Try our new research platform with insights from 80,000+ expert users

Cato SASE Cloud Platform vs Okta Workforce Identity comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 11, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

iboss
Sponsored
Ranking in ZTNA as a Service
11th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
17
Ranking in other categories
Secure Web Gateways (SWG) (10th), Internet Security (4th), Web Content Filtering (3rd), Cloud Access Security Brokers (CASB) (8th), Secure Access Service Edge (SASE) (10th)
Cato SASE Cloud Platform
Ranking in ZTNA as a Service
4th
Average Rating
8.8
Reviews Sentiment
7.7
Number of Reviews
29
Ranking in other categories
WAN Optimization (1st), Cloud Access Security Brokers (CASB) (6th), Software Defined WAN (SD-WAN) Solutions (4th), WAN Edge (4th), Secure Access Service Edge (SASE) (5th)
Okta Workforce Identity
Ranking in ZTNA as a Service
10th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
65
Ranking in other categories
Single Sign-On (SSO) (3rd), Authentication Systems (5th), Privileged Access Management (PAM) (6th), Identity and Access Management as a Service (IDaaS) (IAMaaS) (2nd), Access Management (2nd)
 

Mindshare comparison

As of May 2025, in the ZTNA as a Service category, the mindshare of iboss is 1.9%, up from 1.0% compared to the previous year. The mindshare of Cato SASE Cloud Platform is 11.3%, up from 6.9% compared to the previous year. The mindshare of Okta Workforce Identity is 1.6%, down from 2.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
ZTNA as a Service
 

Featured Reviews

Matt Crockford - PeerSpot reviewer
It's easy to roll out, and their understanding of our business made it seamless
One aspect we value about iboss is its simplicity. Their customer service is brilliant, and they are super responsive and knowledgeable. It's easy to roll out, and their understanding of our business made it seamless. We were impressed by the solution's mental health function, which can detect if someone needs help. It scans what users are browsing and flags warning signs so we can check to see if they are okay. We've had to use it a couple of times. The user interface is highly intuitive. Our IT team picked it up with minimal training. It's arranged so that it's easy to find where things are. Another advantage is the single pane of glass console, which gives you visibility into what's happening. We're not fully there yet because we haven't implemented zero trust, but we're excited about the possibilities from the demos we've seen. We launched a POC of iboss' ChatGPT Risk Protection feature two weeks ago. AI is a great tool, but you need to be careful what you put into it. My biggest fear is employees inputting sensitive corporate information or customer PII data into one of these chatbots. I was impressed by our trial of the feature. It's exactly what we wanted. Now, when a user goes to ChatGPT, there's a banner warning them not to share information, and we can block conversations containing customer data like bank details and email addresses. I don't want to stop people from using it, but we need visibility. We've only tried it on a test group of 15 people. You can configure it to look for specific keywords or integrate it with your DLP policy if you have that configured
Alexander Azikov - PeerSpot reviewer
Provide a seamless experience for end users with internet duplication feature
The setup and onboarding process is very straightforward - I'd rate it a ten out of ten for ease. We use CatoCloud as our cloud provider. They have points of presence, and we connect to the nearest one to our physical location. All the routing, inspection, and logic for what to route, block, or allow happens in the cloud, not on the local device. Our deployment took a couple of weeks because we installed the sites manually. If we had a team to help switch locally, it could have been done in a week. The deployment process is straightforward. We set up all the sites in their cloud system; then, they ship the sockets directly to the location or our main office. We connect the device to the internet, it gets activated, we assign it to a specific site inside the cloud, and it's online and ready to use. It's very easy.
Tor Nordhagen - PeerSpot reviewer
Extremely easy to work with, simple to set up, and reasonably priced
The drawback of this solution is that in our shops, many staff members sometimes have to be borrowed from one shop to another and the solution does not really support having multiple roles. The user experience we would like to have when a person works in shop A which pays their salary is that they should have access to pretty much everything. Maybe you have somebody who is a manager in that shop A, he should be able to order new wear, he should be able to change the pricing, he should be able to empty the cash registry, and ship it to the bank. But when for instance, in COVID, people had to fill in for people in shops where a lot of people were sick, then they had to actually use user accounts of people that work in shop B. If you were employed in shop A, you could not work in shop B without borrowing somebody else's user ID and password. Which is really bad. We haven't been able to work around that and Okta Workforce Identity does not have a solution for it. We are now piloting their identity governance solution. Obviously, it's easy to give somebody access, give them an account, and give them roles, but it's hard to maintain that. For example, if you moved from, say working in a shop to working in a warehouse. But why do you still have all this shop access? The solution has until now not had anything to really support the process of taking away access. But now we are in a better release program of Okta's identity governance solution. Although it's very basic, the solution has started on a journey, but identity governance is something that Okta Workforce Identity really needs to improve. The ability or the options in the solution for changing the look and feel are not good enough because in our partner portal, essentially what they have is an ugly admin interface. The admin interface is good enough for us technical people because that's all we need. We work with the product and we're able to see the data but when it comes to presenting the service portal, Okta Workforce Identity does not have any capabilities really for making it look pretty. To add branding and different graphical user interface elements than Okta basic for essentially delegated admin for the business-to-business portal is horrifying because you're essentially using the tech admin. The only option we had and used, was to take the tech admin console and strip it. so that a vendor that has some goods that are sold in the shops, when they want to add a user on their side, say a driver or a packer on their side who should know how much they've packed in a truck to come to our warehouse, then the user interface that this vendor is using, these functional people will then have to use an extremely basic user interface.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"iboss is among the few products providing inline filtering where no application is needed on the device. It operates on the network side and is not device-based. This feature was one of the main reasons why we stayed with them for so long."
"We were impressed by the solution's mental health function, which can detect if someone needs help. It scans what users are browsing and flags warning signs so we can check to see if they are okay. We've had to use it a couple of times."
"Technical support is pretty sharp and very responsive."
"iboss is easy to use despite its complexity. Multiple engineers manage it, but it's significantly more straightforward to administer than traditional VPNs and web proxies."
"Content filtering is the most useful feature of iboss."
"The security aspect of the solution, particularly the malware behind it, is excellent. That's something that really helped us out. It's not just a simple proxy that just blocks the insights of potential threats that come on behind it. They do malware detection and that helps us a lot."
"From a use-case scenario, what I like the most is the plug-in. I like the fact that we can do the filtering of these devices offsite independent of the network they are connected to, and we do not have to have traffic coming back inside our network."
"First of all, the security policies are essential. I do not have to rely solely on Active Directory for our users."
"The WAN aggregation feature is the most valuable."
"I haven't had any trouble, and practically forget that I'm using it."
"The most valuable feature is that it also works as a next-gen firewall because it has security features."
"The most valuable feature of Cato Networks is the CASB and the documentation is useful."
"It's a pretty straightforward solution."
"The visibility control and security aspects are amazing."
"The solution is stable."
"The main features we use are the firewall and secure web gateway."
"Valuable features include UD, SSO functionality, MFA and Adaptive MFA functionality, ability to link multiple Directory databases with UD."
"The provisioning functionality has been the most valuable. This solution has good performance, fast integration and is very responsive."
"We face no challenges in integrating the product with our legacy systems."
"One of the most beneficial features of the solution is the user provisioning and the de-provisioning feature."
"The initial setup of Okta Workforce Identity is straightforward. I was able to get an environment ready within half a day."
"The support for YubiKey is really good because you don't actually have to type in your username and password."
"The solution so far has been very stable."
"What I found most valuable in Okta Workforce Identity is that it worked together with VMware Workspace One, so there was this device check at the same time. My company used the trusted device method that enabled you to define that only the trusted devices including the Workspace One agent were able to access the applications directly without an additional authentication step."
 

Cons

"I'd like to see them accelerate development on the security side, particularly around data loss prevention."
"Sometimes, obviously, there are bugs."
"One thing I would like to see differently with their Zero Trust platform is that some of the AI aspects related to high-risk activities have more false positives."
"Their on-premise hardware's network interface is capped at one gigabit, which is sort of a problem. If you stand a filter up where all traffic flows through that, according to them, in order to go above a gigabit, you have to have multiple devices, which in today's IT seems a little bit silly. They could easily put in an SFP port into their device that could accommodate 10 gigs or at least offer a box."
"SSL decryption: We had issues with learners using apps instead of using web browsers. This type of encryption is tough for any appliance in a BYOD environment."
"The reporting feature needs improvement."
"To scale up, a new iboss Node Blade Chassis must be purchased."
"Our biggest problem with their service was it did not recognize the device and filtering did not always work correctly."
"They can't do one-to-one NAT (Network Address Translation) in AP (their access point), and that is something that Palo Alto can do."
"There should be a Web Application Firewall feature in the product nodes."
"The tool needs to be more granular. Its reports are not very in-depth."
"For a packaged solution, needing external intervention or a system integrator to get other features not offered by Cato Networks could be an area for improvement. Cato Networks does what it's meant to do and is even overstretching capabilities when introducing new features. The product can only have very few features added on top of what its currently doing. Managed service providers can deliver the extra features you'd need. It's a set of managed services, and what Cato Networks does is very comprehensive. So, for the time being, when the actual incarnation of the SASE solution is deployed, Cato Networks is a very effective product. Naturally, technology will evolve, so everybody knows that in three, four, or five years, there will be a new kid on the block, a new game. Still, at the moment, Cato Networks only needs to improve a little regarding SASE delivery. The product is doing very well, but one feature the Cato Networks team is doing right is preparing for the future through deploying the SSE 360, so the security service is at that edge. It's an excellent strategy to prepare for the future. SSE 360 is what Cato Networks should invest in the most to keep prospering."
"They should include a web application firewall feature in the solution."
"Web application firewalling (WAF) is a feature we would like to have in this solution and does not exist yet."
"Cato Networks could improve their intrusion detection. There is not a lot in place."
"Its functionality is a bit limited in some areas as compared to a Cisco solution. It is not as granular. It doesn't have the manageability, feature set, and capabilities of a larger or an enterprise-level solution. It just needs a more robust feature set and granularity."
"UD attribute mapping, Okta group rules, and dynamic usage could use improvement. It also needs more in-depth functionality and features to integrate with RADIUS solutions."
"SSO and MFA for improved end-user experience, and protection against password spray attacks, account password self-service."
"Okta Workforce Identity could improve the way passwords are reset and how it interfaces with Microsoft."
"We still had to write several internal programs/scripts to complete the user-provisioning process. Okta does not have the ability to provision mailbox accounts for on-premise Exchange or in a hybrid O365 environment. The Group Push function from Okta to AD did not work reliably in our environment."
"It only facilitates provisioning and not de-provisioning."
"There should be automated aggregation and complete classification processes included in it."
"We faced some challenges during the Okta Identity Workforce deployment. Integrating with AWS and other cloud services posed some limitations with federated options. For instance, features like automatic user addition from AWS to the tool were missing, requiring manual intervention. The API is limited compared to the manual configuration possible through the UI."
"The solution can be quite expensive."
 

Pricing and Cost Advice

"It is not expensive, and it is also not cheap. iboss is priced right in the sweet spot for the number of features it offers."
"The overall pricing for iboss is very competitive and transparent."
"We had the cost of purchasing a new appliance along with the implementation and licensing costs. However, the following year, the cost of just licensing was similar to what was paid the previous year for a new appliance along with the implementation and licensing costs."
"We have not priced the solution recently, but they were competitive with other vendors in the past."
"It is expensive compared to one of its competitors."
"It is probably in line with other solutions, but I do not deal with the financial side."
"The solution has reasonable pricing. It has a yearly subscription. The pricing depends on the permit to code. Sometimes, we need to increase the permit, and the cost will automatically change. There's no fixed cost. Unless we request additional modules such as DNS security, ELP, and decent features, there will be no additional cost."
"Cato Networks seems more expensive than Cisco Meraki."
"You pay yearly based on the speed of your network. If you increase the speed of your network, you increase the cost for your throughput. It is by bandwidth for the most part and then licenses for VPN. There is some per-seat licensing for VPN access, but the majority of it is minimal. It is like $30 a year per client. The rest is based on how much bandwidth you'll use. You pay for that upfront for the year, and if you have to increase it, you increase it, and then they let you send more data through. There are no additional costs in addition to the standard licensing fees."
"I'd rate Cato SASE Cloud Platform's pricing as about five or six out of ten. It's not the cheapest solution, but it is cheaper than Palo Alto and even VeloCloud. We've been working with them for a while and have significant discounts. Our licensing costs vary because we keep adding sites, but it's about 280 per month per site. This includes additional features beyond the base product, starting at around 200."
"The price is not an issue for us, as it is priced more competitively than some other vendors."
"The product is very competitively priced, and that's compelling. They don't charge the customer based on the operational cost like other brands such as Palo Alto. Cato has its own fully-fledged cloud, with their own data centers, equipment, and so on, which is an advantage. I rate the solution five out of five for affordability."
"Cato Networks is an expensive product, but it works out of the box, so that's the usual trade-off, make versus buy. If you decide to buy a product that doesn't require much programming, then you'd want to go for Cato Networks, which will work naturally, and immediately without any complex setup. However, the product is a little bit more expensive than the competitors. On a scale of one to five, I'd rate the pricing for Cato Networks as four."
"The price of Cato Networks is in the middle range compared to other solutions. NetFoundry is a less expensive solution than Cato Networks."
"I believe it competes well. The pricing is pretty competitive. I know that Microsoft also provides something similar with its MFA and identity services."
"It has a yearly subscription. As compared to its competitors, it is quite expensive. It also has a complex licensing model."
"The pricing for Okta Workforce Identity could still be improved or made cheaper. It costs from 50 to 100 euros a year per user. Okta Workforce Identity has different packages you can choose from, and my previous company had all of them, particularly the full Okta suite."
"The price of Okta Workforce Identity is competitively priced. We pay annually for the use of the solution."
"This solution is costly. Pricing is decent if you have less users, but it significantly goes up the more users you have, with its cost not justified."
"Though I don't know about the licensing model of the product, I wouldn't be surprised if Okta offers a per user license subscription model."
"License is around US$20,000 annually."
"Okta has fairly competitive pricing."
report
Use our free recommendation engine to learn which ZTNA as a Service solutions are best for your needs.
849,963 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Financial Services Firm
12%
Manufacturing Company
9%
Government
6%
Computer Software Company
26%
Manufacturing Company
11%
Financial Services Firm
8%
Comms Service Provider
5%
Computer Software Company
16%
Financial Services Firm
11%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about iboss?
Content filtering is the most useful feature of iboss.
What needs improvement with iboss?
Our biggest problem with their service was it did not recognize the device and filtering did not always work correctl...
What is your primary use case for iboss?
We used it for student and faculty filtering on campus.
What do you like most about Cato Networks?
The solution is a simple WAN solution. We've onboarded the socket on the Cato platform, and it provides connectivity....
What is your primary use case for Cato Networks?
We have been using Cato Networks as a solution for firewall and secure web gateway.
What advice do you have for others considering Cato Networks?
I would definitely recommend Cato Networks to other users. I'd rate the solution nine out of ten.
What do you like most about Okta Workforce Identity?
Okta has introduced the Universal Directory. It has custom attribute capability and user permissions to read/write on...
What is your experience regarding pricing and costs for Okta Workforce Identity?
Pricing for Okta is reasonably not that much, however, I don't have access to the commercial aspect.
What needs improvement with Okta Workforce Identity?
Okta should have at least a local presense for countries that align with or comply with GDPR or data sovereignty, so ...
 

Also Known As

iBoss Cloud Platform
Cato Networks
No data available
 

Overview

 

Sample Customers

More than 4,000 global enterprises trust the iboss Cloud Platform to support their modern workforces, including a large number of Fortune 50 companies.
Paysafe, AdRoll, Pet Lovers Centre, Arlington Orthopedics, Humphreys & Partners Architects
FedEx, Zoom, Takeda, Lululemon Athletica, GrunHub, jetBlue, McKensson, Bain & Company, Engie, Peloton, Sonos, T-Mobile, Hewlett Packard, MGM Resorts, Ally Financial, Priceline, Albertsons, Itercom, Classy, FICO, Kensho, Live Nation, Drata, Rotary, and others.
Find out what your peers are saying about Cato SASE Cloud Platform vs. Okta Workforce Identity and other solutions. Updated: April 2025.
849,963 professionals have used our research since 2012.