No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Identity Services Engine (ISE) vs ForgeRock comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.1
Cisco Identity Services Engine enhances security, simplifies operations, and reduces costs while boosting productivity and ensuring regulatory compliance.
Sentiment score
5.2
ForgeRock enhanced market efficiency, security, and customer trust, reducing staffing needs and improving time to market without exact ROI figures.
Direct comparisons with Forescout reveal up to 30% to 40% difference in cost savings.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
On a B2B level, it opened up the market for TomTom to sell its services in a more efficient way to car companies.
Principal Consultant at Road2Value
We can use a Linux image from ForgeRock with different systems, applications, websites, and mobile apps to create various types of access for users.
Assistant Architect at a energy/utilities company with 501-1,000 employees
I can definitely see that fewer employees are needed compared to using different SaaS applications.
Identity and Access Management Specialist at a university with 10,001+ employees
 

Customer Service

Sentiment score
6.7
Cisco ISE support is highly rated for knowledge and responsiveness but struggles with response times and communication challenges.
Sentiment score
5.8
ForgeRock customer service is flexible and responsive, but improvements are needed for professional services and ticket resolution speed.
I rate the technical support as one out of ten.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Cisco support has pretty good teams for support and every time we had good answers and we could somehow solve the issues we had.
Network and Technology Information Manager at Akkodis
Sometimes it's challenging to identify which support team is responsible for certain issues, which is a significant concern.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
The support portals offer comprehensive documentation, troubleshooting guides, and community forums that have been helpful for resolving common issues independently.
Software Engineer at a financial services firm with 10,001+ employees
For standard support tickets, response times were very decent, and the support team was helpful in identifying configuration issues, especially with authentication trees, token settings, and directory replications.
Identity and Access Management Specialist at a university with 10,001+ employees
The team is very responsive and takes a sense of ownership and accountability.
Principal Consultant at Road2Value
 

Scalability Issues

Sentiment score
7.3
Cisco ISE supports smooth scalability for diverse enterprises, but virtualization and hardware challenges may require strategic solutions.
Sentiment score
7.3
ForgeRock offers scalable solutions for diverse enterprises, supporting seamless expansion, efficient administration, and integration across multiple environments.
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
However, you can have some latency issues depending on where your devices are.
Network and Technology Information Manager at Akkodis
The access management layer is stateless, so I can scale horizontally by adding more nodes behind a load balancer as traffic increases.
Identity and Access Management Specialist at a university with 10,001+ employees
The platform provides flexible authentication trees, enabling us to design custom MFA flows tailored for different user groups and risk profiles.
Software Engineer at a financial services firm with 10,001+ employees
We scaled up with ForgeRock. My team received an award for implementing it for a 60 million customer base, which was the largest implementation at that time.
Principal Consultant at Road2Value
 

Stability Issues

Sentiment score
7.7
Cisco ISE is stable and reliable, but large deployments may face challenges, requiring proper configuration and effective support.
Sentiment score
7.3
ForgeRock is stable and reliable, though customization affects stability, with users rating it seven to nine out of ten.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Sometimes when we have upgrades or failovers with Cisco Identity Services Engine (ISE), we had some minor issues.
Network and Technology Information Manager at Akkodis
ForgeRock supports integration with legacy systems in our organization by offering a wide range of connectors and APIs.
Software Engineer at a financial services firm with 10,001+ employees
ForgeRock is very stable because it manages access, authentication, and authorization effectively.
Assistant Architect at a energy/utilities company with 501-1,000 employees
 

Room For Improvement

Cisco ISE is hindered by complexity, compatibility issues, costly licensing, and needs improvements in usability, support, and performance.
ForgeRock users suggest improving documentation, UI, DevOps support, onboarding, and training for better customization and admin experience.
The whole setup works well with Cisco access points and Cisco switches, but when you have multiple vendors in the environment, such as HP switches or access points like Aruba, you'll find they will not work well with Cisco Identity Services Engine (ISE).
Technical Services Lead at Telenet Solutions
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
ForgeRock needs to focus on low-code, no-code solutions that allow for drag-and-drop functionality with good orchestration.
CIAM Engineer at a tech vendor with 10,001+ employees
It would be better if they were available for support whenever the customer needs it, especially during migration or go-live time periods.
IAM Solution Architect at a tech services company with 1-10 employees
The main area is complexity. ForgeRock is extremely flexible, but the learning curve can be steep.
Identity and Access Management Specialist at a university with 10,001+ employees
 

Setup Cost

Cisco ISE pricing is complex and costly, with strong vendor partnerships needed for discounts, favoring large enterprises over smaller businesses.
ForgeRock offers flexible pricing with community and enterprise options, seen as fair, supporting various features and open-source choices.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
The license costs can range between $50,000 to $100,000 per year for enterprises.
Technical Services Lead at Telenet Solutions
Cloud solutions are expensive, while on-prem setups with shared environments are cheaper but not effective.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
One has to spend considerable time trying to understand the different modules and different needs for those modules on the licensing front.
Principal Consultant at Road2Value
 

Valuable Features

Cisco ISE excels in security, network access control, and integration, offering adaptability, scalability, and centralized management for organizations.
ForgeRock offers flexible authentication, scalability, and DevOps support with strong API integration, enhancing security and operational efficiency.
Cisco Identity Services Engine (ISE) offers authentication using RADIUS, enhancing network security by separating and segregating networks.
Technical Services Lead at Telenet Solutions
There is value because it helps us secure the network and prevents certain things from happening which could cause financial loss.
Ag Systems & Networks Head at UNBS
The adaptability of Cisco Identity Services Engine (ISE) policy enforcement can fit to the site we have depending on which kind of devices we have on site and then the needs for authentication, granting access and then assigning each device into its correct network for segmentation.
Network and Technology Information Manager at Akkodis
Centralized management makes the biggest difference because it allows us to define, update, and enforce security and compliance rules from a single location.
Software Engineer at a financial services firm with 10,001+ employees
ForgeRock positively impacts our organization as we manage a large number of users with ease, providing a standard IAM solution that simplifies our processes.
CIAM Engineer at a tech vendor with 10,001+ employees
ForgeRock has positively impacted my organization by allowing us to migrate from the older system to the newer ForgeRock component, enabling us to go live with many products across geographies, enhancing security as it is all cloud-based, and with the company taking care of availability, it has reduced costs for the company.
IAM CONSULTANT at a tech services company with 10,001+ employees
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Network Access Control (NAC) (3rd), Cisco Security Portfolio (4th)
ForgeRock
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
37
Ranking in other categories
Identity Management (IM) (10th), Access Management (8th), Customer Identity and Access Management (CIAM) (4th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and ForgeRock aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 18.6%, down 25.3% compared to last year.
ForgeRock, on the other hand, focuses on Access Management, holds 4.2% mindshare, down 6.6% since last year.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)18.6%
Aruba ClearPass18.0%
Fortinet FortiNAC13.7%
Other49.7%
Network Access Control (NAC)
Access Management Mindshare Distribution
ProductMindshare (%)
ForgeRock4.2%
Microsoft Entra ID12.1%
Okta Platform11.1%
Other72.6%
Access Management
 

Featured Reviews

NF
Network and Technology Information Manager at Akkodis
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
SR
Software Engineer at a financial services firm with 10,001+ employees
Centralized access control has improved secure onboarding and supports strict compliance
I wish we had used ForgeRock's adaptive risk-based authentication, which allows dynamic adjustment of authentication requirements based on user behavior. This could have helped us further strengthen our security. Another hidden gem is the built-in support for custom authentication modules and scripting, which gives a great deal of flexibility to tailor authentication flows. The self-service capabilities for password resets and account recovery have been very helpful in reducing support overhead and improving user experience. Discovering and utilizing these features would have definitely made our integration even smoother and would have provided additional value for both our users and our security team. One area of improvement would be the user interface for policy and workflow configuration, which can become complex and sometimes unintuitive, especially for new administrators. A more streamlined and user-friendly UI would help reduce the learning curve. Enhanced out-of-the-box analytics and reporting would also be valuable, as our current options often require custom development or integration with external tools. While extensibility is a strength, documentation for advanced customizations and integrations could be more comprehensive and easier to follow. Improved support for seamless upgrades and backward compatibility would also help minimize downtime. In terms of performance, optimizing the platform for high concurrency environments would be beneficial, especially for organizations with large user bases or peak usage periods. Enhanced scalability features such as more granular or horizontal scaling options would provide better support for distributed deployments. For integrations, having more pre-built connectors and easy integration with modern cloud-native services would accelerate adoption. Improved monitoring and real-time health dashboards would help proactively identify and resolve performance bottlenecks.
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
902,456 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
10%
Government
7%
Computer Software Company
7%
Financial Services Firm
20%
Manufacturing Company
7%
Computer Software Company
6%
Construction Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise5
Large Enterprise18
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What is your experience regarding pricing and costs for ForgeRock?
The pricing, setup cost, and licensing are very straightforward, which is a good success. I appreciate that it is very straightforward and helpful.
What needs improvement with ForgeRock?
There are some areas I want ForgeRock to improve. These areas include policy configuration, documentation clarity, UI complexity, and debugging token flow. I want ForgeRock to improve in documentat...
What is your primary use case for ForgeRock?
I am using ForgeRock for standard support, policy configurations, and documentation clarity. The pricing, setup cost, and licensing are very straightforward, which is a good success. I appreciate t...
 

Also Known As

Cisco ISE
ForgeRock Identity Platform, ForgeRock OpenIDM
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Geico, Thomson Reuters, Salesforce, McKesson, Trinet, SKY, BNP Paribas, Deloitte, Capgemini, North Western University
Find out what your peers are saying about Hewlett Packard Enterprise, Fortinet, Cisco and others in Network Access Control (NAC). Updated: June 2026.
902,456 professionals have used our research since 2012.