The primary use cases include customer environments, BYOD, posture assessment, and dot1x for wireless and wired networks.
Principal consulting architect at a tech vendor with 10,001+ employees
Helps to have a much better security posture overall and provides visibility into response
Pros and Cons
- "The posture assessment is a valuable feature because of the ability to do assessments on the clients before they connect to the network."
- "Cisco ISE has enabled my customers to deploy secure wireless and secure wired networks and gave them a lot of flexibility to do security enforcement."
- "When I work with customers to do my knowledge transfer, they're really overwhelmed with the navigation of the product and the number of things you can do with it. From a user interface standpoint, Cisco could focus on making certain tasks a bit more guided and easier for customers to walk through. That is, a user-friendly interface and streamlined workflows would be great."
What is our primary use case?
How has it helped my organization?
I'm customer-focused, and for my customers, Cisco ISE has enabled them to deploy secure wireless and secure wired networks and gave them a lot of flexibility to do security enforcement.
What is most valuable?
The posture assessment is a valuable feature because of the ability to do assessments on the clients before they connect to the network.
The guests' BYOD portal and onboarding are feature-rich and fairly straightforward and easy to set up.
From a zero-trust standpoint, it is critical that Cisco ISE considers all resources to be external because, in essence, we don't want to allow anybody on the network that hasn't been verified. Even when they're on the network, we want to make sure that they have the least amount of privileges to do their job.
Cisco ISE hasn't eliminated trust, but it's definitely helped us to migrate more toward zero-trust network environments. It helped us to have a much better security posture overall to help eliminate threats and also give visibility into the response.
ISE is generally deployed as a distributed environment, and it makes it easier to have local resources across the distributed environment so that you're not dependent on always-on access to a data center. In case you lose your internet connection or lose an MPLS connection, you can still have a certain amount of security control at the distributed location.
As far as securing access to applications go, with the posture assessment you get a lot more visibility into the applications on the client when you deploy it and a lot more control over enforcing connectivity in the network, especially with secure group access.
What needs improvement?
When I work with customers to do my knowledge transfer, they're really overwhelmed with the navigation of the product and the number of things you can do with it. From a user interface standpoint, Cisco could focus on making certain tasks a bit more guided and easier for customers to walk through. That is, a user-friendly interface and streamlined workflows would be great.
Buyer's Guide
Cisco Identity Services Engine (ISE)
August 2026
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
909,099 professionals have used our research since 2012.
For how long have I used the solution?
I've been using Cisco ISE for about eight years.
What do I think about the stability of the solution?
I've had very few issues with stability and haven't run into any bugs.
What do I think about the scalability of the solution?
It scales quite well. Essentially, you can scale up to about 500,000 users, and most of my customers are south of that.
Which solution did I use previously and why did I switch?
I am familiar with ClearPass. I prefer ISE because most of the environments I'm dealing with are Cisco networks. Having the device administration based on TACACS+ is a plus, with it being a proprietary protocol. ISE definitely implements it better than other solutions. From a conceptual standpoint, ISE makes more sense.
ISE may be a bit difficult for my customers because they're not used to it, but the reality is that the workflows make a lot more sense to me than they did with other solutions like ClearPass.
How was the initial setup?
The first deployment I did was complex because I ran into the same thing my customers did. It's overwhelming at first to figure out because there are so many options and so many different use cases. It was tough to narrow it down to what was important and what could be added later.
However, after having done 30 or 40 deployments, it's now straightforward.
I've deployed the solution in a bunch of different environments. I have manufacturing customers with centralized management and monitoring, so the PAN and the MTS are in data centers that are separate but with PSMs deployed all across the network for the distributed model. There also are some, where everything's pretty much in a data center or is split across two data centers.
What's my experience with pricing, setup cost, and licensing?
Licensing has gotten much simpler since Cisco moved to the DNA model because we just have the three tiers, but it could always stand to be improved upon.
Which other solutions did I evaluate?
I evaluated ClearPass.
What other advice do I have?
To leaders who want to build more resilience within their organization, I would say that it's definitely worth moving toward a zero-trust environment. It's really a rebranding of an old concept of least privileged access, but the tools we have to implement it, such as Cisco ISE and firewalls, at the core and the ability to broker it out to the cloud as well, give us a lot more visibility and a lot more control over the traffic and our data, which is our biggest asset.
If you're evaluating the solution, pick two to three use cases, stick with those, and familiarize yourself with the solution. Try not to get overwhelmed with the interface, and don't try to see everything it can do and let it spin out of control; it's easy to do that. Just start with something you really need to implement and then worry about adding more features later on.
On a scale from one to ten, I would rate Cisco ISE at nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical account manager at a computer software company with 51-200 employees
Eliminates trust from a network and we know exactly what to open and what to trust
Pros and Cons
- "SGTs are valuable because they make it easy to enforce policies, instead of pushing them across all the other platforms."
- "ISE has eliminated trust from our network architecture."
- "I would like to see them simplify the dashboard. It's very configurable, but, at the same time, it's not easy to maneuver through it. They should "Merakify" it."
- "It's damn expensive and the licensing is terrible."
What is our primary use case?
We were looking for secure network access.
How has it helped my organization?
It's important that the solution considers all resources to be external because we are introducing new endpoints to the environment every day. We want to make sure that endpoints are secured. In addition, we want to see what that endpoint is doing in our environments.
ISE has eliminated trust from our network architecture. It has changed the methodology of how we look at security. Instead of having everything open, now we know exactly what to open and what to trust.
What is most valuable?
SGTs are valuable because they make it easy to enforce policies, instead of pushing them across all the other platforms.
What needs improvement?
I would like to see them simplify the dashboard. It's very configurable, but, at the same time, it's not easy to maneuver through it. They should "Merakify" it.
The deployment is complex. I get that it's very configurable, but there is the challenge of how to get to certain things. You go to different places to get the same things done. There needs to be improvement to the GUI.
For how long have I used the solution?
I have been using Cisco ISE (Identity Services Engine) for seven years.
What do I think about the stability of the solution?
It's now way more stable than 2.0 was.
What do I think about the scalability of the solution?
It's scalable, but we get back to the point that you have to deploy multiple nodes across the environment to get the bandwidth for larger environments.
How are customer service and support?
TAC is pretty good. They're solid. The product has been out there for a little bit so that side of things is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We had ClearPass.
How was the initial setup?
It's pretty good when it comes to supporting an organization across a distributed network but it's not easy to implement. It requires a lot of expertise. It requires a full understanding of your environment and the traffic flow.
Our clients have it in multiple locations. At the same time, there are multiple SSIDs on the wireless side and each SSID has a different function for a different group of users. It's not like there is just one set of policies. It has to be multiple policies and sometimes the policies cross each other when moving from one campus to another campus.
Deployment requires a minimum of two solid engineers. One can focus on the network side and the other one can focus on the ISE side.
The way you establish trust is that you first have to "untrust" everything and then you set your points and your profiles and, based on that, you build your policy.
What's my experience with pricing, setup cost, and licensing?
It's damn expensive and the licensing is terrible. There are three different types of licenses: Essential, Advantage, and Premier, and each one of them has certain features. I work with the SLED accounts and it's not easy for customers to find the money. I'm trying to sell their product but, at the same time, to utilize the product fully they have to pay millions of dollars on the licensing alone. And it's software. It's not like I'm selling them hardware with hardware value. It's just software. The prices need to be brought down.
The majority of our clients are still using 2.7, while some have moved to 3.0 or 3.1. That's another issue with the licenses. If you have perpetual licenses on 2.7 and you upgrade to 3, you are forced to go with Essentials. That is one of the issues that I'm seeing with my clients now.
What other advice do I have?
Go for it. It's a great solution. It's very configurable and you can tie your environment together from a wireless or from a wired side. I love the solution.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Cisco Identity Services Engine (ISE)
August 2026
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
909,099 professionals have used our research since 2012.
Senior Network Architect at Commercial Metals Company
Integration with Active Directory means we can find and authorize users based on their AD groups
Pros and Cons
- "The most valuable feature is 801.1x and another very good feature is the TACACS."
- "Without Cisco ISE, we couldn't authorize our users, contractors, and everyone else."
- "I would like to see integration with other vendors, and the RADIUS integration needs to be improved a little bit."
- "Technical support has been okay, but I wouldn't describe it as "very good." We have had some problems with technical support."
What is our primary use case?
We use it mostly for identity, authentication, and authorizations for wireless and wired. The challenges we were looking to address were mostly around the authorization and authentication of the users. We wanted to use the Identity Services Engine to make sure that the users accessing our network were authorized users, with the authentication happening before.
How has it helped my organization?
The integration with Active Directory, and finding and authorizing users based on their Active Directory groups, rather than just their identities, was a big change for us.
What is most valuable?
The most valuable feature is 801.1x and another very good feature is the TACACS.
In addition, it establishes trust for every access request. That's very valuable. We can't authorize users without it. The fact that it considers all resources to be external is very important. Without Cisco ISE, we couldn't authorize our users, contractors, and everyone else. It's our one source of truth for authentication and authorization.
It's also very good when it comes to supporting an organization across a distributed network. We like that.
What needs improvement?
I would like to see integration with other vendors, and the RADIUS integration needs to be improved a little bit.
Other than that, all the features that we're using look good.
For how long have I used the solution?
I have been using Cisco ISE (Identity Services Engine) for about six years.
What do I think about the stability of the solution?
It has been very stable. There's no problem with that, as we have redundancy in place.
What do I think about the scalability of the solution?
It can be scaled very quickly by adding more nodes to the solution. The scalability is very good.
We have it deployed in three data centers in Austin, Texas, Lewisville, Texas, and one in Poland. It's a distributed deployment and we have around 8,000 endpoints on it so far.
How are customer service and support?
Technical support has been okay, but I wouldn't describe it as "very good." We have had some problems with technical support. Sometimes it takes them too long to resolve a problem.
How would you rate customer service and support?
Neutral
What's my experience with pricing, setup cost, and licensing?
The pricing is good. The last time we purchased four new appliances the price was doable for any organization of our size.
Which other solutions did I evaluate?
In my previous job, I used Aruba ClearPass. It's similar to ISE. They're both good.
What other advice do I have?
Design it well in the first place. If you design it well, you can scale it. Always read, line-by-line, the Cisco guide because that's where you'll find all the information about the design and the scalability. If you design it correctly in the first place, you will have a smooth ride.
We want to use it in a hybrid cloud deployment, but we currently use it 100 percent on-premises. As we move more into the cloud, we're trying to integrate that with Cisco ISE to make it our authentication and authorization source. We're not really into the cloud yet. We're just doing some dev. We're building a whole cloud strategy.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Business Systems Analyst at a financial services firm with 201-500 employees
Improved our trust situation, but usability, while improving, still needs work
Pros and Cons
- "It does what it's supposed to. We use a certificate-based authentication method for corporate-managed devices. That means when a user walks in with their managed laptop and plugs it into the network, it chats with Cisco ISE in the background, allows it on the network, and away they go."
- "Cisco ISE definitely helped us pass the audit requirements we had."
- "A main issue is that the upgrade process, over time, is extraordinarily fragile. Repeatedly, over the past several years, when we've tried to upgrade our Cisco ISE implementation, the upgrade has broken it. Ultimately, we have then had to rebuild it because we need it."
What is our primary use case?
Cisco ISE is our network access control solution. We use it to prevent unwanted devices from connecting to our physical network. We also use it for wireless access control on the corporate network, but not on our guest internet network. That difference is because we have Cisco Meraki on the guest wireless.
The solution is in twin private data centers and we did virtual servers, not physical appliances. They're on our VMware platform.
Our business is the lending half of banking only. There are no ATMs or customers coming in with deposits or credit cards. It's a commercial lending operation. We don't have a lot of foot traffic into our locations from our customers. Some might say we're a little overly worried about our physical network, because we're pretty physically secure already. However, we occasionally do customer appreciation events in our locations, at which point there could be 100 people waltzing in and out of any one of our buildings. That's when the regulators say, "That's why you need security." Ultimately, if you let your guard down in the world of security, you're going to get attacked. So, like it or not, we have to button it up.
How has it helped my organization?
Cisco ISE definitely helped us pass the audit requirements we had. We're a type of federally chartered organization and we have a special regulator in the federal space. The need for network access control was born out of audit and penetration test findings. ISE is auditable and we send logs up to our SIEM for analysis.
The solution has also improved our trust situation. It's one of the many pieces that we needed to be buttoned up tight.
What is most valuable?
It does what it's supposed to. We use a certificate-based authentication method for corporate-managed devices. That means when a user walks in with their managed laptop and plugs it into the network, it chats with Cisco ISE in the background, allows it on the network, and away they go.
And when it comes to establishing trust for every access request, no matter where it comes from, it's effective. That's like a "pass/fail" and it passes.
Our environment is a distributed network, across many locations. Cisco ISE runs in a pair of data centers for us: to each client, a primary and a secondary. The database keeps itself synchronized between the two data centers so if one data center is down, we can swing to the other for continuous service. It does its job.
What needs improvement?
A main issue is that the upgrade process, over time, is extraordinarily fragile. Repeatedly, over the past several years, when we've tried to upgrade our Cisco ISE implementation, the upgrade has broken it. Ultimately, we have then had to rebuild it because we need it. There are so many updates and, often, you can't go to a particular update unless you've done all of the updates leading up to it, although I don't think that was our issue.
If they could improve the upgrade process, that would make me sleep a lot better. It's almost like we need to have it pre-qualified before applying an update because our whole world hangs off of it. It is a "center of the known universe" implementation for us.
It is also an incredibly "nerdy" tool, one that is not really well documented for your everyday network and security engineers. It takes a village of specialists to keep something like this running. Cisco is definitely making some improvements in the user interface. It's a little more understandable and approachable. Even for the nerdiest of nerds, having what I call a "kissable baby face" makes it more usable. Cisco knows this and, from version 3 and up, they've been trying to improve the usability and it's getting better. It could use some work.
Not everything is a smart Windows or Mac OS device. We have Windows 10-based user laptops, almost exclusively, and there are some printers and phones and the like that are capable of either a certificate or other 802.1X conversation with Cisco ISE. From an engineering perspective, we just went "way-simple." We do MAC address bypass or MAB tables, which is administratively challenging.
Finally, I believe we've stretched it beyond its capabilities in attempting to make it a multi-client solution, more like a service provider implementation. It's really not architected for that yet. I think that's on the roadmap. This is what I refer to as a monolithic implementation. It is capable of servicing multiple Active Directories and saying, "I recognize this address range equals client X, and this address range equals client Y," and it can interrogate the appropriate Active Directory. But the way that we've implemented that, honestly, is a hack job. It's fully supported, but it's just not multi-client architected. If I had one message for Cisco, it would be: Please make this thing multi-client, or at least more affordable to do separate implementations that somehow get closer together. That's ultimately what multi-client is.
All our various clients are collectively involved with one another. Each of the five owners owns an equal share of the company and all profit and loss flows to each of the owners equitably. It's not that we don't have procurement relationships with one another. However, our regulator continues to believe that separating things is better. That way, if one of you gets taken down, the others aren't affected. Anytime that you have a product that is a type of monolithic implementation, it potentially could affect all of us.
For how long have I used the solution?
For about six and a half years I worked for a cooperatively-owned service bureau, which is where I got the Cisco ISE experience on the service provider side. Now I'm on the customer side or the business side of how these technologies affect our environment, and how hard or how easy they are to integrate.
We've had Cisco ISE in production for about four years now. It was a three-year ramp getting it into production.
What do I think about the stability of the solution?
It works like a champ until you try to upgrade it, and then it becomes risky and fragile. I don't know whether that is because of the complexity of the architecture. We have what I would call a twin database environment. Where we're trying to keep two copies, at a great distance from one another, synchronized. One misstep and there it goes.
What do I think about the scalability of the solution?
It is certainly scalable enough in our environment. We have between 3,000 and 4,000 managed nodes, not counting all of the extra stuff including every type of IOT thing you can imagine: printers, cameras, sensors, a security system. It also doesn't include phones, and we have a phone on every desk, whether there's a user there or not.
When you initially think you've only got, say, 3,000 or 3,500 users, how do you get 15,000 devices on your network? But that's the sad reality these days. Everything is on the network. Every employee typically has three devices on the network at any given time: a phone, a tablet, and a computer. The numbers ratchet up quickly.
The good news is that it's definitely scalable in our environment to handle 25,000 devices spread across between 150 to 200 locations, some of which are very remote.
How are customer service and support?
It is a special class of nerds who know how to work with Cisco ISE, and that's true even inside of Cisco. We have used some third parties, Cisco authorized resellers and solution certified specialists, to deal with this, but that's a last resort. Those are the really expensive people for this because there is such a small community of people who are qualified in this product.
Because it's such a specialized skill, they are not as available as I would like.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We did not have a previous solution.
How was the initial setup?
We were nearly a 100 percent Cisco shop at the time that we selected the product. We had a couple of failed implementations when trying to get it installed. That was likely because we didn't hire the right expertise to assist. Everybody understands the components of it, but when you put it all together, it is just very scientifically complicated.
What was our ROI?
In our case, ROI wasn't really a consideration in going with Cisco ISE. It was a regulatory requirement.
What's my experience with pricing, setup cost, and licensing?
It is fairly expensive and that's part of why we have implemented it in the type of "hack" that we did, to service multiple clients. It would be nice if it were less expensive.
Plan your deployment very carefully. Make sure that you really understand the licensing environment. That was a big surprise, not to my team, but to the end customers who were responsible for the budget for it. Everybody thinks "server-centric," and in this particular case, all of those devices that are being protected ultimately have to have appropriate licensing on the system. There was a lot of, "Oh, I didn't realize I had to buy that part." It's not your everyday product and the pricing model wasn't something people were super familiar with to begin with.
Which other solutions did I evaluate?
We've evaluated some other products since implementing this one. This is not your everyday tool.
The one thing that some of Cisco's competitors have done in this particular space, is to take this stuff to the public cloud. As long as you can do that securely, it is helpful. Maybe that would help in our world. I would love to subscribe to this as a service. In other words, we'd prefer that products like this, products that are that complex, be somebody else's problem and just subscribe to the outcome of them. I'd love this solution to be running in Cisco's world where the real expertise is.
What other advice do I have?
People groan when they realize that they're going to have to do troubleshooting on Cisco ISE; even the nerdiest of nerds. But any product in this space would engender the same reaction. Trying to figure out how I prove that you're allowed to be on my network is not everybody's happy place. We all just want to set it and forget it.
The usability and the upgradability over time, for a product that is in such a critical spot, should be better. I'd love to give it a ten because it was the easiest thing in the world to upgrade. It's just not there yet.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director of cyber security at Borden Ladner Gervais LLP
Secures devices and has good support, but needs a better interface
Pros and Cons
- "The solution is great for establishing trust for every access request no matter where it comes from."
- "The interface is a little bit complex."
- "The interface is very complex, and there are tons and tons and tons of options."
What is our primary use case?
For Cisco ISE specifically, I manage the cybersecurity as well as the networking team. The networking team uses it to track statistics of users coming in and out of the network platform. We use it to track equipment, collect information on identity, and have the help desk leverage the telemetry to troubleshoot. It is part of our day-to-day operations.
This provided security for our sizeable law firm, which has offices across the entire country. Our lawyers like to be mobile. Around six or seven months ago, we started to roll out iPads and really adopted a mobile culture. One of the things that we wanted to do was to provide flexibility for lawyers to walk with a corporate laptop, or walk with their own personal laptop and still have the capabilities to log on and do what they want to do.
We also used it for the many meeting rooms we have. A lot of law firms have tons of meeting rooms, and we needed to secure some of those meeting rooms as well. The technology allowed us to roll 802.1X. We were able to secure ports in the meeting rooms and have a little bit more flexibility as to where users log in.
For example, a couple of years back, we wanted to secure all of the endpoints for the help desk and networking team and all of the backend team and ensure that, irrespective of where one goes with that laptop, when they log in, it'll automatically move them to a secure VLAN. With ISE, we were able to do that and monitor it.
What is most valuable?
One of the things that we found most valuable over the years is the ability for it to provide information to the help desk that allows them to troubleshoot issues. We still use a lot of that today and we're going over to DNA soon. We're adopting some of the DNA technologies now, however, ISE has been the mainstay for us for quite a few years now.
The solution is great for establishing trust for every access request no matter where it comes from. That was one of the biggest use cases for us, as one of the problems that we had was to secure a specific VLAN. If a help desk person had a laptop, and they plugged it into a network cable port somewhere, it would automatically put them on a secure network. If a lawyer uses their laptop, it would put them on a separate network. If a phone is plugged in, it will know it's a phone and put it on a phone network. ISE is the only way we have been able to do that. We've streamlined a lot of our provisioning and de-provisioning processes through Cisco ISE.
It has certainly made it easier to secure our devices. For example, we have offices across the entire country. We are a large law firm and have huge offices in Toronto, Ottawa, Montreal, Calgary, and Vancouver. We also have ISO 27001 and 27017 certified as well and I run that program. One of the big things for us is when auditors come for a visit. All of our locations have a conference floor, a whole floor that's dedicated to conference rooms.
There are tons of large conference rooms. When we get audited, conference floors are usually floors that auditors are allowed to go to, as they're publicly accessible floors. We'll get asked, "How do you secure the port?" When we go into the conference room, they can see the network ports." They will ask, "Well, how do you secure these ports? What if somebody came and plugged their machine in?" We then say, "We use Cisco ISE. Cisco ISE identifies that it doesn't belong to our corporate network. It does a check and then puts them right onto the internet, so we don't need to worry about strangers on our closed network.”
What needs improvement?
The interface is a little bit complex. It doesn't really have an executive dashboard. I'm the director of cybersecurity infrastructure operations for the entire firm, and I'm a very technical person, so I go in, and I can move around and try to figure everything out.
However, the interface is very complex, and there are tons and tons and tons of options. It's quite complex to get into and take a look at. As a result, most of the time, just my networking team would be in there. It's so complex that sometimes I will find something one week, and by next week I can't find it again.
It's too deeply layered. They have to redo the whole interface and have something that's executive based, and another one that's technically based. Even the help desk team and my security team use some of its components, however, they don't go anywhere often, as there are so many options in there. They have to make the interface a little bit more use user-friendly.
For how long have I used the solution?
I've worked with Cisco for about ten years.
What do I think about the stability of the solution?
The stability is ten out of ten. We have not really had issues with it. We've had one or two small things, however, in the 12 years that I've been there, I've had very few issues with their platform.
What do I think about the scalability of the solution?
It scales well. We have no concerns at all. When we decided to roll out 802.1X, we only had it on our endpoint, just laptops. Then we said, "Well, let's scale it out to the wireless access point." We went from 2,000 endpoints to 10,000, since people have mobiles. When we rolled it out to do posture checks on everything wireless, we had no issues.
How are customer service and support?
Technical support is good. I have no issues. Cisco supports its products very well, so we've never really had concerns with that aspect. Also, I have a very, very technical team. My guys are CCIE certified, and they are geniuses in their own rights. They've been in Cisco for 20 years.
They know the product very well and they also work very closely with the Cisco support team. The Cisco support team has very good people. They train their people well, and we've never really had issues that the Cisco team can't resolve if my team can't resolve them. We're taking it for granted that we're getting good support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not use a different solution. We're a Cisco shop, so we've always used Cisco.
How was the initial setup?
I was involved in the initial setup. I manage the networking team. While I don't necessarily push the commands in, I go through architecture sessions with my team, sign off on it and make sure that what it's doing is worth it, it's my budget. I have to get involved.
What was our ROI?
We've seen an ROI. They last a very long time. For example, we have Cisco Campus, which is the next 7000s that we put in 2012, and ten years later, they're still there. We just changed the supervisor modules. However, the chassis is still sitting there and is still working quite fine.
If I'm not mistaken, it's at end of sales already, however, its end of support is in 2024. That's what I like about their products. They support their product for a very, very long time. They easily last for ten years. Even our access switches, which are 4900s, are just being switched out now. Those have been in since probably 2010.
We spend $1.5 million as we have two switches on every single floor. Those are the ones that we're changing out now, and they still work quite fine. Cisco just decided to change them. Their products are very solid and they don't break. We keep them for a very long time. Therefore, the return on investment is not bad. I know when I put it in that I don't need to look at it again for ten more years. I know it's going to be supported for that long.
What's my experience with pricing, setup cost, and licensing?
Cisco is expensive, however, we have a good partnership with our Cisco partner, and we get really good discounts on it. We have a very, very tight relationship with our Cisco representative. We're the largest law firm in Canada and therefore we get special treatment from the Cisco reps in Toronto.
We've had really good relationships with the team at Cisco Canada, and they all know my team, the architects, the solutions engineers, the salespeople, et cetera. They all know us very well. They come to our offices and we go to their offices. We have a very tight relationship.
When it comes to cost, we'll talk to them. They'll tell us when is the best time to buy, and we'll get good discounts. I've never really had to forgo a technology that was critical to the firm due to cost. I can always work with Cisco to find some way to reduce the cost.
Which other solutions did I evaluate?
We always focus on Cisco products.
What other advice do I have?
I'd rate the solution seven out of ten.
It has a lot of rich data in it, however, it's hard to get stuff out of it. You really have to know the product very well and live there to know where to go and find what you are looking for. There's a lot of telemetry in there, however, it's very difficult to actually see how to leverage it.
I've even been telling my security team, "Guys, there's a component in Cisco ISE that you need to work on, and you need to log in more often." Then two years later, they'll ask, "Why don't you guys use it?" The security networking team will say, "Well, we gave them access." My security team will say, "It's too complex. We have no time to go in there. We don't know where to find anything." That's the only problem that they need to fix. They need to make it easier to navigate, it's too deep.
Cisco ISE is a good product. It tightly integrates with all of the networking components, but you can leverage it and get a lot of return and investment out of it. However, you need to make sure that when you're rolling it out and when you're initially putting the platform in, you will need to get your help desk team and security team involved.
Of course, the networking team is the one that's probably going to own it, however, there are so many components in there that can help. The help desk can troubleshoot issues and can provide visibility from the security standpoint, and the networking team owns it anyway. If you get them more involved, they'll be more in tune with using it more often.
There are a lot of help desk and security capabilities in there. Still, just the networking team rolled it out, nobody wants to look at it, as it's a networking piece of the platform, yet really it's not. You can get a lot from this platform. That's probably what I would tell people, just get everyone involved from the get-go, so that they can get more value from it in the long run.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Technology Officer at Oduma Solutions Ltd
Integrates with other applications to manage access
Pros and Cons
- "Cisco ISE provides authentication for various applications. It can integrate with other applications to manage access, including Privileged Access Management for those applications. For a comprehensive environment, Cisco ISE should be able to integrate and provide asset management for an IT organization or any organization."
- "The product is expensive. It would also be a good add-on to have some machine learning."
What is our primary use case?
We used it mainly for network access control and full stream for devices.
What needs improvement?
The product is expensive. It would also be a good add-on to have some machine learning.
For how long have I used the solution?
I have been using Cisco Secure Firewall for one year.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How was the initial setup?
The initial setup is straightforward.
It's also recommended for clients during deployment. You're making everything very efficiently managed within the policies. The deployment is also very smooth, allowing you to configure your rooms easily. Once the initial setup is done, it becomes straightforward to understand, especially regarding Windows maintenance.
It was deployed to protect the network from unauthorized users but does not contribute directly to operational efficiency.
What's my experience with pricing, setup cost, and licensing?
Cisco ISE doesn't come cheap but it's still valid working.
What other advice do I have?
We recommend it to our customers.
Cisco ISE provides authentication for various applications. It can integrate with other applications to manage access, including Privileged Access Management for those applications. For a comprehensive environment, Cisco ISE should be able to integrate and provide asset management for an IT organization or any organization.
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Director, Information Technology Solutions at a healthcare company with 5,001-10,000 employees
Comprehensive and allows you to control access to network resources granularly based on policies
Pros and Cons
- "Cisco ISE is a comprehensive solution that allows you to control access to network resources granularly based on policies."
- "Cisco ISE is very complex and not very easy to deploy."
What is our primary use case?
We use the solution for network access control.
What is most valuable?
Cisco ISE is a comprehensive solution that allows you to control access to network resources granularly based on policies.
What needs improvement?
Cisco ISE is very complex and not very easy to deploy. There are a lot of prerequisites for the tool.
For how long have I used the solution?
I have been using Cisco ISE (Identity Services Engine) for three years.
What do I think about the stability of the solution?
We did not face any issues with the solution’s stability.
What do I think about the scalability of the solution?
Cisco ISE is a very scalable solution.
How are customer service and support?
We are working with a partner for support and are very happy with them.
On a scale from one to ten, where one is bad and ten is good, I rate their support a seven or eight out of ten.
Which solution did I use previously and why did I switch?
Compared to Cisco ISE, Fortinet NAC is more consumer-friendly.
How was the initial setup?
On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup a four out of ten.
What about the implementation team?
The project lasted a few months, but the planning took several months. Cisco ISE itself means nothing. It has to have the network set up to ensure the network penetration is in place, and we're still working on that.
What was our ROI?
Security is about risk control and exposure avoidance. You can only calculate its return on investment based on how you avoid penalty fees. Cisco ISE improves our security stats.
What's my experience with pricing, setup cost, and licensing?
If you consider money only, Cisco ISE is not a cheap solution. Functionality-wise, however, it offers a very good price for the value you receive.
What other advice do I have?
The solution's compliance and policy enforcement capability has benefited our organization by simplifying work.
The solution operates in the background, and users generally don't interact with it. Cisco ISE is the security framework layer between network resources and end users using them. Users do not go into Cisco ISE to do anything.
It's like Active Directory for Identity. If you're an end user, you don't work in Active Directory, but you authenticate Active Directory to use resources on the network. The same applies to Cisco ISE, and users don't interact with it directly. They are affected by it to the extent to which they are accessing network resources.
Cisco ISE has a very comprehensive integration suite and we did not face a lot of challenges in integrating this solution with other security tools. If they know how to use it, I would recommend the solution to other organizations with similar security needs.
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a insurance company with 5,001-10,000 employees
Works seamlessly and provides insights into authentication issues
Pros and Cons
- "I like the logging feature."
- "I don't like the fact that we can see the logs only for 24 hours. Maybe that happens because of the way we set it up."
What is our primary use case?
We use the solution for RADIUS authentication, device authentication, and TACACS. We also use it for Wi-Fi and guest portals.
What is most valuable?
I like the logging feature. I like that I can look at the logs for authentication issues.
What needs improvement?
I don't like the fact that we can see the logs only for 24 hours. Maybe that happens because of the way we set it up.
For how long have I used the solution?
I have been using the solution for six years.
What do I think about the stability of the solution?
The stability solution is really good. Once we get it up and running, it's great. We have to do a major upgrade, and I'm not as thrilled with the upgrades as I am with just a day-to-day job integration. Upgrades aren't my favorite thing.
What do I think about the scalability of the solution?
The product’s scalability is great. We do not have any issues. We could scale it up without any problems.
How are customer service and support?
Sometimes support is better than others. It depends on who you get. Some guys are really sharp, and for some guys, it takes a little bit longer to get the thing escalated.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We used Secure ACS, which was a Cisco tool. Cisco discontinued support for it, so we switched to Cisco Identity Services Engine.
What was our ROI?
The product runs. It does what it needs to do, and we don't have to touch it most of the time. From that standpoint, we have an ROI.
Which other solutions did I evaluate?
The product didn't really have a whole lot of competitors at the time. Aruba ClearPass was probably the only other competitor. We were getting rid of Aruba from our wireless. Identity Services Engine was just farther ahead than ClearPass at that time.
What other advice do I have?
We have a lot of things we use for detecting threats. We use the product more for authentication issues and stuff like that. We don't use it to identify threats per se. We have other tools.
The solution helps free up our IT staff. There are only a couple of us who are Cisco Identity Services Engine administrators. In that way, other people can do other things. Once we set up the solution, there's really not a whole lot of maintenance to it. I don't know how many hours it saves. It just works, and we don't have to touch it most of the time. It does its job.
We were using Cisco ACS before using the product. We changed tools and upgraded. The tool helps us improve cybersecurity resilience. We use it for RADIUS and to validate users. There are a lot of tools that we use. Cisco Identity Services Engine is a good tool. It does 802.1X and RADIUS very well. Cisco shop is the way to go.
Overall, I rate the solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber systems Engineer at a manufacturing company with 10,001+ employees
Has good posturing and prevents other users from insider threats
Pros and Cons
- "We found all the features of the product to be valuable."
- "They should improve their licensing. Licensing is always trouble with Cisco, and Cisco Identity Services Engine is no different. The way the product is licensed could be improved."
What is our primary use case?
We use Cisco ISE Identity Services Engine currently for TACACS and posturing.
How has it helped my organization?
The product elevated my organization’s security level, helped us meet some guidelines, and made our life easy.
What is most valuable?
We found all the features of the product to be valuable. We have no complaints about it. Posturing is valuable to my organization. Now, we're improving our whole environment to go into a Zero Trust policy, and Cisco Identity Services Engine plays a huge role in it. We're defense contractors, so we support DOD and have specific stakes and a baseline to go with. Our strict environment requires us to do certain things, and the solution plays a role in it.
What needs improvement?
They should improve their licensing. Licensing is always trouble with Cisco, and Cisco Identity Services Engine is no different. The way the product is licensed could be improved.
For how long have I used the solution?
I have been using the solution for almost three years.
What do I think about the stability of the solution?
The solution’s stability is good to go so far. Some vulnerabilities had popped up like any other solution, but Cisco remediated them. There was no problem.
What do I think about the scalability of the solution?
We haven’t even scraped to the surface of what the tool could do. It's very scalable, and we will try to use it as much as we can in the future.
How are customer service and support?
We have had no issues with the product’s customer support so far. We had a neutral experience with support.
How would you rate customer service and support?
Positive
What was our ROI?
We have seen a return on investment in terms of not pursuing any other solutions. We didn't need to look further. The product did what it does for us now. We are very content with it. We don't have to invest further into something else.
What's my experience with pricing, setup cost, and licensing?
The solution’s pricing is okay.
What other advice do I have?
The tool secures our infrastructure to a certain point. However, we're not using it in terms of detection. My team is only four people, and we take all the tasks together.
The solution did not help us consolidate tools. However, it does help us with TACACS. TACACS was a big thing that we needed. We are trying to get rid of NPS and RADIUS, and we will probably use the product in the future for Certificate Authority. It could probably consolidate tools, but it's not doing it now. However, it will in the future.
The product has absolutely improved our cybersecurity resilience. With all the posturing we're doing and the Zero Trust policy we are bringing, it prevents other users from insider threats. It helps big time with insider threats. It's a big thing for us in our specific programs.
Give it a shot because we did give it a shot. People at first said it was very pricey, but it wasn't really as pricey as people say it is. It's worth trying it. Zero Trust will be mandated later, especially if you're in the government. The product will play a big role in it.
One of our team members was pursuing a certification in CCMP security. He was specifically on the Cisco Identity Services Engine track. We got that for him to demo and test it out. Eventually, it became part of our product. TACACS, Posturing, and Certificate Authority could be the reason why we chose the solution. We are using it now for 802.1X. All port security is not a thing anymore for us.
Overall, I rate the product a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Services Engineer at a government with 51-200 employees
Significantly improves our security and has been great for segmenting our traffic and getting the users into the right VLANs
Pros and Cons
- "The feature that I found most valuable is profiling. We use that to profile certain types of devices, and then depending on the manufacturer, drop them into the appropriate VLAN without us having to go in and manually add the devices."
- "We would definitely like to see a little bit of an improvement in the web GUI navigation. Some of the things are a little bit hidden in the drop-down menu. If we could get a way to get to those quicker, it'd be much more useful."
What is our primary use case?
We use Cisco ISE to authenticate users or devices onto the network and then drop them into the appropriate VLANs to isolate them and maintain network segmentation.
How has it helped my organization?
Cisco ISE has been a great tool to segment our traffic and get the users into the right VLANs. It definitely does free up a lot of time from manual configurations.
It has definitely improved our security a lot. We used to be a single flat network, and now, we are a segmented network where we have all our different traffic isolated so that in case we do get a breach, not all the customers are affected.
Cisco ISE has been great for securing our infrastructure from end to end so that we can detect and remediate threats. We've already seen it detect some devices that we didn't know about, and they quarantine those devices, allowing us to take the appropriate security actions against them.
Our IT staff has been freed up for other projects with Cisco ISE because we're able to do a little bit more automated configuration. We just throw out a single configuration to the ports, and then the users get dropped into whatever VLAN they need to be in without us having to go to each site and configure these things manually. On a usual workday, it has freed up at least a couple of engineers for two to three hours.
Our cybersecurity resilience has improved with Cisco. Users are now segmented. We have firewalls in between, so we can take a look at all the traffic. We have quarantine enabled in there so that if we get a device on our network that we don't recognize, we can lock it down.
What is most valuable?
The feature that I found most valuable is profiling. We use that to profile certain types of devices, and then depending on the manufacturer, drop them into the appropriate VLAN without us having to go in and manually add the devices.
What needs improvement?
We would definitely like to see a little bit of an improvement in the web GUI navigation. Some of the things are a little bit hidden in the drop-down menu. If we could get a way to get to those quicker, it'd be much more useful.
For how long have I used the solution?
We've been using Cisco ISE for about three years.
What do I think about the stability of the solution?
So far, from what we've been using, we haven't had any problems even with any of the additional patches that we've added. It has been great.
What do I think about the scalability of the solution?
Scalability-wise, it's great. We have plenty of space to add additional nodes. Right now, the ones we do have are not being utilized to a hundred percent, so if we ever do need to add additional, it seems pretty straightforward.
How are customer service and support?
Cisco support has been pretty good over the years, helping us get this stuff up and running. It has definitely taken us a while, and some of the cases have been pretty long, but Cisco support has been pretty good. I'd rate their support a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We weren't using anything in place of Cisco ISE previously. We were pretty lacking in that department. When we got Cisco ISE, we improved our security significantly.
We went for Cisco ISE based on a suggestion from one of our vendor partners who helped us with our network refresh. They said that Cisco ISE was something that they had used previously in lots of larger deployments, and they had seen great success with it.
How was the initial setup?
I was involved in its deployment. It was pretty straightforward. A lot of the issues that we ran into were related to coordination with the users just because it was a change for them, but the actual deployment and everything else were pretty straightforward.
What about the implementation team?
We used MTT. They were great. They walked us through the whole process. They designed the network refresh for us as well as the Cisco ISE integration portion of it.
What was our ROI?
We've seen an ROI. We've freed up some hours, so those engineers who were previously doing more mundane tasks are now able to do something else.
What's my experience with pricing, setup cost, and licensing?
I don't know too much about the actual pricing on it. The licensing part is pretty straightforward. It's a lot more simple than some of the other Cisco licensing models. In that aspect, it's great.
What other advice do I have?
Overall, I'd rate Cisco ISE a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Popular Comparisons
Cisco Secure Firewall
Cisco Umbrella
Aruba ClearPass
Cisco Secure Email
Cisco Secure Network Analytics
Forescout Platform
Fortinet FortiNAC
ThreatLocker Zero Trust Platform
Cisco Secure Endpoint
Cisco Secure Client (including AnyConnect)
F5 BIG-IP Access Policy Manager (APM)
Cisco Secure Workload
ExtremeCloud IQ
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- ForeScout vs. Cisco ISE
- What are the main differences between Cisco ISE and Forescout Platform?
- Can Cisco ISE disallow authentication based on OS?
- Cisco ISE (Identity Services Engine) vs Fortinet FortiNAC: which solution is better and why?
- What are the requirements for integrating the Cisco Data Center and Cisco ISE?
- What is the biggest difference between Aruba ClearPass and Cisco ISE?
- Which is better - Aruba Clearpass or Cisco ISE?
- How would you compare Cisco ISE (Identity Services Engine) vs Forescout Platform?
- How does Cisco ISE compare with Fortinet FortiNAC?
- What is your experience with 802.1X when using EnGenius WAP/switch with Cisco ISE 2.1?













