Try our new research platform with insights from 80,000+ expert users

BeyondTrust Endpoint Privilege Management vs SAP Identity Management comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

BeyondTrust Endpoint Privil...
Average Rating
8.0
Number of Reviews
28
Ranking in other categories
Privileged Access Management (PAM) (4th), Anti-Malware Tools (9th)
SAP Identity Management
Average Rating
7.8
Number of Reviews
13
Ranking in other categories
User Provisioning Software (8th), Identity Management (IM) (16th)
 

Mindshare comparison

While both are Identity and Access Management solutions, they serve different purposes. BeyondTrust Endpoint Privilege Management is designed for Privileged Access Management (PAM) and holds a mindshare of 4.6%, down 6.0% compared to last year.
SAP Identity Management, on the other hand, focuses on Identity Management (IM), holds 2.8% mindshare, down 3.9% since last year.
Privileged Access Management (PAM)
Identity Management (IM)
 

Featured Reviews

Marlin B Pohlman - PeerSpot reviewer
Oct 24, 2022
Admin rights can be granted and revoked within minutes and that is what everything comes down to, for us
The most important factor is the ability to invoke least privilege, which is required under 27701 and GDPR. We have used the solution to remove users' administrative rights and instead provide on-demand, token-based administrative rights. The latter is an option for a single, temporary increase in privileges for a trusted user for a specific time. We use it in a medical environment for HIPAA compliance or medical compliance in a GDPR case. For example, if you have a clinician who needs access to a specific piece of medical information, or if there is an administrator who needs to have administrator rights to a particular database for a limited period of time, we can give it and then revoke it. That's another reason the tool is useful. Also, the fact that we are able to add events straight from event logs and/or the database is important for crisis management and rapid reaction. This ability helps us meet our SLA requirements. In addition, we can elevate approved applications and actions without broad administrative rights. We can temporarily increase privilege based on tasks. If someone puts in a ticket, we increase their privilege for that ticket. We then watch to see if that ticket has been resolved and then we decrease it. Another feature of the platform is instant risk reduction solutions. We can do a risk metric with it, and we do that as part of our risk evaluation. We can increase and decrease privilege and we can actually show that in the ISO 13485 risk metric. And it provides a single solution for managing endpoint security preferences. It does a good job of that.
Kiril Petkov - PeerSpot reviewer
Nov 11, 2022
Stable, especially if you're an experienced user and is suitable for managing access rights for accounts, process sharing, and file sharing, but it isn't straightforward to use or maintain
I'm not so happy about the features provided by SAP Identity Management, but I'm not sure where the problem lies, if it's a product issue, an issue with its deployment, or both. I find SAP Identity Management complicated to use. Maintaining it is also complex. The solution is integrated with only two core systems, so it's not compatible with all applications in terms of providing single sign-on, which makes no sense to me, so this is another area for improvement in SAP Identity Management. Still, the issue could be with the supplier my company is working with, as that supplier provides consultancy and deployment services. It's a popular, experienced, and well-ranked supplier in the local market. However, it's still not guaranteed that the business requirements have been understood correctly and that the deployment was done properly. What I'd like to see in SAP Identity Management in its next release is a more innovative way to use it for handling all access rights rather than having to use different products.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I'm a BeyondTrust partner and I have multiple deployments, four or five banks right now. The features that give us quite an edge compared to what our competitors are offering - like IBM or Thycotic - are the Session Management, that is quite a big one; also the recording of keystrokes. In addition, there is the password vaulting and state-of-the-art Password Management, which I haven't seen in other products."
"I find the comprehensive Privilege Access Management features valuable, including automation, and the ability to integrate with applications and the Windows operating system."
"What I liked about this solution is that it can also integrate for tracking malicious use or sending analytics to a host that can process them. I don't know if CyberArk, Centrify, or Thycotic can do that. The analytics was something the client really wanted, and they already had BeyondTrust. It is very scalable. The agent on the workstation is very thin, and the processing power required on a server is nothing out of the ordinary. It is also very stable and easy to deploy."
"I would say session management on the go is the most valuable feature. When the session is going on, you can stop the session without terminating it for justification. You can cancel it. The recording takes very little space. Those are some things which the customers are worried about when they talk about session recording."
"I find the solution’s features like section management, password management, and analytics valuable."
"The features related to application elevate is amazing. It helped the company to remove almost all admin local users."
"Logs that get collected on the Privilege Management console from the agents are very good. They help us to identify the aspects from which we have to whitelist an application."
"The solution's least privilege enforcement has helped us ensure access is given to only the required people."
"The setup process is straightforward."
"It provides basic automatic user administration and role provisioning to save time."
"What I found most valuable in SAP Identity Management is process automation. The solution also gives transparency about what is happening and why which I find beneficial. Another feature I found valuable in SAP Identity Management is integration. It has very good integration."
"What's most valuable in SAP Identity Management is that it's easily an out-of-the-box solution for connectivity with SAP applications. We do not have to do any customizations, and this makes the solution very compatible with most SAP applications. SAP Identity Management is also very user-friendly."
"The most valuable features of SAP Identity Management are business roles and automated user provisioning."
"Rather than implement a basic SSO, this solution assisted us with setting up two-factor authentication."
"The most valuable feature is the user experience for managing information."
"What I like about SAP Identity Management is that it's stable for experienced users and suitable for access management, not just for SAP accounts, but for Active Directory, including file sharing and process sharing."
 

Cons

"The weaknesses are related to the effort required to migrate from existing technologies or having no Privilege Access Management (PAM) at all to adopting technologies like BeyondTrust. It involves changes in processes and can take a significant amount of time, typically six to twelve months."
"Their technical support could be more responsive and helpful."
"It keeps on breaking every now and then. It is not yet mature. Every time something new comes up or we run into some new issues, the culprit is BeyondTrust because the agents and the adapter are not mature. The new development process goes on, and they're not able to handle things. It should be mature. It shouldn't break every now and then."
"A valuable enhancement could be the capability to deploy agents directly through the console."
"They need to come up with better integrative options which should be customer-centric."
"The deployment process should be clarified or made simpler. It would be helpful if the solution had in-app tutorials for users to look at as they progress through the system. Sometimes we get lost and need to go back to check what exactly the function was. There should be small hints around major key functions. It would go a long way in speeding up the deployment process."
"How the accounts are presented in the solution's UI can be improved."
"It should support XWindows Remote Desktop Access protocol for Linux/Unix."
"A lack of startup connectors to different systems, and could have better connectors for SAP IDM."
"SAP Identity Management can improve risk analysis and authority checks."
"The pricing could be better."
"What needs improvement in SAP Identity Management is its compatibility with third-party applications. We'd like to get connectors or plugin settings to make it easier to manage other applications, whether SAP or non SAP applications. As SAP Identity Management is not compatible with non SAP applications, some of the clients are looking for other IDM applications such as SalePoint and Saviynt, so this is an issue we've observed in the solution."
"I find SAP Identity Management complicated to use. Maintaining it is also complex."
"One of the areas for improvement in the solution is its user interface which needs to be up-to-date and fancier, in particular, have better visualization in terms of the tabs and buttons. The user interface of SAP Identity Management should be improved based on the latest trends."
"It needs to have the SSO for the HANA modules that SAP is releasing."
"I have encountered issues with the host authentication feature."
 

Pricing and Cost Advice

"PowerBroker for a Mac client is three times the price of the Windows version."
"I'm sure everyone should have the cluster environment, which means more expensive, anyway, cheaper than the other solutions."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a seven out of ten."
"This solution is expensive compared to its competitors."
"Price-wise, it is very competitive. In our area, government entities and banks don't go for the monthly payment. It is a headache even for us in terms of finance and procurement to go for monthly payments. Quarterly might be more logical and reasonable, but the minimum that we go for is one year, and sometimes, we even try to compile and give one offering for three years."
"The solution's pricing is high."
"It is relatively more cost-effective compared to the competing product."
"The product’s licensing is different for Windows, Linux, and Mac. The tool’s licensing is yearly."
"When evaluating the price of any product, I first look at how it meets my business requirements and if it meets requirements adequately and predictively. Currently, I don't see this from SAP Identity Management, so pricing for it is expensive, in my opinion."
"The licensing cost varies depending on the specific requirements and deployment size."
"I rate the solution's pricing a four out of ten."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
814,649 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
13%
Manufacturing Company
11%
Government
8%
Manufacturing Company
16%
Computer Software Company
15%
Financial Services Firm
10%
Energy/Utilities Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What do you like most about BeyondTrust Endpoint Privilege Management?
The solution's least privilege enforcement has helped us ensure access is given to only the required people.
What do you like most about SAP Identity Management?
The tool's most valuable features are its access control and approval of access requests. The self-service password reset feature is efficient. Role management capabilities streamline user access b...
What needs improvement with SAP Identity Management?
I have encountered issues with the host authentication feature.
What is your primary use case for SAP Identity Management?
Our clients utilize the tool to automate user provisioning and manage identity, security, and user roles within their IT environment. It is configured as a tenant for this purpose, and it includes ...
 

Also Known As

BeyondTrust PowerBroker, BeyondTrust Endpoint Privilege Management for Windows, BeyondTrust Endpoint Privilege Management for Mac, BeyondTrust Endpoint Privilege Management for Linux, BeyondTrust Endpoint Privilege Management for Unix, Avecto Defendpoint
SAP NetWeaver Identity Management, NetWeaver Identity Management
 

Learn More

Video not available
 

Overview

 

Sample Customers

Aera Energy LLC, Care New England, James Madison University
State of Indiana, Automotive Resources International (ARI), Alliander N.V., Chemion Logistik GmbH, Seoul National University Bundang Hospital (SNUBH)
Find out what your peers are saying about CyberArk, Delinea, One Identity and others in Privileged Access Management (PAM). Updated: November 2024.
814,649 professionals have used our research since 2012.