One of the valuable features is the randomly generated password. It is a strong way to protect the security access to the network and servers in our department of Homeland Security Environmental Management System.
Sr. Oracle DBA at a government with 10,001+ employees
One of the valuable features is the randomly generated password
What is most valuable?
How has it helped my organization?
It has helped us with security.
What needs improvement?
Updates get difficult for the client. It needs to improve. I experienced difficulty in upgrading the software myself. With a tech engineer's help, I was able to manually delete some directories and was finally able to upgrade successfully. The codes should be easier and have an auto-feature to upgrade.
For how long have I used the solution?
We have used this solution for two years.
Buyer's Guide
Symantec Privileged Access Manager
December 2024
Learn what your peers think about Symantec Privileged Access Manager. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
What do I think about the stability of the solution?
We did not encounter any issues with stability.
What do I think about the scalability of the solution?
We did not encounter any issues with scalability.
Which solution did I use previously and why did I switch?
We did not use different solution before.
How was the initial setup?
The initial setup was straightforward.
What other advice do I have?
Make it easier to upgrade the software.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security Engineer at EarthLink
Video Review
In addition to helping with security, it also helps with how we audit which credentials are being used
What is most valuable?
With CA PAM, it's mainly the vaulting of credentials that we're looking for, and then after that, probably the bastion functionality where we force all of our administrators through that to get to the servers. We'll also do session recording of both RDP and the SSH sessions through it.
How has it helped my organization?
It definitely helps with security. It also helps with how we audit which credentials are being used. When somebody actually logs in to CA PAM, they have to go in through second factor authentication. Once they're logged in, whatever credentials they check out, we get to see that and our auditors get to see that. It helps out in that way.
What needs improvement?
A better discovery interface of accounts.
It does do discovery of accounts for Windows servers, and you could do UNIX servers as well, but it's kind of clunky how it does it.
What do I think about the stability of the solution?
It's a very stable solution, but we also built it to be highly available and redundant as well. We built it out where we have four appliances in one single cluster across two data centers.
What do I think about the scalability of the solution?
It's pretty scalable from what we can see. We have four appliances in a single cluster across two data centers, and we can actually even grow that if we wanted to.
How are customer service and technical support?
I haven't had to call in any cases yet, but we've been working with the CA services team to help us implement the solution. They've been really really good.
Which solution did I use previously and why did I switch?
Over time security has been becoming more prevalent, mainly because of the number of attacks out there. We found that just by looking at our whole portfolio of solutions that we already had in place, there were definitely some small gaps and areas that we needed to fill. PAM was one of the solutions that we found to help us with vaulting credentials, rapidly changing credentials.
Beforehand, for administrators to change certain credentials, they would have to go in and there would be change control processes that they had to go through. The vaulting automates a lot of that for us.
How was the initial setup?
When we set up CA PAM, it's a OVA. It's an appliance, a virtual appliance, that we just needed to throw in VMware, spin it up, and there it is. From there it was just connecting in other things like our storage, our time server, and whatever else. Very very simple to set up.
Which other solutions did I evaluate?
For us, we mainly wanted a solution that worked in the scenarios that we were looking for.
We've demoed numerous products. After even just watching the demos we weeded some out. Then we actually brought a few in-house that we liked, and we did proof of concepts. We found out that some products just didn't work the way we wanted them to in our environment.
The reason we chose CA PAM is it worked in the scenarios that we wanted it to, and it just worked without problems.
What other advice do I have?
Rating: I would say probably a seven or an eight. As I said, the interface is not the easiest to navigate and it doesn't really have the discovery piece or fully baked discovery. Overall, the solution works and there's just multiple ways of doing things. You don't have to use the whole GUI interface to get your stuff in. There's ways of importing our credentials and what not through Excel spreadsheets and what not. It's really easy how the import/export mechanism works.
I would definitely tell them [peers] to do an in-house proof of concept of the solution to make sure that solution works for their environment.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Symantec Privileged Access Manager
December 2024
Learn what your peers think about Symantec Privileged Access Manager. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
Security Engineer
Some of the valuable features are transparent login and cluster synchronization. There are a lot of gaps in the documentation.
What is most valuable?
Transparent login and cluster synchronization. This is quite stable compared with other products. It is easy to manage for the administrator.
How has it helped my organization?
After the CA acquisition of Xceedium, I was able to see a lot of improvement in technical support.
What needs improvement?
There are a lot of gaps in the documentation. The documentation has to improve like anything else. There are a lot of things which are not covered in the documentation, and there are a few things which are covered in the documentation, but are not clear.
To mention the features which are not covered and which are not clear would require a separate document. Here are some examples:
- Authentication methods: PAM does support a few authentication mechanisms to login to PAM. But the documentation does not have the details of how to integrate TACACS+ in PAM. The documentation explains it at a very high level.
- Application Connectors: PAM does support different application connectors. But for CISCO devices, the details are not clear.
- Roles and Privileges: There are almost 200 privileges in Credential Management. There is not a document which has the details for the privileges and their functionality.
- Segregation of Duties: There is not a document for PAM roles. For example, if the user has “Standard User” as a role, he cannot have “Approver Role” from CM. It is a limitation in PAM. This limitation might be due to security or operational functionality. But it should be documented if it is limitation of PAM.
For how long have I used the solution?
We have been using this solution for two and a half years.
What do I think about the stability of the solution?
I faced stability issues in the past, but I have not faced any stability issues lately.
What do I think about the scalability of the solution?
I have not faced any scalability issues.
How are customer service and technical support?
I would give technical support a rating of 6/10.
Which solution did I use previously and why did I switch?
We did not use a previous solution.
How was the initial setup?
The setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
There are currently other tools on the market which are much cheaper than PAM. They can do almost all of what PAM does, and even do it better. CA can think of reducing the pricing for PAM.
Which other solutions did I evaluate?
We did not evaluate other solutions.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Engineer at a university with 51-200 employees
Great features that provide comprehensive coverage of what's required for the PAM solution
Pros and Cons
- "Comprehensive coverage of the required features for the PAM solution."
- "The management console could be improved."
What is our primary use case?
Our clients are generally enterprise businesses, mainly in the financial sectors. We are resellers and I'm head of the security business unit.
What is most valuable?
The best features are the comprehensive coverage of the required features for the PAM solution like a credential vault, a session recording, an endpoint agent, security analytics. All those things.
What needs improvement?
I think the management console could be improved. I have just watched a demo video for the management console and I think it may need to be simplified. I haven't yet had hands-on experience with the solution so it's difficult to comment on possible additional features.
For how long have I used the solution?
I've been using this solution for two months.
What do I think about the stability of the solution?
The stability looks okay.
What do I think about the scalability of the solution?
Scalability seems to be fine.
How are customer service and technical support?
I haven't used the support because I've relied on the documentation until now. I think there could be some improvement with that.
What other advice do I have?
I would recommend that anyone thinking of using this solution carry out a proof of concept first.
I would rate this solution an eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Principal Consultant
Some of the valuable features are safe access to company resources and an intuitive management interface
What is most valuable?
Some of the valuable features are safe access to company resources, quick, comprehensible, and intuitive management interface, and good integration capabilities. Control on targets could be extended through CA PAM Server Control component. It now includes an optional risk evaluation engine (CA Threat Analytics for Privileged Access Manager).
How has it helped my organization?
- Quick setup
- Support for different types of existing user stores
- Management automation through REST interface
- Integration with Identity Management solutions easily for automatic user provisioning.
What needs improvement?
I would like it to support more types of integration.
For how long have I used the solution?
We have used this solution since CA acquired Xceedium.
What do I think about the stability of the solution?
There were no stability issues.
What do I think about the scalability of the solution?
There were no scalability issues.
How are customer service and technical support?
I would give technical support a rating of an eight out of 10.
Which solution did I use previously and why did I switch?
Many customers switched to CA PAM, because the list of useful features quickly expands.
How was the initial setup?
The deployment was very fast, as it is commonly deployed as a virtual appliance.
What's my experience with pricing, setup cost, and licensing?
Contact the sales department.
Which other solutions did I evaluate?
We evaluated Hitachi ID PAM and IBM PIM.
What other advice do I have?
Proceed!
Disclosure: My company has a business relationship with this vendor other than being a customer: We sell and implement CA PAM.
Security Consultant
One of the most valuable items is the load balancing feature
What is most valuable?
One of the most valuable items is the load balancing feature.
What needs improvement?
The live session recording is still not in the features.
For how long have I used the solution?
We have used this solution for over a year.
What do I think about the stability of the solution?
There were no issues with stability.
What do I think about the scalability of the solution?
There were no issues with scalability.
How are customer service and technical support?
I would give technical support a rating of 7/10.
Which solution did I use previously and why did I switch?
This is the first solution.
How was the initial setup?
The setup is one of the advantages of CA PAM, as compared with the other solutions.
Which other solutions did I evaluate?
We evaluated CyberArk, BeyondTrust, and Dell.
What other advice do I have?
The implementation of this product is not a problem and is simple.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Finance at a tech services company with 10,001+ employees
Have a test environment for testing any upgrades/patches first, before pushing it to production
What is most valuable?
Manager user/admin’s password, so it’s more secure and password will be changed on time.
What needs improvement?
When there’s new patches or upgrades, please test the new release well, so it won’t break the functional parts.
What do I think about the stability of the solution?
It’s very stable, unless we do some patches or upgrade, then it’ll break some functional parts.
What do I think about the scalability of the solution?
So far, no.
How are customer service and technical support?
So far, it's fair. Because sometimes, it takes me a few days/weeks to get attention.
Which solution did I use previously and why did I switch?
No.
How was the initial setup?
I didn’t get involved in the initial setup.
What's my experience with pricing, setup cost, and licensing?
I don’t handle that.
Which other solutions did I evaluate?
I didn't get involved in that evaluation, either.
What other advice do I have?
Have a test environment for testing any upgrades/patches first, before pushing it to production.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
IAM Architect at a tech services company with 5,001-10,000 employees
So far, we’re using the RDP-gateway and the “published application” features
Pros and Cons
- "The RDP-gateway: For limiting which server an operator can access."
- "I’m no fan of Java as an application front-end, as it tends to have issues depending on what browser one’s using."
What is most valuable?
So far, we’re using the RDP-gateway and the “published application” features.
- The RDP-gateway: For limiting which server an operator can access.
- The “published applications” feature: To minimize the exposure of sensitive usernames and passwords.
How has it helped my organization?
The exposure of sensitive usernames and passwords has been limited in a massive way. This allows us to give much needed access to LDAP servers and databases without the operator knowing the username and/or password. They just have a link to click on after logging into the PAM virtual appliance.
What needs improvement?
I’m no fan of Java as an application front-end, as it tends to have issues depending on what browser one’s using. Have nothing further right now due to limited exposure to the more technical parts of the product.
For how long have I used the solution?
We’ve had it running for approximately six months so far.
What do I think about the stability of the solution?
No issues so far, except the typical Java/web-browser problems that all Java-based products have.
What do I think about the scalability of the solution?
Do not know as of right now, as we only have one instance in production at the moment.
How are customer service and technical support?
So far, I would rate it high. I have gotten fast and accurate answers to my questions and any issues have been resolved in a timely manner.
Which solution did I use previously and why did I switch?
We used the now discontinued Shared Account Management component of CA Privileged Identity Manager.
How was the initial setup?
The initial setup is really easy. The only thing to worry about is to add all needed networks to your virtual appliance prior to the initial boot. This is a pain and should be fixed in my opinion.
What's my experience with pricing, setup cost, and licensing?
I do not know as I only work with the technical parts of the product, I do not worry about pricing and licensing.
What other advice do I have?
Make sure you have all your network needs mapped out prior to installation, as you have to add all needed networks to the virtual appliance prior to the first boot.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Download our free Symantec Privileged Access Manager Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Privileged Access Management (PAM)Popular Comparisons
CyberArk Privileged Access Manager
Delinea Secret Server
BeyondTrust Endpoint Privilege Management
WALLIX Bastion
One Identity Safeguard
ARCON Privileged Access Management
MasterSAM PMS
Buyer's Guide
Download our free Symantec Privileged Access Manager Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Privileged Identity Management, what aspect do you think is the most important to look for?
- How was the 2020 Twitter Hack carried out? How could it have been prevented?
- Which is the best Privileged Account Management solution?
- What are the top 5 PAM solutions that can be implemented which cover both hybrid and cloud?
- What are the top 5 PAM solutions?
- How will AI and ML help or work with PIM/PAM?
- Is BeyondTrust Endpoint Privilege Management really expensive compared to other tools or software?
- What is the difference between PAM and PAS?
- What is the difference between IDAM , PIM and PAM?
- Which PAM tool do you prefer: CyberArk Privileged Access Manager, One Identity Safeguard, Delinea Secret Server, or BeyondTrust Privileged Remote A