Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs ForgeRock comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
143
Ranking in other categories
Network Access Control (NAC) (1st), Cisco Security Portfolio (2nd)
ForgeRock
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
30
Ranking in other categories
Identity Management (IM) (13th), Access Management (10th), Customer Identity and Access Management (CIAM) (7th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and ForgeRock aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 24.5%, down 30.0% compared to last year.
ForgeRock, on the other hand, focuses on Access Management, holds 7.5% mindshare, up 6.8% since last year.
Network Access Control (NAC) Market Share Distribution
ProductMarket Share (%)
Cisco Identity Services Engine (ISE)24.5%
Aruba ClearPass23.9%
Fortinet FortiNAC18.0%
Other33.599999999999994%
Network Access Control (NAC)
Access Management Market Share Distribution
ProductMarket Share (%)
ForgeRock7.5%
Microsoft Entra ID24.8%
Auth09.2%
Other58.5%
Access Management
 

Featured Reviews

SunilkumarNaganuri - PeerSpot reviewer
Enhanced device administration hindered by complex deployment and security limitations
Cisco Identity Services Engine (ISE) needs to improve the profiling preauthentication. They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases. This will give them a roadmap for software-defined access (SDA) use cases and network segmentation. Threat detection capabilities are very weak. Additionally, the product is vulnerable and has many bugs.
Ahmet Murat Ülker - PeerSpot reviewer
Easy to use, but customizations can be complicated to handle
I would suggest others use the product after asking them to consider their use cases. SSO may be a use case for some, and using the product as an IDM tool may be a use case. At the moment, my company is not deploying all the components of ForgeRock itself. My company uses ForgeRock for OAuth 2.0. For example, my company is not deploying the IDM and identity gateway components. You should consider your use case and select the required components for that use case. My company does not use the SSO features of the tool. My company uses SSO to access ForgeRock's AM Console for individual users. My company does not use single sign on features of the product and instead, we use Auth0. I rate the tool a seven or eight out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"They have recently made a lot of improvements. My clients don't have much to complain about."
"There are a lot of integrations available with multiple vendors. This has made the solution easier to work with."
"The solution offers automation and real-time visibility, which aids in monitoring and troubleshooting issues with endpoints."
"We were originally a Cisco shop and Cisco ISE integrated well with our other Cisco switches and networks."
"I love the policy sets, they are really nice and dynamic."
"The live logs and live sessions for troubleshooting are the most valuable features because they provide a detailed report of any issues."
"Improves switch account management."
"The solution cuts down on the repercussions of getting malware or ransomware."
"In terms of the tool's operational efficiency, ForgeRock Access Management is used in a lot of environments, different regions, and in different stages of production environments."
"The most valuable features of ForgeRock are social login and data protection."
"I like the intelligent authentication feature."
"It works very well, especially in Identity and Access Management. It helps detect anomalies in user behavior patterns."
"Installation and configuration are pretty easy for ForgeRock OpenIDM."
"The product is easy to use in a development environment."
"The solution's most valuable feature is the authentication for the consumers. The integration with other third-party applications is excellent."
"ForgeRock is an extensive product with many functionalities and capabilities, much more than many other tools combined."
 

Cons

"Cisco ISE requires a lot of time-consuming administration."
"It should be virtualized because many people have begun migrating to the cloud. They should offer a hybrid version."
"The integrations with the switches and the wireless controllers are not really straightforward. There is what they call the best practice for them, but it may not be what we have on-premise."
"I would like to see them simplify the dashboard. It's very configurable, but, at the same time, it's not easy to maneuver through it. They should "Merakify" it."
"Cisco ISE does not recognize devices and that is an issue we faced during its integration with our existing devices."
"I don't see as many customers as I should adopting the onboarding feature. I think Cisco should make that process a lot easier and less intrusive on the end users' devices."
"If Cisco could grant more control, the features could be more focused on network and security administration, reducing the need for integration with other components."
"It would be ideal if Cisco could provide some short training videos or documentation to customers to help them understand how to use the product."
"I don't think ForgeRock directly supports integrations with Slack, making it an area where improvements are required."
"We're worried about the scaling. We're told it will be okay and there won't be issues, however, I'm not 100% convinced."
"I think the upgrade process is sometimes a little complicated and there are failures that occur."
"They should improve the solution by include reporting."
"In an upcoming release, the solution could improve by limiting the need to do customizations."
"The solution's documentation is not very good, and they do not give more details."
"We would like this solution to be developed for use with mobile applications."
"It should have a better user interface. Its flexibility should also be improved. It is not about simplifying; it is more about flexibility. Each company has its own requirements, and ForgeRock can provide more flexibility in terms of the use of existing modules to implement features for the customers."
 

Pricing and Cost Advice

"The pricing is complicated."
"It would be beneficial to have a single license that included all of the features."
"There are other cheaper options available."
"ISE has always been expensive compared to other products in terms of what it does on a user level."
"If you consider money only, Cisco ISE is not a cheap solution."
"The Essentials licensing is reasonable, but I would like the Premier version to be perpetual instead of a subscription."
"Over the years, licensing has been confusing and complicated because there are so many different licenses for each different product and each different iteration of the product."
"It has a fair price. It is better than it was before."
"The license is purchased annually per user. However, you can negotiate if you are signing for a longer period of time. When comparing this solution to others on the market it is priced fair, it is not at the top of the price range or at the bottom end."
"We have multiple clients we are looking at right now. We are at a very small number, however, the idea and the goal is to grow. We are looking at about $100,000 and $50,000 a minimum a month cost. That'd be minimum maybe in a couple of years."
"It's a bit pricey and could be more competitive."
"The pricing of the solution is fair but I do not have the full details."
"Its licensing is on a yearly basis, but it also depends on the contract that you have with the vendor. They have multiple types of contracts. There are additional costs to the standard licensing fees. If you need some of the features, you have to pay more."
"ForgeRock is an expensive solution."
"ForgeRock's pricing is more competitive than other products."
"Its price is comparable to other products in the market."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
867,676 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
9%
Manufacturing Company
9%
Government
9%
Financial Services Firm
23%
Computer Software Company
12%
Manufacturing Company
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business43
Midsize Enterprise31
Large Enterprise90
By reviewers
Company SizeCount
Small Business13
Midsize Enterprise4
Large Enterprise13
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What do you like most about ForgeRock?
The most valuable features of ForgeRock are social login and data protection.
What is your experience regarding pricing and costs for ForgeRock?
Our company was considering switching back to Keycloak from ForgeRock, so as to not pay any license fees. ForgeRock also supports M-PIN and biometric features that Keycloak does not provide. My com...
What needs improvement with ForgeRock?
In the past, I saw that Splunk was integrated with a testing portal, and then it was integrated with Slack. I don't think ForgeRock directly supports integrations with Slack, making it an area wher...
 

Also Known As

Cisco ISE
ForgeRock Identity Platform, ForgeRock OpenIDM
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Geico, Thomson Reuters, Salesforce, McKesson, Trinet, SKY, BNP Paribas, Deloitte, Capgemini, North Western University
Find out what your peers are saying about Cisco, Hewlett Packard Enterprise, Fortinet and others in Network Access Control (NAC). Updated: August 2025.
867,676 professionals have used our research since 2012.