Try our new research platform with insights from 80,000+ expert users

CyberArk Endpoint Privilege Manager vs VMware Carbon Black App Control comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CyberArk Endpoint Privilege...
Ranking in Application Control
5th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
35
Ranking in other categories
Endpoint Compliance (4th), Privileged Access Management (PAM) (3rd), Anti-Malware Tools (5th), Ransomware Protection (7th)
VMware Carbon Black App Con...
Ranking in Application Control
1st
Average Rating
9.2
Reviews Sentiment
7.1
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of April 2025, in the Application Control category, the mindshare of CyberArk Endpoint Privilege Manager is 3.3%. The mindshare of VMware Carbon Black App Control is 24.6%, down from 32.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Control
 

Featured Reviews

Sumit Chavan - PeerSpot reviewer
Helps secure the infrastructure and control users with admin rights
There are many features that are currently missing. A customization option is required for certain policies. For instance, if we need to stop PowerShell scripting, we have to create a different policy for that. Being able to create a sub-level policy within a top-level policy would be good. Currently, no user-based policy option is available inside the EPM console. We can only create computer-based policies. The database is available, but there is a drawback in not being able to create local groups on the EPM console. We only have to depend on Active Directory. This limits infrastructure security as we depend on the Active Directory team to manage user groups. If they remove any users, we lose control. If we could create groups locally and block them or set specific policies, we would have more control. Local endpoint management is missing from the EPM site. Moreover, there is an issue with policies not running as expected when we make enhancements. We have to find multiple ways to whitelist applications or enhance policies.
AM
We can isolate problem machines and limit their access
We use App Control to scan the network for virtual machines that have unauthorized applications. We can isolate the problem VMs and control application access.  More than two years. I rate Carbon Black App Control 10 out of 10 for stability. I rate App Control six out of 10 for scalability.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Their customer support was excellent."
"CyberArk Endpoint Privilege Manager has significantly improved our security posture by preventing virus incidents and restricting users from downloading unwanted applications."
"Users can scale the solution."
"I like that you can remove the admin rights from the user's computer and have control over the environment. That means you can delete the local admins and grant them proper privileges with the console. So, they will get proper permissions for applications they need, but we don't have to do it. In the domain where we don't have control, the user can only do specified actions, but not all of them."
"CyberArk Endpoint Privilege Manager is very easy to manage, which I like. The solution also has a dashboard where you can see which software is suspicious, which I find valuable."
"The most valuable feature is that it does lifecycle management and that it will change to whatever the end target is."
"The solution's technical support is good."
"This is the number one product for privilege account security."
"The API integration is good."
"The effectiveness of application whitelisting is very good."
"The visibility, reporting, and the ability to stop or prevent malicious or undesired applications from being installed are the most valuable features."
"All the functions within VMware Carbon Black App Control are valuable."
"The visibility is valuable."
"If any malicious activity, like VAT viruses, anything RNE, ZOD malware, or something similar, comes in we know that unless we approve it, it's going to be blocked."
"I use the console to check for threats and I find it to be very user-friendly."
"We use App Control to scan the network for virtual machines that have unauthorized applications. We can isolate the problem VMs and control application access."
 

Cons

"The product is expensive."
"My recommendation for improvement is to add functionality for when users request access to an application. There's a pop-up UI, but it's not very customizable. I suggest creating a UI where we can write scripts or use SDKs to enhance it. This could automatically create tickets in a system like ServiceNow when users request an application. If a manager approves, we could automatically push policies to those users."
"CyberArk Endpoint Privilege Manager is a perfect solution, but CyberArk Endpoint Privilege Manager for Linux has many issues. Another area for improvement in CyberArk Endpoint Privilege Manager, specifically for Windows, is that there's no way for you to check credential theft from a text file, such as a notepad file."
"It cannot be on-prem. It is only cloud-based. Sometimes, that's a restriction in terms of usage."
"Performance could be better. We have a couple of problems with CyberArk right now. One of the problems is performance in our environment. Support also takes a long time to respond. If the user already has local admin rights, then I can't collect any events in the console from this device. There are also some options in CyberArk that are not working properly, and are not helpful in this case. I can't collect any information to create a proper policy for the device. I have to investigate everything manually, or even disable the local admin from the device. I can collect the events only after this, and it's very time consuming. In my case, it's a waste of resources."
"The installation process is pretty difficult."
"They need much better integration with Azure AD."
"CyberArk should consider whitelisting important applications like PowerShell and DLL that are currently not allowed due to some malicious content."
"The solution should have overhead in keeping lists of applications that you want don't want to run."
"Carbon Black does not use the database for identifying the file, the fields, or malware."
"I rate App Control six out of 10 for scalability."
"The initial setup is somewhat complex."
"Another issue is that even sometimes if you approve, for example, Adobe as a publisher, you say any product or anything that's from Adobe has to run. It generally runs, but especially in a large environment and with a lot of users, sometimes, due to some certification validation issues or some other issue, it might stop the process from running. Genuine processes like Adobe and Chrome can get blocked. so that needs to be improved."
"I would like to see the addition of some more features that are in other, similar solutions."
"Its setup is very complex, and it requires guidance from the support team, but it is well worth the effort."
"The reporting is not good and needs to be improved."
 

Pricing and Cost Advice

"licensing for this solution is based on the number of APV (privileged users), and the number of sessions that you want to record."
"I rate the solution's pricing an eight out of ten since the price can be too high for smaller businesses."
"The tool's pricing is reasonable for customers."
"The tool is a bit pricey compared to its competitors. My company does work with competitors, but I don't have hands-on experience with other software. I've just done some comparisons."
"The price of CyberArk Endpoint Privilege Manager is expensive. The solution is priced based on the number of accounts onboarded and the number of concurrent sessions. Everyone else is included in the price, such as support."
"I think that it was in the range of $200,000 that had to get approved."
"The price of CyberArk Endpoint Privilege Manager is expensive."
"I feel that the price of the product is nominal. It must be around 10 to 15 USD per installation. I rate the product price an eight to nine out of ten, where one is high price, and ten is low price."
"The pricing for this product is competitive and our customers who told us that often, Carbon Back is the cheaper solution."
"Its price is reasonable and what is expected for these types of products."
"We pay a fee for support, which is renewed annually."
report
Use our free recommendation engine to learn which Application Control solutions are best for your needs.
845,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
11%
Government
8%
Educational Organization
52%
Computer Software Company
7%
Financial Services Firm
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What do you like most about CyberArk Endpoint Privilege Manager?
The most valuable feature of the solution is its performance.
What is your experience regarding pricing and costs for CyberArk Endpoint Privilege Manager?
CyberArk Endpoint Privilege Manager is slightly expensive, but costs can be negotiated to become more competitive.
What do you like most about VMware Carbon Black App Control?
We use App Control to scan the network for virtual machines that have unauthorized applications. We can isolate the problem VMs and control application access.
What is your primary use case for VMware Carbon Black App Control?
We use App Control to scan the network for virtual machines that have unauthorized applications. We can isolate the problem VMs and control application access.
 

Also Known As

Viewfinity
CB Protection, Carbon Black CB Protection
 

Overview

 

Sample Customers

Information Not Available
Kaas Tailored, Core-Mark, Indeed, Hologic, Landmark Credit Union, Project Worldwide
Find out what your peers are saying about CyberArk Endpoint Privilege Manager vs. VMware Carbon Black App Control and other solutions. Updated: March 2025.
845,406 professionals have used our research since 2012.