Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Manager, Information Security and Cyber Defense at a tech services company with 10,001+ employees
Consultant
It's seamless with several hundred internal applications. We’d like them to go back to the C version of the admin console.

What is most valuable?

The most valuable features are security and ease-of-use.

Tokenization of the web applications is easy for application owners to integrate with the tool. On the back end the dev side, and the deployment cycle with web agents and policy creation are easy.

How has it helped my organization?

It's seamless with several hundred internal applications, which is a time and frustration-saving mechanism. It definitely gives a productivity increase with less time logging into things instead of logging in from application to application, while maintaining the security layer.

What needs improvement?

We’d like them to go back to the C version of the admin console. It was much smoother than the web-based version. Everything else is pretty good.

What do I think about the stability of the solution?

Very stable product. The only time we’ve had problems with it is deep behind SiteMinder, which feels the ramifications. The application we’re protecting usually has the issue, not the SiteMinder/SSO itself.

Buyer's Guide
Symantec Siteminder
December 2024
Learn what your peers think about Symantec Siteminder. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.

What do I think about the scalability of the solution?

Very easy to scale. They have a good sizing guide it vertically scales very easily.

How are customer service and support?

Once you get past the first level, it’s good support. Typically once you’ve supported the CA product for a couple of years, you probably know more than first-level support, so it’s frustrating to explain to them the issue.

How was the initial setup?

It was already in production when I joined.

What other advice do I have?

It’s definitely an industry leader in the web access realm. It’s easy to deploy and integrate.

You need to understand the overall design of your web infrastructure, and what do you want to protect – the entry point or the entry point and application server? Design questions, really. You need to decide whether you want fine-grain or course-grain authorization. For the CA solution, make a support matrix and understand other peripheral products in the environment.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user558654 - PeerSpot reviewer
Manager at a consultancy with 10,001+ employees
Real User
When using this product, different applications are not trying to build their own security solutions.

What is most valuable?

It is a flexible platform.

Using this product makes it easier for enterprises to integrate a majority or even all their apps into one single solution for access. Its easy-to-use functionality is the most valuable part.

How has it helped my organization?

The primary benefit of this product is security. It improves the overall security posture of the organization.

Secondly, establishing such a platform helps in saving costs as different applications are not trying to build their own security solutions and spend more money there.

What needs improvement?

A simple feature that still does not exist but it should be implemented as soon as possible, is that if a user is accessing an internet app from the internet, then it should perform a desktop single sign-on. But, if the same application is accessed outside of the network, the users should be given a page login. I don't want customization to implement this behavior, since this should be a simple configuration within SSO functionality. This should detect whether you are accessing from inside/outside of the network and accordingly present the authentication. This feature does not exist today and it is something, that almost all our clients ask for.

What do I think about the stability of the solution?

This is a mature and stable product. It has been a leader in the market for around 10-15 years. I can't imagine another competing product out there.

What do I think about the scalability of the solution?

This product is both stable and scalable. I've seen up to 5-6 million users.

How are customer service and technical support?

One advice for all would be to build relationships with the CA technical support team.

It is important to utilize your account manager if you're a customer or your partner contact if you're a partner, as this is the best way to get more information from them. In my opinion, building these relationships makes the entire the experience better.

Which solution did I use previously and why did I switch?

Some of our clients, at times, have thought of using different solutions. The main reason for that is sometimes they do not have skill to harness the capability of this product along with the features that it offers.

When the client approaches CA, it provides an answer that is more product-oriented, rather than solution-oriented, so there is a communication gap. When we are at the client's side, we bridge this gap and that's why our customers are more successful working with us and CA together, rather than working directly with CA.

How was the initial setup?

I was involved in the initial setup process for some of our clients.

For SSO and its setup, the process was straightforward.

What other advice do I have?

It is very important to educate yourself in regards to the capabilities of this product by interacting with CA or attending conferences like CA World as they give you an insight about all that the product has to offer.

Single Sign-On is a mature product and hence I would be confident in recommending it to our clients.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Symantec Siteminder
December 2024
Learn what your peers think about Symantec Siteminder. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
reviewer1266123 - PeerSpot reviewer
Assistant General Manager at a computer software company with 10,001+ employees
Real User
Good SSO functionality with what appears to be a simple setup and deployment
Pros and Cons
  • "The single sign-on is the solution's most valuable feature"
  • "We're currently unable to find information about if the solution can do a full implementation with SQL. Some better and more accessible documentation for new users or those curious about the product would be helpful."

What is our primary use case?

We primarily want to use the solution to implement our SSO, Single Sign-On solution.

What is most valuable?

The single sign-on is the solution's most valuable feature.

What needs improvement?

Since we're in the early stages of examining the solution, it's hard to predict what might be lacking.

We're currently unable to find information about if the solution can do a full implementation with SQL. Some better and more accessible documentation for new users or those curious about the product would be helpful.

We want to implement a simple application. Currently, from what we're finding, we're not sure if it would work the way we need it to.

For how long have I used the solution?

The solution is quite new to us and I only really started looking at it about two or three weeks ago. We're in the testing phase.

How are customer service and technical support?

We've never contacted technical support.

Which solution did I use previously and why did I switch?

For a long time, we used SiteMinder, We're currently looking into what might be a better solution for SSO. That's why we're currently evaluating CA SSO. We'd been using the previous solution for two or three years but it hasn't been able to provide us with what we needed. Currently, we're trying to implement CA on servers for IPMP.

How was the initial setup?

The initial setup seems straightforward, but we're curious about the aspect of SSO for SQL servers. We're also investigating from the net side to see what requirements are needed. We haven't implemented or deployed it yet.

What about the implementation team?

We have our own in-house team that will handle the implementation.

What other advice do I have?

I'm an implementor, so I help clients implement the solution for their companies.

We're still in the process of testing the solution. We're currently not providing services on it as we are still in the testing phase.

So far, with a simple implementation of the SSO, I'd rate the solution eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
PeerSpot user
it_user351696 - PeerSpot reviewer
Software Development Manager at a comms service provider with 1,001-5,000 employees
Vendor
We now have a standardized way of integrating with applications so the application owners don't have to handle authentication or security. A more modern management interface would be nice.

Valuable Features

The best feature would be single sign-on across multiple applications for our customer-facing sites. We don't want our customers to have to enter their user ID and password multiple times. We have a suite of a dozen or so sites as well as about 200 external sites that we federate with. Single sign-on is important, and federation is important.

We have a standardized way of integrating with applications so the application owners don't have to handle authentication or security. We handle that for them, so we use the burden from other application owners.

Improvements to My Organization

It puts the expertise around authentication and security on our organization where it belongs. The company doesn't have to depend on each individual application to maintain their own security. This allows us to really maintain control over the security aspect of it.

It's also enabled a quicker time-to-market for new applications that have to handle user ID and password security.

Room for Improvement

A more modern management interface would be nice. The existing interface feels like it's about 10 years old.

Use of Solution

It's been probably about 10 years since we integrated with it.

Deployment Issues

We've had no issues deploying it.

Stability Issues

It's been stable for the last 4-5 years, though we had some significant issues early on. We had some performance-related issues that caused some outages. Outages actually happened pretty frequently back then. If one centralized authentication mechanism went down, all the applications that depend on it were also unavailable. We've gotten past that, so we're much more of a reliable, robust platform now.

Scalability Issues

We serve about 10 million users all over the country in the US. Scaling it is not a problem as we just add more servers at that point. The one good thing about SiteMinder is that to scale you basically just add more servers. You can piggyback, use the same basic architecture, and just add more.

Customer Service and Technical Support

We have support contracts with CA, but it's hit or miss. We have to have an escalation path with a direct red phone to senior management support because of the nature of our contracts. We had to utilize that frequently, rather than go through the lower-tier support. Our infrastructure is different enough than CA's reference infrastructure that we take a lot of time to bring somebody new up to speed. We have a direct line to people who really know our implementation pretty well, and have been working with us for a number of years, so it helps.

Other Solutions Considered

Some years ago we had some other vendors early on. But we've got a pretty well-established build out with CA right now, so if we have some significant new functionality in the future, we'll certainly look at other vendors too.

Other Advice

There's a lot of manual work that has to go through transferring a configuration from a lower environment to an upper environment production, so be prepared for that.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user558159 - PeerSpot reviewer
Senior Security Analyst at a financial services firm with 5,001-10,000 employees
Real User
Multiple users with multiple applications can be authenticated in a single location. It's a stable, durable product.

What is most valuable?

I think the most valuable features are handling user authentication and integration with the other applications within the suite, like Single Sign-On.

How has it helped my organization?

Multiple users with multiple applications can be authenticated in a single location.

What needs improvement?

I really can't answer this right now. We have so many other products that serve our needs. There are other vendors that satisfy some of our requirements, so I'm not exactly sure what CA would be able to provide us with.

What do I think about the stability of the solution?

For the most part, SSO is very stable. Since deployment, it's been very stable for us. We do very regular metrics on availability and we're in the high, high 90s, 99% I think, so it's a very stable, durable product.

What do I think about the scalability of the solution?

I think there are some drawbacks to the scalability. At a recent conference, we heard that it's going to be a lot easier to scale for larger companies. That's going to be good in the future.

How are customer service and technical support?

Sometimes technical support is slow to respond, and that’s typical. Normally, the first response is, "send us your logs", so they can review our environment. There are specific people assigned to our account, so they know what our environment is like, but they still want to have the log so they can look at it. Sometimes that slows the process of problem resolution.

Which solution did I use previously and why did I switch?

This decision was made before my time. I came in when the decision was made to go with CA for identity management. Our company was going through a transition of ownership and all the decisions were made at the time. That was about 7 or 8 years ago.

How was the initial setup?

I came 2 or 3 months after the initial setup, so I wasn't part of that. We had a third-party company help us with our development and deployment, so they pretty much took the ball and ran with it. I don't know how complex it was for them. When they presented it to us at deployment time, we were ready to go.

Which other solutions did I evaluate?

We were looking for anything that would have satisfied our requirements.

What other advice do I have?

Make sure you know who your support staff is, who your vendor representatives are for your account and really get to know them. Give them the requirements that you need and make sure that they're following through. Build good rapport with them. That way they can help you determine what you need to do and feel free in giving different types of suggestions.

When selecting a vendor, we look for:

  • responsiveness
  • technical support of the product
  • accessibility of the technical support teams
  • product knowledge
  • ability to train their customers on their product
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user558573 - PeerSpot reviewer
Technical Lead at a hospitality company with 1,001-5,000 employees
Real User
For authentication purposes, we can keep security out of our applications. More UI templates would be nice.

What is most valuable?

With Single Sign-On, we don't have to do anything in our system.

After they deploy the application, everything works seamlessly. That's the main benefit that we get out of this product. For authentication purposes, we can keep security out of our applications, which is productive for us.

How has it helped my organization?

We can rapidly onboard different partners. We don't have to wait for months to do that. For this, we use the Federation feature from CA Single Sign-On, which helps us a lot.

What needs improvement?

There is a need to introduce more templates in the UI side and this would help design this aspect better. As of now, there are only a few samples available.

There is scope for improvement in this product.

What do I think about the stability of the solution?

It works fine. We did not find any stability issues. It is very rare to see something go wrong, so the application is quite stable.

However, we have noticed that when you update to the latest version, it can be unstable. Right now, we are in a stable environment.

What do I think about the scalability of the solution?

You can scale it very easily. It works exactly the way the product has been documented. We can scale it well and we did not find any issues with it.

How are customer service and technical support?

The technical support level is moderate. I would give it a 5/10 rating.

It depends both ways - we need immediate solutions however from their end, it takes time to get answers.

Which solution did I use previously and why did I switch?

We required such a product, as we were using an old solution. That’s how we started using CA Single Sign-On with the CA SiteMinder.

How was the initial setup?

The setup was not straightforward. I would give it a 7/10 rating - 1 being simple and 10 being complex. So, it was quite complex.

What other advice do I have?

I would advise others to use this tool as it is robust and mostly it solves all the problems that arise in our industry.

We did consider other vendors. However, after we saw the demo for this product, we decided to purchase this product.

The factors we looked into before purchasing this product are the benefits of this product, how CA functions with other tools, costs, the level of support provided, upgrades and so on.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user349443 - PeerSpot reviewer
Information Security Analyst at a financial services firm with 1,001-5,000 employees
Vendor
It helps with compliance because we can make sure who a user is, log-in information, etc. It’s difficult to initially configure, but once you know where the traps are, it’s not a big deal.

Valuable Features

Single sign-on allows you to log into multiple areas and sessions with just one user login. SiteMinder uses a cookie to pass the credentials along to different applications, and it’s encrypted. You can determine how long the session will last before users have to log in again. And if you have NTFS capability, it just automatically logs in again for them, using a firewall to protect LDAP.

Improvements to My Organization

We use it for our tier-1 applications through GLBA and SOX. It helps with compliance because we can make sure who a user is, log-in information, etc.

Room for Improvement

It’s never been an out-of-box solution except for IIS, which installs web servers for you. Basically, you do a bit of configuration, and the client on the other end is heavier use. That’s the beauty of SiteMinder -- you can do anything with it.

It’s really difficult to initially configure, but once you know where the traps are, it’s not a big deal. It’s done everything we’ve needed it to do.

It could use better air handling -- if your policy doesn’t work, you just get some dots instead of real information without looking at the logs. It would be nice to find the info without hunting in the logs.

Stability Issues

Once every one to two years, the service will freeze, but if you have redundancy, all you have to do is restart. If you have redundancy, it’s not a big deal. The way it works, is that it does a round robin so that if one server goes down the other three handle the traffic.

Scalability Issues

Very scalable. You just have to have a central database where all servers hook up to the policy store, and all servers can use the database without a problem. You can then add as many servers as you want.

Customer Service and Technical Support

We’ve been using it since they were Netegrity, who had amazing an KB. But unless you’re standing up a new application, you don’t need it. We only get tech support involved when we have a new application.

Initial Setup

I’ve been running SiteMinder since v4, the first time I had to learn everything. It’s easy to export the policy to the policy store, which is your most valuable thing. It’s on v12 now, and I haven’t had to update for two years. We’re no longer handling the server admin, that’s another team, but we’re handling all the policy configurations. We can take that and go from version to version with no problem.

Other Advice

As far as software goes, it’s as close to the energizer bunny as it gets. Every now and again, service will freeze, but other than that it just goes.

It depends on whether you can log in directly to your LDAP and manage it, because that would be easier. If you need the ability for just logging without buying an application and want good security, it’s an awesome solution.

Most people use it as an external firewall, but all our firewalls are internal, so this is a good back stop.


Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user349428 - PeerSpot reviewer
Software Engineer at a healthcare company with 1,001-5,000 employees
Real User
It's really increased the security of our applications and, in some cases, without requiring multiple usernames and passwords. The installation documentation is not good enough.

Valuable Features

We use it a lot for federation, authenticating in-house or on premises, and that gives us access to an outside SaaS provider.

Also, we like the reverse proxy tool so much that in some instances we’re using SSO just for that and not even single sign-on.

Improvements to My Organization

It's really increased the security of our applications, and in some cases, has provided much more security. It does this even while some applications don't require multiple usernames and passwords.

Room for Improvement

The documentation is not good enough, particularly the installation documentation could be improved. Some things are left open to interpretation and others are simply not documented at all. CA will take liberties and make assumptions that your system is a certain way, and so the documentation is based on that.

Stability Issues

It’s very stable, but we found some bugs and got workarounds quickly. We stress out SSO, from what I understand CA's reasoning is, but they're quick to resolve the issues.

Scalability Issues

We've had no issues at all with scalability, as it covers everything we do even at thousands of logins per minute.

Customer Service and Technical Support

We use them a lot and they're quick to pick up cases. We have almost a dedicated team with them that escalates up issues.

Initial Setup

It’s fairly complex as it has lots of pieces. We’re in the process of upgrading and we’re building a mirrored environment and then moving everything over to it.

Other Advice

CA is great to work with, but to use it, just learn the product suites and how they interact. Make sure you have a good layout and make sure you have everything you need.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user