No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Identity Services Engine (ISE) vs Symantec Privileged Access Manager comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Network Access Control (NAC) (2nd), Cisco Security Portfolio (4th)
Symantec Privileged Access ...
Average Rating
7.8
Reviews Sentiment
7.0
Number of Reviews
53
Ranking in other categories
Privileged Access Management (PAM) (15th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and Symantec Privileged Access Manager aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 18.4%, down 24.5% compared to last year.
Symantec Privileged Access Manager, on the other hand, focuses on Privileged Access Management (PAM), holds 1.9% mindshare, up 1.5% since last year.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)18.4%
Aruba ClearPass17.5%
Fortinet FortiNAC11.9%
Other52.2%
Network Access Control (NAC)
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
Symantec Privileged Access Manager1.9%
Idira Privileged Access Manager8.6%
Safeguard by One Identity4.3%
Other85.2%
Privileged Access Management (PAM)
 

Featured Reviews

NF
IT Network Manager at a tech services company with 10,001+ employees
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
Muzi Lubisi - PeerSpot reviewer
Senior technical Consultant at CA Africa
Secure management of sensitive servers and seamless applications with direct linking
The credential injection feature is highly valued, particularly for RDP sessions. A majority of customers use it for RDP, and a couple for Linux servers. The broader capabilities, including access to multiple systems, web-based applications, and clustering, have never posed an issue. The threat analytics aspect is also a robust feature that analyzes all pertinent information.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"TACACS and .1X security are the most valuable features. TACACS acts for user control, so no one can authenticate to our network devices, and .1X is to validate that unauthorized devices are plugged into our network."
"It integrates with the rest of our platform, like our firewall, and helps us a lot. It also does a good job establishing trust for every access request."
"The .1x authentication schema is the most valuable aspect of the solution."
"Before, we had mid-range scores, but over the last couple of years, between implementing ISE and a few other technologies and SIEMs, we've gotten into the 90th percentile with our pen-testing scores."
"If you deploy it with the correct policies, it's a wonderful product."
"I like the guest access feature, which has been important for us."
"Stable network administration solution that can be installed easily, and comes with fast technical support."
"Cisco has implemented a special ATC partner program to help partners and customers to have a smooth deployment."
"It reduces the viral attacks on my website. It also allows certain users access to see what happens daily."
"One of the most valuable items is the load balancing feature."
"We can check the activities in the server for fragile files and documents in case of any issues."
"The best features are the comprehensive coverage of the required features for the PAM solution like a credential vault, a session recording, an endpoint agent, security analytics."
"Monitoring privileged users’ actions is valuable because of the high level of trust and wide-ranging access insiders typically enjoy."
"The solution has the capability to address hybrid eco-systems, both on-premises and cloud services, and integration with the AD RBAC model is also a great feature, as we can tie it to the central repository."
"The DB clustering is a really good benefit of using CA PAM."
"The most important feature is that we do not need to know the passwords any more; just having access to the end point; and that it’s easy to manage users and the account."
 

Cons

"The knocks I have against the product are the number of bugs that we encounter, constantly, and the amount of upgrading that we have to do."
"Setup wasn't easy, especially if you haven’t worked with it intensively."
"Since we have started, we struggled a lot to implement this solution into our network, and we opened a case a couple of times. Up until this point, nothing else needs to be improved with this product."
"I would like the product to include support for OSVS version three."
"An area that could be improved is the agent. The challenge now is that agent and most of the computers have changed. They could think about agent-less deployment."
"The primary issue is the slowness of the application and the web interface. We have multiple admin nodes and app nodes. So when I need to get some information about a particular user, the GUI would take ten to fifteen seconds in loading when we need to know right away."
"Cisco ISE has almost all the features we are looking for now, but sometimes the configuration, such as the conditions, is a little difficult to understand and not so easy to navigate."
"Technical support has been okay, but I wouldn't describe it as "very good." We have had some problems with technical support."
"They need to do a little bit more on the mainframe side.​"
"The user interface and dependence on applets and Windows could use some improvement."
"We had some issues with the load balancing feature when configured for clustering."
"The first setup was complex. The implementation, to me, was very bad."
"Instead of just giving passwords to the user based on job function, from auditing perspective, turn that cycle around. That would really help from an auditing standpoint."
"I believe continued expansion of integration to multiple systems including SSO and SAML technologies will provide a more-expansive, enterprise view of access orchestration, which will in turn strengthen the security of the environment."
"The OOTB reporting functionality is lacking."
"When there are new patches or upgrades, they need to test the new release well so it will not break the functional parts."
 

Pricing and Cost Advice

"The pricing is good. The last time we purchased four new appliances the price was doable for any organization of our size."
"Being fully honest, the Cisco licensing model right now is really confusing. We don't know what licenses we have where. We have Smart licensing, but the different levels are way confusing."
"Pricing and licensing are not my expertise. As far as budgeting is concerned, we run an ELA with Cisco. It's a part of our ELA."
"I would rate the pricing an eight out of ten, one being cheap and ten being expensive."
"Licensing has got much simpler since Cisco moved to the DNA model because we just have the three tiers, but it could always stand to be improved upon."
"The technology is good, but to use some of the other features, and capabilities, they request that we purchase the Cisco DNA Center. As a result, the bundled price is a little high."
"The solution is not that cheap."
"It is fair."
"It is more expensive than other solutions on the market."
"Pricing is fair compared to other top vendors."
"Don’t go with an agent model. Don’t go with a model that has you buying a thousand different parts. Go with PAM that gives you everything, or you’ll just be paying costs of implementing another tool that PAM would have just given you up front."
"Appliances are relatively cheap, don’t skimp. Make sure you have redundancy, high availability, and enough appliances to manage the concurrent workload."
"The version we are using is affordable compared to BeyondTrust, which is maybe three to four times as expensive, but it depends on the features."
"They offer per-device, per-user, or monthly and yearly licensing models."
"The licensing is simple and scalable."
"It is reasonably priced."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
914,262 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
10%
Outsourcing Company
9%
Comms Service Provider
7%
Outsourcing Company
21%
Construction Company
13%
Comms Service Provider
6%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise30
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What is your experience regarding pricing and costs for Symantec Privileged Access Manager?
Due to the nature of the solution, it is hard to gauge, but compared to competitors, the pricing is very good. I would rate it as an eight and a half out of ten.
What needs improvement with Symantec Privileged Access Manager?
Recent releases need improvement in webpage management. For instance, navigating through a webpage that acts like a wizard, where I proceed to the next page and enter more information, is not handl...
What is your primary use case for Symantec Privileged Access Manager?
With the customers that I have so far, I help them broker RDP sessions to sensitive servers, particularly those that manage aspects like physical access. I have also done it for backend databases, ...
 

Also Known As

Cisco ISE
CA PAM, Xceedium Xsuite, CA Privileged Access Manager
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
NEOVERA, Telesis, eSoft
Find out what your peers are saying about Hewlett Packard Enterprise, Cisco, ThreatLocker and others in Network Access Control (NAC). Updated: September 2026.
914,262 professionals have used our research since 2012.