No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon vs Saviynt Identity Cloud comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
117
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
CrowdStrike Falcon
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
174
Ranking in other categories
Endpoint Protection Platform (EPP) (3rd), Endpoint Detection and Response (EDR) (2nd)
Saviynt Identity Cloud
Average Rating
7.4
Reviews Sentiment
6.2
Number of Reviews
28
Ranking in other categories
Identity Management (IM) (14th), Privileged Access Management (PAM) (14th), Access Management (16th), Non-Human Identity Management (NHIM) (8th), Identity Security and Posture Management (ISPM) (1st), Identity Governance Administration (IGA) (4th)
 

Mindshare comparison

Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon5.7%
Microsoft Defender for Endpoint6.5%
SentinelOne Singularity Endpoint4.5%
Other83.3%
Endpoint Protection Platform (EPP)
Identity Governance Administration (IGA) Mindshare Distribution
ProductMindshare (%)
Saviynt Identity Cloud14.8%
SailPoint Identity Security Cloud25.9%
Identity Manager by One Identity11.3%
Other48.0%
Identity Governance Administration (IGA)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
JW
Senior Security Engineer at a financial services firm with 10,001+ employees
Centralized endpoint protection has strengthened compliance and accelerated incident response
There are a number of areas that I only touch a handful of times, but when I get in there, I realize why I don't do that. The main area would be within the support area. The support bot is not really as smart as you would expect it, especially in this day and age of LLM and other capabilities that I know CrowdStrike Falcon is already capable of doing. Additionally, I would appreciate a little bit more easy to read insights of some of the dashboards or maybe manipulation of the dashboards. It is still a little cumbersome to build custom dashboards and it's not as intuitive as you would think. Documentation is abysmal and needs to be improved dramatically. I know that there's a big effort to do this, however, even the new effort is honestly worse than it was before. Those are definitely major areas of improvement, just more in the usability of the features.
reviewer2774067 - PeerSpot reviewer
Software Engineer at a tech consulting company with 11-50 employees
Has reduced manual work and shortened project timelines through faster deployment and intuitive workflows
One of the challenges regarding Saviynt is the lack of material available on the web, as searching on Google or YouTube often yields little information. Advertising Saviynt is necessary because I was not aware of it a couple of months ago, and it is a very helpful product for many organizations. In India, IGA solutions are not widely recognized, and Saviynt can utilize this point by promoting itself in the cybersecurity field. A significant challenge is the lack of people discussing Saviynt in the open market, as the forums provide slower responses compared to platforms like Reddit. Advancements related to AI would be very helpful. Saviynt should provide pricing for their university certifications, which is currently not publicly available. Information about enrolling requires an ID that is not easily obtained, as it can only be acquired through an organization. Some small wishlist features are related to APIs. As I work on projects, I find certain features to be much needed, but at a glance, they may not seem necessary. As I continue working with Saviynt, these small API-related features become apparent and would greatly enhance the experience.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We switched because there were a lot of added features with Palo Alto that Check Point didn't have, and it was an upgrade for us."
"Palo Alto Networks Traps improves our security posture and lowers risk by providing next-gen methods to combat against modern threats on all the major platforms."
"Stability is one of the features we like the most."
"The tool is easy to use."
"After installing this solution, it identified, blocked, and provided the complete attack chain, which was very helpful."
"We use it for malicious connections from malicious websites, to identify payloads that might be inside the traffic, to identify malicious processes or bugs that are running on the network, and any activities that tend to lead to data infiltration."
"It is easy to use."
"We use Cortex XDR by Palo Alto Networks for its ability to detect based on behavior rather than simple virus scan to prevent malicious activities."
"The feature that I find to be the most valuable, is being able to look at the system analysis and being able to baseline what is installed on the system."
"Falcon's best feature is its detection and blocking of threats."
"CrowdStrike Falcon has positively impacted my organization by providing good protection, logs, and reports, which I find very good."
"The product is really good, but there is a lot of additional features that you need to have for it to be a complete solution."
"We use it to monitor everything related to the activity and to block any malicious activity."
"My advice to others looking into using CrowdStrike Falcon is to not look at anything else and to use it instead."
"Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because it gives us a lot of granularity on what goes on, what processes are being run, and what is actually being executed if anyone is trying to get onto our endpoints."
"CrowdStrike Falcon serves as a next-gen AV, which basically does AI-based behavioral analysis to detect and act on malware or ransomware."
"The product's initial setup phase is easy."
"It's overall a good thing to have everything consolidated in one place."
"Some of the self-service capabilities are quite powerful."
"Saviynt is superior because it is user-friendly, and their fundamental phenomena are no-code, low-code, which means no customization is needed for the implementation part."
"It is a flexible tool because it works on JSON."
"The most valuable features of Saviynt are database utility and report generation. These two features have a major impact, particularly when you are trying to create a report because, in other systems, you need to use a third-party utility such as a BI tool or any other reporting tool to fetch the data and send out the report to a third party team. In Saviynt, it's a system within a system, so you don't have to use any third-party tool because you can directly do your query and write that code on Saviynt and then send that report to the team."
"It's a highly functional system and a very well rounded solution."
"It gives very good and in-depth knowledge about a particular identity, and everything is through a single click, so we get to know the workflows related to a particular identity with a single click."
 

Cons

"The product's pricing needs improvement. They could provide more discounts. Additionally, the dashboard and control panel could be enhanced."
"It takes time to scan the servers and devices."
"This is a very costly product."
"Cortex XDR could be improved with more GUI features."
"Cortex XDR by Palo Alto Networks can improve mobile integration to allow access to the console."
"For Cortex XDR by Palo Alto Networks, if I had to point out improvements, I would say the UI is still somewhat difficult for beginners."
"There are some limitations on the Traps agents."
"It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control. Currently, Cortex is good in terms of the security of the endpoints, but it is not as good as other vendors in terms of the management of the endpoint."
"The main complaint that myself and leadership have about CrowdStrike Falcon is that the cost has become expensive compared to competitors."
"On the firewall management side, there should be more granularity. There should also be more granularity for device control. Everything else is brilliant."
"I'm concerned about the recent issue that involved a faulty update."
"The ability to receive text alerts natively in the console would be kind of cool."
"The technical support team often just replies to an issue with a link to an article rather than actually calling back and talking to someone and making sure the problem is solved. To me, that's kind of weak."
"A year and a half ago or more, if you put in a support request by email, then it wasn't timely addressed. It could be a day to three days before you received a response, which was a bit frustrating. There was a lot of customer feedback around this issue, which has been greatly refined."
"We encounter occasional issues, such as when disabling network access for a host that uses CrowdStrike."
"The current database schema presents challenges and has potential for improvement."
"The biggest drawback is that for every change you want to make, you have to go back to them and ask for it."
"It should support more customizations. In SailPoint, we can do many customizations, but we are not able to do that in Saviynt. For workflows and other things, we can only use what is already in place. Saviynt has a lot of scope for improvement on the customization part."
"The UI doesn’t enhance the user experience."
"One of the challenges regarding Saviynt is the lack of material available on the web, as searching on Google or YouTube often yields little information."
"The solution does not work very well as the number of users increases."
"Both SailPoint IdentityNow and Saviynt have some bugs, but SailPoint is considered more mature with fewer bugs due to its longer establishment in the market since around 2005. SailPoint had its share of bugs in the early days, but they have resolved them over time, resulting in a stable product. Saviynt, on the other hand, was launched around 2013 or 2014 and is actively working to improve its product. Despite having some bugs, Saviynt is making progress and aims to build a stable product, but it is not there yet."
"Saviynt cannot customize based on customer needs."
"On a scale from one to ten (where one is the worst and ten is the best), I would rate my experience with Saviynt so far as maybe only a four-out-of-ten."
 

Pricing and Cost Advice

"The price was fine."
"It's about $55 per license on a yearly basis."
"I don't have any issues with the pricing. We are satisfied with the price."
"This is an expensive solution."
"Very costly product."
"I am using the Community edition."
"Cortex XDR by Palo Alto Networks is quite an expensive solution."
"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"The pricing and licensing are reasonable. I don't think we are getting charged more than what it is worth. It is fair, but I do not like how it is a la carte. I realize they do that so other organizations can buy and get the agent, getting it cheaper than you could otherwise. However, if you want the main core package, which has all the main features with the exception of maybe the multi-cloud protections, that can get pricier for an organization. So, you have to pick and choose what you want. I do not care for a la carte pricing."
"It is expensive compared to SentinelOne, but as the market leader, it is worth it."
"Our licensing fees were between $50,000 and $60,000 per year, which was pretty expensive for a small business."
"In my opinion, the pricing of CrowdStrike Falcon seems aggressive."
"I do not have experience with the cost or licensing of the product."
"CrowdStrike Falcon's price is good."
"The product is expensive."
"All I can say about the licensing cost is that it's negotiable."
"The pricing is comparable to Azure Entra ID. Kind of the same"
"Saviynt's pricing is acceptable and licensing costs are yearly."
"Saviynt has a competitive price."
"If you need to make any changes then there are additional fees."
"The price of the license for this product is quite expensive."
"We are not into the licensing part. The clients take care of the licensing part."
"The product is less expensive than one of the competitors."
"The solution has a pay-as-you-go licensing model, and you can subscribe monthly or yearly."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
912,517 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
10%
Financial Services Firm
10%
Manufacturing Company
9%
Outsourcing Company
9%
Computer Software Company
8%
Financial Services Firm
14%
Manufacturing Company
8%
Educational Organization
8%
Outsourcing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business58
Midsize Enterprise46
Large Enterprise83
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise15
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
Is Crowdstrike Falcon better than Trend Micro Deep Security?
I like that Crowdstrike allows me to easily correlate data between my firewalls. What’s most useful for my needs is t...
What is your experience regarding pricing and costs for Saviynt?
Saviynt is very affordable compared to its competitors. It is cloud-based, making it significantly cheaper than on-pr...
What needs improvement with Saviynt?
When you ask about any drawbacks or downsides in Saviynt Identity Cloud, one very interesting point that I observe is...
What is your primary use case for Saviynt?
I would like to discuss the use case. Saviynt Identity Cloud is primarily used for identity management and access gov...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Shell, McKesson, Kimberly-Clark, Ingram Micro, Intermountain Health Care, Forterra, CoreLogic
Find out what your peers are saying about Microsoft, SentinelOne, CrowdStrike and others in Endpoint Protection Platform (EPP). Updated: September 2026.
912,517 professionals have used our research since 2012.