Try our new research platform with insights from 80,000+ expert users

Cisco Duo vs Zscaler Zero Trust Exchange Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 27, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

iboss
Sponsored
Ranking in ZTNA as a Service
8th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
19
Ranking in other categories
Secure Web Gateways (SWG) (5th), Internet Security (3rd), Web Content Filtering (1st), Cloud Access Security Brokers (CASB) (7th), Secure Access Service Edge (SASE) (8th)
Cisco Duo
Ranking in ZTNA as a Service
5th
Average Rating
8.8
Reviews Sentiment
7.1
Number of Reviews
78
Ranking in other categories
Single Sign-On (SSO) (4th), Authentication Systems (2nd), Access Management (5th), Cisco Security Portfolio (4th), Multi-Factor Authentication (MFA) (2nd)
Zscaler Zero Trust Exchange...
Ranking in ZTNA as a Service
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
64
Ranking in other categories
Data Loss Prevention (DLP) (2nd), Cloud Access Security Brokers (CASB) (5th), Application Control (4th), Secure Access Service Edge (SASE) (1st), Remote Browser Isolation (RBI) (1st)
 

Mindshare comparison

As of October 2025, in the ZTNA as a Service category, the mindshare of iboss is 2.4%, up from 1.3% compared to the previous year. The mindshare of Cisco Duo is 2.3%, down from 2.6% compared to the previous year. The mindshare of Zscaler Zero Trust Exchange Platform is 17.4%, down from 20.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
ZTNA as a Service Market Share Distribution
ProductMarket Share (%)
Zscaler Zero Trust Exchange Platform17.4%
Cisco Duo2.3%
iboss2.4%
Other77.9%
ZTNA as a Service
 

Featured Reviews

Matt Crockford - PeerSpot reviewer
It's easy to roll out, and their understanding of our business made it seamless
One aspect we value about iboss is its simplicity. Their customer service is brilliant, and they are super responsive and knowledgeable. It's easy to roll out, and their understanding of our business made it seamless. We were impressed by the solution's mental health function, which can detect if someone needs help. It scans what users are browsing and flags warning signs so we can check to see if they are okay. We've had to use it a couple of times. The user interface is highly intuitive. Our IT team picked it up with minimal training. It's arranged so that it's easy to find where things are. Another advantage is the single pane of glass console, which gives you visibility into what's happening. We're not fully there yet because we haven't implemented zero trust, but we're excited about the possibilities from the demos we've seen. We launched a POC of iboss' ChatGPT Risk Protection feature two weeks ago. AI is a great tool, but you need to be careful what you put into it. My biggest fear is employees inputting sensitive corporate information or customer PII data into one of these chatbots. I was impressed by our trial of the feature. It's exactly what we wanted. Now, when a user goes to ChatGPT, there's a banner warning them not to share information, and we can block conversations containing customer data like bank details and email addresses. I don't want to stop people from using it, but we need visibility. We've only tried it on a test group of 15 people. You can configure it to look for specific keywords or integrate it with your DLP policy if you have that configured
Thomas Botts - PeerSpot reviewer
Managing security policies effectively with seamless authentication
The feature of Cisco Duo that I prefer the most is the policies, being able to control what we need to within the policies. You can get pretty granular. There isn't a lot of training that goes on in school districts. Email is an easy way where many people give out their credentials, so the level of protection is something that we definitely need in a school district. Cisco Duo's strong security authentication system has been easy when logging in, although the teachers don't appreciate it as much. We have it configured so users essentially just hit accept. If it sees any sort of built-in risk, then it steps up authentication. It's pretty easy. I appreciate it. I've encountered advantages with Cisco Duo in that it has stopped significant pushback from teachers. It has prevented credential sharing and unauthorized access. We've seen a huge decrease since we've rolled it out across the entire district.
Sumit Bhanwala - PeerSpot reviewer
Cloud-based platform simplifies device and data center management
I find it to be good. The solution is cloud-based with the latest inspection engines, which I find to be amazing. We are less dependent on data centers and device management, which reduces our efforts significantly. It improves our device management, data center management, and updating devices. We need fewer engineers for this management, and it reduces time and efforts for data center management, device upgrades, and IT support.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"First of all, the security policies are essential. I do not have to rely solely on Active Directory for our users."
"The iboss system is highly reliable. The false positive rates are small compared to some other systems we've experienced through other partner agencies who use competing solutions."
"iboss is among the few products providing inline filtering where no application is needed on the device."
"The solution has massively improved our security posture, giving us full visibility into what our staff does online."
"Its initial setup was straightforward."
"Because of iboss, I did not have to assign web filtering tasks to my techs on a daily basis."
"We were impressed by the solution's mental health function, which can detect if someone needs help. It scans what users are browsing and flags warning signs so we can check to see if they are okay. We've had to use it a couple of times."
"From a use-case scenario, what I like the most is the plug-in. I like the fact that we can do the filtering of these devices offsite independent of the network they are connected to, and we do not have to have traffic coming back inside our network."
"Another feature is the single pane of glass management. That's important for analytics and also for troubleshooting. It means there's one place that you go to at least start the troubleshooting process."
"Cisco Duo helps minimize the risk of attack vectors and prevents unauthorized access to our data since it's tied with multi-factor authentication, which helps block threats."
"I like the set time that users can log into devices during the day and how many times they can do so. I also like the ability to restrict the regions from which the user can get in. Users outside of our country or even the town cannot log in."
"The UI of Cisco Duo is easy to use, especially the web backend, and it's really intuitive and easy to set up."
"All features of the solution are effective, particularly those involved in identifying vulnerabilities and updates."
"The most appealing feature of Cisco Duo is the phone notification system that simply pops up on your phone."
"It was a simple way of providing two-factor authentication for remote access when we hit the COVID pandemic. It was very easy and quick to get it going."
"By deploying Duo, we have virtually eliminated the risk of direct deposit redirection as a result of credentials that have been compromised via phishing."
"This secure connection allows users to connect to the Zscaler VPN and access the resources on the office network, making it a highly valuable component of our system."
"The most valuable feature is its seamless integration capabilities, streamlining the process by eliminating the need for extensive installations."
"I like its ease of use. It has a single pane of glass for the ZIA and ZPA pieces. It is very manageable. It is also very easy to deploy for secure access, and it gives half-decent coverage for visibility in terms of what the users use and what data is being proxied through the access gateway."
"The product’s most valuable features are inbound and outbound scanning and API control."
"Zscaler Cloud DLP provides you with basic DLP features that you get out of the box such as keywords, regular expressions, and data identifiers, for example, your social security numbers, and credit card numbers, with everything built into the product, so you can directly use those features within the policies. You don't need to create it from scratch, and to me, this is the biggest benefit of Zscaler Cloud DLP. You have a lot of templates to choose from in the solution, rather than having to create templates from scratch or reinvent templates."
"The VPN is great for the stability on offer and for the cloud updates and insights you can get."
"The most valuable features of Zscaler Private Access are its ability to integrate with multiple IDPs and application segmentation."
"Its impressive scalability allows the combination of multiple dictionaries and using them as one engine, resulting in narrower data loss gaps."
 

Cons

"Sometimes, obviously, there are bugs."
"Our iboss subscription access should be more secure with an OTP or VPN etc. It is easy to gain access if, for example, hackers obtain my username and password."
"I am currently doing a PoC of the zero trust aspect of it. Compared to other similar solutions, it is hard to get around each feature. It takes a while to get used to it."
"Our biggest problem with their service was it did not recognize the device and filtering did not always work correctly."
"SSL decryption: We had issues with learners using apps instead of using web browsers. This type of encryption is tough for any appliance in a BYOD environment."
"Their on-premise hardware's network interface is capped at one gigabit, which is sort of a problem. If you stand a filter up where all traffic flows through that, according to them, in order to go above a gigabit, you have to have multiple devices, which in today's IT seems a little bit silly. They could easily put in an SFP port into their device that could accommodate 10 gigs or at least offer a box."
"Sometimes when you call in support, you get someone who is just following a sheet. It feels like a runaround. You feel that you are running into that support wall."
"One thing I would like to see differently with their Zero Trust platform is that some of the AI aspects related to high-risk activities have more false positives."
"Integration between Duo Security and FTDs needs improvement. Integrating Next Generation Firewall safety with Duo Security currently requires a proxy agent between Active Directory and the appliance. It's an additional factor that we need to think about. It would be great to have direct integration with FTD so that we don't have to worry about middleware products. For the rest of the Cisco Secure solutions, the APIs need improvement."
"Duo Security should better organize its tile feature to organize applications better."
"We first deployed Duo Security for our company with the VPN, and afterward, about a year later, we implemented it for a customer of ours where we offered infrastructure as a service. When I tried to establish a VPN connection through Duo Security, it did not function well on that version, which was the latest one at the time. So, I had to make a copy of the machine and then implement Duo Security with the VPN because it did not function well with the newer version."
"I'm unsure how to disable the ping notification sound on my phone when using Cisco Duo."
"When you come to the push in Duo Security, there are some integrations where you have to use the code instead of the push functionality."
"While two-factor authentication with mobile devices provides a high level of security, it's still not foolproof, as someone could potentially steal your phone. It would be beneficial to have information about the authentication location."
"I wouldn't mind seeing some options for remembering a device for a short period of time or a specific login, particularly for administrative engineering staff, as we may be logging in to four or five different services."
"It could be a little bit more intuitive when it comes to the sign-up process. I know they send out an email, but sometimes our users get a little confused. It could be an end-user problem, but Cisco could work on that a little."
"We often face performance and latency issues with Zscaler SASE."
"In the next release, I would like to see RE2 Regex supported."
"To enhance their offering, it is advisable for them to focus on strengthening the foundation of their architecture. Additionally, they should consider integrating a broader range of services that go beyond what managed service providers typically offer independently."
"The tool must provide IP-blocking features."
"Having a Zscaler-specific device could streamline this process and provide a more consistent user experience across diverse branches."
"While Zscaler supports client-initiated connections, it does not support server-initiated connections. This is a feature that Zscaler may consider adding in the future."
"It has massive room for improvement. The Zscaler product itself is okay, but it doesn't give enough granularity for us as an organization to stipulate rules or processes, especially for data-driven services. For instance, we can stick on SSL inspection, but it's just a click box. It doesn't allow us to go any further into the detail of the SSL inspection. We also can't pull it out without having an additional logging server. It just doesn't give us enough granularity. They should give us more control over the interfaces because it is all backend. They weren't very open to discussing their backend architecture with us in terms of their own data centers. They can maybe a little bit more open about what components are there and how the backend infrastructure works alongside Zscaler. Its licensing can be better. Some of the additional licensing costs are quite high, and they should have certain features ready and available as a baseline rather than having to purchase additional licenses for it. Their support should also be improved. I initially had a consultant from Zscaler for its deployment, but the support that I had throughout the deployment of the project wasn't the best."
"The stability could be improved."
 

Pricing and Cost Advice

"We have not priced the solution recently, but they were competitive with other vendors in the past."
"The overall pricing for iboss is very competitive and transparent."
"It is probably in line with other solutions, but I do not deal with the financial side."
"We had the cost of purchasing a new appliance along with the implementation and licensing costs. However, the following year, the cost of just licensing was similar to what was paid the previous year for a new appliance along with the implementation and licensing costs."
"It is not expensive, and it is also not cheap. iboss is priced right in the sweet spot for the number of features it offers."
"It is expensive compared to one of its competitors."
"I haven't seen it in a while, but it's at par with everything else licensing-wise."
"Cisco has the most expensive products because market leaders tend to charge a lot."
"Overall, the pricing is fair. Customers can wrap it into their Enterprise Agreement, making it easier for them to solve their issues."
"I haven't seen any information on the pricing in four years, so I can't comment on that."
"Its price is reasonable. It is not highly expensive."
"It falls in line with everything else."
"It's a bit confusing because we're on a three-year plan with a certain number of licenses, and we've gone over that number. They told us that when we renew, they will add all these licenses. We've expanded quickly, so everyone's kind of scared because no one knows what the bill is with the long pricing cycle."
"I only need the solution for IT staff, which makes it relatively cheap. If I deployed it for the whole company, it would be costly, so it depends on the number of users. Duo Security is affordable compared to other products in the segment."
"My company is a Zscaler Private Access partner, so the customers pay for the license fees."
"The licensing model for Zscaler Cloud DLP allows you to only buy what you need. You don't need to buy it as a whole, so it's good."
"As per industry leads, Zscaler CASB is an expensive solution."
"There is definitely an ROI."
"In terms of market positioning, I would describe Zscaler Private Access as offering optimal pricing. Based on our experience, Cato Networks tends to be slightly more expensive."
"Pricing for Zscaler Private Access is moderate. It's acceptable, though I can't give you the exact price currently. It's not too expensive, and on a scale of one to five, I would rate it a four out of five in terms of pricing."
"The solution is expensive."
"The cost is expensive. It depends on the number of users."
report
Use our free recommendation engine to learn which ZTNA as a Service solutions are best for your needs.
872,706 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Computer Software Company
11%
Manufacturing Company
9%
Comms Service Provider
6%
Computer Software Company
18%
Manufacturing Company
10%
Government
6%
Financial Services Firm
6%
Computer Software Company
13%
Financial Services Firm
13%
Manufacturing Company
9%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise6
Large Enterprise5
By reviewers
Company SizeCount
Small Business28
Midsize Enterprise16
Large Enterprise36
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise11
Large Enterprise41
 

Questions from the Community

What needs improvement with iboss?
For zero trust implementation, we encountered complexity issues, especially with a large infrastructure company Exxon...
What is your primary use case for iboss?
Previously when I used iboss, we did the POC for iboss for ExxonMobil. Four or five people wanted to move from our ol...
What is your experience regarding pricing and costs for iboss?
Regarding pricing, setup costs, and licensing, iboss is not cheap, and that's my only concern. There are cheaper alte...
How does Duo Security compare with Microsoft Authenticator?
We switched to Duo Security for identity verification. We’d been using a competitor but got the chance to evaluate Du...
What do you like most about Duo Security?
They are users who, as mentioned before, utilize RDPAP and MDPAP. It includes functionalities related to finance, spe...
What is your experience regarding pricing and costs for Duo Security?
My experience with pricing, setup, costs, and licensing is that I do not get into pricing much; I leave it to procure...
What is the better solution - Prisma Access or Zscaler Private Access?
We looked into Prisma Access before choosing Zscaler Private Access (ZPA). Palo Alto’s Prisma Access is a secure ac...
What do you like most about Zscaler SASE?
The most valuable features of Zscaler Private Access are reliability, scalability, and availability.
What needs improvement with Zscaler SASE?
The solution needs to improve a lot of aspects.
 

Also Known As

iBoss Cloud Platform
Duo Security
Zscaler SASE, Zscaler DLP, Zscaler CASB, Zscaler CSPM, Zscaler Browser Isolation, Zscaler Posture Control
 

Overview

 

Sample Customers

More than 4,000 global enterprises trust the iboss Cloud Platform to support their modern workforces, including a large number of Fortune 50 companies.
Information Not Available
Siemens, AutoNation, GE, NOV
Find out what your peers are saying about Cisco Duo vs. Zscaler Zero Trust Exchange Platform and other solutions. Updated: September 2025.
872,706 professionals have used our research since 2012.