Try our new research platform with insights from 80,000+ expert users

Cisco Duo vs Prisma Access by Palo Alto Networks comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 28, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

iboss
Sponsored
Ranking in ZTNA as a Service
7th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
19
Ranking in other categories
Secure Web Gateways (SWG) (5th), Internet Security (3rd), Web Content Filtering (1st), Cloud Access Security Brokers (CASB) (7th), Secure Access Service Edge (SASE) (8th)
Cisco Duo
Ranking in ZTNA as a Service
3rd
Average Rating
8.8
Reviews Sentiment
7.1
Number of Reviews
114
Ranking in other categories
Single Sign-On (SSO) (3rd), Authentication Systems (2nd), Access Management (3rd), Cisco Security Portfolio (1st), Multi-Factor Authentication (MFA) (1st)
Prisma Access by Palo Alto ...
Ranking in ZTNA as a Service
2nd
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
66
Ranking in other categories
Secure Web Gateways (SWG) (4th), Cloud Access Security Brokers (CASB) (1st), Enterprise Infrastructure VPN (5th), Secure Access Service Edge (SASE) (1st)
 

Mindshare comparison

As of March 2026, in the ZTNA as a Service category, the mindshare of iboss is 2.4%, up from 1.7% compared to the previous year. The mindshare of Cisco Duo is 2.3%, down from 2.3% compared to the previous year. The mindshare of Prisma Access by Palo Alto Networks is 11.3%, down from 15.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
ZTNA as a Service Market Share Distribution
ProductMarket Share (%)
Prisma Access by Palo Alto Networks11.3%
Cisco Duo2.3%
iboss2.4%
Other84.0%
ZTNA as a Service
 

Featured Reviews

reviewer2701851 - PeerSpot reviewer
Managing Director
Enhances web security with a single pane of glass and flexible deployment
I don't see any need for improvement; one of the really good things about iboss as a company is that they listen to customer feedback. I have suggested enhancements, and they are responsive, making changes for the better, and they do a lot of testing. To improve iboss, although we haven't used it, we considered the VPN solution that comes with the highest tier licensing, which includes DLP and various other add-ons. We prefer using another product which automatically logs you back onto your network when turning on your PC. With iboss, the connection is manual, which doesn't meet our needs. Additionally, sizing can be tricky because, although the initial recommendations may seem adequate, actual usage may require more gateways than anticipated.
Charles Slaustas - PeerSpot reviewer
Information Technology Contractor at Insight global
Supports seamless authentication for users across multiple organizations and personal portals
The features I use in Cisco Duo include Duo Pushes to confirm my identity to the device, and eventually as MFA security was increased, I actually had to use exchange passcodes. Sometimes, I have to go into the site and get into Cisco Duo to retrieve the passcode, and many of them have been two-factor, where the sites send a passcode that I have to enter into Cisco Duo. It has been more of the latter. I have not seen issues with lagging or crashing on Cisco Duo's end; it was usually on the client end, often because someone set up a bad upgrade or there were connection issues with the Cisco Duo cloud through the administrative site.
IgorPinter - PeerSpot reviewer
Director at PULSEC
Zero-trust access has improved remote security and now simplifies cloud-based firewall management
Regarding the integration part for Prisma Access by Palo Alto Networks, the integration with identity providers is pretty much good. It is basically firewall as a service, so it performs well. I completed the integration without any issues. What Palo Alto Networks can do better for Prisma Access by Palo Alto Networks is probably to have the point of presence available in more locations. The point of presence from the Serbia region has the nearest POP in Frankfurt, which is an issue since it is your gateway—when you start browsing the internet, you go through a commercial connection in Germany. They definitely need to spread the service in other countries.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We were impressed by the solution's mental health function, which can detect if someone needs help. It scans what users are browsing and flags warning signs so we can check to see if they are okay. We've had to use it a couple of times."
"Content filtering is the most useful feature of iboss."
"The console is cloud-based, which is something I really appreciate."
"Iboss is a solution that prevents advanced persistent threats, and has a zero tolerance for attacks."
"Technical support is pretty sharp and very responsive."
"iboss is among the few products providing inline filtering where no application is needed on the device. It operates on the network side and is not device-based. This feature was one of the main reasons why we stayed with them for so long."
"Its initial setup was straightforward."
"Granular setup, which was able to set different levels of filters using the OUs in the AD."
"Duo offers dual-factor authentication for our logins. I put in my credentials and hit go. Then I get an alert on my Apple watch, and I approve it. That part is just phenomenal."
"It has continuously evolved by introducing new solutions and products to address emerging security threats in our industry, demonstrating its commitment to staying ahead of evolving security challenges."
"Cisco Duo seems very scalable; in my last contracting position, it was a large one for a major worldwide airline that had hundreds of thousands of devices that could use Cisco Duo, and it scaled very well."
"Cisco Duo has strengthened the ability to defend against both phishing and identity-based attacks."
"Cisco Duo benefits the company by increasing the security footprint, and it is easy to manage users, disable users, or bypass if needed in case of an emergency."
"Cisco Duo benefits my organization by making it easy for me to reach out to customers using Cisco Duo so they can integrate on my platform using their credentials."
"The feature that my organization started using more recently in Cisco Duo is offline authentication."
"My total rating for Cisco Duo is ten out of ten."
"Prisma Access is very stable, and I am very much satisfied with its stability, rating it nine to ten out of ten."
"Security is absolutely spot-on, really top-notch. It's the result of all the components that come together, such as the HIP [Host Information Profile] and components like Forcepoint, providing end-user content inspection, and antivirus. It incorporates DLP features and that's fantastic because Prisma Access makes sure that all of the essential prerequisites are in place before a user can log in or can be tunneled into."
"It's much faster and more secure than legacy solutions. It is also quite stable and scalable as well. We are able to see all the traffic in one place."
"Prisma SaaS is very easy to use; it's common sense — it's the best-in-class."
"The remediation process is easy compared to other platforms."
"I think the stability of Prisma Access by Palo Alto Networks is excellent, and I would rate it ten out of ten."
"I would recommend Prisma Access by Palo Alto Networks as it is really good, but it would be much better if the pricing were lower so that I could provide cloud firewall services instead of physical firewalls to customers."
"The always-on feature is fantastic for the users. They don't have to think about it. When they go to a coffee shop to do work, there's no need to remember to toggle the VPN on. We'll protect them. URL filtering is the same at home as it is in the office."
 

Cons

"The reporting feature needs improvement. It doesn't give you the expected results. It is quite difficult to get the specific reports needed, and it is not as intuitive as the rest of the platform."
"If they could implement an extra security layer preventing access to iboss from the open internet, it would be great."
"Sometimes when you call in support, you get someone who is just following a sheet. It feels like a runaround. You feel that you are running into that support wall."
"Fold that in with the risk intelligence they're getting from all of the different subscriptions they are a part of. Now, these security companies subscribe to things like emerging threats, databases, etc. You can fold all this intelligence to decide what's happening on an endpoint. I would love to see them start moving into that space. That would compete directly with Microsoft. Maybe that's why they haven't. Having that ability native within the solution would be great. The other area in which I would love to see improvement is more detailed descriptions of why they block websites."
"Our iboss subscription access should be more secure with an OTP or VPN etc. It is easy to gain access if, for example, hackers obtain my username and password."
"To scale up, a new iboss Node Blade Chassis must be purchased."
"The area I would like to see improvement in is the ability with in the reporter to navigate directly to the content the user is traversing. It is kind of there, but it's not perfect. Quite frequently, I receive links that lead me to pages with error messages."
"One thing I would like to see differently with their Zero Trust platform is that some of the AI aspects related to high-risk activities have more false positives."
"The new smart license model doesn't always work. It's very complicated."
"I wish that the support would be a little bit more prompt and a little bit more flexible because there are certain things that they will do and certain things they won't do."
"I think the prices of Cisco Duo are quite fair, but the main problem is that Microsoft Authenticator is built-in with M365, so everyone is switching to that and using it instead of Cisco Duo because it costs extra as a standalone product."
"Cisco Duo could be improved by building the agent with the many agents we already use, such as Cisco AMP and Cisco Secure Client, which would simplify our environment by eliminating the need for a third agent for secure applications."
"Often, people do not receive expiration messages, and sometimes, for security reasons, accounts get disabled without notifying the end user, so they mistakenly think something has gone wrong when it really just needs to be re-enabled on the external system."
"To improve Cisco Duo, the biggest consideration is the licensing standpoint; the most common issue I've found is customers not setting up the Active Directory sync properly, leading to inflated licensing usage when they try to delete inactive users that are still being charged."
"We have users who move throughout the world, and their levels of connectivity change. It can be a challenge, if someone is in Bahrain, to authenticate via Duo."
"I would like to see Duo Security increase the time that the users have to log into the devices. The maximum time interval is 50 minutes at the moment, and I would like it to be 60 minutes. When you try to log into a device and have to authenticate yourself, sometimes it's not very pleasant. It's not the best thing particularly if you have to do this every 50 minutes, which is the maximum time that Duo gives. This makes it difficult to use and does not save time."
"The cloud setup is straightforward, and the onboarding process is much better, but the on-premises initial setup is slightly complex."
"Palo Alto needs to improve the GlobalProtect agent to work as a secure web gateway agent, not only as a VPN agent because some companies would want only a secure gateway. They wouldn't want a full VPN. So, Palo Alto has to make the VPN agent work as a secure web gateway agent for those customers who want only the secure web gateway solution."
"Pricing for Prisma Access and Prisma SD WAN is high due to the need for different hardware flavors like IONs."
"The product's price is an area of concern where improvements are required. The solution's price should be lowered."
"There can be some latency issues with the solution that should be improved."
"I would like to see better pricing and an easier logging process. Also, if there was a way to log a global log, everything could go onto the system. It would be better if there was a third log, otherwise one would have to do everything manually."
"The documentation is generally good, but they could provide a more detailed description of all the configuration steps. I have to search for information or call support. Palo Alto could add more knowledge base articles about configuration with screenshots and walkthroughs. That would be helpful. When configuring a product, you want to see examples of how it is done."
"I haven't seen any SD-WAN configuration capability. If Prisma Access would support SD-WAN, that would help... SD-WAN devices should be able to reach Prisma Access, and Palo Alto should support different, vendor-specific devices, not just Palo Alto devices, for SD-WAN configuration."
 

Pricing and Cost Advice

"It is expensive compared to one of its competitors."
"We have not priced the solution recently, but they were competitive with other vendors in the past."
"It is probably in line with other solutions, but I do not deal with the financial side."
"The overall pricing for iboss is very competitive and transparent."
"We had the cost of purchasing a new appliance along with the implementation and licensing costs. However, the following year, the cost of just licensing was similar to what was paid the previous year for a new appliance along with the implementation and licensing costs."
"It is not expensive, and it is also not cheap. iboss is priced right in the sweet spot for the number of features it offers."
"Its price is reasonable. It is not highly expensive."
"The pricing was a lot more than what we were paying for our previous solution."
"I haven't seen it in a while, but it's at par with everything else licensing-wise."
"I am not aware of the pricing. There are two departments, and I don't have any information about them."
"The product’s pricing is reasonable."
"Price wise, it's not cheap, but it's not expensive at all either. It's in the middle."
"My experience with pricing, setup costs, and licensing has been good, with no issues. I am pleased that the prices remained stable after Cisco acquired the solution."
"I believe the licensing model is excellent as it offers flexibility to our customers, allowing them to adopt a crawl, walk, or run approach."
"Prisma Access by Palo Alto Networks has flexible licensing models with different categories. It comes with different features which can be removed if not needed. However, its pricing is high."
"In terms of pricing, considering that it is a two or three years old solution, they should apply big discounts for the next two or three years. This approach will be better for them to capture the market."
"It's pricey, it's not cheap. But you get what you pay for."
"The licensing fees are paid on a yearly basis and for what we get, the price is good."
"We have to pay additional costs for maintenance and support services."
"The solution requires a license and the technical support has extra costs. The licensing model could improve."
"Palo Alto is the Cadillac solution, so their products are pretty expensive. That's just the way it is. Their solution surpasses anything else. Cisco AnyConnect, Zscaler, and all of the other products don't compare. Palo Alto is the market leader with the most features. It saves you work, and you don't have to worry about it."
"There's no reason not to buy the enterprise version that gives you unlimited PoPs, but you must understand the limitations you impose on yourself if you do that. If you go crazy, that allowlist will be too big for Kubernetes clusters."
report
Use our free recommendation engine to learn which ZTNA as a Service solutions are best for your needs.
883,448 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Computer Software Company
10%
Manufacturing Company
9%
Comms Service Provider
6%
Manufacturing Company
11%
Computer Software Company
8%
Financial Services Firm
8%
Comms Service Provider
8%
Financial Services Firm
11%
Manufacturing Company
11%
Computer Software Company
9%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business41
Midsize Enterprise23
Large Enterprise53
By reviewers
Company SizeCount
Small Business24
Midsize Enterprise21
Large Enterprise27
 

Questions from the Community

What needs improvement with iboss?
For zero trust implementation, we encountered complexity issues, especially with a large infrastructure company Exxon...
What is your primary use case for iboss?
Previously when I used iboss, we did the POC for iboss for ExxonMobil. Four or five people wanted to move from our ol...
What is your experience regarding pricing and costs for iboss?
Regarding pricing, setup costs, and licensing, iboss is not cheap, and that's my only concern. There are cheaper alte...
How does Duo Security compare with Microsoft Authenticator?
We switched to Duo Security for identity verification. We’d been using a competitor but got the chance to evaluate Du...
What is your experience regarding pricing and costs for Duo Security?
Compared to other vendors, Cisco Duo is on the pricey end. However, the other vendors do not have the wide range of f...
What needs improvement with Duo Security?
The primary issue is adoption. When I used to work for Deloitte, I did consulting and advisory for at least 95 of the...
What is the better solution - Prisma Access or Zscaler Private Access?
We looked into Prisma Access before choosing Zscaler Private Access (ZPA). Palo Alto’s Prisma Access is a secure ac...
What do you like most about Prisma Access by Palo Alto Networks?
The most valuable features of the solution are in the areas of the secure remote access it provides while also being ...
What is your experience regarding pricing and costs for Prisma Access by Palo Alto Networks?
From my experience, Palo Alto is more expensive compared to solutions like Netskope and Triscale.
 

Also Known As

iBoss Cloud Platform
Duo Security
Palo Alto Networks Prisma Access, Prisma Access, GlobalProtect, Palo Alto GlobalProtect Mobile Security Manager, Prisma SaaS by Palo Alto Networks, Prisma Access
 

Overview

 

Sample Customers

More than 4,000 global enterprises trust the iboss Cloud Platform to support their modern workforces, including a large number of Fortune 50 companies.
Information Not Available
Concord Hospital, State of Colorado, Essilor International, RheinLand Versicherungsgruppe, University of Westminster, Universidade Nove de Julho, SPAR Austria, CAME Group, ZipRealty, Greenhill & Co., IKT Agder, Aviva Stadium, Animal Logic, Management & Training Corporation, Brigham Young University Hawaii, School District of Chilliwack
Find out what your peers are saying about Cisco Duo vs. Prisma Access by Palo Alto Networks and other solutions. Updated: February 2026.
883,448 professionals have used our research since 2012.