Try our new research platform with insights from 80,000+ expert users
it_user181038 - PeerSpot reviewer
Enterprise Security Architect at a tech services company with 51-200 employees
Consultant
SSO capabilities over various technologies is a strength of this product but the federation capabilites are very limited

What is most valuable?

Centralized policy management and reverse proxy-based architecture make it very flexible in terms of deployment, adoption, and implementation. SSO capabilities over various technologies is another strength of this product.

How has it helped my organization?

This product enhanced the overall security at perimeter and improved user experience via SSO. A central place for policy and credentials simplifies the authentication over application landscape.

What needs improvement?

The product has not been updated with emerging technologies over the years specifically around AJAX, REST and Mobile app integration. Also the federation capabilites are very limited.

For how long have I used the solution?

I have deployed this product at various clients over the last 10 years.

Buyer's Guide
IBM Tivoli Access Manager [EOL]
January 2025
Learn what your peers think about IBM Tivoli Access Manager [EOL]. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.

What was my experience with deployment of the solution?

Initial deployment of the product is always critical and issues do come up but not due to limitation in the product. Most of the issues were around bad planning or incorrect deployment.

What do I think about the stability of the solution?

No, there were bugs identified many times but mostly they were fixed via patch release or a workaround was offered.

What do I think about the scalability of the solution?

No, if deployed correctly it is highly scalable product.

How are customer service and support?

Customer Service:

Fantastic customer service from IBM.

Technical Support:

Technical support is good as you can raise issue any time and based on criticality of the issue IBM can provide support immediately. In some cases even on-premise support is also available.

Which solution did I use previously and why did I switch?

A home grown solution was replaced by ISAM to change and configure SSO quickly for applications and at the same time using a scalable product was other major consideration.

How was the initial setup?

The initial setup is always complex due to number of applications and user base involved. As the product is a front door for all applications this is very critical and complex setup. Also due to internal and external users and multiple authentication mechanisms involved for different type of users it gets complicated.

What about the implementation team?

IBM team was used for the initial deployment and support and the support provided by them was fantastic. They offer quality consultants all across the globe with short notice.

Which other solutions did I evaluate?

Yes, it was compared with Siteminde.

What other advice do I have?

This is a great product with proven history. A little better planning is required before deploying it. Given the change in web technologies and SSO protocols it might be better to check other products in market too.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user177240 - PeerSpot reviewer
it_user177240Tivoli Access Manager SME at a government with 1,001-5,000 employees
Real User

CA site-minder used to be he major competitor. With ISAM 9 IBM products still lead the market.

Products that supports newer technologies mainly OAuth2, SAML2 are likely to be popular in future.

If you do not need reverse proxy it is also possible to configure Apache HTTP server (free) with some LDAP (may be free available) and configure J2EE authorization from application server.

Reverse proxies add lot of features and flexibility and comes will a huge price tag.

See all 4 comments
PeerSpot user
Tivoli Access Manager SME at a government with 1,001-5,000 employees
Real User
Easy integration with existing web applications however the Redundant Policy servers had to be manually configured.

Valuable Features

Scalability and the easy integration with existing web applications with no or minimal change to applications.

Improvements to My Organization

Tivoli Access Manger lets you separate security from applications and manage at one place. Several applications can be rolled into to the same security model.

Room for Improvement

Redundant Policy servers had to be manually configured using LB.

Use of Solution

12 years.

Deployment Issues

No

Stability Issues

No

Scalability Issues

No

Customer Service and Technical Support

Customer Service:

Excellent.

Technical Support:

Excellent.

Initial Setup

It is straightforward. However it also takes experience to roll out this product.

Implementation Team

We used a vendor team and they were excellent.

Other Solutions Considered

CA Siteminder was considered.

Other Advice

ISAM 8.0 the new version of Tivoli Access Manager may be considered for large web security implementations.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
IBM Tivoli Access Manager [EOL]
January 2025
Learn what your peers think about IBM Tivoli Access Manager [EOL]. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
it_user711612 - PeerSpot reviewer
Senior Consultant at a insurance company with 1,001-5,000 employees
Vendor
Reverse proxy provides central control over authentication and authorization.
Pros and Cons
  • "The integration effort with the end application is quite straightforward and easy."
  • "Multi-factor authentication with social integration needs to improve."

How has it helped my organization?

It is a single product that caters for all the business needs throughout the organization. It provides a seamless integration that in turn encourages most of the applications to use the SSO features.

What is most valuable?

Reverse proxy is the most valuable feature as it provides central control over authentication and authorization. The integration effort with the end application is quite straightforward and easy.

What needs improvement?

Multi-factor authentication with social integration needs to improve.

What do I think about the stability of the solution?

There were no stability issues.

What do I think about the scalability of the solution?

There were no scalability issues.

How are customer service and technical support?

An acceptable prompt response is received from the technical team depending on the severity of the issue.

Which solution did I use previously and why did I switch?

More features were found in this product compared to the previous solution that we were using.

How was the initial setup?

It needs quite a lot of time to design the architecture and properly layout the deployment for the high availability setup.

Which other solutions did I evaluate?

We looked at a couple of other products namely CA and Oracle.

What other advice do I have?

Properly understand the requirement and deploy the application correctly as the product comes with a vast number of features, that we might not use unless we don't check wisely.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user185811 - PeerSpot reviewer
Information Security Engineer with 1,001-5,000 employees
Vendor
Logging needs improvement.

What is most valuable?

Identity management

How has it helped my organization?

We have managed to automate the creation of all employees, and the company's clients and then assign the accounts/accesses according to business need.

What needs improvement?

TIM logging

For how long have I used the solution?

Three and a half years.

What was my experience with deployment of the solution?

Little issues that were quick to resolve. I don't understand why they have to separate the deployment, as I have used other products that make the deployment as easy as possible.

What do I think about the stability of the solution?

Never.

What do I think about the scalability of the solution?

Never.

How are customer service and technical support?

Good.

Which solution did I use previously and why did I switch?

I have only ever used this product.

How was the initial setup?

The initial set-up is a bit complex for a novice as the Linux version of it needs you to be somewhat good with Linux. There are certain OS requirements which if you are not familiar with Linux, you going to struggle a bit.

What about the implementation team?

Through a vendor team, and their level of expertise was very high.

Which other solutions did I evaluate?

No other options were evaluated.

What other advice do I have?

It is a very good product to implement.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user3222 - PeerSpot reviewer
Manager of System Security with 501-1,000 employees
Vendor
A strong part of an integrated IAM stack

Valuable Features:

Tivoli Access Manager (or IBM Security Access Manager) is a fully featured web authentication, sso and authorization product.The product supports multiple user information repositories and also integrates with a variety of strong authentication solutions.Supports reverse proxy as well as adapters placed directly on web servers and app servers.Later product versions supports fine grained authorization as well as XACML based authorization configuration. The DP integration provides support for authn and authz for web services.

Room for Improvement:

Complex to install and run. Requires the full IBM stack to reach full potential.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user628068 - PeerSpot reviewer
Application Development Team Lead at a tech services company with 1,001-5,000 employees
Consultant
It is a secure way of accessing clients through various application portals.

What is most valuable?

  • Simplified architecture
  • Security

How has it helped my organization?

It is a totally secure way of accessing clients through various application portals for more than ten EU countries, just by using single sign-on. Moreover, its EAI makes customization easier with the Java/J2EE Applications.

What needs improvement?

  • Multi-source authentication
  • Common configs: These need to be moved into a single config file at the appliance level

For how long have I used the solution?

I have used this solution for three years.

What do I think about the stability of the solution?

There were no stability issues. However, trends are changing so fast and so are the clients' requirements. The clients also want their hold on the product. They are showing interest in customization.

What do I think about the scalability of the solution?

There were no scalability issues.

Which solution did I use previously and why did I switch?

This is my first product. However, I am moving, along with my clients, towards ForgeRock OpenIdentity Stack.

How was the initial setup?

It totally depends on the way the client wants to set up and implement the product. The security requires complex implementation. This is where no one wants to compromise.

What's my experience with pricing, setup cost, and licensing?

The pricing is always costly.

Which other solutions did I evaluate?

After working for three years with this solution, I am now looking for other products.

What other advice do I have?

It is the best product for bigger organizations, but trends are changing so fast. You should look at ForgeRock OpenIdentity Stack if you are looking for a slightly lower price range.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are implementation partners.
PeerSpot user
it_user181527 - PeerSpot reviewer
Consultant at a consultancy with 51-200 employees
Consultant
It’s a very flexible and customizable product but installation and configuration need improving

What is most valuable?

It’s a very flexible and customizable product.

How has it helped my organization?

  • It provided a secure and robust end to end security solution.
  • You can fine tune authentication and authorization
  • It’s also easily scalable.

What needs improvement?

  • Installation and configuration.
  • If you don’t know the requirements of the supporting components, it could be complicated to install and this has been improved in the later versions that are renamed to IBM Tivoli Security Access Manager.
  • Also the knowledge base articles on the internet are limited.

For how long have I used the solution?

Several years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

This is a very stable product that can run forever.

What do I think about the scalability of the solution?

There are no issues with scalability with this product. Easily to do with no downtime.

How are customer service and technical support?

Customer Service:

Good. Nothing to complain about.

Technical Support:

The technical support are very skilled and has helped solve all issues that I needed help with in a timely fashion.

Which solution did I use previously and why did I switch?

No previous solution used.

How was the initial setup?

Not as straight forward as Microsoft products where the dependencies are bundled in the installation.

What about the implementation team?

I was part of the in-house team and we managed to handle it without the help from the vendor.

What's my experience with pricing, setup cost, and licensing?

The setup cost is like any other product, and once setup, this product requires very low maintenance.

Which other solutions did I evaluate?

No other options were evaluated.

What other advice do I have?

Most often IBM Tivoli Access Manager is not involved when backend applications are developed an this can sometimes cause the applications to not function properly and you need to spend time troubleshooting and do changes in the application.

An IBM Tivoli Access Manager technician should be involved from the start when developing a new application.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Consultant at a tech consulting company with 51-200 employees
Consultant
WebSEAL provides a large number of authentication options out of the box but the admin UI needs to be friendlier.

What is most valuable?

Reverse proxy component, known as WebSEAL. It provides large number of authentication options that are out of the box.

How has it helped my organization?

I am a consultant and work on designing and implementing this tool for our customers. It has helped them to improve and control web and mobile application security.

What needs improvement?

This product is also available in the appliance offering which has not yet matured and has many issues. Most of the time application of fix-packs cause problems to existing functionality. Also, all the features of the product are not available in the appliance version. Lastly, there is huge room to improve the administration UI to make more user friendly.

For how long have I used the solution?

10 years.

What was my experience with deployment of the solution?

Deployment is quite easy, and the only issues that were faced were with fix pack applications afterwards.

What do I think about the stability of the solution?

Not really.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

Overall, it's decent. Many times it depends on the IBM support team member handling the customers' issue.

Technical Support:

Overall, it's decent. Many times it depends on the IBM support team member handling the customers' issue.

Which solution did I use previously and why did I switch?

I have not used a different solution.

How was the initial setup?

Initial set-up is straightforward.

What other advice do I have?

It's one of the best available products of its class. Worth investing in.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user