Senior Network Engineer at a tech services company with 1,001-5,000 employees
Real User
Top 20
2024-08-12T06:50:42Z
Aug 12, 2024
For improvements, I think technical support could be enhanced. The time zone difference makes remote support difficult - I'm in Indonesia, and they're in the US. Maybe the Forescout Platform could provide engineers from Asia Pacific.
I'd like to see improvements in the reporting aspect of Forescout Platform. While the dashboards are good, the reports are lacking and need enhancement, especially in terms of standardization and customization options. Apart from that, all the features and functionalities are working well without any issues.
Customer support could be improved by providing direct assistance from Forescout employees or specialists at customer sites to enhance the support experience and effectiveness. The scalability also needs some enhancement.
Senior Tech Consultant at Ministry of Finance, UAE
Consultant
Top 20
2024-03-29T13:29:34Z
Mar 29, 2024
The product needs to improve its support. I know a case that dragged on for about one and a half years. They eventually suggested professional services and closed the ticket. We followed their advice, engaging the account manager and professional service team, only to discover that the issue was a bug. After reopening the case, it's been about six months, and the problem still hasn't been resolved. Forescout Platform's support often takes a long time to respond to tickets. Even after we reply, there's another lengthy wait for feedback, and their responses sometimes seem to delay resolution with unnecessary questions. For instance, they might ask for details about previous issues. Meanwhile, competitors may offer temporary solutions but often lack or are unsatisfactory regarding technical or research and development support from Forescout Platform's team. Another area where it can improve is when dealing with multiple sites and overlapping subnets. While it works well for individual sites, it struggles when managing several sites with overlapping subnets, especially with authentication portals. I think the Forescout Platform could use some extra features or improvements in the future. Specifically, it could be better at working with other security tools. For example, when it connects with VPNs or security scanners, it could work a bit better. The tool has already made some efforts in this area, but I think it could do even more to make these devices work together
The solution's customer support is bad and should be improved. When our customers try to reach or discuss with the support team, they don't even answer.
Chief Executive Officer at Grand Ortus Solutions Pvt Ltd
Real User
Top 5
2023-12-21T11:44:43Z
Dec 21, 2023
Incorporating additional features such as NetFlow DLP, would serve as valuable add-ons. Regarding pricing, there is room for improvement to enhance competitiveness with other vendors and solutions.
Chief Technology Officer at Mehbub General Trading PLC
Reseller
Top 5
2023-07-27T12:32:38Z
Jul 27, 2023
Weaknesses of the product are usually present from the side of vendors. In the case of Cisco's vendors, they do have a presence in the South African region. The fact that Forescout Platform doesn't have a presence in the South African region is a weakness because of which you can't ask for help from them if you have any problems. Though they offer support, Forescout Platform does not offer a vendor like other products do for even East Africa ensuring they deliver better services to their customers. The aforementioned area can be considered for improvement. Maybe integration with or onboarding an XDR solution is something I would like to see in future product releases.
Senior Information Security Engineer at United Bank for Africa
Real User
Top 10
2023-02-02T01:23:33Z
Feb 2, 2023
If older network devices are used there can be some compatibility issues while using the Forescout Platform. Additionally, if the switches that are deployed in your infrastructure are not captured properly to the endpoints there might be some difficulties with Forescout Platform trying to monitor the network traffic. Traffic management is an area the vendor should work on.
CEO at a tech services company with 51-200 employees
Real User
2022-11-02T11:30:00Z
Nov 2, 2022
Unfortunately, Forescout Platform can only be accessed by Android systems. iOS is not supported, so there are some limitations to the operating system. I would like to see all devices have access to the solution. Forescout needs to upgrade its development in the future.
We have found that the agent-based authentication, available within this solution could be improved. The price-point for this solution is very high, which should be looked at in comparison with similar products currently on the market.
Forescout Platform isn't flexible with connections to devices like printers and forces you to re-enter details like the MAC address after any breakdowns.
Forescout Platform could improve the vulnerability management as well as the control on the endpoint, which needs to be connected to my network. In an upcoming release, they should add security features, such as malware and threat protection.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Real User
Top 10
2022-08-11T16:32:46Z
Aug 11, 2022
The product is excellent. As a product, there is nothing to complain about. However, they should improve their overall support. Let me provide an example. Assume you are in the United Kingdom, and you are also familiar with the cars in your neighborhood, and any manufacturer you have heard of. And let's say Forescout is one of the niche products, similar to Rolls-Royce. You know that Rolls-Royce is good, but you need some kind of information accessibility to use that. The comfort is good, and you can obviously drive it, but you need to understand all of the features. You need that level of knowledge, that level of information is clearly not available. First and foremost, that information is not accessible. The second point to mention is that once you purchase the later support and services. That is, they will continue to charge you for every service. Things they should have told you ahead of time are that if you run into problems during the deployment, they will keep asking you to engage the product's professional services, which they will charge you for. And from the standpoint of support, they should be adaptable. When they are aware that customers have made significant investments in these expensive licenses. And it is expected that they will receive adequate assistance. That is where they are falling short. You own a Rolls-Royce, but you are having trouble making the most of its features and functions.
Business Development Specialist at Wire Speed Systems`
Real User
2022-06-19T05:54:06Z
Jun 19, 2022
Custom integrations need to be better. I'd like to have the option, for example, to integrate the Forescout Platform with a customized application or any other software out there that I am using at the same time. I would like the Forescout Platform to be deployable on cloud solutions, like Huawei. It's not compatible with Huawei at the moment. It can be deployed only on Amazon and AWS.
The most common complaint I hear about Forescout is about their technical support. Some sort of highly scalable platform, such as a private cloud, that can be distributed across a network quickly and grow rapidly, would be beneficial. I believe that the overall user experience has not always been preferable.
Head of data centers at a non-profit with 10,001+ employees
Real User
Top 10
2022-05-08T13:23:11Z
May 8, 2022
Forescout Platform could improve the integration or compatibility with other solutions, such as Chinese-made and other market solutions. They do not have any integration with H3C, RUCKUS Switching, Lenovo, CommScope, IBM Switching etc. which are network/Communication Brands. They do not have integration with new solutions in the market. They do integrate well with Brocade, Cisco, Juniper, and quite a few more but they could expand the integration.
Senior Advisor/Architect at a consultancy with 51-200 employees
Real User
2022-04-27T11:58:44Z
Apr 27, 2022
I don't think we tested the full potential of Forescout. We had some delay implementing it into our organization, due internal organizational issues and also due to a lack of device registrations. Meanwhile we decided to switch to a new network provider that doesn't have Forescout in its portfolio. We favour one-stop shopping for network and security services, and will migrate to Aruba ClearPass (portfolio).
This solution could be improved if there was functionality or module integration to connect Forescout with open source, container areas or Terraform. It would also be useful if this solution could run with network plugins to Kubernetes.
Instrutor at a tech services company with 1,001-5,000 employees
Real User
2022-01-04T21:31:06Z
Jan 4, 2022
If you want to deploy a new solution to block, you can't do it by yourself. You need the Forescout to deploy these solutions. They could prove this by making it better. There are virtual machine limitations, this is not a solution that they use to protect my company. In the next release of the solution, it could benefit from being more flexible to allow for more freedom.
Products & Solutions Manager Cyber Security | Forensics at a tech services company with 201-500 employees
Consultant
2021-09-10T15:11:57Z
Sep 10, 2021
As a user, if I am using a laptop that is Wi-Fi connected, Forescout identifies my port connectivity as one user license, and if I take that same laptop with the same username to a wired network, which is also the same network that is used for the Wi-Fi connection, Forescout detects it as a separate license. At times, I am working on wireless and sometimes I enter a zone where there is no wireless connection, which forces a land connection. This is an issue that needs to be resolved because it consumes another license for the same device and the same user. This issue has been escalated to Forscout directly. There was integration with Microsoft SCCM previously, and have suddenly stopped the open integration module for Microsoft. Customers are not aware of what is available to them in terms of the open integration module. Forescout Platform advised that there are many options available and many things they can do, but they don't tell customers exactly what they are. They need clear documentation and direction as to what the customer can expect from the open integration module. Customers need some clarity on what they can do and what is not possible to do. When it comes to a full open integration we need to rely on the professional services from Forescout directly, no one can implement it as there is a limited amount of knowledge available. They need to be more considerate, and there should be good documentation available to the customer. They need to improve their selling approach or the consultant approach. One of their use cases is an ITM use case, and ITSS asset management, but they don't really do ITSS management. They only detect the ITSS and all the parameters around that test, but they do not have any integration with any database system where they can store all these details and act like a typical ITSS management system. They should remove that use case in full. They should say that we complement your ITSS management by detecting the unknown assets in your network. This would be right.
Ingeniero Senior en seguridad y telecomunicaciones at a non-tech company with 1,001-5,000 employees
Real User
2021-02-25T07:45:14Z
Feb 25, 2021
The licensing costs are quite high. With the amount of hardware we have, we need too many licenses to make the product effective and it's ultimately just too costly. We may have some problems with compatibility - specifically with Cisco switches. We have the perimeter a Check Point firewall as an alarm for VPN connections. We have users integrating the VPN Check Point with Forescout. We can't seem to scale due to compatibility issues and price.
Senior Network Engineer at a government with 5,001-10,000 employees
Real User
2020-09-18T14:27:00Z
Sep 18, 2020
The reporting feature needs improvement. An example is that currently, you cannot configure what report files will be named. I think that the reporting feature needs more flexibility. It has about 15 templates and you have to use one of them, but it is not easy to understand what each of them is. It would be nice to have more control over the format of the reports. Also, it would be nice if the configuration backup feature had more flexibility. It only supports FTP, SFTP, or SCP. That makes it impossible to write backups to a Windows share.
Better integration with third-party vendors is needed because as it is now, the list of third-party solutions that we can integrate and automate is quite limited. We would like to see the list of vendors expanded to be broader. The types of products that we would like to integrate with are firewalls, patch management solutions, and SIEM applications, for example.
Product Manager - IT Security at a tech services company with 11-50 employees
Real User
2020-08-12T07:01:00Z
Aug 12, 2020
Truth be told, I'm good with it. I'm yet to have something with the solution that I don't feel comfortable with. It's fine. I've not seen a cause or a reason why I should want something to be changed, but that doesn't take out the fact that there's always room for improvement. What I would love to see is a situation where my Forescout can integrate with different security technologies. Where it can share contextual information bidirectionally. I had written to Forescout about this and they told me they have that functionality already. So I think that settles it. They can share device context with the security technology and that technology can also be shared with Forescout. To build a form of connective strategy towards security. They have a dedicated module for the security technology I'm concerned about. But with that software, I should be able to integrate my Forescout with any other third party security technology, to build that connected security strategy I talked about. So far, it's good. It meets my requirements that I had concern about.
Forescout Platform is too expensive, so the price should be reduced. Although Forescout manages endpoints and network devices, there is no capability for user management. This is something that should be added. For example, if I find that something is wrong in the services and need to disable a user's access, there should be no need to go to Active Directory and disable the user there. As it is now, computers and devices can be disabled, but not users.
Head IT Infrastructure and Security at United Capital Plc
Real User
2020-05-19T18:28:00Z
May 19, 2020
I would advise Forescout through their research and development to look for features that they can add. Also, based on the what other competition may be selling, if they find any useful feature, they should add those to their product.
Senior Security Engineer at a healthcare company with 10,001+ employees
Real User
2020-05-13T13:50:00Z
May 13, 2020
When adding what is in scope to a policy, it would be nice if you could select multiple policies instead of one policy at a time to add what is in the scope for network segmentation. I have found that during the install and configuration of the policies that if you want to modify multiple policies or enable multiple policies that you need to define what is in the scope (IP range or segments) one rule at a time. This caused some slow downs when implementing policies. I could see after doing this repeatedly that it may lead to some premature clicking in an area that you may not have wanted, depending on how your segments are setup, and may cause issues later down the road.
The product could be improved in different ways: * The speed of identification * More guest management features (i.e. extending time frames) * Sometimes, the identification profiles completely change after device upgrades. It would be beneficial to keep or merge these records if enough correlating data points exist, so as not to segment devices. Some of the features introduced into the product line could have better documentation, which could provide for an overall better experience for administrators.
Sr. Network Engineer at William Blair & Company
Real User
2020-05-12T16:02:00Z
May 12, 2020
Better reporting and analysis of access (based on client) would be helpful. Also, a tool that allows tracing a user through the rules to authentication. More detailed analysis during the authentication process, especially for troubleshooting access issues. We have found that troubleshooting RADIUS controls is quite arduous, as it is today. A trace function could easily resolve this by providing a means by which access issues from a certificate to passwords or accounts could easily be identified and remediated.
It could be better, they could work on the wide-area network and easier because it's a bit clumsy at the moment when we go on to a remote site. It works well in the head office but we've had challenges trying to install it across other sites. So pricing and support for branch offices. The interface is okay for the local office, but it's hard to get visibility from remote branches.
The biggest disadvantage is the pricing. I can see that the product has value. I see that the product is really good. I think that the pro is it's really stable, but price-wise, I think it's bad. But you have to pay for quality. But the pricing can be a little bit improved in my point of view. It will be harder to choose if we start comparing features and prices and when we made the initial choice. Our choice was based mainly on features. There was no price comparison involved. I think that it is not in the same landscape. The landscape has changed and there are a lot of contenders in this field. The price scale could be improved.
Chief Information Security Officer at a tech services company with 501-1,000 employees
Real User
2020-02-20T06:38:06Z
Feb 20, 2020
There's always room for improvement for the solution. Off the top of my head, I really can't determine anything that is lacking right now. Basically there is no room for improvement that I can describe. The solution does have a bit of complexity, and there's some complexity in the deployment. Users need to be trained before undertaking an initial setup.
For the user, the policy that they have implemented sometimes needs adjustments. Sometimes the features that the customer asks for aren't involved in the main installation, and I need to bolt an add-on in. However, I never know if this policy is the right one when I do this.
They should improve features related to IT security. ForeScout should analyze behavior to see if the behavior is malicious behavior and block this device. They should develop the ability to analyze the behavior of the device in my environment. The interface of this solution and the integration part needs improvement. The difference between the 7th and the 8th version is the dashboard. They should improve it.
Forescout Platform provides today’s busy enterprise organizations with policy and protocol management, workflow coordination, streamlining, and complete device and infrastructure visibility to improve overall network security. The solution also provides concise real-time intelligence of all devices and users on the network. Policy and protocols are delineated using gathered intelligence to facilitate the appropriate levels of remediation, compliance, network access, and all service...
For improvements, I think technical support could be enhanced. The time zone difference makes remote support difficult - I'm in Indonesia, and they're in the US. Maybe the Forescout Platform could provide engineers from Asia Pacific.
I'd like to see improvements in the reporting aspect of Forescout Platform. While the dashboards are good, the reports are lacking and need enhancement, especially in terms of standardization and customization options. Apart from that, all the features and functionalities are working well without any issues.
Customer support could be improved by providing direct assistance from Forescout employees or specialists at customer sites to enhance the support experience and effectiveness. The scalability also needs some enhancement.
The product needs to improve its support. I know a case that dragged on for about one and a half years. They eventually suggested professional services and closed the ticket. We followed their advice, engaging the account manager and professional service team, only to discover that the issue was a bug. After reopening the case, it's been about six months, and the problem still hasn't been resolved. Forescout Platform's support often takes a long time to respond to tickets. Even after we reply, there's another lengthy wait for feedback, and their responses sometimes seem to delay resolution with unnecessary questions. For instance, they might ask for details about previous issues. Meanwhile, competitors may offer temporary solutions but often lack or are unsatisfactory regarding technical or research and development support from Forescout Platform's team. Another area where it can improve is when dealing with multiple sites and overlapping subnets. While it works well for individual sites, it struggles when managing several sites with overlapping subnets, especially with authentication portals. I think the Forescout Platform could use some extra features or improvements in the future. Specifically, it could be better at working with other security tools. For example, when it connects with VPNs or security scanners, it could work a bit better. The tool has already made some efforts in this area, but I think it could do even more to make these devices work together
The solution's customer support is bad and should be improved. When our customers try to reach or discuss with the support team, they don't even answer.
Incorporating additional features such as NetFlow DLP, would serve as valuable add-ons. Regarding pricing, there is room for improvement to enhance competitiveness with other vendors and solutions.
Weaknesses of the product are usually present from the side of vendors. In the case of Cisco's vendors, they do have a presence in the South African region. The fact that Forescout Platform doesn't have a presence in the South African region is a weakness because of which you can't ask for help from them if you have any problems. Though they offer support, Forescout Platform does not offer a vendor like other products do for even East Africa ensuring they deliver better services to their customers. The aforementioned area can be considered for improvement. Maybe integration with or onboarding an XDR solution is something I would like to see in future product releases.
Forescout needs to improve its cloud management and remote connectivity.
Forescout Platform's technical support needs to be improved - it could be faster, and its team could be more knowledgeable.
If older network devices are used there can be some compatibility issues while using the Forescout Platform. Additionally, if the switches that are deployed in your infrastructure are not captured properly to the endpoints there might be some difficulties with Forescout Platform trying to monitor the network traffic. Traffic management is an area the vendor should work on.
Unfortunately, Forescout Platform can only be accessed by Android systems. iOS is not supported, so there are some limitations to the operating system. I would like to see all devices have access to the solution. Forescout needs to upgrade its development in the future.
The cost is too high. We are looking at some other solution where costs might be lower.
We have found that the agent-based authentication, available within this solution could be improved. The price-point for this solution is very high, which should be looked at in comparison with similar products currently on the market.
Forescout Platform isn't flexible with connections to devices like printers and forces you to re-enter details like the MAC address after any breakdowns.
Forescout Platform could improve the vulnerability management as well as the control on the endpoint, which needs to be connected to my network. In an upcoming release, they should add security features, such as malware and threat protection.
The product is excellent. As a product, there is nothing to complain about. However, they should improve their overall support. Let me provide an example. Assume you are in the United Kingdom, and you are also familiar with the cars in your neighborhood, and any manufacturer you have heard of. And let's say Forescout is one of the niche products, similar to Rolls-Royce. You know that Rolls-Royce is good, but you need some kind of information accessibility to use that. The comfort is good, and you can obviously drive it, but you need to understand all of the features. You need that level of knowledge, that level of information is clearly not available. First and foremost, that information is not accessible. The second point to mention is that once you purchase the later support and services. That is, they will continue to charge you for every service. Things they should have told you ahead of time are that if you run into problems during the deployment, they will keep asking you to engage the product's professional services, which they will charge you for. And from the standpoint of support, they should be adaptable. When they are aware that customers have made significant investments in these expensive licenses. And it is expected that they will receive adequate assistance. That is where they are falling short. You own a Rolls-Royce, but you are having trouble making the most of its features and functions.
Other solutions have TACACS+, but Forescout does not. In the next release, I would like to see Forescout have accounting.
Forescout Platform could improve the costs of integrations.
Custom integrations need to be better. I'd like to have the option, for example, to integrate the Forescout Platform with a customized application or any other software out there that I am using at the same time. I would like the Forescout Platform to be deployable on cloud solutions, like Huawei. It's not compatible with Huawei at the moment. It can be deployed only on Amazon and AWS.
The most common complaint I hear about Forescout is about their technical support. Some sort of highly scalable platform, such as a private cloud, that can be distributed across a network quickly and grow rapidly, would be beneficial. I believe that the overall user experience has not always been preferable.
Forescout Platform could improve the integration or compatibility with other solutions, such as Chinese-made and other market solutions. They do not have any integration with H3C, RUCKUS Switching, Lenovo, CommScope, IBM Switching etc. which are network/Communication Brands. They do not have integration with new solutions in the market. They do integrate well with Brocade, Cisco, Juniper, and quite a few more but they could expand the integration.
I don't think we tested the full potential of Forescout. We had some delay implementing it into our organization, due internal organizational issues and also due to a lack of device registrations. Meanwhile we decided to switch to a new network provider that doesn't have Forescout in its portfolio. We favour one-stop shopping for network and security services, and will migrate to Aruba ClearPass (portfolio).
This solution could be improved if there was functionality or module integration to connect Forescout with open source, container areas or Terraform. It would also be useful if this solution could run with network plugins to Kubernetes.
The installation is not secure because it takes high admin privileges.
If you want to deploy a new solution to block, you can't do it by yourself. You need the Forescout to deploy these solutions. They could prove this by making it better. There are virtual machine limitations, this is not a solution that they use to protect my company. In the next release of the solution, it could benefit from being more flexible to allow for more freedom.
As a user, if I am using a laptop that is Wi-Fi connected, Forescout identifies my port connectivity as one user license, and if I take that same laptop with the same username to a wired network, which is also the same network that is used for the Wi-Fi connection, Forescout detects it as a separate license. At times, I am working on wireless and sometimes I enter a zone where there is no wireless connection, which forces a land connection. This is an issue that needs to be resolved because it consumes another license for the same device and the same user. This issue has been escalated to Forscout directly. There was integration with Microsoft SCCM previously, and have suddenly stopped the open integration module for Microsoft. Customers are not aware of what is available to them in terms of the open integration module. Forescout Platform advised that there are many options available and many things they can do, but they don't tell customers exactly what they are. They need clear documentation and direction as to what the customer can expect from the open integration module. Customers need some clarity on what they can do and what is not possible to do. When it comes to a full open integration we need to rely on the professional services from Forescout directly, no one can implement it as there is a limited amount of knowledge available. They need to be more considerate, and there should be good documentation available to the customer. They need to improve their selling approach or the consultant approach. One of their use cases is an ITM use case, and ITSS asset management, but they don't really do ITSS management. They only detect the ITSS and all the parameters around that test, but they do not have any integration with any database system where they can store all these details and act like a typical ITSS management system. They should remove that use case in full. They should say that we complement your ITSS management by detecting the unknown assets in your network. This would be right.
The licensing costs are quite high. With the amount of hardware we have, we need too many licenses to make the product effective and it's ultimately just too costly. We may have some problems with compatibility - specifically with Cisco switches. We have the perimeter a Check Point firewall as an alarm for VPN connections. We have users integrating the VPN Check Point with Forescout. We can't seem to scale due to compatibility issues and price.
The reporting feature needs improvement. An example is that currently, you cannot configure what report files will be named. I think that the reporting feature needs more flexibility. It has about 15 templates and you have to use one of them, but it is not easy to understand what each of them is. It would be nice to have more control over the format of the reports. Also, it would be nice if the configuration backup feature had more flexibility. It only supports FTP, SFTP, or SCP. That makes it impossible to write backups to a Windows share.
Better integration with third-party vendors is needed because as it is now, the list of third-party solutions that we can integrate and automate is quite limited. We would like to see the list of vendors expanded to be broader. The types of products that we would like to integrate with are firewalls, patch management solutions, and SIEM applications, for example.
The solution needs more definitive pricing. The costs are hard to nail down.
Truth be told, I'm good with it. I'm yet to have something with the solution that I don't feel comfortable with. It's fine. I've not seen a cause or a reason why I should want something to be changed, but that doesn't take out the fact that there's always room for improvement. What I would love to see is a situation where my Forescout can integrate with different security technologies. Where it can share contextual information bidirectionally. I had written to Forescout about this and they told me they have that functionality already. So I think that settles it. They can share device context with the security technology and that technology can also be shared with Forescout. To build a form of connective strategy towards security. They have a dedicated module for the security technology I'm concerned about. But with that software, I should be able to integrate my Forescout with any other third party security technology, to build that connected security strategy I talked about. So far, it's good. It meets my requirements that I had concern about.
Forescout Platform is too expensive, so the price should be reduced. Although Forescout manages endpoints and network devices, there is no capability for user management. This is something that should be added. For example, if I find that something is wrong in the services and need to disable a user's access, there should be no need to go to Active Directory and disable the user there. As it is now, computers and devices can be disabled, but not users.
I would advise Forescout through their research and development to look for features that they can add. Also, based on the what other competition may be selling, if they find any useful feature, they should add those to their product.
When adding what is in scope to a policy, it would be nice if you could select multiple policies instead of one policy at a time to add what is in the scope for network segmentation. I have found that during the install and configuration of the policies that if you want to modify multiple policies or enable multiple policies that you need to define what is in the scope (IP range or segments) one rule at a time. This caused some slow downs when implementing policies. I could see after doing this repeatedly that it may lead to some premature clicking in an area that you may not have wanted, depending on how your segments are setup, and may cause issues later down the road.
The product could be improved in different ways: * The speed of identification * More guest management features (i.e. extending time frames) * Sometimes, the identification profiles completely change after device upgrades. It would be beneficial to keep or merge these records if enough correlating data points exist, so as not to segment devices. Some of the features introduced into the product line could have better documentation, which could provide for an overall better experience for administrators.
Better reporting and analysis of access (based on client) would be helpful. Also, a tool that allows tracing a user through the rules to authentication. More detailed analysis during the authentication process, especially for troubleshooting access issues. We have found that troubleshooting RADIUS controls is quite arduous, as it is today. A trace function could easily resolve this by providing a means by which access issues from a certificate to passwords or accounts could easily be identified and remediated.
It could be better, they could work on the wide-area network and easier because it's a bit clumsy at the moment when we go on to a remote site. It works well in the head office but we've had challenges trying to install it across other sites. So pricing and support for branch offices. The interface is okay for the local office, but it's hard to get visibility from remote branches.
The solution could always improve by adding more features to make it more robust.
The biggest disadvantage is the pricing. I can see that the product has value. I see that the product is really good. I think that the pro is it's really stable, but price-wise, I think it's bad. But you have to pay for quality. But the pricing can be a little bit improved in my point of view. It will be harder to choose if we start comparing features and prices and when we made the initial choice. Our choice was based mainly on features. There was no price comparison involved. I think that it is not in the same landscape. The landscape has changed and there are a lot of contenders in this field. The price scale could be improved.
There's always room for improvement for the solution. Off the top of my head, I really can't determine anything that is lacking right now. Basically there is no room for improvement that I can describe. The solution does have a bit of complexity, and there's some complexity in the deployment. Users need to be trained before undertaking an initial setup.
The ability to block external devices in Mac is lacking and needs to be added.
For the user, the policy that they have implemented sometimes needs adjustments. Sometimes the features that the customer asks for aren't involved in the main installation, and I need to bolt an add-on in. However, I never know if this policy is the right one when I do this.
We experienced some detection issues when checking compliance for the Sophos agent.
They should improve features related to IT security. ForeScout should analyze behavior to see if the behavior is malicious behavior and block this device. They should develop the ability to analyze the behavior of the device in my environment. The interface of this solution and the integration part needs improvement. The difference between the 7th and the 8th version is the dashboard. They should improve it.
* Battled with the use of SNMP v1 instead of v2c * Direct web interface rather than installation of a client.
Multitenancy should be included in the next version so it could be used as a managed service provider.
* JAVA Memory management - leaving the app running for multiple days requires relaunch * Search - needs boolean functionality (or psudeau operand now working)