No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Duo vs Prisma Access by Palo Alto Networks comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

iboss
Sponsored
Ranking in ZTNA as a Service
8th
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
21
Ranking in other categories
Secure Web Gateways (SWG) (5th), Internet Security (3rd), Web Content Filtering (1st), Cloud Access Security Brokers (CASB) (7th), Secure Access Service Edge (SASE) (8th)
Cisco Duo
Ranking in ZTNA as a Service
2nd
Average Rating
8.8
Reviews Sentiment
7.0
Number of Reviews
118
Ranking in other categories
Single Sign-On (SSO) (4th), Authentication Systems (2nd), Access Management (4th), Cisco Security Portfolio (1st), Multi-Factor Authentication (MFA) (1st)
Prisma Access by Palo Alto ...
Ranking in ZTNA as a Service
5th
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
65
Ranking in other categories
Secure Web Gateways (SWG) (4th), Cloud Access Security Brokers (CASB) (1st), Enterprise Infrastructure VPN (7th), Secure Access Service Edge (SASE) (1st)
 

Mindshare comparison

As of April 2026, in the ZTNA as a Service category, the mindshare of iboss is 2.6%, up from 1.8% compared to the previous year. The mindshare of Cisco Duo is 2.4%, up from 2.3% compared to the previous year. The mindshare of Prisma Access by Palo Alto Networks is 10.5%, down from 15.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
ZTNA as a Service Mindshare Distribution
ProductMindshare (%)
Cisco Duo2.4%
Prisma Access by Palo Alto Networks10.5%
iboss2.6%
Other84.5%
ZTNA as a Service
 

Featured Reviews

Ashok Ananthula - PeerSpot reviewer
Senior Consultant Proxy Engineering at a financial services firm with 10,001+ employees
Cloud gateway has strengthened remote web security and now needs better Mac and ISP support
The problem our organization had is that iboss failed for the Mac devices. It is not able to give a successful agent for the Mac agents. That is where in 2025, we had to migrate to the Palo Alto-based platform. If your use case is for just Windows laptops,you can consider this platform as an option One issue is the data center resiliency part. In India especially, they are not tied up with the Tier 1 ISPs like Tata or Airtel; they were having Tier 2 ISPs and encountered many issues reaching few major sites that my organization depends on, and they were having problems that they could not fix quickly. They also lack a mechanism to route that traffic within their data center; rather, they ask customers to make a pac file change to route it to Singapore explicitly. It would be better if they route from their backend , i mean even if I send it to India DC, they should be able to route it internally to make that work; however, they fail to do that and ask the customer to route it in the pac file. Another suggestion is that in China, they do not have the proper setup; they used to have numerous problems with slowness and lack of premium circuits in China as well. That leads to multiple sites working slowly with latency-related issues. So the main issue is the ISP-related problems that need to be solved.
Charles Slaustas - PeerSpot reviewer
Information Technology Contractor at Insight global
Supports seamless authentication for users across multiple organizations and personal portals
The features I use in Cisco Duo include Duo Pushes to confirm my identity to the device, and eventually as MFA security was increased, I actually had to use exchange passcodes. Sometimes, I have to go into the site and get into Cisco Duo to retrieve the passcode, and many of them have been two-factor, where the sites send a passcode that I have to enter into Cisco Duo. It has been more of the latter. I have not seen issues with lagging or crashing on Cisco Duo's end; it was usually on the client end, often because someone set up a bad upgrade or there were connection issues with the Cisco Duo cloud through the administrative site.
IgorPinter - PeerSpot reviewer
Director at PULSEC
Zero-trust access has improved remote security and now simplifies cloud-based firewall management
Regarding the integration part for Prisma Access by Palo Alto Networks, the integration with identity providers is pretty much good. It is basically firewall as a service, so it performs well. I completed the integration without any issues. What Palo Alto Networks can do better for Prisma Access by Palo Alto Networks is probably to have the point of presence available in more locations. The point of presence from the Serbia region has the nearest POP in Frankfurt, which is an issue since it is your gateway—when you start browsing the internet, you go through a commercial connection in Germany. They definitely need to spread the service in other countries.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Technical support is pretty sharp and very responsive."
"The security aspect of the solution, particularly the malware behind it, is excellent. That's something that really helped us out. It's not just a simple proxy that just blocks the insights of potential threats that come on behind it. They do malware detection and that helps us a lot."
"Iboss is a solution that prevents advanced persistent threats, and has a zero tolerance for attacks."
"Because of iboss, I did not have to assign web filtering tasks to my techs on a daily basis."
"Technical support is pretty sharp and very responsive."
"iboss is easy to use despite its complexity. Multiple engineers manage it, but it's significantly more straightforward to administer than traditional VPNs and web proxies."
"Its initial setup was straightforward."
"We chose iboss for both zero trust and proxy (SWG) because their SWG was superior."
"All features of the solution are effective, particularly those involved in identifying vulnerabilities and updates."
"I like the set time that users can log into devices during the day and how many times they can do so. I also like the ability to restrict the regions from which the user can get in. Users outside of our country or even the town cannot log in."
"The product is reliable and easy to use."
"It's a lot easier for our end users to connect to our network. You don't have to type in a code. You get push notifications, that's probably the best thing about it. The fewer clicks they have to do to be online, the better it is. They can easily get into the network and do remote work."
"The feature of Cisco Duo that I prefer the most is the policies, being able to control what we need to within the policies."
"My experience with Cisco Duo's strong security authentication system has been good; it is seamless and easy to integrate, and it is flexible."
"Cisco Duo has helped my organization reduce its overall authentication-related costs."
"It has continuously evolved by introducing new solutions and products to address emerging security threats in our industry, demonstrating its commitment to staying ahead of evolving security challenges."
"The Autonomous Digital Experience Management (ADEM) offered by Palo Alto is a good reporting tool. It gives insights into how things are going within the network. It takes all the data from the users' endpoints and does an analysis, and it suggests changes as well."
"It has predefined or preconfigured rules, which are getting periodically updated. They are providing continuous improvements and periodically updating all search queries that they are looking for. That is one thing that helps us to stay vigilant and focused. If we query our AWS account for any breaches or vulnerabilities with any of the cloud tests, and it alerts us based on these predefined rules. It also provides an option to configure our own rules, and based on these rules, it can query the cloud trail logs, pull the information, and trigger alerts in real-time. I haven't explored this feature much because there are multiple accounts, and we don't have enough time to explore this feature. It also provides multiple integrations. When vulnerabilities or breaches are happening, you should be aware of them immediately. It provides integration with tools such as Slack, PagerDuty so that you can get alerted as soon as the high severity stuff comes up. For example, you have a security group that has allowed public traffic on port 22. As TechOps, you should be aware of this immediately. You cannot scan each machine or look into all security groups to identify it. So, Prisma helps us and alerts us when this kind of high-priority stuff comes up. It has different statistics, analytics, and graphs for data. The description of alerts is also pretty good. They describe what are the possible causes for this and what are the solutions. From Prisma Cloud, you can directly go to the AWS account. When you click on an alert, a resource, or a resource ID, it takes you to the AWS console where you need to log in. If you are already logged in, it will take you to that instance directly, and you can fix the issue there. I have found this feature very useful."
"The most valuable feature of Prisma Access is its ability to provide enterprise-class security for both Internet and internal application access."
"In my experience, Prisma Access is a great platform."
"The solution is not very complex and is easy to manage for people who may or may not have knowledge about Palo Alto Networks."
"The tool's consolidation is pretty quick."
"We had a very good experience with their solutions, especially with their endpoint protections and the next-generation firewalls."
"Overall, it's a great solution that works quite well."
 

Cons

"The dashboards for local use could be better."
"Sometimes, obviously, there are bugs."
"The dashboards for local use could be better."
"Sometimes the agent stops working in iboss, and we have to reinstall the agent."
"Regarding pricing, setup costs, and licensing, iboss is not cheap, and that's my only concern."
"The problem our organization had is that iboss failed for the Mac devices; it is not able to give a successful agent for the Mac agents, and that is where in 2025 we had to migrate to the Palo Alto-based platform."
"The reporting feature needs improvement. It doesn't give you the expected results. It is quite difficult to get the specific reports needed, and it is not as intuitive as the rest of the platform."
"The solution could be stronger on the integration side and offer more cloud applications like G Suite or Oracle."
"When you come to the push in Duo Security, there are some integrations where you have to use the code instead of the push functionality."
"I'd like to see it integrated into other applications. I know there are some integrations, but I haven't been able to explore that any further."
"Improving Cisco Duo might involve alerting us about telephony credits when people receive texts. We hit zero at one point, and we were running around in circles without any idea until I discovered it."
"General announcements when new features come out with Cisco Duo should be broadcasted to customers who are using it, which might bring more accessibility to their documents so users can be more in tune with updates."
"Cisco Duo could be improved, possibly by adding features for the healthcare space. If you're selling something to a healthcare provider, there needs to be consideration for how to launch Cisco Duo with a handheld device that is not native, where you can install the application."
"I'm unsure how to disable the ping notification sound on my phone when using Cisco Duo. I don't know how to silence it."
"An enhancement they might make is if they can log it to Splunk since they're big into Splunk. Instead of me having to go into that portal to look at things when someone is trying to log in and they forgot their password, I can look in and tell them they forgot their password or didn't respond to the prompt. That would be an improvement."
"We first deployed Duo Security for our company with the VPN, and afterward, about a year later, we implemented it for a customer of ours where we offered infrastructure as a service. When I tried to establish a VPN connection through Duo Security, it did not function well on that version, which was the latest one at the time. So, I had to make a copy of the machine and then implement Duo Security with the VPN because it did not function well with the newer version."
"There can be some latency issues with the solution that should be improved."
"The one point I have deducted is because it is very hard to get support sometimes."
"The BGP filtering options on Prisma Access should be improved."
"In general, it is good, but everything could be a little bit better. For example, they are working on including more data to catch or trying to reduce the gaps between the matches."
"They can add some new characteristics. For example, when an incident triggers, they can automatically send a template for a particular match that is related to the policy. We don't have that right now. It is something to improve. There could be more automation for certain actions. For example, for a particular group, it can send an administrator alert to their manager. It was one of the concerns of our customers."
"Though the monitoring is fine, the solution should improve its application graphs and interface monitoring."
"Palo Alto needs to improve the GlobalProtect agent to work as a secure web gateway agent, not only as a VPN agent because some companies would want only a secure gateway. They wouldn't want a full VPN. So, Palo Alto has to make the VPN agent work as a secure web gateway agent for those customers who want only the secure web gateway solution."
"I haven't seen any SD-WAN configuration capability. If Prisma Access would support SD-WAN, that would help... SD-WAN devices should be able to reach Prisma Access, and Palo Alto should support different, vendor-specific devices, not just Palo Alto devices, for SD-WAN configuration."
 

Pricing and Cost Advice

"It is expensive compared to one of its competitors."
"We had the cost of purchasing a new appliance along with the implementation and licensing costs. However, the following year, the cost of just licensing was similar to what was paid the previous year for a new appliance along with the implementation and licensing costs."
"The overall pricing for iboss is very competitive and transparent."
"It is probably in line with other solutions, but I do not deal with the financial side."
"It is not expensive, and it is also not cheap. iboss is priced right in the sweet spot for the number of features it offers."
"We have not priced the solution recently, but they were competitive with other vendors in the past."
"I am not aware of the pricing. There are two departments, and I don't have any information about them."
"My experience with the pricing, setup cost, and licensing of Cisco Duo has been great. We've been there for 10 years. While we haven't gone through the setup part for a while, licensing is straightforward and convenient for higher education because student populations are included. So, we don't have to pay extra for it. We just pay for our knowledge workers, which has been great, and the cost is reasonable."
"The cost was reasonable. Licensing was pretty straightforward for a change."
"From a business perspective, it is a little bit costly. The licensing is on a per-user basis."
"It falls in line with everything else."
"Duo Security is free."
"It's a bit confusing because we're on a three-year plan with a certain number of licenses, and we've gone over that number. They told us that when we renew, they will add all these licenses. We've expanded quickly, so everyone's kind of scared because no one knows what the bill is with the long pricing cycle."
"Cisco has the most expensive products because market leaders tend to charge a lot."
"The pricing can be difficult because it came to us with another agreement, but it can be negotiated. I highly recommend people to compare this product's performance and pricing against BetterCloud, because I feel BetterCloud is better than Prisma SaaS if they're starting from scratch."
"The licensing fees are paid on a yearly basis and for what we get, the price is good."
"The licensing model for this product is complicated and changes all the time, making it very hard for the user to comprehend the configuration."
"Based on what I have heard from others, it is a pricey solution as compared to its peers, but I am not sure. However, considering the features that it offers, it is a break-even point. You get whatever they are promising."
"I would advise choosing your options according to your company's needs. Just go for what you want and do not pay for anything extra in terms of licensing. You need to determine how much bandwidth is required in your company network, and according to that, you should pay for the license. The mobile user license is based on the number of users who are going to use the VPN solution. You need to determine how many mobile users you are going to have in your network, and you should pay according to that. There are no other costs in addition to licensing, but if you go for the consultant services of Palo Alto networks to deliver the solution for you, then you need to pay something extra. That is not a part of licensing."
"They price their products using credit modules."
"It is a little expensive. Because it is one of the best in the market, it is a little bit more expensive than other vendors."
"As compared to other solutions, Prisma Access is much cheaper. It is probably 30% to 40% cheaper than other solutions, but I do not know the exact cost."
report
Use our free recommendation engine to learn which ZTNA as a Service solutions are best for your needs.
886,976 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Computer Software Company
9%
Manufacturing Company
9%
Construction Company
7%
Financial Services Firm
11%
Manufacturing Company
10%
Comms Service Provider
7%
Educational Organization
6%
Financial Services Firm
12%
Manufacturing Company
10%
Computer Software Company
9%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise7
Large Enterprise8
By reviewers
Company SizeCount
Small Business42
Midsize Enterprise24
Large Enterprise57
By reviewers
Company SizeCount
Small Business24
Midsize Enterprise21
Large Enterprise27
 

Questions from the Community

What needs improvement with iboss?
iboss can increase security in cyberspace. I have heard they are doing DDoS filtering, but I am not certain if they a...
What is your primary use case for iboss?
I use iboss for corporate VPN and all the corporate VRF, with basically all user traffic proxying to the internet.
What is your experience regarding pricing and costs for iboss?
Regarding pricing, setup costs, and licensing, iboss is not cheap, and that's my only concern. There are cheaper alte...
How does Duo Security compare with Microsoft Authenticator?
We switched to Duo Security for identity verification. We’d been using a competitor but got the chance to evaluate Du...
What is your experience regarding pricing and costs for Duo Security?
I cannot speak to the financial planning of the organization, but I can confirm that Cisco Duo falls within the secur...
What needs improvement with Duo Security?
Areas that have room for improvement in Cisco Duo include pricing, as Cisco is quite expensive, and the fact that Cis...
What is the better solution - Prisma Access or Zscaler Private Access?
We looked into Prisma Access before choosing Zscaler Private Access (ZPA). Palo Alto’s Prisma Access is a secure ac...
What do you like most about Prisma Access by Palo Alto Networks?
The most valuable features of the solution are in the areas of the secure remote access it provides while also being ...
What is your experience regarding pricing and costs for Prisma Access by Palo Alto Networks?
From my experience, Palo Alto is more expensive compared to solutions like Netskope and Triscale.
 

Also Known As

iBoss Cloud Platform
Duo Security
Palo Alto Networks Prisma Access, Prisma Access, GlobalProtect, Palo Alto GlobalProtect Mobile Security Manager, Prisma SaaS by Palo Alto Networks, Prisma Access
 

Overview

 

Sample Customers

More than 4,000 global enterprises trust the iboss Cloud Platform to support their modern workforces, including a large number of Fortune 50 companies.
Information Not Available
Concord Hospital, State of Colorado, Essilor International, RheinLand Versicherungsgruppe, University of Westminster, Universidade Nove de Julho, SPAR Austria, CAME Group, ZipRealty, Greenhill & Co., IKT Agder, Aviva Stadium, Animal Logic, Management & Training Corporation, Brigham Young University Hawaii, School District of Chilliwack
Find out what your peers are saying about Cisco Duo vs. Prisma Access by Palo Alto Networks and other solutions. Updated: April 2026.
886,976 professionals have used our research since 2012.