Try our new research platform with insights from 80,000+ expert users

Cisco Duo vs Prisma Access by Palo Alto Networks comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 28, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

iboss
Sponsored
Ranking in ZTNA as a Service
7th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
19
Ranking in other categories
Secure Web Gateways (SWG) (5th), Internet Security (3rd), Web Content Filtering (1st), Cloud Access Security Brokers (CASB) (7th), Secure Access Service Edge (SASE) (8th)
Cisco Duo
Ranking in ZTNA as a Service
3rd
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
86
Ranking in other categories
Single Sign-On (SSO) (3rd), Authentication Systems (2nd), Access Management (4th), Cisco Security Portfolio (2nd), Multi-Factor Authentication (MFA) (1st)
Prisma Access by Palo Alto ...
Ranking in ZTNA as a Service
2nd
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
66
Ranking in other categories
Secure Web Gateways (SWG) (4th), Cloud Access Security Brokers (CASB) (1st), Enterprise Infrastructure VPN (5th), Secure Access Service Edge (SASE) (1st)
 

Mindshare comparison

As of January 2026, in the ZTNA as a Service category, the mindshare of iboss is 2.6%, up from 1.5% compared to the previous year. The mindshare of Cisco Duo is 2.3%, down from 2.5% compared to the previous year. The mindshare of Prisma Access by Palo Alto Networks is 11.7%, down from 15.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
ZTNA as a Service Market Share Distribution
ProductMarket Share (%)
Prisma Access by Palo Alto Networks11.7%
Cisco Duo2.3%
iboss2.6%
Other83.4%
ZTNA as a Service
 

Featured Reviews

reviewer2701851 - PeerSpot reviewer
Managing Director
Enhances web security with a single pane of glass and flexible deployment
I don't see any need for improvement; one of the really good things about iboss as a company is that they listen to customer feedback. I have suggested enhancements, and they are responsive, making changes for the better, and they do a lot of testing. To improve iboss, although we haven't used it, we considered the VPN solution that comes with the highest tier licensing, which includes DLP and various other add-ons. We prefer using another product which automatically logs you back onto your network when turning on your PC. With iboss, the connection is manual, which doesn't meet our needs. Additionally, sizing can be tricky because, although the initial recommendations may seem adequate, actual usage may require more gateways than anticipated.
Charles Slaustas - PeerSpot reviewer
Information Technology Contractor at Insight global
Supports seamless authentication for users across multiple organizations and personal portals
The features I use in Cisco Duo include Duo Pushes to confirm my identity to the device, and eventually as MFA security was increased, I actually had to use exchange passcodes. Sometimes, I have to go into the site and get into Cisco Duo to retrieve the passcode, and many of them have been two-factor, where the sites send a passcode that I have to enter into Cisco Duo. It has been more of the latter. I have not seen issues with lagging or crashing on Cisco Duo's end; it was usually on the client end, often because someone set up a bad upgrade or there were connection issues with the Cisco Duo cloud through the administrative site.
IgorPinter - PeerSpot reviewer
Director at PULSEC
Zero-trust access has improved remote security and now simplifies cloud-based firewall management
Regarding the integration part for Prisma Access by Palo Alto Networks, the integration with identity providers is pretty much good. It is basically firewall as a service, so it performs well. I completed the integration without any issues. What Palo Alto Networks can do better for Prisma Access by Palo Alto Networks is probably to have the point of presence available in more locations. The point of presence from the Serbia region has the nearest POP in Frankfurt, which is an issue since it is your gateway—when you start browsing the internet, you go through a commercial connection in Germany. They definitely need to spread the service in other countries.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Granular setup, which was able to set different levels of filters using the OUs in the AD."
"I would rate the technical support of iboss a solid 10 without a shadow of a doubt."
"iboss has significantly lowered the number of security incidents. It is crazy how much it blocks and how much it is aware of the outside danger."
"Its initial setup was straightforward."
"Iboss is a solution that prevents advanced persistent threats, and has a zero tolerance for attacks."
"The solution has massively improved our security posture, giving us full visibility into what our staff does online."
"We chose iboss for both zero trust and proxy (SWG) because their SWG was superior."
"It was a very easy product to install. It can be deployed very fast."
"The thing that I appreciate the most about Cisco Duo is the ease of setup."
"It is really scalable. It is easy once you get an application in. You can import users from Active Directory and enroll users really fast."
"It's a lot easier for our end users to connect to our network. You don't have to type in a code. You get push notifications, that's probably the best thing about it. The fewer clicks they have to do to be online, the better it is. They can easily get into the network and do remote work."
"It's simple. It's reliable. I haven't had any issues with it."
"Documentation is the most valuable feature, and if you ever have to reach out to them with a question, their support is also fantastic."
"Compared to Cisco, the general support I experience is fantastic; I have no complaints about it."
"Cisco Duo is rock solid in terms of stability and reliability."
"The Verified Duo Push feature is valuable. It gives an extra level of security beyond just the regular push."
"A feature I've found very helpful is run time security because most of the products on the market will look at security during the build time, and they don't really look at what happens once you're going into production."
"The setup is relatively straightforward."
"It supports auto-scaling for mobile users. It auto-scales depending on the mobile user traffic. For example, if 1,000 people are working from home today, and tomorrow, the number increases to 2,000, it is not going to be an issue."
"The most valuable features of the solution stem from the fact that it offers stability and scalability while being a very secure product."
"The users can securely access any cloud data centers or cloud platforms. In terms of the features, it has all the features that Palo Alto Next-Generation Firewall has. It is also very stable and scalable."
"I like it because it's very easy to use. You install the client and you have to know your gateway, but that's something we give to our users. Beyond that, it takes about three seconds to train them on how to use it. And it just works well. That's great for us because it means less administrative time."
"It is geographically dispersed, and it sits on top of Google and AWS platforms. Therefore, you don't face the standard issues, such as latency or bandwidth issues, that you usually face in the case of on-prem data centers."
"We're now able to go after contracts that require a Zero Trust solution and Prisma's other technology solutions."
 

Cons

"The dashboards for local use could be better."
"I'd like to see them accelerate development on the security side, particularly around data loss prevention."
"Their on-premise hardware's network interface is capped at one gigabit, which is sort of a problem. If you stand a filter up where all traffic flows through that, according to them, in order to go above a gigabit, you have to have multiple devices, which in today's IT seems a little bit silly. They could easily put in an SFP port into their device that could accommodate 10 gigs or at least offer a box."
"Our biggest problem with their service was it did not recognize the device and filtering did not always work correctly."
"The solution could be stronger on the integration side and offer more cloud applications like G Suite or Oracle."
"The reporting feature needs improvement. It doesn't give you the expected results. It is quite difficult to get the specific reports needed, and it is not as intuitive as the rest of the platform."
"Our biggest problem with their service was it did not recognize the device and filtering did not always work correctly."
"One thing I would like to see differently with their Zero Trust platform is that some of the AI aspects related to high-risk activities have more false positives."
"Cisco Duo can be improved with better ways to set users up. Currently, we might not be doing it perfectly as we're having them email in phone numbers to get them set up with Duo Mobile."
"Integration between Duo Security and FTDs needs improvement. Integrating Next Generation Firewall safety with Duo Security currently requires a proxy agent between Active Directory and the appliance. It's an additional factor that we need to think about. It would be great to have direct integration with FTD so that we don't have to worry about middleware products. For the rest of the Cisco Secure solutions, the APIs need improvement."
"The pain point for us at one point was the Duo Authentication Proxy since we're on-premises and not in the cloud. We had to have a proxy machine that's in our DMZ to talk to Duo for us. The configuration of that was a little complicated."
"Reducing or eliminating the "telephony credits" system used by Duo would be great."
"I would like to see Duo Security increase the time that the users have to log into the devices. The maximum time interval is 50 minutes at the moment, and I would like it to be 60 minutes. When you try to log into a device and have to authenticate yourself, sometimes it's not very pleasant. It's not the best thing particularly if you have to do this every 50 minutes, which is the maximum time that Duo gives. This makes it difficult to use and does not save time."
"Cisco Duo could be improved if there were a way to make two-factor authentication quicker."
"While two-factor authentication with mobile devices provides a high level of security, it's still not foolproof, as someone could potentially steal your phone. It would be beneficial to have information about the authentication location."
"I would appreciate seeing Cisco Duo improved with a tighter integration with Active Directory to secure not just Remote Desktop to a server, but all the remote levels of connection that you can make to a server."
"Its integration with non-Palo Alto products can be improved. Currently, it is easy to integrate it with other Palo Alto products such as Cortex XDR. It integrates well with other Palo Alto products. A major part of our network is based on Palo Alto products, but for those companies that use multi-vendor products in their infrastructure, Palo Alto should optimize the integration of Prisma Access with the network devices from other vendors."
"The BGP filtering options on Prisma Access should be improved."
"When it comes to integration mechanisms, Prisma SaaS does not support reverse proxy type of integrations."
"It applies commits to the firewalls slowly. There isn't an API you can use for anything. We've previously had trouble with the egress IP addresses though we expressed to engineering that those mustn't change. They changed several times without warning, causing a lot of headaches."
"There is some particular traffic that the security team wants to filter out and apply their own policies and they cannot."
"There is room for improvement in the multi-environment visibility, especially around containers."
"Palo Alto Prisma 10 came out over a year ago. Palo Alto added this identity management feature. The legacy way Palo Alto selected which user is sitting on an IP address it passes through has been clunky."
"Sometimes, we encountered a portal crash. When we told Palo Alto they said it might be the browser or cache, but I think they need to improve it on their side."
 

Pricing and Cost Advice

"It is not expensive, and it is also not cheap. iboss is priced right in the sweet spot for the number of features it offers."
"It is expensive compared to one of its competitors."
"We have not priced the solution recently, but they were competitive with other vendors in the past."
"We had the cost of purchasing a new appliance along with the implementation and licensing costs. However, the following year, the cost of just licensing was similar to what was paid the previous year for a new appliance along with the implementation and licensing costs."
"It is probably in line with other solutions, but I do not deal with the financial side."
"The overall pricing for iboss is very competitive and transparent."
"The licensing is very good because it does not cost a lot of money. It's affordable for all-sized customers, including enterprises. There is an additional cost for premium support."
"The pricing was a lot more than what we were paying for our previous solution."
"During testing we are allowed a certain number of licenses for free."
"Our licensing fee is currently on an annual basis."
"I believe the licensing model is excellent as it offers flexibility to our customers, allowing them to adopt a crawl, walk, or run approach."
"Its price is reasonable. It is not highly expensive."
"My experience with pricing, setup costs, and licensing has been good, with no issues. I am pleased that the prices remained stable after Cisco acquired the solution."
"My experience with the pricing, setup cost, and licensing of Cisco Duo has been great. We've been there for 10 years. While we haven't gone through the setup part for a while, licensing is straightforward and convenient for higher education because student populations are included. So, we don't have to pay extra for it. We just pay for our knowledge workers, which has been great, and the cost is reasonable."
"There's no reason not to buy the enterprise version that gives you unlimited PoPs, but you must understand the limitations you impose on yourself if you do that. If you go crazy, that allowlist will be too big for Kubernetes clusters."
"The solution is expensive."
"I would advise choosing your options according to your company's needs. Just go for what you want and do not pay for anything extra in terms of licensing. You need to determine how much bandwidth is required in your company network, and according to that, you should pay for the license. The mobile user license is based on the number of users who are going to use the VPN solution. You need to determine how many mobile users you are going to have in your network, and you should pay according to that. There are no other costs in addition to licensing, but if you go for the consultant services of Palo Alto networks to deliver the solution for you, then you need to pay something extra. That is not a part of licensing."
"Prisma Access by Palo Alto Networks has flexible licensing models with different categories. It comes with different features which can be removed if not needed. However, its pricing is high."
"They price their products using credit modules."
"Prisma Access is a little bit expensive."
"I'm still comparing, but the solution is quite expensive."
"This is not an expensive product and everything is included with one license."
report
Use our free recommendation engine to learn which ZTNA as a Service solutions are best for your needs.
881,078 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Computer Software Company
10%
Manufacturing Company
9%
Comms Service Provider
6%
Manufacturing Company
11%
Computer Software Company
10%
Comms Service Provider
7%
Government
7%
Financial Services Firm
12%
Manufacturing Company
11%
Computer Software Company
11%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise6
Large Enterprise5
By reviewers
Company SizeCount
Small Business31
Midsize Enterprise18
Large Enterprise39
By reviewers
Company SizeCount
Small Business24
Midsize Enterprise21
Large Enterprise27
 

Questions from the Community

What needs improvement with iboss?
For zero trust implementation, we encountered complexity issues, especially with a large infrastructure company Exxon...
What is your primary use case for iboss?
Previously when I used iboss, we did the POC for iboss for ExxonMobil. Four or five people wanted to move from our ol...
What is your experience regarding pricing and costs for iboss?
Regarding pricing, setup costs, and licensing, iboss is not cheap, and that's my only concern. There are cheaper alte...
How does Duo Security compare with Microsoft Authenticator?
We switched to Duo Security for identity verification. We’d been using a competitor but got the chance to evaluate Du...
What is your experience regarding pricing and costs for Duo Security?
My experience with pricing, setup cost, and licensing reveals that one of the most powerful features is the licensing...
What needs improvement with Duo Security?
One downside of Cisco Duo is the expense, as there are clients that can afford only the basic package, which does not...
What is the better solution - Prisma Access or Zscaler Private Access?
We looked into Prisma Access before choosing Zscaler Private Access (ZPA). Palo Alto’s Prisma Access is a secure ac...
What do you like most about Prisma Access by Palo Alto Networks?
The most valuable features of the solution are in the areas of the secure remote access it provides while also being ...
What is your experience regarding pricing and costs for Prisma Access by Palo Alto Networks?
From my experience, Palo Alto is more expensive compared to solutions like Netskope and Triscale.
 

Also Known As

iBoss Cloud Platform
Duo Security
Palo Alto Networks Prisma Access, Prisma Access, GlobalProtect, Palo Alto GlobalProtect Mobile Security Manager, Prisma SaaS by Palo Alto Networks, Prisma Access
 

Overview

 

Sample Customers

More than 4,000 global enterprises trust the iboss Cloud Platform to support their modern workforces, including a large number of Fortune 50 companies.
Information Not Available
Concord Hospital, State of Colorado, Essilor International, RheinLand Versicherungsgruppe, University of Westminster, Universidade Nove de Julho, SPAR Austria, CAME Group, ZipRealty, Greenhill & Co., IKT Agder, Aviva Stadium, Animal Logic, Management & Training Corporation, Brigham Young University Hawaii, School District of Chilliwack
Find out what your peers are saying about Cisco Duo vs. Prisma Access by Palo Alto Networks and other solutions. Updated: December 2025.
881,078 professionals have used our research since 2012.