The most sophisticated attacks can arise from sources that are not behind 80/443."
"The most valuable feature is the ability to change the gateway. For example, if there's a problem with a specific region or vendor, we can make modifications. The solution is scalable, and there are different gateways that can be created depending on the demand."
"A feature I've found very helpful is run time security because most of the products on the market will look at security during the build time, and they don't really look at what happens once you're going into production."
"The product's initial setup phase is simple."
"You have the ability to create your own expressions for your data. Palo Alto understands that DLP is not the same for all consumers. You might have a particular need to fulfill, and they give you the opportunity to create a custom expression to match the specific format that you have. For a confidential file property that you have in your files, you can add a metadata field. It gives you that opportunity to create that."
"Panorama provides centralized management capabilities for all our firewalls and locations so that we can manage different data centers through a single device, a very valuable feature. We don't have to log into various devices to oversee them individually."
"The feature with the highest rating for me is its employee management. I can also praise how versatile it is in terms of operating systems. It has good support for multiple operating systems and can easily manage them all. Not just that, but it can also support any kind of tool that can be run on all these operating systems."
"It has good stability."
"Among the most important improvements is the ability to set up different groups with different deployment policies."
"The most valuable feature is the interface with SCAP, which is the Security Content Automation Protocol."
"Workspace ONE adds a lot of value compared to Microsoft because Microsoft is a late entry into the market, and they're still developing their product from an end-user perspective. Workspace ONE has a slight edge because of AirWatch. VMware has developed its product over a longer period of time, so they have better integrations as a whole solution."
"If an outside person tries to track or hack information, it is not possible without us being notified."
"We've found the solution to be easy to use."
"It's all about centralizing your data and making sure that your data is centralized and secure."
 

Cons

"The stability depends on the service from where you access it. Because sometimes, the place you are in, you have Gateway. You don't have Gateway. The gateway is overutilized. At the end, you need to go through their gateways. And this is the key point here. You have a tracking point. If it's not well orchestrated, and it scales up as you add more to the existing team, you will suffer"
"We just submitted an enhancement request reflecting the main area we want to see improvement in; the APIs. Currently, we're able to build dashboards, but it's somewhat backward because we use our MDM API to create them. Lookout should provide API to customers so we can query our data and use it in our cloud, and this is the only outstanding area for improvement with the product right now."
"From the analysis that we've done, they do seem to be maybe a step behind in trying to enter the market with a new solution. But when they do pick up, they do come out with some good products."
"Lookout was moving into the SSE space. And so their work on SecureWeb Gateway and SD-WAN is still sort of evolving."
"Prisma would be a stronger solution if it could aggregate resources by project or by application. So say we have an application we've developed in AWS and five applications we've developed in Azure. The platform will group it according to those applications, but it's based on the tags we use in Azure, which means I have to rely on development teams to tag resources properly."
"Sometimes, we encountered a portal crash. When we told Palo Alto they said it might be the browser or cache, but I think they need to improve it on their side."
"The documentation is generally good, but they could provide a more detailed description of all the configuration steps. I have to search for information or call support. Palo Alto could add more knowledge base articles about configuration with screenshots and walkthroughs. That would be helpful. When configuring a product, you want to see examples of how it is done."
"The user interface could be better. They need to work a little bit on the console. It is similar to their firewalls but not exactly. They need to clean it up a bit."
"While Palo Alto has understood the essence of building capabilities around cloud technology and have come up with a CASB offering, that is a very new product. There are other companies that have better offerings for understanding cloud applications and have more graceful controls. That's something that Palo Alto needs to work on."
"The solution’s stability could be improved."
"I would like to see better pricing and an easier logging process. Also, if there was a way to log a global log, everything could go onto the system. It would be better if there was a third log, otherwise one would have to do everything manually."
"They can add some new characteristics. For example, when an incident triggers, they can automatically send a template for a particular match that is related to the policy. We don't have that right now. It is something to improve. There could be more automation for certain actions. For example, for a particular group, it can send an administrator alert to their manager. It was one of the concerns of our customers."
"We're unhappy with the quality of support we get for it. We're unhappy with how upgrades occur, so we are migrating away from it. We have an on-premise AirWatch solution and for us to do upgrades we have to call AirWatch to be able to perform the upgrades. They're busy, and scheduling it is not timely enough for us."
"This product makes use of SAML across the board, which has seven known security flaws. It would be good if the company created a way to protect against SAML flaws. One way would be to integrate a firewall server or an endpoint out in the cloud with which you could establish trust. If you knew nothing about SAML and you did some Google searches about what SAML is, what are the flaws, and what are the known vulnerabilities, eventually, you'll find that there are seven flaws. There are two methods that you can use to solve those seven problems. They essentially involve putting a firewall or putting rules, such as access controls, so that anybody in the world can't just come in, authenticate, and either be a good guy or be someone trying to knock on my door and get into my house. If I could eliminate that, it would be awesome."
"The product's initial setup phase was quite complex."
"The console comes bunched together as a package and inbuilt. Its called Workspace ONE. Whenever we have an issue, we contact the service provider, and instead of a fix, we are just getting the next version of Workspace ONE."
"From an identity perspective, there is a lot of room for improvement when it comes to integration with other solutions. I would say it needs more capabilities in terms of direct integrations, including cloud identity solution integrations."
"The portal is not user-friendly."
"One of the things that I want them to improve on, if possible, is the management of Mac devices, MacBook Pro, for example. They do it, but they have scope for improvement, in my opinion. It's not that it's that bad, it just a small need."
"Its performance is quite good on Apple phones or even mid-range phones. If you install an AirWatch on a phone that is not too powerful, you will have performance issues. That's only because the phone is not too powerful, and there is not enough memory, etc. They could do a lighter version for a less powerful phone. It would also be useful for very small companies that don't want to spend money on expensive phones. Having said that, I don't think that is their target market. If their target market is enterprise, all enterprises perhaps have an agreement with Google or Apple, and they would get a phone that has already been tested, and they know that AirWatch will work on that phone."
 

Pricing and Cost Advice

"Lookout is definitely on the lower end when it comes to price point and that seems to be the only differentiator. The technology is in place in this space and it's really about who is coming in at the better price point now."
"The licensing costs are good. Prisma has much more options and support for security, but it has a higher cost. For example, Lookout costs 2/3rd of Prisma's licensing price."
"The pricing is fair; it's comparable to our previous solution, and we carried out multiple POCs and POVs (proof of value). The product is worth the money we pay for it."
"In terms of feature performance versus cost, they're a good value."
"Prisma Access is one of the best compared to other products on the market. The cost is favorable, and Palo Alto provides a simple architecture, so I recommend the solution to anyone using a different product. There are no hidden costs besides the license; what you see is what you get."
"The solution requires a license and the technical support has extra costs. The licensing model could improve."
"I would advise choosing your options according to your company's needs. Just go for what you want and do not pay for anything extra in terms of licensing. You need to determine how much bandwidth is required in your company network, and according to that, you should pay for the license. The mobile user license is based on the number of users who are going to use the VPN solution. You need to determine how many mobile users you are going to have in your network, and you should pay according to that. There are no other costs in addition to licensing, but if you go for the consultant services of Palo Alto networks to deliver the solution for you, then you need to pay something extra. That is not a part of licensing."
"There's no reason not to buy the enterprise version that gives you unlimited PoPs, but you must understand the limitations you impose on yourself if you do that. If you go crazy, that allowlist will be too big for Kubernetes clusters."
"The licensing cost is about 18,000 euros."
"Palo Alto is the Cadillac solution, so their products are pretty expensive. That's just the way it is. Their solution surpasses anything else. Cisco AnyConnect, Zscaler, and all of the other products don't compare. Palo Alto is the market leader with the most features. It saves you work, and you don't have to worry about it."
"Actually the solution is very expensive. I don't know the particulars since the purchasing team dealt with it."
"The solution is expensive."
"We are paying about $145,000 a year on a three-year subscription with no ability to scale up or scale down within that class model."
"I think the pricing of the product needs advisement. It would be great to bundle the VM products together. I think the actual box itself should be included in the license. At present, it is not paired with the mobile device."
"The price of VMware Workspace ONE is reasonable."
"While the platform offers comprehensive solutions, it can be expensive, especially if you only need it for occasional testing and deployment."
"The price of VMware Workspace ONE is expensive. However, for the features that are provided, the price is reasonable. There is a subscription to use the solution."
"In some cases, a customer may feel the solution is expensive."
"The solution can be costly when the customer is dealing with multiple platforms. If a customer is only dealing with iOS, Windows, and Android then Intune is the better choice because there are free licenses."
"It's definitely a bit on the expensive side. It is more for smaller organizations and not large, massive enterprises. I am not sure about any additional costs. As far as we could tell, the billing was what the billing was."
report
Use our free recommendation engine to learn which Secure Access Service Edge (SASE) solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Manufacturing Company
10%
Financial Services Firm
10%
Government
6%
Computer Software Company
15%
Manufacturing Company
11%
Financial Services Firm
11%
Government
6%
Computer Software Company
16%
Financial Services Firm
9%
Government
9%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Lookout?
The licensing costs are good. Prisma has much more options and support for security, but it has a higher cost. For ex...
What needs improvement with Lookout?
The solution could improve identity integration as well. Zero trust, it's a good start as a zero-trust solution. More...
What is the better solution - Prisma Access or Zscaler Private Access?
We looked into Prisma Access before choosing Zscaler Private Access (ZPA). Palo Alto’s Prisma Access is a secure ac...
What do you like most about Prisma Access by Palo Alto Networks?
The most valuable features of the solution are in the areas of the secure remote access it provides while also being ...
What is your experience regarding pricing and costs for Prisma Access by Palo Alto Networks?
As compared to other solutions, Prisma Access is much cheaper. It is probably 30% to 40% cheaper than other solutions...
How does Microsoft Intune compare with VMware Workspace One?
Microsoft Intune is a great tool for managing a mobile device fleet while keeping access control. The solution makes ...
How does VMware Workspace One compare with VMware Horizon 7?
VMware Workspace One has a powerful set of helpful features. The solution offers very good documentation, the initial...
What do you like most about VMware Workspace ONE?
The platform provides a stable environment for operations and quickly creates new environments. Additionally, it offe...
 

Also Known As

CipherCloud
Palo Alto Networks Prisma Access, Prisma Access, GlobalProtect, Palo Alto GlobalProtect Mobile Security Manager, Prisma SaaS by Palo Alto Networks, Prisma Access
VMware AirWatch
 

Overview

 

Sample Customers

Concord Hospital, State of Colorado, Essilor International, RheinLand Versicherungsgruppe, University of Westminster, Universidade Nove de Julho, SPAR Austria, CAME Group, ZipRealty, Greenhill & Co., IKT Agder, Aviva Stadium, Animal Logic, Management & Training Corporation, Brigham Young University Hawaii, School District of Chilliwack
Australian Sports Commission, Stockport NHS Foundation Trust, Lomond School, Merck, United Bank, Medical College of Wisconsin, Latymer Upper School, 2gether NHS Foundation Trust, Dowling Aaron Inc., Trillium Lakelands District School Board, Harrogate Grammar School, Duke University Football, Delta Air Lines, Adventist Health System, Giochi Preziosi, Cramlington Learning Village, Intermountain Healthcare, Safexpress, TAG Aviation
Find out what your peers are saying about Palo Alto Networks, Cisco, Zscaler and others in Secure Access Service Edge (SASE). Updated: June 2024.
787,061 professionals have used our research since 2012.