Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs ForgeRock comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
144
Ranking in other categories
Network Access Control (NAC) (1st), Cisco Security Portfolio (2nd)
ForgeRock
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
30
Ranking in other categories
Identity Management (IM) (14th), Access Management (12th), Customer Identity and Access Management (CIAM) (7th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and ForgeRock aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 24.2%, down 29.5% compared to last year.
ForgeRock, on the other hand, focuses on Access Management, holds 6.8% mindshare, up 5.6% since last year.
Network Access Control (NAC) Market Share Distribution
ProductMarket Share (%)
Cisco Identity Services Engine (ISE)24.2%
Aruba ClearPass23.6%
Fortinet FortiNAC17.9%
Other34.30000000000001%
Network Access Control (NAC)
Access Management Market Share Distribution
ProductMarket Share (%)
ForgeRock6.8%
Microsoft Entra ID24.0%
Auth08.4%
Other60.8%
Access Management
 

Featured Reviews

SunilkumarNaganuri - PeerSpot reviewer
Enhanced device administration hindered by complex deployment and security limitations
Cisco Identity Services Engine (ISE) needs to improve the profiling preauthentication. They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases. This will give them a roadmap for software-defined access (SDA) use cases and network segmentation. Threat detection capabilities are very weak. Additionally, the product is vulnerable and has many bugs.
Ahmet Murat Ülker - PeerSpot reviewer
Easy to use, but customizations can be complicated to handle
I would suggest others use the product after asking them to consider their use cases. SSO may be a use case for some, and using the product as an IDM tool may be a use case. At the moment, my company is not deploying all the components of ForgeRock itself. My company uses ForgeRock for OAuth 2.0. For example, my company is not deploying the IDM and identity gateway components. You should consider your use case and select the required components for that use case. My company does not use the SSO features of the tool. My company uses SSO to access ForgeRock's AM Console for individual users. My company does not use single sign on features of the product and instead, we use Auth0. I rate the tool a seven or eight out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The ability to allow or deny hosts onto the network is valuable. It provides great security to the network environment."
"When you push out the policy, it is able to populate the entire network at one time."
"The posture assessment is a valuable feature because of the ability to do assessments on the clients before they connect to the network."
"The policy sets give us more granular groups for end-user access."
"We have seen ROI. It has done its job. It has protected us when we needed it to."
"We found all the features of the product to be valuable."
"It has allowed us to pull in multiple authentication databases, then centralize them into a captive portal system."
"With NAC, the profiling feature is valuable. We're able to see what we have out there in the network and dynamically assign policies to it. We can then use that to enforce TrustSec policy or anything else with NAC."
"We used it to implement multi-factor authentication and to improve our security posture as well as reducing the potential for attacks."
"We create and define the permissions and configurations for the users."
"ForgeRock products are customizable, and the out-of-the-box features are solid, too. I primarily use the OIDC compliance features. It's just a configuration. it's easy to set up and customize trees. We can add our own features if necessary. Banks and corporations have different standards and specific validations."
"ForgeRock has CIAM, which other products didn't have, and they have DevOps ready."
"ForgeRock is an extensive product with many functionalities and capabilities, much more than many other tools combined."
"The most valuable features of ForgeRock are social login and data protection."
"Even though we have very small business interests with them today, they see that we plan on growing drastically over the next two years. Therefore, we have excellent support and we are now at a point where we are not calling tech support. We pick up a phone and call the Account Manager and they'll get everything resolved for us. We don't have to queue along with everybody else and go through a long process."
"I like the intelligent authentication feature."
 

Cons

"There is room for improvement in its ability to allow end users to self-enroll their devices. Instead, you should be able to assign that permission by AD group, which is currently not available."
"The Cisco wireless​ controller needs to add more than one physical port."
"There are always some things that I would request."
"Whenever we see the authentication logs, we can't see what device we're logging into... We can see who logged in, but we can't see the IP address of the device... I'm sure that's available. We just haven't figured out how to properly deploy it."
"ISE is a little clunky. The front-end feels like it is from the 1980s."
"The product is expensive. It would also be a good add-on to have some machine learning."
"The web UI should be made similar to the one in DNAC."
"It is too complex. It should be easy to use. We are not such a big team. We only have three engineers to work with this, and we don't use all of the functionality of the product. Its range of functionality is too wide for us, and this is the reason why we are thinking of switching to a more simple product. We have shortlisted a Microsoft solution. We have a big footprint for Microsoft products, especially in security. As a global strategy, we try to leverage to the maximum what is possible around Microsoft."
"I find that it's quite expensive for just an open-source system. Support is quite expensive."
"The solution's deployment should be made easier."
"The identity management model needs a bit of improvement."
"The solution requires more simplified customization. However, part of the problem is my clients determining their own preferences. Technology can help and do many things, but you have to define your own policies to ensure that the solution or service works within those parameters. Helping customers understand their business and different processes is another issue not relating to the functionality of this solution."
"The solution could improve by adding more advertising and marketing."
"In an upcoming release, the solution could improve by limiting the need to do customizations."
"It should be a little bit easier to implement. It is user-friendly, but there is always scope for improvement."
"ForgeRock is an open source solution and is available to everyone but it is not freeware. If you need support, you need a subscription for ForgeRock. Many of its functionalities need to be built up with the help of a consultant."
 

Pricing and Cost Advice

"The solution’s pricing is okay."
"For the Avast virus scan, we pay around USD $95 per machine for five years which includes all updates and technical support."
"The price can be lower, especially for subscriptions. It should be a lot cheaper to have a wide range of customers. The price should be comparable to competitive products like Forescout or Fortinet FortiNAC. Forescout is cheaper for customers looking for a cloud solution."
"I believe I have paid around $1,000 in licensing fees. The license is annual."
"Cisco ISE is not inexpensive, but the solution is well-built and worth the expense."
"This solution requires an annual license and it is a bit expensive than competitors."
"In general, licensing can be quite complex with Cisco products. It would be nice if it was a bit more intuitive and had fewer "gotchas" in there."
"The solution is not that cheap."
"The pricing of the solution is fair but I do not have the full details."
"ForgeRock's pricing is more competitive than other products."
"Its licensing is on a yearly basis, but it also depends on the contract that you have with the vendor. They have multiple types of contracts. There are additional costs to the standard licensing fees. If you need some of the features, you have to pay more."
"ForgeRock is an expensive solution."
"It's a bit pricey and could be more competitive."
"The license is purchased annually per user. However, you can negotiate if you are signing for a longer period of time. When comparing this solution to others on the market it is priced fair, it is not at the top of the price range or at the bottom end."
"Its price is comparable to other products in the market."
"We have multiple clients we are looking at right now. We are at a very small number, however, the idea and the goal is to grow. We are looking at about $100,000 and $50,000 a minimum a month cost. That'd be minimum maybe in a couple of years."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
872,029 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Manufacturing Company
10%
Financial Services Firm
9%
Government
9%
Financial Services Firm
23%
Computer Software Company
11%
Manufacturing Company
8%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise31
Large Enterprise91
By reviewers
Company SizeCount
Small Business13
Midsize Enterprise4
Large Enterprise13
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What do you like most about ForgeRock?
The most valuable features of ForgeRock are social login and data protection.
What is your experience regarding pricing and costs for ForgeRock?
Our company was considering switching back to Keycloak from ForgeRock, so as to not pay any license fees. ForgeRock also supports M-PIN and biometric features that Keycloak does not provide. My com...
What needs improvement with ForgeRock?
In the past, I saw that Splunk was integrated with a testing portal, and then it was integrated with Slack. I don't think ForgeRock directly supports integrations with Slack, making it an area wher...
 

Also Known As

Cisco ISE
ForgeRock Identity Platform, ForgeRock OpenIDM
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Geico, Thomson Reuters, Salesforce, McKesson, Trinet, SKY, BNP Paribas, Deloitte, Capgemini, North Western University
Find out what your peers are saying about Cisco, Hewlett Packard Enterprise, Fortinet and others in Network Access Control (NAC). Updated: October 2025.
872,029 professionals have used our research since 2012.