Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs NetIQ Identity Governance comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Number of Reviews
139
Ranking in other categories
Network Access Control (NAC) (1st), Cisco Security Portfolio (1st)
NetIQ Identity Governance
Average Rating
8.0
Number of Reviews
9
Ranking in other categories
Identity Management (IM) (25th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and NetIQ Identity Governance aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 29.2%, down 31.6% compared to last year.
NetIQ Identity Governance, on the other hand, focuses on Identity Management (IM), holds 0.6% mindshare, up 0.6% since last year.
Network Access Control (NAC)
Identity Management (IM)
 

Featured Reviews

Rohit-Joshi - PeerSpot reviewer
Aug 3, 2023
Enables us to ensure that any machine that comes into the network is patched and secure
Posturing is the most valuable feature. There are other tools available that can do some of their other features, like network authentication. The posturing was something because of the nature of the industry that we are in. There are people who go outside for work. Their machines are at times not in the network, and not patched properly. We don't know when they're going to come back, whether it is in a good state, whether it has antivirus, whether it's installed on those machines. Posturing is something that we have made our baseline policy that whenever a machine comes back to our network, it should have a certain level of the operating system and a level of security and antivirus installed. We couldn't have done this posturing without Cisco ISE. This is its greatest feature. It does help me to detect and remediate my network. It enables me to detect any external threat that comes to my network and remediate. If a machine comes into my network that does not qualify per my baseline policy, I have a policy that the machine gets redirected to where it can be patched and remediated. I can ensure that it is fully patched and secure. The entire idea of having ISE is to enhance cybersecurity resilience. The zero trust architecture was coined by the cybersecurity team itself. It was a task given to us in the infrastructure space to see how we can bring resilience into the cybersecurity network and ISE was the solution.
JoelHercik - PeerSpot reviewer
Nov 30, 2022
A mature, capable solution that should be available as a cloud solution
They haven't really evolved the product to the cloud, so they don't have a cloud solution. It's just deployable in the cloud, so in some cases that holds them back in a competitive situation. I don't know if they're intent on taking their solution to the cloud, but if they do, that would be one improvement. It would allow them to be competitive down market in medium to small enterprises. I don't know if they care to address that market or not because it doesn't seem like they've made that move, but that would be one way for them to do that. As for additional features, I would suggest stronger integration. I think enabling more universal industry standard integrations would probably help them with different applications.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"A lot of customers use a third party to manage their guest Wi-Fi. Cisco ISE presents the ability to bring that in-house so that customers can have full control over it, change the branding, and get extra telemetry from it and the user data. It works really well for our customers."
"I love the policy sets, they are really nice and dynamic."
"The integration with Active Directory is the most valuable feature for us."
"The return on investment we have seen is related to time in terms of troubleshooting. The logs, such as the security logs, inform us of the issues that people have had. ISE has been very instrumental in helping isolate those issues. We've seen a lot of cost savings because we don't have to pay an IT person to waste time doing something that should be instantaneous."
"The posture assessment is a valuable feature because of the ability to do assessments on the clients before they connect to the network."
"It's scalable."
"It does a good job of establishing trust for each access request, no matter the source. It's also very effective at helping with the distributed network and at securing access."
"I have found that all of the features are valuable. It is very easy to deploy because we are able to port users directly from Active Directory (AD) and LDAP."
"NetIQ Identity Governance has improved the security of my company."
"This solution has been around for a long time. It has had lots of successful deployments and releases."
"We’re very satisfied with technical support. Usually we get people with the right knowledge who understand the solution very well."
"I like the queries and find the catalog to be comparatively powerful."
"You can run reports and verify the access each user has. There is a process that runs automatically for access review. It sends an email to the manager and provides a task for the manager to review the users and access. The manager can approve or reject, and then it goes to the application owner for further review. This feature is especially important in large customer environments, as manual review can be challenging."
"When doing a review you can either make manual or automatic fulfillment to immediately apply the manager's decision to the system, like removing or adding new permissions to the user account."
"I really like the separation of the duties. It is the most ambitious model in the server because you have to create all the different rules, especially business rules. You have to check with the client and set different policies and rules, and then, you to have refine them. You will notice what is bad in the company and where the real problem is."
"All three functionalities, access certification, the configuration of duties, and role mining - especially role mining - are very advanced compared with the competition."
 

Cons

"It should be virtualized because many people have begun migrating to the cloud. They should offer a hybrid version."
"I don't see as many customers as I should adopting the onboarding feature. I think Cisco should make that process a lot easier and less intrusive on the end users' devices."
"There should be a single button that can be pressed to dismiss all of the alarms at once."
"The installation is not straightforward, it took us approximately one month."
"There are issues with respect to the posture assessment function. It's been observed that customers are not receiving total access to the network because the assessment agent is glitchy and malfunctions from time-to-time. I would like to see refining of the compliance assessment and adding more detailed compliance of endpoints on the user end."
"The area where things could be improved is education. It's complicated to deploy initially because you have to know what you're getting into."
"The policies could be adjusted to make them more easily implementable."
"In the next release, I would want to see this kind of solution in the cloud as opposed to on prem because when enhancements are made to the software, if it's in the cloud, it's overnight. I mean you're not going to have to respin the servers that the license sits on, it's all microservices kinds of things in the cloud. That would be my recommendation. If I'm a customer, that's what I'm looking at - for cloud based software subscriptions."
"With NetIQ, you have to install two or more products. It would be better if we could install one product and have one server and one dashboard."
"The solution should provide more connectors in future releases. The solution also should offer more monitoring."
"They haven't really evolved the product to the cloud, so they don't have a cloud solution."
"NetIQ Identity Governance is not flexible. Sometimes, filtering information to provide users with options, such as selecting the application to which they want to request access, can be challenging. It needs to improve application integration as well."
"Technical support is horrible."
"The product could use more advanced features related to Identity Intelligence."
"We need more connectors to cloud applications like AWS."
"The initial setup has room for improvement."
 

Pricing and Cost Advice

"The price of Cisco ISE (Identity Services Engine) is expensive and we are thinking about changing to FortiGate."
"For the Avast virus scan, we pay around USD $95 per machine for five years which includes all updates and technical support."
"The licensing is subscription-based and based on the user account."
"Cisco is expensive, but it's the cost for all the functions and value it brings. Functions like internet solutions, integrations, security, and many more features are important, but it's expensive for some clients."
"It's damn expensive and the licensing is terrible... If you have perpetual licenses on 2.7 and you upgrade to 3, you are forced to go with Essentials. That is one of the issues that I'm seeing with my clients now."
"I am not aware of the current price for Cisco ISE, but considering it is a Cisco product, it is likely to be quite high."
"Previously, Cisco ISE had a perpetual licensing model, but now they have shifted to a subscription-based licensing system."
"Its price is probably good if you use all of its features and functionalities to protect your environment. If you use only a part of the functionality, its price is too high. It is just a question of value and the functionality you use."
"In terms of pricing, the tool seems a bit cheaper compared to other SaaS solutions."
"It's expensive relative to the cloud solutions that are out there."
"I give the cost a nine out of ten."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
814,649 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
26%
Computer Software Company
16%
Financial Services Firm
7%
Government
7%
Computer Software Company
29%
Financial Services Firm
16%
Manufacturing Company
10%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What do you like most about NetIQ Identity Governance?
You can run reports and verify the access each user has. There is a process that runs automatically for access review. It sends an email to the manager and provides a task for the manager to review...
What needs improvement with NetIQ Identity Governance?
NetIQ Identity Governance is not flexible. Sometimes, filtering information to provide users with options, such as selecting the application to which they want to request access, can be challenging...
What is your primary use case for NetIQ Identity Governance?
I use NetIQ Identity Governance to certify access.
 

Also Known As

Cisco ISE
NetIQ Access Governance Suite, Novell Access Governance Suite
 

Learn More

 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Western & Southern Financial Group
Find out what your peers are saying about Cisco, HPE Aruba Networking, Fortinet and others in Network Access Control (NAC). Updated: October 2024.
814,649 professionals have used our research since 2012.