The product is for privileged access for a jump server using a PIV card.
Works at a tech vendor with 10,001+ employees
This product is for privileged access for a jump server using a PIV card.
What is most valuable?
How has it helped my organization?
So far, with the functionality of what we had, there has not been much improvement at this point of time. I am not able to comment at this time.
What needs improvement?
I think it works just enough because it is a mandate from the customer to have the privileged access for the administrators to manage the servers using the PIV cards. We haven't used it long enough to comment on areas for improvement.
We clearly know what the functionality is that we need from the product. I think this has been accomplished by the functionality that exists in the PAM of Xceedium.
For how long have I used the solution?
We have been using this solution for six months.
Buyer's Guide
Symantec Privileged Access Manager
December 2024
Learn what your peers think about Symantec Privileged Access Manager. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,158 professionals have used our research since 2012.
What do I think about the stability of the solution?
We don't use it that often and it is only for admin users. So far, there have been no issues with stability.
What do I think about the scalability of the solution?
There were no issues with scalability.
How are customer service and support?
I would give technical support a rating of 10/10. It's a matter of a learning curve for my administrators. When they requested support, they were quick to respond. It's not really a problem. It's basically a lack of awareness of the product. It was quickly resolved talking to the technical support people.
Which solution did I use previously and why did I switch?
There was not a previous solution.
How was the initial setup?
We did not have any team members who were trained in Xceedium. For the setup, we got directions from the manual that was provided by the reseller.
We then went to Xceedium, which is now CA. They helped us if we had any issues from the technical point of it.
I would rate the setup as 80/20: 80% being simple and the remaining 20% needed some help from the technical folks at CA.
Which other solutions did I evaluate?
We did not evaluate different products. There was no choice for us. We didn't have a choice to evaluate other solutions because they mandated the use of this product.
What other advice do I have?
I think it's a good solution for anybody who is looking for a single sign-on implementation for administration of the servers.
It's a straightforward solution. It has been in the federal space for quite some time. It has been part of our TRM.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Solution Architect at a tech consulting company with 501-1,000 employees
The DB clustering is a really good benefit of this solution.
Pros and Cons
- "CA PAM is working well for us."
- "The DB clustering is a really good benefit of using CA PAM."
- "An improvement for this solution is that it should not be constantly based on user name and password. There should be a condition to edit and update your username."
What is our primary use case?
My primary use case for this solution is for work in data center components. We use it with our data center devices.
What is most valuable?
The DB clustering is a really good benefit of using CA PAM.
What needs improvement?
An improvement for this solution is that it should not be constantly based on user name and password. There should be a condition to edit and update your username. Also, it would be nice to have a single sign-on, but that particular portal doesn't allow any copy/paste.
In addition, I have an additional suggestion. I will give you a scenario. In regards to the licensing, I have some concerns. The NAS team, they want to have 24/7 support. The NAS team is the one actually using this CA PAM. So, the total count is some hundred members. But at other times, the login is 23 members. So it's like a batch. Every 7 hours there is a batch change, so every 7 hours 23 members will change. But when I ask for a licensing part, they are saying we have to take 100 license, not 23 license. Each time I have to ask for 100 licenses, even though I have only 23 members at a time using the solution. If there were any options for concurrent usage of a license, that would be a better option.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
I find it is a stable product for our organization. But, we have had to do some debugging sessions occasionally.
Which solution did I use previously and why did I switch?
We have previous experience with CyberArk.
How was the initial setup?
The initial setup was easy and straightforward.
What's my experience with pricing, setup cost, and licensing?
I would prefer better licensing options for the 20-100 users we have at a given time.
Which other solutions did I evaluate?
We also considered CyberArk.
What other advice do I have?
So when we are trying develop some particular portal, when you are looking with loop-back IP, connecting the backend by a loop-back IP, the response is coming by an actual IP - that's the portal design. Because it is redirecting multiple URLs, the portal designed like in such a way like it will take your input and redirect your many multiple URLs with the connection and respond back to your browser, but the browser always it comes back with the actual IP, not the loop-back IP. In this case, the CA PAM is working well for us.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Symantec Privileged Access Manager
December 2024
Learn what your peers think about Symantec Privileged Access Manager. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,158 professionals have used our research since 2012.
Tech Lead at a financial services firm with 5,001-10,000 employees
Automates the security of DevOps pipeline for the shared secrets across environments
Pros and Cons
- "For me, it is the robust API which is the most valuable feature. This allows for low maintenance costs and allows applications to automatically connect. This is great to automate security of the DevOps pipeline for shared secrets across environments. Also, being on Linux and a virtual appliance is great."
- "I wish it could create local accounts on desktops."
What is most valuable?
For me, it is the robust API which is the most valuable feature. This allows for low maintenance costs and allows applications to automatically connect. This is great to automate security of the DevOps pipeline for shared secrets across environments. Also, being on Linux and a virtual appliance is great.
How has it helped my organization?
Before we had a vaulting solution that had a manual provisioning of the DB and privileged accounts. Now, we can automate this provisioning through APIs which are easy to understand and implement.
What needs improvement?
I wish it could create local accounts on desktops. But, what I really want to do with it is automatically manage DevOps pipelines through tools like Docker/Puppet/Chef. It would manage shared secrets to the segregated environments. I am hoping that the API is helpful for this.
For how long have I used the solution?
We have used it just for a PoC, but we are purchasing it soon. From going through the selection process, we felt CA PAM was the best option for our company.
How are customer service and technical support?
CA technical support has been very responsive the past couple years. It has come a long way.
Which solution did I use previously and why did I switch?
I have used ERPM, but it was difficult to upgrade the product. The structure of the vaulting policies was not conducive to Ally’s organization. Plus, it ran on Windows, which in our world you want to always go with a Linux solution, when possible.
How was the initial setup?
In the PoC, it seems very easy to get started.
What's my experience with pricing, setup cost, and licensing?
Don’t go with an agent model. Don’t go with a model that has you buying a thousand different parts. Go with PAM that gives you everything, or you’ll just be paying costs of implementing another tool that PAM would have just given you up front. PAM can monitor exponentially more devices than it competitors. This covers a large audit item for us.
Which other solutions did I evaluate?
We looked at CyberArk, BeyondTrust, ERPM and ObserveIT.
What other advice do I have?
If you truly want to secure a DevOps world that is constantly changing the architecture and number of boxes, then you need CA PAM.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior Security Engineer at a comms service provider with 10,001+ employees
Reduces viral attacks on my website but the setup is complex
Pros and Cons
- "It reduces the viral attacks on my website. It also allows certain users access to see what happens daily."
- "The setup is complex."
What is our primary use case?
It reduces the viral attacks on my website. It also allows certain users access to see what happens daily.
What is most valuable?
The password manager is a valuable feature. It saves time for the user. The users do not have to remember the password or change the password. It is a user-friendly solution.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The stability is very good.
What do I think about the scalability of the solution?
There is enough power to support our whole organization and the scalability potential is very wide. We currently have between 50-100 users of the solution.
How is customer service and technical support?
The tech support is good. They are very helpful.
How was the initial setup?
The setup was complex. It took one month and we needed collaboration between various different departments. We used a consultant to help us. We needed two people to integrate the solution and we currently employ one person for maintenance.
What's my experience with pricing, setup cost, and licensing?
It is reasonably priced.
What other advice do I have?
This solution is our gateway to access other servers. We plan to continue with this product as our company grows.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Project Coordinator at a logistics company with 10,001+ employees
Gives us the ability to rotate passwords automatically via a scheduled job or password view
What is most valuable?
Gives us the ability to rotate passwords automatically in the vault, on in any interval, via a scheduled job or password view. This takes out the management of passwords from the user and CA PAM can control the password maintenance.
How has it helped my organization?
Without getting too specific, we are able to manage root account passwords on 1600+ Linux servers. Our users can transparently login with those credentials when needed.
What needs improvement?
The OOTB reporting functionality is lacking. The ability to view a simple breakdown of the various data. They offer an all or nothing solution that does work for my organization. We need to be able to distribute reports to various groups that have users working in CA PAM without showing them all the activity. However, there are APIs that can be utilized to make custom reports. The product is good and enhancements are coming to improve the product. Reporting is what is lacking in this version of the product.
For how long have I used the solution?
We have used the product since September 2016.
What do I think about the stability of the solution?
At this point, there were no issues with stability.
What do I think about the scalability of the solution?
At this point, there were no issues with scalability.
How are customer service and technical support?
The technical support has be an essential part of our deployment. They are very responsive and work diligently to resolve the issues.
Which solution did I use previously and why did I switch?
We didn’t have a previous solution.
How was the initial setup?
We have ten appliances and the setup was straightforward. We had no issues setting up our infrastructure.
What's my experience with pricing, setup cost, and licensing?
I was not involved in the negotiations of the product.
Which other solutions did I evaluate?
We started out with eight different products and wound up doing an RFP with four finalists, and CA PAM was one of them. The other three were BeyondTrust, CyberArk, and Hitachi ID.
What other advice do I have?
My only advice is to make sure you perform a through PoC in your environment to make sure all aspects of the system work for you.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
CIO/Management Consultant at a tech company with 51-200 employees
Privileged users see only those systems and access methods to which they’re expressly allowed access.
What is most valuable?
The CA PAM’s ability to seamlessly integrate and provide a demarcation between users and systems is the most attractive aspect. It:
- Enables all control to start with Xsuite’s Deny All, Permit by Exception (DAPE) approach to limit privilege access controls.
- Enables all privileged users to see only those systems and access methods to which they’re expressly allowed access. Privileged users include Vendor Integration and Partners.
- Enables and verifies all system policies, providing an additional level of control by selectively filtering commands issued.
- Enables unauthorized commands to be blocked, with optional user warnings and policy violation alerts to security teams and logs.
- Enables sessions of users attempting to violate policies to be terminated, or accounts deactivated; enterprise policy control.
- Enables “leapfrogging” prevention, which allows one system to be used as a launch point for additional attacks / lateral movement.
- Enables full stack and system integration.
- Enables service integration with all systems using APIs or application to application.
These features greatly assist us and our clients in protecting their data privacy.
How has it helped my organization?
In retrospect, we and our clients have seen a reduction in service-related issues for application server and mainframe environments, a reduction in the provisioning lifecycle and requirements for systems such as mainframes, and a substantial increase in security flow and protection.
What needs improvement?
I believe continued expansion of integration to multiple systems including SSO and SAML technologies will provide a more-expansive, enterprise view of access orchestration, which will in turn strengthen the security of the environment.
For how long have I used the solution?
I have been involved with this product for three years, both using and implementing for client architectures.
What do I think about the stability of the solution?
I have not encountered any issues with stability.
What do I think about the scalability of the solution?
I have not encountered any issues with scalability; this is a true enterprise expandable product for mid-market and beyond.
How are customer service and technical support?
In my experience with the CA PAM, their support apparatus has improved immensely over the past 12 months and continues to improve based on client feedback. Indications from my clients are that CA Technologies actually listens to their concerns and takes action.
Which solution did I use previously and why did I switch?
Being in the technology sector for many years, we did not initially use products such as the CA PAM. We relied on common architecture, such as Microsoft and Oracle. As the need for more segregation of duties became prevalent, we looked to enhance our security with privileged access management. The feedback from most clients surrounding PAM is it provides a segregated extension of access control framework to enable better protection of customer privacy/data.
How was the initial setup?
The initial setup is not complex. The design and integration can become complex without the proper solution architecture and understanding the impacts changes in technology place on a companies operational process and employee behavioral management. These topics became more complex to manage and establish than the product itself.
What's my experience with pricing, setup cost, and licensing?
Product pricing and licensing is related to short-term or long-term business planning. In many cases, this solution should be looked at as a long-term solution. Therefore, considering the long-term savings in perpetual vs annual licensing is paramount to a progressive architecture. Therefore, I believe it is in the interest of the business to make these decisions prior to OEM engagement; they need to be vetted and defined as a value to the company at large.
Which other solutions did I evaluate?
No other options were evaluated because this PAM has made substantial gains in system integration, which outweigh industry choices.
What other advice do I have?
I am a proponent of the product in many ways but most importantly, I believe a solid, well-thought-out strategy and solid architectural plan for the future needs to be the priority, not buying a product to fit the unknown.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: My company is a CA Technologies OEM partner.
Senior Solutions Architect, at a tech services company with 10,001+ employees
It can wrap system connectivity information into its internal Java-based shell. Online Help is not detailed enough.
What is most valuable?
- Ease of use.
- The way in which it can learn about the connectivity to systems, e.g., VMware vCenter Console; it can wrap that into its internal Java-based shell. Therefore, one does not need a terminal server solution.
- The non-Java based client.
- Two integration options with AD using SAML and the AD GC ports.
- The API explorer.
This system comes with a built in Java client which handles the connectivity to remote systems, e.g. the VMware vCenter Console Web Interface.
When you add the system to the CA PAM, you can put the connection into “learn mode” where you map out where the username and the password and submit fields are. You can then configure the system in PAM with the relevant credentials and then based on the information it “learned” about where the username and password and submit fields are and what needs to go where, it presents you with a vCenter Web Interface and logs you onto vCenter automatically based on your PAM permissions. This vCenter Web Console is effectively proxied via this Java Client that CA PAM has available and happens through the PAM system – the end user does not make a direct connection to vCenter.
In other PAM solutions that we tested, one had to setup a Microsoft Remote Desktop Server (TS) and publish the vCenter Web Interface and integrate that published app with the PAM solution so that when a user wants to access the particular vCenter server, PAM initiates the Remote Desktop Server published app – inserts the credentials – to provide you with access to vCenter.
When integrating with Active Directory for authentication purposes – most vendors support LDAP. For larger AD environments, the LDAP integration supports the Microsoft MSFT ports (3268 & 3269) that allows one to look for nested group memberships across multiple child domains. Another way to integrate with AD is to use SAML.
We were able to use both methods with the CA PAM solution. With another vendor we tested, they did not support SAML.
How has it helped my organization?
We only did an evaluation of the product, but we do feel that it will improve our security and governance posture and shave time off our engineers having to connect to systems managed by the PAM solution. It also gives us the accountability we are looking for.
What needs improvement?
- Reporting is very limited.
- Online Help is not detailed enough.
- Canned reports provided results for all targets and cannot simply be run for a particular customer when used in a service provider environment; one has to create some custom filtering.
- Multi-tenancy (reporting, AD users, customer devices, customer credentials).
- Interface and routing configuration (no individual routing tables per interface, cannot see routing table).
- Network connectivity to multiple networks where these networks might have overlapping IP address spaces.
- Session recording not included by default without an additional license.
- Session recording mount point is often disconnected after a system restart.
- Additional configuration required for multi-domain AD forests in order to find groups in child domains and to expand their membership.
For how long have I used the solution?
We used it over a period of about 2-3 months, up to slightly less than two months ago as part of our proof of concept tests.
What do I think about the stability of the solution?
I have not encountered any stability issues; it is very stable.
What do I think about the scalability of the solution?
I have not encountered any scalability issues; it scaled easily.
How are customer service and technical support?
Technical support is very good.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
Initial setup was straightforward, but we had some problems initially understanding what needed to be done to get an end device under management and how to set up the networking.
What's my experience with pricing, setup cost, and licensing?
- Take note that Session Recording is not included by default.
- One would likely also have to invest in other infrastructure in a service provider environment when wanting to use the same solution for multiple clients to allow for the necessary networking.
- Additional costs that need to be catered for:
- Storage space, NAS or SAN for session recording data.
- A Terminal Server and CALs for more-complex end devices, e.g., Cisco UCS – the client needs to be run from a Terminal Server as a published application by the PAM solution
Which other solutions did I evaluate?
We ran a PoC with CA and BeyondTrust at the same time.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security Consultant at a tech services company with 10,001+ employees
One stop access for all things involving privileged access management
Pros and Cons
- "We can enforce complicated password policies and very important frequent password changes."
- "The product is very scalable in terms of concurrent sessions that it can handle at a time, number of device it can support, accounts that it can manage, or number of nodes that you can deploy in a cluster."
- "We experience stability issues after every patch upgrade. This is a place where CA needs to improve drastically."
- "The service account management functionality needs to be extended to application pools, SQL database, PowerShell scripts, service account discovery, etc."
What is our primary use case?
- Privileged account management
- Session management
- Session recording
- One stop access for all things involving privileged access management.
How has it helped my organization?
- Earlier admins used to access critical system from their desktop, which was a security threat considering the wide variety of compromises happening on endpoint. Now, all the privileged access is tunneled through PAM.
- With password management, we can enforce complicated password policies and very important frequent password changes, i.e., weekly.
- Most importantly, we now have recordings for each and every privileged session which is used for auditing, compliance, and investigations.
What is most valuable?
Privileged account management for Windows (domain and local) and Unix.
What needs improvement?
Service account management is a key area where the product needs to develop. Currently, the product supports service account discovery, but only if the host name of the server is known. For unknown host names, it is still a dark area.
In comparison with Thycotic and CyberArk, the service account management functionality needs to be extended to application pools, SQL database, PowerShell scripts, service account discovery, etc.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
We experience stability issues after every patch upgrade. This is a place where CA needs to improve drastically.
What do I think about the scalability of the solution?
The product is very scalable in terms of concurrent sessions that it can handle at a time, number of device it can support, accounts that it can manage, or number of nodes that you can deploy in a cluster. It comes in four forms.
- Physical appliance
- Virtual instance
- AWS
- Azure (just launched).
How are customer service and technical support?
The technical support has improved a lot in last year with the advent of the European technical support team.
Which solution did I use previously and why did I switch?
No previous solution was used.
How was the initial setup?
Initial setup is very straightforward and ease to configure. It is similar to any appliance-based network security device.
What's my experience with pricing, setup cost, and licensing?
Pricing is fair compared to other top vendors, like CyberArk. The licensing is simple and scalable.
Which other solutions did I evaluate?
We did not evaluate any other solutions.
What other advice do I have?
Go for it if your key areas are password/session management of Windows/Unix/database.
Be careful if you want to use this for service account management.
There are some technical challenges while integrating the web-based console (security devices) for transparent login/single sign-on.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Buyer's Guide
Download our free Symantec Privileged Access Manager Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Privileged Access Management (PAM)Popular Comparisons
CyberArk Privileged Access Manager
Delinea Secret Server
BeyondTrust Endpoint Privilege Management
WALLIX Bastion
One Identity Safeguard
ARCON Privileged Access Management
MasterSAM PMS
Buyer's Guide
Download our free Symantec Privileged Access Manager Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Privileged Identity Management, what aspect do you think is the most important to look for?
- How was the 2020 Twitter Hack carried out? How could it have been prevented?
- Which is the best Privileged Account Management solution?
- What are the top 5 PAM solutions that can be implemented which cover both hybrid and cloud?
- What are the top 5 PAM solutions?
- How will AI and ML help or work with PIM/PAM?
- Is BeyondTrust Endpoint Privilege Management really expensive compared to other tools or software?
- What is the difference between PAM and PAS?
- What is the difference between IDAM , PIM and PAM?
- Which PAM tool do you prefer: CyberArk Privileged Access Manager, One Identity Safeguard, Delinea Secret Server, or BeyondTrust Privileged Remote A
Session recording is included and only additional infrastructure required is storage space for session recording.