We use ISE for TACACS and 802.1X authentication, wired and wireless. We also use ISE for our VPN authentication, as well as for different policies. We were trying to solve some security holes with Mac solutions, and ISE was a good fit.
Network Engineer at Universal Health Services, Inc.
The solution is reliable and the policy sets are really nice and dynamic
Pros and Cons
- "I love the policy sets, they are really nice and dynamic."
- "This solution helps to support an organization across a distributed network."
- "ISE is a little clunky. The front-end feels like it is from the 1980s."
- "Technical support is horrible. If we call and ask them for help, their first response is always that we should upgrade."
What is our primary use case?
How has it helped my organization?
It helped our security, which is nice.
What is most valuable?
I love the policy sets, they are really nice and dynamic.
This solution helps to support an organization across a distributed network. It's built for enterprises and large-scale deployment. It does what it's supposed to do.
What needs improvement?
ISE is a little clunky. The front-end feels like it is from the 1980s.
The usability, as far as programmability goes, needs to be improved.
Buyer's Guide
Cisco Identity Services Engine (ISE)
September 2026
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,322 professionals have used our research since 2012.
For how long have I used the solution?
I've been using Cisco ISE for about three years.
What do I think about the stability of the solution?
The solution is pretty stable. I haven't had any problems.
What do I think about the scalability of the solution?
Cisco ISE is very scalable.
How are customer service and support?
Technical support is horrible. If we call and ask them for help, their first response is always that we should upgrade. That is a horrible response. We pay another company to support us because the technical support can't, even though we pay them to do so. I would give them a two out of ten.
How was the initial setup?
We have a distributed deployment model. They're all virtual appliances, distributed geographically.
We've got six ISE nodes. Everything is redundant and distributed across multiple data centers. We then used them again for 802.1X, TACACS, and other authentications and policies.
What other advice do I have?
It's hard to dig into at first, so seek help and education.
I'd give Cisco ISE (Identity Services Engine) an eight on a scale from one to ten because it's Cisco, it's reliable. It has a lot of development and other vendors around it because it is Cisco. It works and is pretty stable.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead Technical Architec at Commercial Bank of Ethiopia
Review about Cisco ISE (Identity Services Engine)
Pros and Cons
- "It's easy to change and add policies."
- "Some of ISE's features need to be more agile. For example, we couldn't integrate our data because Cisco needs your data to be in its own format."
What is our primary use case?
We use Cisco ISE to set different policies for various profiles. For example, someone on their own device has a different set of policies and postures than a person on a company machine.
Currently, we are using Cisco's dictionary for both device and user authentication. When I say "device authentication," I mean we authenticate users who access network devices.
We consider the running policy when users want to access a data center server. The user is forwarded to the ISE servers to be authenticated, and they're given a password defined on the ISE for them according to the policy.
We have two virtual servers with different rules. For example, one is used to authenticate and audit, and the other to authorize and authenticate. And since most of our centers don't support full ISE integration, we use only some features. That means not all our users are not authenticated via the ISE.
What is most valuable?
It's easy to change and add policies.
What needs improvement?
Some of ISE's features need to be more agile. For example, we couldn't integrate our data because Cisco needs your data to be in its own format.
For how long have I used the solution?
We implemented Cisco ISE about a year ago.
What do I think about the scalability of the solution?
We have capacity limitations with retail, and we aren't integrating ISE for all the users. We have about 2,000 end-users that need to be integrated, and we added the entire thing to about 1,000 devices.
How are customer service and support?
I rate Cisco support eight out of 10. We initially had difficulty integrating ISE with another solution we use from Huawei. We deleted the existing profiles defined on ISE and lost our definitions and profile features that were there before. We ordered the platform through these resellers, but they haven't been helpful, so we get more support from Cisco. They are very good.
How would you rate customer service and support?
Positive
How was the initial setup?
Setting up this solution wasn't that difficult for me because I was involved with all of these projects. We implemented everything last year and deployed a portion of the modules integrated into our environment. It wasn't that difficult to install and apply to get these permissions.
What about the implementation team?
A contractor came to help us deploy everything as part of the bank's data center solution. Since then, I have installed one of the components that we deployed at the time. It was a local tech company that got the platform given to them. That's how they got everything implemented with it together.
What was our ROI?
The return on investment depends on how you utilize the solution. We haven't utilized it well thus far, so I would rate it four or six out of 10.
What's my experience with pricing, setup cost, and licensing?
There is a limit on the number of nodules supported. The number of users per license is limited to around 2,000, so the license price should be adjusted to take these limitations into account or we should be allowed to add more users to the same devices.
We use ISE because most of our networking devices are from Cisco, including the VIRL lab. I have to compare other vendors, but I don't think the cost difference is so much that I would switch solutions.
What other advice do I have?
I rate Cisco ISE eight out of 10. It works fine in our experience.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco Identity Services Engine (ISE)
September 2026
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,322 professionals have used our research since 2012.
Accounting Executive at a tech services company with 11-50 employees
Highly granular and effective NAC, but also complex to deploy
Pros and Cons
- "The way the ISE works is you can get into defining. Let's say, in my case, I've got a Windows laptop and I've got an Apple product and those have unique identifiers, unique back addresses. It would say that this in my profile so I could get to those apps with either device, 24/seven. That's how granular the ISE or these NAC Solutions can get."
- "In terms of stability, they are rock solid."
- "In the next release, I would want to see this kind of solution in the cloud as opposed to on prem because when enhancements are made to the software, if it's in the cloud, it's overnight. I mean you're not going to have to respin the servers that the license sits on, it's all microservices kinds of things in the cloud. That would be my recommendation. If I'm a customer, that's what I'm looking at - for cloud based software subscriptions."
- "I can tell you, even as a Cisco person, ISE was considered very complex and difficult to deploy."
What is our primary use case?
The ISE product is used to make sure that folks can get access to the application servers that they need to get access to, let's say for accounting and another group like sales and marketing, they would have no business accessing each other's servers, those apps. So you would set up a policy that allows accounting to do what they have to do whether they're remote or on campus and then the sales and marketing folks could never access that. They are totally blocked. It's a virtual firewall, basically.
What is most valuable?
The way the ISE works is you can get into defining. Let's say, in my case, I've got a Windows laptop and I've got an Apple product and those have unique identifiers, unique back addresses. It would say that this in my profile so I could get to those apps with either device, 24/seven. That's how granular the ISE or these NAC Solutions can get. That you have to have that same device.
They can get into the antivirus. They will check the antivirus to see if it's the most current version and if it's not, if that's your policy, it will let you go through and access the app if the antivirus has been updated. But if the policy was that it has to be the most current version, then it can block you until you upgrade the antivirus.
What needs improvement?
As far as what could be improved, to continually be thinking about ransomware, cyber attacks, and all those kinds of things. They always have to be innovating. Always have to be improving. I can't give you anything specific because these cyber guys are always coming up with new ways to get in. You just really have to be aware of what's going on.
In the next release, I would want to see this kind of solution in the cloud as opposed to on prem because when enhancements are made to the software, if it's in the cloud, it's overnight. I mean you're not going to have to respin the servers that the license sits on, it's all microservices kinds of things in the cloud. That would be my recommendation. If I'm a customer, that's what I'm looking at - for cloud based software subscriptions.
What do I think about the stability of the solution?
In terms of stability, they are rock solid. If you set the policy and you implement it, it's not going to break.
What do I think about the scalability of the solution?
They scale. You just have to buy licenses. Whether you're talking about 5,000 users or more, it's just a licensing model.
What I saw most customers trying to do was to outsource it to the partner. A value added reseller would have to do that. They typically haven't been trained. They have to go to school, get certifications and that kind of stuff. That's always a requirement, but most people weren't going to tackle that themselves. They're going to farm it out to somebody who has done it before, who has the expertise to do it.
I do anticipate increased usage. Pick a vendor, like Cisco and Aruba, because for all the threats that are out there, they are always going to have some kind of a NAC strategy. You have to. You really have to. The days of the firewall or perimeter security are over. There are just too many possible ways people can come into your network - disgruntled employees, someone that got paid off, you never know. This is always going to be here.
How are customer service and support?
They're very good. All of them are very good.
Which solution did I use previously and why did I switch?
It has been pretty much Cisco from the beginning. With another VAR recently, we were pitching the Aruba ClearPass. And actually the ClearPass will run on top of a Cisco infrastructure, which is kind of cool. That's unique, but the ISE doesn't go that way. You won't run ISE on top of an Aruba infrastructure, but Aruba built that solution from day one to be compatible with Cisco switches and routers and wireless stuff. I thought that was pretty compelling.
Cisco has their ISE, their Identity Services Engine. The other one that I would tell a customer to look at would be the Aruba ClearPass. I don't know enough about the Juniper Solution to make any comment about that. But those are the two that I think about the most for identity solutions.
How was the initial setup?
The first part is to figure out what you want, what the customer wants to protect, who needs to be protected, and to gather all the data you can on users, contact information, the devices they use, the Mac addresses of the devices, what time of day, what apps... I mean you really have to dig into all that. It's not easy. It's hard. The bigger the customer, the more complex it is going to be. But if you don't do that, the deployment is not going to go well. Really consulting on the front end has to occur.
On the consulting part, it depends on how big the customer is, how many you're talking about - 5,000 users or 50 users. That drives the answer. I would say if you don't take 30 days to scope it correctly and document, if you do something less than that, the execution deployment is going to go sideways and that can be months. Those things are months. Those could be six months or so. You've got to pick a pilot case. You build a template, you do a small group, and then you see how the reactions are, see if the users accept that policy, make sure it's right. I would do it group by group. Accounting first, or IT first. And then you do the sales and marketing and HR and all those kinds of things.
What was our ROI?
In terms of ROI, the only thing that comes to mind is if you look at whatever the current market data says for a breach cost if you have ransomware attack or something, if you choose to rebuild your network, as opposed to paying the ransom, what does that cost? Is that $100,000 a day? Is that a million dollars a day? So whatever that cost is, go look at the cost of the NAC licensing, ISE or ClearPass. And that answers the question for you. If you can block the threats on the front end, you can avoid the whole ransomware conversation.
What's my experience with pricing, setup cost, and licensing?
I have not looked at the pricing in a while. I don't really know. These companies are putting together enterprise license agreements, like a site license, and they'll do multiyear and they'll make them pretty aggressive. If you are buying three security packages from them, for example, they'll give you a significant discount. If you're at two, when you look at the cost to go to a third one, they'll just do it because it discounts the whole package altogether.
As for extra fees and costs, it is just a subscription model, pretty predictable.
What other advice do I have?
I can tell you, even as a Cisco person, ISE was considered very complex and difficult to deploy. That was coming from both the customers and the partners that had to deploy it. It can be very complex and you really have to know what you're doing. The thing that we always stress with customers is to go through and build a policy first. Decide what you want to block, and who is going to have access to what, and do some due diligence on the front end because once the policy is created, then you can deploy what we have all agreed to. As opposed to just trying to wing it and figure as you go - that is not a good play. That was always the comment from the Cisco customers.
My advice to prospective users it to find a consultant or a VAR that has done it before. I think that is key. And then talk to a customer that they did it for.
On a scale of one to ten, I would rate Cisco ISE a seven. That is because it is so complex. I mean, it's not a trivial task.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant general manager at Beximcocomputers
Highly-Recommended Solution with Commendable Integration Capabilities
Pros and Cons
- "The valuable feature of the solution lies in its integration capabilities with other applications."
- "The tracking mechanism in Cisco ISE is relatively costly, especially its vendor-specific protocol."
What is our primary use case?
We primarily use the solution for network access control solution and network device access management. The solution comes with features like posturing.
What is most valuable?
The valuable feature of the solution lies in its integration capabilities with other applications. This facilitates seamless operations like Microsoft migration across networks and call center management. The ability to segregate multiple domain users in the Access Network ensures efficient, logical management.
What needs improvement?
The tracking mechanism in Cisco ISE is relatively costly, especially its vendor-specific protocol. It would be beneficial if it could support open source or other devices with a similar checking mechanism, but unfortunately, it remains proprietary.
For how long have I used the solution?
I have been working with the solution for the past five years.
What do I think about the stability of the solution?
The solution is highly-stable. I rate it a perfect ten.
What do I think about the scalability of the solution?
The solution is scalable. We have three users for the Cisco ISE.
How are customer service and support?
Their customer service and support is excellent.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup is straightforward. Effective planning is crucial for the setup of Cisco ISE. Placement of the virtual solution requires careful consideration of network accessibility from all branches. Different components may need placement in various areas in a large network. So, thoughtful planning for the architecture is important. It takes around two days for the deployment.
What's my experience with pricing, setup cost, and licensing?
Previously, Cisco ISE had a perpetual licensing model, but now they have shifted to a subscription-based licensing system. We now have to pay recurring costs. This change in the pricing model has presented challenges for many customers accustomed to the simplicity of the previous licensing model.
What other advice do I have?
I recommend this solution to all. Overall, I rate it a perfect 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network Manager at a government with 201-500 employees
Helps save us time and seamlessly integrates with our entire suite
Pros and Cons
- "The most valuable feature of Cisco ISE is its seamless integration with the switches and the entire suite, enabling wireless access and smooth client information retrieval."
- "If Cisco could grant more control, the features could be more focused on network and security administration, reducing the need for integration with other components."
What is our primary use case?
We use Cisco ISE for the authentication of wireless clients.
How has it helped my organization?
Cisco ISE has saved me a couple of hours per month in terms of not having to manually onboard clients. However, there are still some manual tasks that need to be uploaded to Cisco ISE.
What is most valuable?
The most valuable feature of Cisco ISE is its seamless integration with the switches and the entire suite, enabling wireless access and smooth client information retrieval.
What needs improvement?
One of the problems we have had is that there are many features on Cisco ISE that we are not utilizing. In the real world, it requires multiple parties to come together, just like the AD or OU. Therefore, it won't be solely the responsibility of the network or security personnel to ensure that the solution works as intended and utilizes all the features. It necessitates collaboration among various stakeholders. If Cisco could grant more control, the features could be more focused on network and security administration, reducing the need for integration with other components. This would be beneficial for my organization.
For how long have I used the solution?
I have been using Cisco ISE for one and a half years.
What do I think about the stability of the solution?
Cisco ISE is extremely stable.
What do I think about the scalability of the solution?
As long as we have the funds to purchase the license, Cisco ISE is highly scalable.
How are customer service and support?
We have a contact person in Singapore whom we can reach at any time for support.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was straightforward because we used an integrator.
What about the implementation team?
We used an integrator for the implementation.
What was our ROI?
The cost-benefit analysis primarily considers the time saved through manual labor.
What's my experience with pricing, setup cost, and licensing?
The recent changes in the licensing model have caused some issues with the team.
Which other solutions did I evaluate?
We have a rigorous procurement process and carefully evaluated other options before selecting Cisco ISE.
One of the other solutions we evaluated was the Aruba Wireless feed and its accompanying authentication, but we determined that Cisco ISE was superior and more beneficial.
What other advice do I have?
I would rate Cisco ISE with a nine out of ten based on its overall benefits. However, since I am unable to utilize all the features due to the need for coordination from numerous other teams, I would personally assign it a benefit score of only five out of ten.
We attempted role-based access with the Cisco ISE integration, but it didn't work out effectively because it is more of an upper-level issue regarding organization and role level. Multiple teams had to collaborate, and there was a need to configure the Active Directory and Organizational Unit groups. This also involved restructuring and similar tasks. As individuals moved between OU groups, someone had to consistently update the OU groups to ensure the success of the process.
We have made a significant investment in Cisco infrastructure; therefore, we have chosen Cisco ISE as a logical option for our authentication mechanism.
Cisco ISE has not directly assisted our organization in enhancing its cybersecurity resilience.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager of Systems Architecture at a computer software company with 51-200 employees
Keeps us safe from rogue devices and helps to ensure that all devices meet the requirements for patches and certificates
Pros and Cons
- "It's keeping our company safe from rogue devices connecting to our network. From a security standpoint, there's peace of mind knowing that every device that connects is a good one."
- "The upgrades could be better. Every time we try to do an upgrade, we have problems. It's a pain."
What is our primary use case?
We use it to ensure that any device that connects to our network or wireless environment is a company-owned asset and has all the security certificates. We aren't doing too much remediation. We just identify whether it's one of our assets and whether it's allowed.
How has it helped my organization?
In our company, we have a lot of remote workers. Knowing that even devices that are coming through a VPN comply with our policies, whether they're in the office or they're remote, face the same level of scrutiny is a benefit to our company.
We can set as in-depth alerts as we want to. We can set up an alert through email, text, etc.
It has helped to improve our cybersecurity resilience. It helps to ensure that all devices meet the patching and certificate requirements.
What is most valuable?
It's keeping our company safe from rogue devices connecting to our network. From a security standpoint, there's peace of mind knowing that every device that connects is a good one.
What needs improvement?
The upgrades could be better. Every time we try to do an upgrade, we have problems. It's a pain.
For how long have I used the solution?
I've only been with the company for six months, but they adopted Cisco ISE about three to five years ago.
How are customer service and support?
Support has always been good. Overall, I'd rate them an eight out of ten. Sometimes it feels that their first-level support hasn't been trained in-depth.
How would you rate customer service and support?
Positive
How was the initial setup?
We have redundant solutions across all of our data centers, policy nodes, and authentication nodes. As far as I know, we started off in a small deployment with our wireless. We profiled our devices to ensure that they belonged to our companies before we let them access, and then from there, we expanded into profiling wired ports as well, so we started very small and then moved to a larger solution.
In terms of our plans to increase its usage, we may use Cisco ISE in different ways, but the number of nodes that we have will probably stay the same. With version 2, we're moving more of our deployment to the cloud, so we'll move from the on-premise solution to the cloud. We've already started the process. We have some nodes built in the cloud, and we just have to move the production and then remove our on-prem. We're using Oracle Cloud for our highest deployments. It will be fully cloud.
What was our ROI?
We've seen a return on investment from the security aspect.
What other advice do I have?
I'd advise starting just the way we did. Start small because there are a lot of use cases of Cisco ISE. If you try to do it all at once, you might be disappointed, so start small and pick an area that you'd like to focus on, get that piece done, and then go from there.
It hasn't really helped to free up our IT staff for other projects. It also hasn't helped us consolidate any tools.
Overall, I'd rate Cisco ISE an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Data Engineer at a healthcare company with 5,001-10,000 employees
Does everything under the sun but is hard to upgrade and manage
Pros and Cons
- "It works as a good RADIUS server. It has lots of features. It works with all the proprietary Cisco AB pairs and features."
- "It could be less monolithic. It's one huge application, and it does everything under the sun, so it's hard to deal with and upgrade and manage."
What is our primary use case?
Right now we use Wireless.1X and TACACS for device management. It's in our wired network too, but only use it for MAC address bypass.
How has it helped my organization?
It has helped to consolidate tools and applications. Previously, we had Windows NPS in some places and then Cisco ACS in other places. Now, Cisco ISE is all I use. This consolidation hasn't had a whole lot of impact on our organization. It wasn't that big of a deal to begin with.
What is most valuable?
It works as a good RADIUS server. It has lots of features. It works with all the proprietary Cisco AB pairs and features.
What needs improvement?
It could be less monolithic. It's one huge application, and it does everything under the sun, so it's hard to deal with and upgrade and manage.
For how long have I used the solution?
I've been using Cisco ISE for three or four years.
What do I think about the stability of the solution?
Overall, it's pretty stable.
What do I think about the scalability of the solution?
It seems to be pretty good for what we're doing with it.
How are customer service and support?
Cisco TAC support is hit or miss. It depends on who you got. I'd rate them a six out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We didn't have any network access control. For the wireless, we had ACS, and some places used NPS from Windows.
We chose Cisco ISE because we have a Cisco network. It seemed like the obvious choice.
How was the initial setup?
The initial setup was pretty easy, but trying to get all the switches to talk to ISE was pretty complex. It required a lot of configuration and learning, and we found a lot of bugs and issues along the way.
What about the implementation team?
Initially, we took the help of Presidio. They were good. They knew a lot about it and helped us a lot.
What other advice do I have?
In terms of detection and remediation of threats, it wouldn't detect anything. If we integrated it with other products, it could cut certain clients off from the network, but we haven't gotten that far yet.
It hasn't helped to free up our IT staff. It has probably consumed more time.
I don't have a lot of familiarity with other products, so I'd rate it a six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a financial services firm with 201-500 employees
Helps to ensure that we're secure and no unauthorized devices are accessing the network
Pros and Cons
- "TACACS and .1X security are the most valuable features. TACACS acts for user control, so no one can authenticate to our network devices, and .1X is to validate that unauthorized devices are plugged into our network."
- "Its user interface could be better. It's not bad. They've just redesigned the whole user interface. It's not terribly difficult. The drop-down menus are easy to use. However, when you're looking for some things in the user interface, it takes a minute to find where you were prior."
What is our primary use case?
We use it for Cisco device TACACS authentication and .1X security.
How has it helped my organization?
We have a better state of mind that we're secure, and we don't have unauthorized devices accessing the network. In a financial institution, we want to keep everything as secure as possible. We don't want anything plugged in.
It has helped to consolidate tools. We had arpwatch monitoring, which we no longer have to use, and then TACACS is securing the network. We didn't have a tool before, so that added a layer of security for us.
It has improved our cybersecurity resilience. We have authentication logging for everything that's authenticated or denied. We use a Splunk forwarder. We get notifications if something is denied for authentication.
What is most valuable?
TACACS and .1X security are the most valuable features. TACACS acts for user control, so no one can authenticate to our network devices, and .1X is to validate that unauthorized devices are plugged into our network.
What needs improvement?
Its user interface could be better. It's not bad. They've just redesigned the whole user interface. It's not terribly difficult. The drop-down menus are easy to use. However, when you're looking for some things in the user interface, it takes a minute to find where you were prior.
For how long have I used the solution?
I've been using Cisco ISE for a year.
What do I think about the stability of the solution?
Its stability is great.
What do I think about the scalability of the solution?
Its scalability is also great. We have 350 users.
How are customer service and support?
Their support is excellent. I've opened two support tickets so far, and they were able to remediate the issue within a few hours.
How was the initial setup?
It's fairly difficult. We have third-party support to assist with the setup.
Our setup is on-prem and virtual in Azure.
What about the implementation team?
It was a third-party support, not a reseller.
What other advice do I have?
It's a very good tool for security. It's a lot of work to initially set up, but once it's set up, it's pretty easy to use.
It hasn't yet saved the time of our IT staff. It's still fairly new, so we haven't had much time to use the product fully. It has only been a year since we started using it, so it's still pretty new.
Overall, I'd rate Cisco ISE a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a energy/utilities company with 1,001-5,000 employees
Enhances security, protects us at the access layer, and helps to enforce policies dynamically
Pros and Cons
- "With NAC, the profiling feature is valuable. We're able to see what we have out there in the network and dynamically assign policies to it. We can then use that to enforce TrustSec policy or anything else with NAC."
- "There should be more visibility into TrustSec policy actions. When TrustSec blocks something or makes any kind of changes to the network, we don't always see that. We have to log into the switch itself, or we have to get some type of Syslog parsing to do that."
What is our primary use case?
We use it for NAC and wireless, and for our TrustSec policy. These are the three primary use cases we have so far.
How has it helped my organization?
It's a network access control solution for us. Previous to Cisco ISE, we didn't have one, so, from a security standpoint, it increased our security visibly.
It has enhanced our security. We have a solution now that can protect us at the access layer, which we didn't have before.
It has helped to consolidate any tools or applications. We only have to use one product for RADIUS, TACACS, and authentication servers. NAC and other things are consolidated into one system, which is nice.
It has helped our organization improve its cybersecurity resilience. The security at the access layer through NAC has been nice, and then the ability to enforce policies dynamically using profiling and NAC and TrustSec is good.
What is most valuable?
With NAC, the profiling feature is valuable. We're able to see what we have out there in the network and dynamically assign policies to it. We can then use that to enforce TrustSec policy or anything else with NAC.
What needs improvement?
There should be more visibility into TrustSec policy actions. When TrustSec blocks something or makes any kind of changes to the network, we don't always see that. We have to log into the switch itself, or we have to get some type of Syslog parsing to do that. Cisco DNA Center may do it, but it would be better if that was integrated into Cisco ISE.
In terms of securing our infrastructure from end to end so we can detect and remediate threats, it's a little bit difficult in terms of visibility, but, generally, we would just go through the logs and see if there's a problem or not.
For how long have I used the solution?
I've been working in this organization for three to four years, and they have been using it prior to my joining.
What do I think about the stability of the solution?
It's very stable for us.
What do I think about the scalability of the solution?
It isn't something we have had to deal with.
How are customer service and support?
They're pretty good. Compared to others, Cisco is probably above average. With Cisco TAC, usually, if the first level doesn't resolve it, you can get up to a higher level within a day or two, which is better than a lot of other vendors we've been working with lately, such as Palo Alto. Cisco tech support is doing pretty well. I'd rate them a seven out of ten. Being able to access higher-level engineers and escalate things more quickly is always going to improve any case.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Before Cisco ISE, we didn't have a similar solution.
How was the initial setup?
It was implemented before I joined, but it was probably phased. It was first for wireless and then became more of a NAC thing. It was a long process. It was somewhat difficult just because of how much was required of it. I don't think it was particularly painful.
What was our ROI?
We get a return on investment from it. It's a solution that's often required for IT insurance, etc. It's definitely needed but do we need to have one from Cisco? I don't know, but there's definitely an ROI there.
What other advice do I have?
To someone researching this solution who wants to improve cybersecurity in their organization, I'd say that make sure you know what you're getting into. Understand and have a good plan going into it and have operational support for not just networking, but also help desk and other IT teams before deploying this solution.
I don't know if Cisco ISE has saved us any time because it's an enhancement to our security that we didn't have before. It probably takes a little more time than not having it. Having no security is super easy because you don't have to worry about anything, but if you have any security product, you have to do work to support that.
Overall, I'd rate Cisco ISE an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a hospitality company with 10,001+ employees
Video Review
Helped us get away from pre-shared keys, and allows us to see what's connected to the network
Pros and Cons
- "[One of the most valuable features] is just the ease of use. It's pretty simple to set up certs that we can add to our clients to make sure that they connect properly, [as is] whitelisting Mac addresses."
- "It works so well we haven't had to reach out too much."
- "Automation [is an area for improvement]. It seems like everywhere I look, automation is super important. Automation and integrations. That's the area it could be improved..."
- "Automation and integrations are the areas it could be improved, as we get more and more away from a lot of human involvement and into machine learning and just trusting that these systems could automatically help us."
What is our primary use case?
One of our use cases is using it for authentication for the wireless. Our internal corporate network is using the Cisco ISE server to authenticate clients and make sure that we have the right clients on the wireless side, as well as on the wired side. We just introduced that about a year ago to make sure all our wired clients are our clients and not some "rando" plugging into the network.
How has it helped my organization?
Definitely, getting away from pre-shared keys has been the biggest key. It is allowing users to connect to the internal network, the employee's network, from anywhere, across the entire US. It is allowing that ease of use.
It's also allowing us to see what's connected to the network. We can see that there are only really clients. We can see what's connected on the wired side and what's getting blocked, and understand [things] from our users. "Okay, that's getting plugged in. What do you guys use this for?" It's adding a layer of defense that's super important to our organization.
I don't think we've gotten away from trust completely, but it has helped a lot. It's allowed, on the server side and on the infrastructure side, to allow certain clients. We don't have to trust the client necessarily. We know that that's a corporate client and we don't have to play any guessing games. The corporate client that we want on that specific network is going to have the right cert and the right thing. It allows access control without a lot of human involvement.
It's helped significantly. We have fewer IoT devices on internal networks and that's the key. Your clients have the right firewall protections and the right anti-virus. Those are on the internal network so you're not putting stuff [on it] that you don't know whether it has a security vulnerability or if it's easily hacked. You're allowing those to be in separated networks that silo them off with a PSK. And you're keeping the internal network to clients that you know are protected.
What is most valuable?
[One of the most valuable features] is just the ease of use. It's pretty simple to set up certs that we can add to our clients to make sure that they connect properly, [as is] whitelisting Mac addresses.
It also integrates really well with some of our other services like ServiceNow. A ticket comes in and then, boom, it's automatically going to the ISE, and then ISE is allowing that client with that Mac address to get on the network easily.
[In addition, regarding establishing trust for every access request, no matter where it comes from] it does the job. It's a perfect solution in order to manage a large corporate network.
It allows that access control [for a distributed network]. That's super significant. It allows you to segment things and allows only certain devices to access the network.
What needs improvement?
Automation [is an area for improvement]. It seems like everywhere I look, automation is super important. Automation and integrations. That's the area it could be improved, as we get more and more away from a lot of human involvement and [into] machine learning and just trusting that these systems could automatically help us.
For how long have I used the solution?
My name is Edward Martinez. Network engineer. Our company has about 5,000 employees, and we're in the beverage industry.
[I've been using Cisco ISE (Identity Services Engine)] ever since I started. That was one of the main services that I had to understand and get involved with as soon as I started at our company.
What do I think about the stability of the solution?
I haven't had many issues in terms of its stability. It doesn't really ever go down. Anytime we ever have any issues with it, it's usually human error.
How are customer service and support?
In the past, I've always had pretty good support from Cisco. Their TAC is really good. They're pretty straightforward. I haven't had many experiences with ISE, honestly. It works so well we haven't had to reach out too much.
I would rate their support about a nine out of 10. It works most of the time. It depends on the engineer you run into. It depends on the people you deal with.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
[The main challenge] was authentication and not using PSK, traditional pre-shared keys. They wanted to get away from pre-shared keys; people share them. They wanted something that would allow clients to just connect automatically, not have a pre-shared key, and be secure. That's the most important part, making sure that the right clients are getting on our internal corporate network.
[Our company] was just using PSK and that solution was really built around access control of our corporate networks. They were using PSKs at every site and rotating those PSKs, or had site-specific PSKs. Now, when somebody comes into the office, they can just connect to the employees' network automatically, and it's the same across the board at every site.
It was this idea that we needed to simplify things. We needed to make it easier on our users to go into an office and connect to the internet and not have to ask an IT guy there or make a ticket. That was the important part.
How was the initial setup?
I've just been involved with the secondary deployment, using the ISE on our wired ports.
It was pretty straightforward. It was funny. We did it during COVID so it was really easy when nobody was in the office to implement the solution. It kind of worked out that way, when there was nobody in the office.
But otherwise, people have started to come back and we haven't had really many issues in terms of authentication. It's really easy. People have wired in and if their client has the right cert, it's been a breeze. They've been authenticated and it takes a minimal amount of time.
What about the implementation team?
We have an operations partner that we deal with pretty often. It's an Austrian company, NTS. They work with Cisco a lot on our solutions and, obviously, we're evaluating it with them and then making choices based off of that. I'm the onsite hands. I do a lot of the configuration on the switches, but they're doing a lot of the advising.
What was our ROI?
You're seeing less tickets and you have fewer security issues. I think the return on investment is there. It has really improved our situation in our corporate offices.
What other advice do I have?
Resilience is super important. The solution needs to be able to hold up and promise what it [intends] to deliver. In cyber security, that's super important because if you have any slight exploit, you're going to have malware attacks, ransomware attacks. That's [a] big [issue] in our company as, more and more, you hear about legacy systems being affected. These legacy systems sometimes don't go away. Sometimes you need them. You have to do your best to either patch them up or protect them either through a firewall or an access control system.
[It's about] protecting the network infrastructure from exploits and really allowing us to segment IoT devices and the corporate network. And because [on] the corporate network, once you get into it, there really isn't anything protecting against accessing critical storage systems, accessing mission-critical servers, [or] our sales numbers, it's super important that we have the ISE so that we're only allowing the things that we want into the network that we trust.
[What I would tell leaders who want to build more resilience within their organization would be] evaluate solutions, prioritize it, get manpower behind it. Also, too often they put cyber security on the back burner. They're trying to maintain operations and sometimes cyber security can get in the way of operations. But trust that system, once you build it up, will protect you and that it's worth the investment in terms of money, labor, and time.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Cisco Secure Firewall
Cisco Umbrella
Aruba ClearPass
Cisco Secure Email
Cisco Secure Network Analytics
Forescout Platform
ThreatLocker Zero Trust Platform
Cisco Secure Endpoint
Fortinet FortiNAC
Cisco Secure Client (including AnyConnect)
F5 BIG-IP Access Policy Manager (APM)
Cisco Secure Workload
ExtremeCloud IQ
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- ForeScout vs. Cisco ISE
- What are the main differences between Cisco ISE and Forescout Platform?
- Can Cisco ISE disallow authentication based on OS?
- Cisco ISE (Identity Services Engine) vs Fortinet FortiNAC: which solution is better and why?
- What are the requirements for integrating the Cisco Data Center and Cisco ISE?
- What is the biggest difference between Aruba ClearPass and Cisco ISE?
- Which is better - Aruba Clearpass or Cisco ISE?
- How would you compare Cisco ISE (Identity Services Engine) vs Forescout Platform?
- How does Cisco ISE compare with Fortinet FortiNAC?
- What is your experience with 802.1X when using EnGenius WAP/switch with Cisco ISE 2.1?














