No more typing reviews! Try our Samantha, our new voice AI agent.

ARCON Privileged Access Management vs Cisco Identity Services Engine (ISE) vs Symantec Privileged Access Manager comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
ARCON Privileged Access Management2.5%
CyberArk Privileged Access Manager11.4%
Delinea Secret Server4.9%
Other81.2%
Privileged Access Management (PAM)
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)21.7%
Aruba ClearPass20.8%
Fortinet FortiNAC15.0%
Other42.5%
Network Access Control (NAC)
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
Symantec Privileged Access Manager1.6%
CyberArk Privileged Access Manager11.4%
Delinea Secret Server4.9%
Other82.1%
Privileged Access Management (PAM)
 

Featured Reviews

DS
System and DBA at a energy/utilities company with 1,001-5,000 employees
Enhanced security through session monitoring and activity recording
From an end-user point of view, it would be beneficial if the system could provide information about the last login. This would help identify if the server was accessed by me or if someone has potentially stolen my credentials. It would provide a clearer picture of whether ARCON Privileged Access Management is accessed by an authentic user.
NF
Network and Technology Information Manager at Akkodis
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
Muzi Lubisi - PeerSpot reviewer
Senior technical Consultant at CA Africa
Secure management of sensitive servers and seamless applications with direct linking
The credential injection feature is highly valued, particularly for RDP sessions. A majority of customers use it for RDP, and a couple for Linux servers. The broader capabilities, including access to multiple systems, web-based applications, and clustering, have never posed an issue. The threat analytics aspect is also a robust feature that analyzes all pertinent information.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The session management capabilities are helpful. The session recording feature for system handling is good. It also eliminates the need to open many ports for end-users, simplifying access."
"That dashboard is okay."
"One standout feature of ARCON is its ability to resolve lagging issues, especially noticeable in Linux environments."
"It has improved our government compliance score in terms of audits."
"Pricing and licensing are good, very aggressive."
"The password vaulting is robust."
"The deployment process for the solution was easy...The solution's technical support team was good."
"ARCON will give you all the features in a very cost-effective solution."
"TACACS and .1X security are the most valuable features. TACACS acts for user control, so no one can authenticate to our network devices, and .1X is to validate that unauthorized devices are plugged into our network."
"We have become more reliable because we do not have any vulnerabilities coming into our network, which is important since a lot of employees are using their own endpoints to connect to our infrastructure."
"I like that Cisco ISE is easy to use."
"Cisco ISE's integration with other external identity servers like Duende is very simple and easy."
"Cisco ISE has enabled my customers to deploy secure wireless and secure wired networks and gave them a lot of flexibility to do security enforcement."
"In terms of stability, they are rock solid."
"Cisco ISE has provided more mobility for the organization while controlling access no matter how the users connect to the network."
"I would recommend this solution as it is very easy to set up and has a very easy user interface."
"I’m very satisfied with the product."
"Used for securing privileged accounts."
"It will provide us with more security."
"We have received good support from the tech support team."
"The solution has the capability to address hybrid eco-systems, both on-premises and cloud services, and integration with the AD RBAC model is also a great feature, as we can tie it to the central repository."
"The most valuable element is the keystroke tracking feature."
"It has been reliable down the line with new features and updates."
"This application is very easy, fast, and trustworthy!"
 

Cons

"We expect improvement in the dashboards to provide visibility of password compliance status, whenever a password is opened from the vault. Also, flexibility to customize the live dashboard."
"There are some features lacking but they typically are added when the upgrades are released."
"Currently, along with the upgrade of the ARCON solution, we have to consider the desktops and the endpoints from where the solution will have to be accessed. We have to upgrade those endpoints and desktops as well. So upgrades are not smooth."
"They should respond to open queries within the time limit they have set."
"For the in-house built applications, they need to provide good, solid access through their portal."
"One thing which needs improvement is where it is keeping video logs of Windows Servers, whatever activities are being carried out by the administrator."
"There are no APIs readily available... I'm working on automation for ARCON so that whatever the ARCON administrator is doing will be automated, rather than having to do it manually. For that, I had to spend months to get the API developed myself. Having that handy out of the box, that would really help..."
"Bulk password automation is not available in ARCON when compared to other products."
"I have complaints. I don't enjoy the licensing model."
"The stability of the solution needs to be improved. It's not ideal. It's lacking overall."
"The UI is not as intuitive as some other products, even products inside of Cisco's wheelhouse."
"The initial setup was a little bit complex. It's not that simple because it requires a lot of prerequisites for the solution to get a hold on."
"The UI and UX could be more seamless and easier to use."
"There should be a single button that can be pressed to dismiss all of the alarms at once."
"Cisco ISE could be simplified somewhat. I would also prefer certificate-based authentication over confirmation-based authentication for all the processes. It's possible for us to do a workaround, but the process needs to be simplified."
"Scalability is good as far as adding another node. However, if you ever wanted to increase the node that you have, then you need to buy a bigger license. You also have to build a new VM for it because you can't just scale it."
"I wouldn't recommend this solution because the support isn't good, and the response time isn't good."
"The setup was complex."
"It's difficult to locate the reports, there are limits on what reports can be run from the GUI, and the report formats are lacking."
"There is already a feature for that. It is not too great to use."
"They need to improve how it scales."
"So far, with the functionality of what we had, there has not been much improvement at this point of time."
"Broadcom has neglected product development since acquiring Symantec, and nothing major has been added to PAM."
"I would like to see improvements in branding customization and multi-tenancy."
 

Pricing and Cost Advice

"The product is available with competitive pricing. Licensing is not complex. We calculated the license requirements by counting the number of admins and the number of devices which were going to integrate with it."
"There are no major concerns with licensing because we can handle multiple servers in our kiosk system."
"I am not in a position to give any financials, but whatever we have paid, it is value for money. Their licensing model is good. They have been flexible for us."
"ARCON Privileged Access Management's pricing is reasonable."
"The product's pricing is good value. Go for user-based licensing, without any limit on the target servers."
"Product pricing is based on users and connections. We did not have to pay more for additional features."
"The cost of this product is very cheap, comparatively in the global market."
"ARCON is a will give you all the features in a very cost-effective solution. Pricing and licensing is very good compared to other players in the market."
"According to my sales and account team, the prices we're getting are pretty good."
"It's an expensive solution when compared to other vendors."
"Cisco is expensive, but it's the cost for all the functions and value it brings. Functions like internet solutions, integrations, security, and many more features are important, but it's expensive for some clients."
"The price of the solution is price fair for the features you receive."
"The price is a bit on the high side."
"The price of Cisco ISE (Identity Services Engine) is expensive and we are thinking about changing to FortiGate."
"We are running Version 2.9 because Version 2.9 of the ISE has a persistent license — it's a one-time payment. The latest version (3.1) is only available if you do a yearly subscription."
"The solution’s pricing is reasonable."
"Don’t go with an agent model. Don’t go with a model that has you buying a thousand different parts. Go with PAM that gives you everything, or you’ll just be paying costs of implementing another tool that PAM would have just given you up front."
"It is reasonably priced."
"The prices are not low, but one can ask for a discount. It’s not the cheapest PAM solution."
"Pricing is fair compared to other top vendors."
"Cost-wise, CA was better compared to others in the market. ​"
"Appliances are relatively cheap, don’t skimp. Make sure you have redundancy, high availability, and enough appliances to manage the concurrent workload."
"They offer per-device, per-user, or monthly and yearly licensing models."
"The version we are using is affordable compared to BeyondTrust, which is maybe three to four times as expensive, but it depends on the features."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
885,376 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
9%
Manufacturing Company
8%
Computer Software Company
7%
Government
7%
Manufacturing Company
11%
Computer Software Company
9%
Financial Services Firm
8%
Government
8%
Comms Service Provider
9%
Marketing Services Firm
9%
Construction Company
9%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise11
Large Enterprise17
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise30
 

Questions from the Community

What needs improvement with ARCON Privileged Access Management?
From an end-user point of view, it would be beneficial if the system could provide information about the last login. ...
Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cann...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if some...
What is your experience regarding pricing and costs for Symantec Privileged Access Manager?
Due to the nature of the solution, it is hard to gauge, but compared to competitors, the pricing is very good. I woul...
What needs improvement with Symantec Privileged Access Manager?
Recent releases need improvement in webpage management. For instance, navigating through a webpage that acts like a w...
What is your primary use case for Symantec Privileged Access Manager?
With the customers that I have so far, I help them broker RDP sessions to sensitive servers, particularly those that ...
 

Also Known As

ARCON ARCOS, ARCON PAM
Cisco ISE
CA PAM, Xceedium Xsuite, CA Privileged Access Manager
 

Overview

 

Sample Customers

RAK Bank, AXIS Bank, Reliance Capital, Kotak Life Insurance, MTS
Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
NEOVERA, Telesis, eSoft
Find out what your peers are saying about CyberArk, One Identity, Okta and others in Privileged Access Management (PAM). Updated: March 2026.
885,376 professionals have used our research since 2012.