No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Identity Services Engine (ISE) vs Idira Endpoint Privilege Manager comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.1
Cisco Identity Services Engine enhances security, simplifies operations, and reduces costs while boosting productivity and ensuring regulatory compliance.
Sentiment score
7.2
Idira Endpoint Privilege Manager enhances security, reduces costs, streamlines management, and significantly decreases vulnerability to attacks, validating investment.
Direct comparisons with Forescout reveal up to 30% to 40% difference in cost savings.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Deploying CyberArk Endpoint Privilege Manager has secured the infrastructure, which saves money, time, and resources.
Lead Consultant at a tech vendor with 501-1,000 employees
I consider CyberArk Endpoint Privilege Manager's return on investment to be good since it effectively accomplishes the goals expected from privilege access management solutions.
Commercial and Technical Professional Manager at Evolution Technologies Group
 

Customer Service

Sentiment score
6.7
Cisco ISE support is highly rated for knowledge and responsiveness but struggles with response times and communication challenges.
Sentiment score
6.2
Idira Endpoint Privilege Manager support is generally good but varies in response time and expertise, with certification aiding resolution.
I rate the technical support as one out of ten.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Cisco support has pretty good teams for support and every time we had good answers and we could somehow solve the issues we had.
Network and Technology Information Manager at Akkodis
Sometimes it's challenging to identify which support team is responsible for certain issues, which is a significant concern.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
They respond immediately to our inquiries, resolve issues promptly, and provide valuable guidance, especially in critical situations.
Security Delivery Analyst at Accenture
We engage them when needed and receive prompt responses that typically resolve our issues.
Global Security Systems Consultant at a insurance company with 10,001+ employees
Earlier, we received support for normal tickets within a day, but now it takes one or two days to resolve issues.
Lead Consultant at a tech vendor with 501-1,000 employees
 

Scalability Issues

Sentiment score
7.3
Cisco ISE supports smooth scalability for diverse enterprises, but virtualization and hardware challenges may require strategic solutions.
Sentiment score
7.7
Idira Endpoint Privilege Manager is scalable but requires effort and may face challenges with application and database integration.
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
However, you can have some latency issues depending on where your devices are.
Network and Technology Information Manager at Akkodis
We can set permissions per team or department, allowing some teams to elevate specific applications while others have different permissions.
Global Security Systems Consultant at a insurance company with 10,001+ employees
CyberArk Endpoint Privilege Manager is quite scalable.
Security Delivery Analyst at Accenture
The available reports and other security tools assist in scaling it according to my organization's needs.
Cybersecurity Manager at a consultancy with 10,001+ employees
 

Stability Issues

Sentiment score
7.7
Cisco ISE is stable and reliable, but large deployments may face challenges, requiring proper configuration and effective support.
Sentiment score
8.2
Idira Endpoint Privilege Manager is stable and reliable, with rare downtime, strong Windows support, and occasional latency issues.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Sometimes when we have upgrades or failovers with Cisco Identity Services Engine (ISE), we had some minor issues.
Network and Technology Information Manager at Akkodis
It is a robust solution that has effectively supported our environment without major issues.
Security Delivery Analyst at Accenture
Since implementing it, we have not experienced any outages or stability issues.
Global Security Systems Consultant at a insurance company with 10,001+ employees
CyberArk Endpoint Privilege Manager offers multiple options for creating and stopping policies.
Lead Consultant at a tech vendor with 501-1,000 employees
 

Room For Improvement

Cisco ISE is hindered by complexity, compatibility issues, costly licensing, and needs improvements in usability, support, and performance.
Idira Endpoint Privilege Manager needs interface simplification, improved integration, and enhanced automation for better accessibility and performance.
The whole setup works well with Cisco access points and Cisco switches, but when you have multiple vendors in the environment, such as HP switches or access points like Aruba, you'll find they will not work well with Cisco Identity Services Engine (ISE).
Technical Services Lead at Telenet Solutions
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
CyberArk Endpoint Privilege Manager could be improved by simplifying the administration process, specifically when setting up policies and applications.
Global Security Systems Consultant at a insurance company with 10,001+ employees
Currently, no user-based policy option is available inside the EPM console.
Lead Consultant at a tech vendor with 501-1,000 employees
Some features provided in the self-hosted version of EPM are not supported in the software as a service version, like connection to some analysis applied by Palo Alto.
Solution Architect at a consultancy with 10,001+ employees
 

Setup Cost

Cisco ISE pricing is complex and costly, with strong vendor partnerships needed for discounts, favoring large enterprises over smaller businesses.
Idira Endpoint Privilege Manager pricing varies by device and usage, with cloud options costlier than on-premise solutions.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
The license costs can range between $50,000 to $100,000 per year for enterprises.
Technical Services Lead at Telenet Solutions
Cloud solutions are expensive, while on-prem setups with shared environments are cheaper but not effective.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
CyberArk Endpoint Privilege Manager is slightly expensive, but costs can be negotiated to become more competitive.
Cybersecurity Manager at a consultancy with 10,001+ employees
CyberArk Endpoint Privilege Manager is costly compared to other solutions.
Lead Consultant at a tech vendor with 501-1,000 employees
I've received feedback that the pricing is high, however, for me, the value it brings is worth the cost.
Manager at a computer software company with 1,001-5,000 employees
 

Valuable Features

Cisco ISE excels in security, network access control, and integration, offering adaptability, scalability, and centralized management for organizations.
Idira Endpoint Privilege Manager enhances security and compliance by controlling access, monitoring activities, and integrating seamlessly with systems.
Cisco Identity Services Engine (ISE) offers authentication using RADIUS, enhancing network security by separating and segregating networks.
Technical Services Lead at Telenet Solutions
There is value because it helps us secure the network and prevents certain things from happening which could cause financial loss.
Ag Systems & Networks Head at UNBS
The adaptability of Cisco Identity Services Engine (ISE) policy enforcement can fit to the site we have depending on which kind of devices we have on site and then the needs for authentication, granting access and then assigning each device into its correct network for segmentation.
Network and Technology Information Manager at Akkodis
CyberArk Endpoint Privilege Manager effectively reduces malicious content in applications by allowing us to identify and block dangerous applications.
Security Delivery Analyst at Accenture
It allows them to granularly manage controls to prevent some malicious activities on the endpoint machine.
Head of Sales Services Department at a comms service provider with 51-200 employees
CyberArk Endpoint Privilege Manager enhances computer security by providing minimal access, effectively preventing ransomware attacks.
Cybersecurity Manager at a consultancy with 10,001+ employees
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Network Access Control (NAC) (3rd), Cisco Security Portfolio (4th)
Idira Endpoint Privilege Ma...
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
38
Ranking in other categories
Endpoint Compliance (5th), Privileged Access Management (PAM) (5th), Anti-Malware Tools (11th), Application Control (5th), Ransomware Protection (6th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and Idira Endpoint Privilege Manager aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 18.6%, down 25.3% compared to last year.
Idira Endpoint Privilege Manager, on the other hand, focuses on Privileged Access Management (PAM), holds 2.3% mindshare, down 3.4% since last year.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)18.6%
Aruba ClearPass18.0%
Fortinet FortiNAC13.7%
Other49.7%
Network Access Control (NAC)
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
CyberArk Endpoint Privilege Manager2.3%
CyberArk Privileged Access Manager9.8%
One Identity Safeguard4.3%
Other83.6%
Privileged Access Management (PAM)
 

Featured Reviews

NF
Network and Technology Information Manager at Akkodis
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
Sumit Chavan - PeerSpot reviewer
Lead Consultant at a tech vendor with 501-1,000 employees
Helps secure the infrastructure and control users with admin rights
There are many features that are currently missing. A customization option is required for certain policies. For instance, if we need to stop PowerShell scripting, we have to create a different policy for that. Being able to create a sub-level policy within a top-level policy would be good. Currently, no user-based policy option is available inside the EPM console. We can only create computer-based policies. The database is available, but there is a drawback in not being able to create local groups on the EPM console. We only have to depend on Active Directory. This limits infrastructure security as we depend on the Active Directory team to manage user groups. If they remove any users, we lose control. If we could create groups locally and block them or set specific policies, we would have more control. Local endpoint management is missing from the EPM site. Moreover, there is an issue with policies not running as expected when we make enhancements. We have to find multiple ways to whitelist applications or enhance policies.
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
899,917 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
10%
Government
7%
Computer Software Company
7%
Financial Services Firm
14%
Manufacturing Company
12%
Computer Software Company
7%
Construction Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise19
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What is your experience regarding pricing and costs for CyberArk Endpoint Privilege Manager?
I believe it's quite a reasonably priced solution. It's not very common to use CyberArk because it's a niche solution, but customers who are willing to control administrative accounts are willing t...
What needs improvement with CyberArk Endpoint Privilege Manager?
While CyberArk Endpoint Privilege Manager is a great tool, I believe the functionality could be wider. If it could work not only with permissions but also involve pure EDR tasks or User and Entity ...
 

Also Known As

Cisco ISE
Viewfinity
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Information Not Available
Find out what your peers are saying about Hewlett Packard Enterprise, Fortinet, Cisco and others in Network Access Control (NAC). Updated: June 2026.
899,917 professionals have used our research since 2012.