We use it for MAC Authentication Bypass, 802.1X authentication, and certification and validation against Active Directory. Because MAC devices can't be enrolled in the domain, we were doing a manual installation of certificates.
Technical Leader at Línea Directa S.A.S / Aplicación e Ingreso
We are very secure now because only corporate endpoints can be authenticated on our wireless
Pros and Cons
- "Authentication is the most valuable feature because it puts our company at another level of security."
What is our primary use case?
How has it helped my organization?
We are a very secure enterprise now because only our corporate endpoints can be authenticated on our wireless. Before, any device could be connected to our production network. And the corporate endpoints have antivirus and anti-malware. Things are more and more secure.
What is most valuable?
Authentication is the most valuable feature because it puts our company at another level of security. It establishes trust for every access because we use only corporate endpoints. If somebody has another device, they can't connect it to the enterprise network because we haven't implemented bring-your-own-device yet. We have five warehouse buildings and all our operations are around logistics and that means external people don't come to our buildings.
For how long have I used the solution?
I have been using Cisco ISE (Identity Services Engine) for three years.
Buyer's Guide
Cisco Identity Services Engine (ISE)
May 2025

Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
852,649 professionals have used our research since 2012.
What do I think about the stability of the solution?
It's very stable.
What do I think about the scalability of the solution?
It's expensive to scale Cisco ISE, but our situation is stable so we don't need to scale it for now. In the future, we will need a more scalable solution.
It is used for all our departments, all end-users, all corporate endpoints. And when we use MAC Authentication Bypass, we include printers and VIP cell phones.
How are customer service and support?
Tech support is very good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We didn't have a previous solution.
How was the initial setup?
The deployment was a little complex, but not because of the solution. It was more an issue for our people because it was a mindset change.
It took us about six months to deploy. Because we didn't have a previous solution, we just deployed it one department at a time across our four departments.
What about the implementation team?
We used an integrator, ITS Infocom. Experience-wise, it was very good. On our side, we had three people involved.
What was our ROI?
Since implementing Cisco ISE, we haven't had any attacks against our application.
What's my experience with pricing, setup cost, and licensing?
Pricing is not a problem for Cisco because it has a lot of features and not much competition, although it's more expensive than other products. But if I do a cost-benefit analysis, Cisco provides high quality.
Which other solutions did I evaluate?
We looked at Aruba. Cisco ISE is much better.
What other advice do I have?
Be patient with the implementation. It can be very difficult for the clients, the people using it, because it requires a change of mindset.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Associate consultant at HCL Technologies
Efficient for wireless security and highly scalable solution for our use cases
Pros and Cons
- "The product is stable."
- "There is room for improvement in CLI. Most things are done through the GUI, and there aren't many commands or troubleshooting options available compared to other Cisco products like switches and routers."
What is our primary use case?
We use it to secure our networks. We can secure our switches and wireless networks, basically everything.
We use it primarily for wireless security, but it can be used for many other things as well, like LAN and WAN security.
What needs improvement?
There is room for improvement in CLI. Most things are done through the GUI, and there aren't many commands or troubleshooting options available compared to other Cisco products like switches and routers. We have more visibility on the CLI for those devices, but the GUI seems limited. Moreover, sometimes, GUI seems very pathetic.
For how long have I used the solution?
I have experience working with this solution. I have been using it for four to five years. We still use the old version, but we plan to migrate to the new version soon because they recently changed their licensing model.
What do I think about the stability of the solution?
The product is stable. We don't face many challenges. It's stable, so I would rate it around a nine out of ten.
What do I think about the scalability of the solution?
The product is scalable. I would rate the scalability a ten out of ten. We have medium-sized businesses as our clients.
How are customer service and support?
There was some delay.
How would you rate customer service and support?
Positive
How was the initial setup?
Setup wasn't difficult because we already had a solution in place. It was very easy to install.
What about the implementation team?
The deployment definitely took weeks.
What's my experience with pricing, setup cost, and licensing?
I would rate the pricing an eight out of ten, one being cheap and ten being expensive.
What other advice do I have?
Overall, I would rate the solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Cisco Identity Services Engine (ISE)
May 2025

Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
852,649 professionals have used our research since 2012.
Network Manager at a government with 201-500 employees
Helps save us time and seamlessly integrates with our entire suite
Pros and Cons
- "The most valuable feature of Cisco ISE is its seamless integration with the switches and the entire suite, enabling wireless access and smooth client information retrieval."
- "If Cisco could grant more control, the features could be more focused on network and security administration, reducing the need for integration with other components."
What is our primary use case?
We use Cisco ISE for the authentication of wireless clients.
How has it helped my organization?
Cisco ISE has saved me a couple of hours per month in terms of not having to manually onboard clients. However, there are still some manual tasks that need to be uploaded to Cisco ISE.
What is most valuable?
The most valuable feature of Cisco ISE is its seamless integration with the switches and the entire suite, enabling wireless access and smooth client information retrieval.
What needs improvement?
One of the problems we have had is that there are many features on Cisco ISE that we are not utilizing. In the real world, it requires multiple parties to come together, just like the AD or OU. Therefore, it won't be solely the responsibility of the network or security personnel to ensure that the solution works as intended and utilizes all the features. It necessitates collaboration among various stakeholders. If Cisco could grant more control, the features could be more focused on network and security administration, reducing the need for integration with other components. This would be beneficial for my organization.
For how long have I used the solution?
I have been using Cisco ISE for one and a half years.
What do I think about the stability of the solution?
Cisco ISE is extremely stable.
What do I think about the scalability of the solution?
As long as we have the funds to purchase the license, Cisco ISE is highly scalable.
How are customer service and support?
We have a contact person in Singapore whom we can reach at any time for support.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was straightforward because we used an integrator.
What about the implementation team?
We used an integrator for the implementation.
What was our ROI?
The cost-benefit analysis primarily considers the time saved through manual labor.
What's my experience with pricing, setup cost, and licensing?
The recent changes in the licensing model have caused some issues with the team.
Which other solutions did I evaluate?
We have a rigorous procurement process and carefully evaluated other options before selecting Cisco ISE.
One of the other solutions we evaluated was the Aruba Wireless feed and its accompanying authentication, but we determined that Cisco ISE was superior and more beneficial.
What other advice do I have?
I would rate Cisco ISE with a nine out of ten based on its overall benefits. However, since I am unable to utilize all the features due to the need for coordination from numerous other teams, I would personally assign it a benefit score of only five out of ten.
We attempted role-based access with the Cisco ISE integration, but it didn't work out effectively because it is more of an upper-level issue regarding organization and role level. Multiple teams had to collaborate, and there was a need to configure the Active Directory and Organizational Unit groups. This also involved restructuring and similar tasks. As individuals moved between OU groups, someone had to consistently update the OU groups to ensure the success of the process.
We have made a significant investment in Cisco infrastructure; therefore, we have chosen Cisco ISE as a logical option for our authentication mechanism.
Cisco ISE has not directly assisted our organization in enhancing its cybersecurity resilience.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Software Engineer with 501-1,000 employees
A one-stop solution to streamline security policy management
Pros and Cons
- "They have recently made a lot of improvements. My clients don't have much to complain about."
- "It should be virtualized because many people have begun migrating to the cloud. They should offer a hybrid version."
What is our primary use case?
We use ISE for security group tagging in terms of guests and visitors who access the network to make sure that they actually go through this to control their privilege access to ensure they don't actually access the internal network, etc.
Our clients use ISE as a form of security policy management so that users and devices between the wired, wireless, and VPN connections to the corporate network, can be managed accordingly.
Take a house for example. Sometimes you need to access a room via a certain keyhole, so you use a key that is unique to that door. With ISE, you can segment this process in terms of policy management based on the security tag. You actually grant the user access based on the tagging.
That's the IT trend — saving a lot on operating costs to manage the different users and access methods.
Within our company, we have roughly 200 employees using this solution.
What is most valuable?
My clients are always talking about the segregation capabilities. Segmentation refers to how you can actually segregate employee and non-employee client access.
What needs improvement?
They have recently made a lot of improvements. My clients don't have much to complain about — it's a one-stop-shop.
It should be virtualized because many people have begun migrating to the cloud. They should offer a hybrid version.
What do I think about the stability of the solution?
It's stable but there's a limitation of up to 200,000 users. If you have a big number of users, then you have to customize the installation process.
What do I think about the scalability of the solution?
It's only scalable up to 20,000 users.
How are customer service and technical support?
I would say Cisco's support has been getting worse. I think they outsource a lot of skillsets.
How was the initial setup?
The initial setup is pretty straightforward. They actually provide a lot of help to IT administrators which makes setting it up rather easy.
The whole setup takes about three days because you need to basically configure the network, test the configuration, and then you need to cut over to production.
What was our ROI?
Our customers definitely see a return on their investment with this solution.
What's my experience with pricing, setup cost, and licensing?
I think licensing costs roughly $2,000 a year. ISE is more expensive than Network Access Control.
What other advice do I have?
If you wish to use ISE, you must have a deep understanding of IT. If you don't, setting it up properly will be very complex.
Overall, on a scale from one to ten, I would give this solution a rating of nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
OPCO IT Manager at MTN
Enables us to protect our network but it should be more user-friendly
Pros and Cons
- "For guests we give them limited access to the internet when they come in so that access has been useful. Previously, we just used to give them the APN key which they would leave with. Now, we give them credentials to use that are for a limited period of time."
- "In order to make it a ten, it should be more user-friendly. You need somebody who is knowledgeable about it to use it. It's not easy to use. We have to rely heavily on technical support."
What is our primary use case?
We use this solution to protect the network especially when someone brings their own device and to lock out access to anybody connecting to the network. Also to make sure that the people connect to the correct VLAN. So, mainly for security wifi access so that when people want to connect to our wifi they have to log in using their credentials.
How has it helped my organization?
We give guests limited access to the internet when they come in so that access has been useful. Previously, we just used to give them the APN key which they would leave with. Now, we give them credentials to use that are for a limited period of time.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
It is stable. Any time we found an issue we would get in touch with the reseller to help fix it. Then they tell us where the problem is and we'll know where to look.
What do I think about the scalability of the solution?
It is scalable. We have around 350 users. We required two staff members for maintenance but they don't have enough knowledge so we have to reach out externally for more help.
How are customer service and technical support?
Their technical support has been good. They have been responsive every time we have an issue. They get logs, check and then give us feedback of which corrections to do.
How was the initial setup?
The initial setup was complex. We had to engage an expert. When we rolled it out we would find challenges and then we would have to find a way of fixing those challenges. Out of nowhere, it would lock out all users. Then we discovered that no, the password had expired for the service account. We needed to make it none expiry.
Deployment took about a month. We had to do project planning, discuss the plan with the team, and by the end, it was a month.
What about the implementation team?
We used a reseller for the implementation and we had a good experience with them.
What's my experience with pricing, setup cost, and licensing?
If you go directly with Cisco for the implementation it's very, very expensive.
Which other solutions did I evaluate?
We also looked at Aruba.
What other advice do I have?
It's a good product but it requires technical support and knowledge otherwise it will be difficult to manage and run it. It requires somebody to be configuring issues. You need protection as you advance in the usage but it's a good product.
I would rate this solution an eight out of ten. In order to make it a ten, it should be more user-friendly. You need somebody who is knowledgeable about it to use it. It's not easy to use. We have to rely heavily on technical support.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director, Information Technology Solutions at a healthcare company with 5,001-10,000 employees
Comprehensive and allows you to control access to network resources granularly based on policies
Pros and Cons
- "Cisco ISE is a comprehensive solution that allows you to control access to network resources granularly based on policies."
- "Cisco ISE is very complex and not very easy to deploy."
What is our primary use case?
We use the solution for network access control.
What is most valuable?
Cisco ISE is a comprehensive solution that allows you to control access to network resources granularly based on policies.
What needs improvement?
Cisco ISE is very complex and not very easy to deploy. There are a lot of prerequisites for the tool.
For how long have I used the solution?
I have been using Cisco ISE (Identity Services Engine) for three years.
What do I think about the stability of the solution?
We did not face any issues with the solution’s stability.
What do I think about the scalability of the solution?
Cisco ISE is a very scalable solution.
How are customer service and support?
We are working with a partner for support and are very happy with them.
On a scale from one to ten, where one is bad and ten is good, I rate their support a seven or eight out of ten.
Which solution did I use previously and why did I switch?
Compared to Cisco ISE, Fortinet NAC is more consumer-friendly.
How was the initial setup?
On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup a four out of ten.
What about the implementation team?
The project lasted a few months, but the planning took several months. Cisco ISE itself means nothing. It has to have the network set up to ensure the network penetration is in place, and we're still working on that.
What was our ROI?
Security is about risk control and exposure avoidance. You can only calculate its return on investment based on how you avoid penalty fees. Cisco ISE improves our security stats.
What's my experience with pricing, setup cost, and licensing?
If you consider money only, Cisco ISE is not a cheap solution. Functionality-wise, however, it offers a very good price for the value you receive.
What other advice do I have?
The solution's compliance and policy enforcement capability has benefited our organization by simplifying work.
The solution operates in the background, and users generally don't interact with it. Cisco ISE is the security framework layer between network resources and end users using them. Users do not go into Cisco ISE to do anything.
It's like Active Directory for Identity. If you're an end user, you don't work in Active Directory, but you authenticate Active Directory to use resources on the network. The same applies to Cisco ISE, and users don't interact with it directly. They are affected by it to the extent to which they are accessing network resources.
Cisco ISE has a very comprehensive integration suite and we did not face a lot of challenges in integrating this solution with other security tools. If they know how to use it, I would recommend the solution to other organizations with similar security needs.
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Software Engineer with 501-1,000 employees
Good technology that works well with networks, routers and switches, but should include third-party integration
Pros and Cons
- "When you push out the policy, it is able to populate the entire network at one time."
- "Third-party integration is important, as well as the continuous adaptation feature which is the AIOps. It would be helpful to include the AIOps."
What is our primary use case?
We are resellers. We provide and deploy solutions for our customers.
Cisco ISE (Identity Services Engine) helps the operation to automate.
What is most valuable?
It works very well with the network, router, and switches. It is able to enforce the policy and assigns the traffic a Security Group tag.
A Google user is able to enforce access throughout the router and switches ensuring the traffic going through has the same policy.
When you push out the policy, it is able to populate the entire network at one time.
It's quite good, the market is using this solution.
What needs improvement?
This solution has enhanced features that make it difficult to use. To make it easier, it should be made without PxGrid.
It should be able to work with third-party routers and switches. We want to work in an environment where there are multi-vendors that require PxGrid.
Their software-defined access is not easy to implement. You have to have a good understanding of how to implement it. It would be helpful if they could make it easier for the customer to adopt.
Third-party integration is important, as well as the continuous adaptation feature, which is the AIOps. It would be helpful to include the AIOps.
For how long have I used the solution?
They are currently on version 3.1.
What do I think about the stability of the solution?
If the customer has more than 200,000 users, the performance becomes a bit laggy.
What do I think about the scalability of the solution?
In terms of scalability, it's available on the cloud, but I have not yet tested the features on the cloud.
It is used mainly by our customers, who use it for their entire infrastructure. They have anywhere from 50,000 to 100,000 users.
How are customer service and technical support?
Technical support could be better. They outsource the support.
We are brought all around the world, it is similar to following the sun.
Which solution did I use previously and why did I switch?
Currently, I am using SD-WAN (Software-Defined WAN) from Silver Peak.
How was the initial setup?
To complete the installation, you need to be technically knowledgeable. The setup could be easier.
What's my experience with pricing, setup cost, and licensing?
For the content, and the technologies it is made to be a bit more complex.
The technology is good, but to use some of the other features, and capabilities, they request that we purchase the Cisco DNA Center. As a result, the bundled price is a little high.
Once you purchase the DNA, you will need the SNA then the license, overall it's very expensive.
If, however, you implement Cisco ISE without the DNA and the SDA, the price is reasonable.
What other advice do I have?
To avoid running into any complications when getting this solution up and running, you should get technically trained and comfortable with it before applying it.
I would rate Cisco ISE (Identity Services Engine) a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Manager of IT at a financial services firm with 10,001+ employees
Enables us to control certificates of each device, preventing unauthenticated devices from entering our network
Pros and Cons
- "The access policies, and all of the policies in Cisco ISE, are important to us."
- "The user interface could be more user-friendly."
- "The pricing is fair."
What is our primary use case?
We use it for the identification of our devices, users, and wireless users.
How has it helped my organization?
Unauthenticated devices are not allowed on our network and that has been an improvement for our company. With Cisco ISE, we control the certificates of each device so that devices have internet access. The solution has eliminated trust from our network architecture.
What is most valuable?
The access policies, and all of the policies in Cisco ISE, are important to us.
What needs improvement?
The user interface could be more user-friendly.
For how long have I used the solution?
I have been using Cisco ISE (Identity Services Engine) for about six years.
What do I think about the stability of the solution?
The stability has been perfect. Our company has been using it for more than 10 years and it's stable. It's really good.
What do I think about the scalability of the solution?
The scalability is also good.
How are customer service and support?
The customer service has been perfect.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not have a previous solution.
What's my experience with pricing, setup cost, and licensing?
The pricing is fair. We have a base license and an OpEx license.
Which other solutions did I evaluate?
We looked at other solutions, but that was a long time ago.
What other advice do I have?
I would recommend ISE to colleagues. We are happy with it and we want to use it in the cloud, next. Our on-prem devices go end-of-support in 2023 and we will try to use it on the cloud.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Popular Comparisons
Cisco Secure Firewall
Cisco Umbrella
Aruba ClearPass
Cisco Secure Endpoint
Fortinet FortiNAC
Forescout Platform
Cisco Secure Email
Cisco Secure Network Analytics
Cisco Secure Client (including AnyConnect)
Cisco Secure Workload
F5 BIG-IP Access Policy Manager (APM)
ThreatLocker Zero Trust Endpoint Protection Platform
ExtremeCloud IQ
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- ForeScout vs. Cisco ISE
- What are the main differences between Cisco ISE and Forescout Platform?
- Can Cisco ISE disallow authentication based on OS?
- Cisco ISE (Identity Services Engine) vs Fortinet FortiNAC: which solution is better and why?
- What are the requirements for integrating the Cisco Data Center and Cisco ISE?
- What is the biggest difference between Aruba ClearPass and Cisco ISE?
- Which is better - Aruba Clearpass or Cisco ISE?
- How would you compare Cisco ISE (Identity Services Engine) vs Forescout Platform?
- How does Cisco ISE compare with Fortinet FortiNAC?
- What is your experience with 802.1X when using EnGenius WAP/switch with Cisco ISE 2.1?