No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Identity Services Engine (ISE) vs IBM Security Identity Governance and Intelligence comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Network Access Control (NAC) (2nd), Cisco Security Portfolio (4th)
IBM Security Identity Gover...
Average Rating
7.6
Reviews Sentiment
6.7
Number of Reviews
2
Ranking in other categories
User Provisioning Software (15th), Identity Management (IM) (30th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and IBM Security Identity Governance and Intelligence aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 19.4%, down 25.8% compared to last year.
IBM Security Identity Governance and Intelligence, on the other hand, focuses on User Provisioning Software, holds 2.9% mindshare, up 1.9% since last year.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)19.4%
Aruba ClearPass18.5%
Fortinet FortiNAC14.5%
Other47.6%
Network Access Control (NAC)
User Provisioning Software Mindshare Distribution
ProductMindshare (%)
IBM Security Identity Governance and Intelligence2.9%
SailPoint Identity Security Cloud19.3%
One Identity Manager9.5%
Other68.3%
User Provisioning Software
 

Featured Reviews

NF
Network and Technology Information Manager at Akkodis
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
reviewer1830612 - PeerSpot reviewer
Head, Cybersecurity at a tech services company with 11-50 employees
We use the solution to ensure organizations conform to industry base certifications and best practices
We use the product to ensure organizations conform to industry base certifications and best practices and do not contradict their security policies within the base points they specify in the system, which are used to match everything against their governance use cases I think the product's most…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"After the product was installed, no one could access the secure connection network; in order for any laptop or any endpoint device to attach to my network, it needs to be authorized or be certified to be connected."
"For my use cases, the in-depth troubleshooting into why a client can't connect or why they failed, is very valuable. I can go back to someone and say, 'Hey, it's not my network. It's their certificates or user error,' or something else."
"The policy sets give us more granular groups for end-user access."
"Among the most valuable features is TACACS."
"By implementing ISE, it can lighten the overhead of the Cisco Catalyst Switches by not implementing port security, Dynamic Arp Inspection, DHCP Snooping, and this will also improve the switch's performance since the ISE server takes over the duty of posturing with its Policy Service Node persona."
"In terms of scalability, you need to factor in your licenses. With a virtual platform, the scalability is more than sufficient. We have over one thousand users."
"The solution offers automation and real-time visibility, which aids in monitoring and troubleshooting issues with endpoints."
"The feature that I most like is that it can notify me whenever someone plugs in their device, which is not allowed, and I get notifications for new laptop devices."
"We use the product to ensure organizations conform to industry base certifications and best practices and do not contradict their security policies within the base points they specify in the system, which are used to match everything against their governance use cases."
"Lifecycle management, governance and documentation."
"This solution has a very good dashboard and the documentation is also very good, and life cycle management and governance are also good features in this solution."
"I would rate the price eight out of 10, with 10 as the best value for money."
 

Cons

"Migration could be better. Right now, we back up with the new version, and it requires a lot of licensing and other things."
"I'd like to see an easier way to upgrade to larger versions, as well as more best practices that are easier to locate on their support page."
"The UI is not as intuitive as some other products, even products inside of Cisco's wheelhouse."
"The web UI should be made similar to the one in DNAC."
"Cisco ISE is very complex and not very easy to deploy."
"Cisco ISE has numerous features that are impractical, and I won't utilize them since they require payment."
"Whenever we see the authentication logs, we can't see what device we're logging into... We can see who logged in, but we can't see the IP address of the device... I'm sure that's available. We just haven't figured out how to properly deploy it."
"Cisco ISE's performance could be better, faster, and more robust."
"The solution is also a bit pricey for the Nigeria region."
"The solution is a bit pricey for some regions."
"I think improvements could be made in the self service center, making it easier for the user to understand."
"Self service center is not always easy to understand."
 

Pricing and Cost Advice

"Hardware appliances are expensive...Now moving to DNA-styled licensing, we have subscription-based licensing for everything. I hope it will continue to be fair, but we will have to wait and see."
"I believe I have paid around $1,000 in licensing fees. The license is annual."
"There is a license to use this solution and the price is reasonable."
"The recent changes in the licensing model have caused some issues with the team."
"If you're not going through an agreement, it's very expensive."
"Cisco is expensive, but it's the cost for all the functions and value it brings. Functions like internet solutions, integrations, security, and many more features are important, but it's expensive for some clients."
"That's where things got a bit more complicated. Previously, it was a one-time purchase and we just had to renew support. These days, there's a subscription model, which is supposed to be easier and cheaper as well, but it's more pricey"
"Being fully honest, the Cisco licensing model right now is really confusing. We don't know what licenses we have where. We have Smart licensing, but the different levels are way confusing."
"I would rate the price eight out of 10, with 10 as the best value for money."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
896,099 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
10%
Government
7%
Computer Software Company
7%
Construction Company
15%
Government
12%
Financial Services Firm
11%
Computer Software Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
No data available
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
Ask a question
Earn 20 points
 

Also Known As

Cisco ISE
IGI, IBM Security Identity Manager, ISIM
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
E.ON Global Commodities
Find out what your peers are saying about Hewlett Packard Enterprise, Cisco, Fortinet and others in Network Access Control (NAC). Updated: May 2026.
896,099 professionals have used our research since 2012.