Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs CyberArk Privileged Access Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Customer Service

Sentiment score
5.3
Cisco ISE support is valued for expertise but criticized for delays, reactive approach, and integration challenges.
Sentiment score
6.5
CyberArk's support is knowledgeable and efficient, but some users face slow initial responses and documentation challenges.
I rate the technical support as one out of ten.
Sometimes it's challenging to identify which support team is responsible for certain issues, which is a significant concern.
They are helpful, but complex issues can take a long time to resolve, which can delay solutions for urgent customer issues.
They do not go into analyzing the issue.
CyberArk's customer service has improved recently and is now very responsive.
 

Room For Improvement

Sentiment score
4.4
Cisco ISE users face challenges with complexity, performance issues, integration, intuitive interface, documentation, and licensing concerns.
Sentiment score
4.6
CyberArk Privileged Access Manager needs UI updates, improved integrations, simpler deployment, better performance, enhanced reporting, and flexible pricing.
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases.
They want everything to be on the cloud, but even in the SaaS version of CyberArk Privileged Access Manager, they need to deploy some servers on-premises.
The graphical user interface could be simplified and harmonized for better usability.
Upgrades require a lot of resources, as it impacts the entire organization.
 

Scalability Issues

Sentiment score
7.1
Cisco ISE offers scalable solutions for diverse enterprises, supporting expansions with additional nodes or licenses for efficient endpoint management.
Sentiment score
7.7
CyberArk Privileged Access Manager scales effectively across environments, though careful planning is needed to avoid potential license issues.
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
I would rate it a nine out of ten for scalability.
We started small and expanded it to an enterprise level, and are now moving to the cloud for further growth.
The SaaS version is more flexible, allowing easier scaling with increased users.
 

Setup Cost

Sentiment score
3.5
Cisco ISE's pricing model is complex and costly, with subscription expenses, though discounts benefit larger clients.
Sentiment score
5.9
CyberArk Privileged Access Manager is costly but comprehensive; careful planning and consultation can optimize costs for larger enterprises.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
Cloud solutions are expensive, while on-prem setups with shared environments are cheaper but not effective.
CyberArk is expensive compared to other products I know.
CyberArk is comparatively expensive compared to other PAM solutions, such as Delinea, especially during renewal.
It is very expensive.
 

Stability Issues

Sentiment score
7.7
Cisco ISE is generally stable, though some face issues during updates; reliability improves with proper configuration and recent versions.
Sentiment score
7.8
CyberArk Privileged Access Manager is stable and reliable, with most issues stemming from human errors or configuration rather than product flaws.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
Proper fine-tuning and expertise ensure the product performs well.
Overall, the stability of the solution is high.
 

Valuable Features

Sentiment score
8.0
Cisco ISE offers robust security and ease of use, integrating AAA management with scalability and improved GUI, enhancing network control.
Sentiment score
8.2
CyberArk Privileged Access Manager offers secure credential storage, session monitoring, and integration to enhance security and compliance efficiency.
The solution is integrated with other Cisco devices and can offer automation for an organization, making deployments more dynamic and providing real-time visibility.
Cisco Identity Services Engine (ISE) is very good at device administration.
CyberArk Privileged Access Manager helps ensure data privacy because we now know who is using which credentials and at what time.
As a security professional, I have real-time visibility into ongoing sessions.
When you give access to a user, it monitors and detects if the user's behavior is unusual.
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
141
Ranking in other categories
Network Access Control (NAC) (1st), Cisco Security Portfolio (1st)
CyberArk Privileged Access ...
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
197
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (3rd), Privileged Access Management (PAM) (1st), Mainframe Security (2nd), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 28.8%, down 31.6% compared to last year.
CyberArk Privileged Access Manager, on the other hand, focuses on Privileged Access Management (PAM), holds 20.9% mindshare, down 23.8% since last year.
Network Access Control (NAC)
Privileged Access Management (PAM)
 

Featured Reviews

Bill Masci - PeerSpot reviewer
Helps across a distributed network, giving you a central way of authenticating everybody
A lot of people tell you the hardware requirements for ISE are pretty substantial. If you're running a virtual environment, you're going to be dedicating quite a bit of resources to an ISE VM. That is something that could be worked on. The upgrade process is not very simple. It's pretty time-consuming. If you follow it step by step you're probably going to have a good time, but there are still a lot of things that could be a lot more user-friendly from an administrator's perspective. [They could be] easing a lot of the issues that people have. Instead of just saying the best practice is to migrate to new nodes [what would be helpful] would be to make that upgrade process easier. The UI is a lot nicer in 3.0. It's pretty slow, but for the most part, it's easy to find what you're looking for, especially things like RADIUS live logs, TACACS live logs. From a troubleshooting perspective, it's really nice finding stuff. For setting up policies, from that perspective, it could be a little bit better looking.
SatishIyer - PeerSpot reviewer
Lets you ensure relevant, compliant access in good time and with an audit trail, yet lacks clarity on MITRE ATT&CK
When I was a component owner for PAM's Privileged Threat Analytics (PTA) component, what I wanted was a clear mapping to the MITRE ATT&CK framework, a framework which has a comprehensive list of use cases. We reached out to the vendor and asked them how much coverage they have of the uses cases found on MITRE, which would have given us a better view of things while I was the product owner. Unfortunately they did not have the capability of mapping onto MITRE's framework at that time. PTA is essentially the monitoring interface of the broker (e.g. Privileged Access Management, the Vault, CPM, PSM, etc.), and it's where you can capture your broker bypass and perform related actions. For this reason, we thought that this kind of mapping would be required, but CyberArk informed us that they did not have the capability we had in mind with regard to MITRE ATT&CK. I am not sure what the situation is now, but it would definitely help to have that kind of alignment with one of the more well-known frameworks like MITRE. For CyberArk as a vendor, it would also help them to clearly spell out in which areas they have full functionality and in which ares they have partial or none. Of course, it also greatly benefits the customers when they're evaluating the product.
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
823,875 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
27%
Computer Software Company
15%
Financial Services Firm
7%
Government
7%
Educational Organization
32%
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
CyberArk Privileged Access Manager comes at a high cost. But the solution is worth its price.
 

Also Known As

Cisco ISE
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Learn More

 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Rockwell Automation
Find out what your peers are saying about Cisco, HPE Aruba Networking, Fortinet and others in Network Access Control (NAC). Updated: November 2024.
823,875 professionals have used our research since 2012.