No more typing reviews! Try our Samantha, our new voice AI agent.

CyberArk Endpoint Privilege Manager vs ForgeRock comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.2
CyberArk Endpoint Privilege Manager enhances security, reduces risks and costs, saves resources, and protects sensitive information effectively.
Sentiment score
5.2
ForgeRock enhanced market efficiency, security, and customer trust, reducing staffing needs and improving time to market without exact ROI figures.
Deploying CyberArk Endpoint Privilege Manager has secured the infrastructure, which saves money, time, and resources.
Lead Consultant at a tech vendor with 501-1,000 employees
I consider CyberArk Endpoint Privilege Manager's return on investment to be good since it effectively accomplishes the goals expected from privilege access management solutions.
Commercial and Technical Professional Manager at Evolution Technologies Group
On a B2B level, it opened up the market for TomTom to sell its services in a more efficient way to car companies.
Principal Consultant at Road2Value
We can use a Linux image from ForgeRock with different systems, applications, websites, and mobile apps to create various types of access for users.
Assistant Architect at a energy/utilities company with 501-1,000 employees
I can definitely see that fewer employees are needed compared to using different SaaS applications.
Identity and Access Management Specialist at a university with 10,001+ employees
 

Customer Service

Sentiment score
6.2
CyberArk Endpoint Privilege Manager support is knowledgeable but needs improvements in response times, accessibility, and first-level assistance.
Sentiment score
5.8
ForgeRock customer service is flexible and responsive, but improvements are needed for professional services and ticket resolution speed.
They respond immediately to our inquiries, resolve issues promptly, and provide valuable guidance, especially in critical situations.
Security Delivery Analyst at Accenture
We engage them when needed and receive prompt responses that typically resolve our issues.
Global Security Systems Consultant at a insurance company with 10,001+ employees
Earlier, we received support for normal tickets within a day, but now it takes one or two days to resolve issues.
Lead Consultant at a tech vendor with 501-1,000 employees
The support portals offer comprehensive documentation, troubleshooting guides, and community forums that have been helpful for resolving common issues independently.
Software Engineer at a financial services firm with 10,001+ employees
For standard support tickets, response times were very decent, and the support team was helpful in identifying configuration issues, especially with authentication trees, token settings, and directory replications.
Identity and Access Management Specialist at a university with 10,001+ employees
The customer support is very flexible and supportive, particularly in the area of automation and customer deployments.
Cybersecurity Consultant at Nnamdi Azikiwe University
 

Scalability Issues

Sentiment score
7.7
CyberArk Endpoint Privilege Manager efficiently scales for large deployments, praised for growth-centered architecture despite integration complexities.
Sentiment score
7.3
ForgeRock offers scalable solutions for diverse enterprises, supporting seamless expansion, efficient administration, and integration across multiple environments.
We can set permissions per team or department, allowing some teams to elevate specific applications while others have different permissions.
Global Security Systems Consultant at a insurance company with 10,001+ employees
CyberArk Endpoint Privilege Manager is quite scalable.
Security Delivery Analyst at Accenture
The available reports and other security tools assist in scaling it according to my organization's needs.
Cybersecurity Manager at a consultancy with 10,001+ employees
The access management layer is stateless, so I can scale horizontally by adding more nodes behind a load balancer as traffic increases.
Identity and Access Management Specialist at a university with 10,001+ employees
The platform provides flexible authentication trees, enabling us to design custom MFA flows tailored for different user groups and risk profiles.
Software Engineer at a financial services firm with 10,001+ employees
We scaled up with ForgeRock. My team received an award for implementing it for a 60 million customer base, which was the largest implementation at that time.
Principal Consultant at Road2Value
 

Stability Issues

Sentiment score
8.2
CyberArk Endpoint Privilege Manager is stable, with 99.99% uptime, reliable on Windows, needing console improvements and minimal memory.
Sentiment score
7.3
ForgeRock is stable and reliable, though customization affects stability, with users rating it seven to nine out of ten.
It is a robust solution that has effectively supported our environment without major issues.
Security Delivery Analyst at Accenture
Since implementing it, we have not experienced any outages or stability issues.
Global Security Systems Consultant at a insurance company with 10,001+ employees
CyberArk Endpoint Privilege Manager offers multiple options for creating and stopping policies.
Lead Consultant at a tech vendor with 501-1,000 employees
ForgeRock supports integration with legacy systems in our organization by offering a wide range of connectors and APIs.
Software Engineer at a financial services firm with 10,001+ employees
ForgeRock is very stable because it manages access, authentication, and authorization effectively.
Assistant Architect at a energy/utilities company with 501-1,000 employees
 

Room For Improvement

CyberArk Endpoint Privilege Manager needs improved integration, user interface, and pricing, along with enhanced compatibility and functionality.
ForgeRock users suggest improving documentation, UI, DevOps support, onboarding, and training for better customization and admin experience.
CyberArk Endpoint Privilege Manager could be improved by simplifying the administration process, specifically when setting up policies and applications.
Global Security Systems Consultant at a insurance company with 10,001+ employees
Currently, no user-based policy option is available inside the EPM console.
Lead Consultant at a tech vendor with 501-1,000 employees
Some features provided in the self-hosted version of EPM are not supported in the software as a service version, like connection to some analysis applied by Palo Alto.
Solution Architect at a consultancy with 10,001+ employees
ForgeRock needs to focus on low-code, no-code solutions that allow for drag-and-drop functionality with good orchestration.
CIAM Engineer at a tech vendor with 10,001+ employees
It would be better if they were available for support whenever the customer needs it, especially during migration or go-live time periods.
IAM Solution Architect at a tech services company with 1-10 employees
The main area is complexity. ForgeRock is extremely flexible, but the learning curve can be steep.
Identity and Access Management Specialist at a university with 10,001+ employees
 

Setup Cost

CyberArk Endpoint Privilege Manager's high pricing is justified by its quality, features, and appeal to large enterprises in finance.
ForgeRock offers flexible pricing with community and enterprise options, seen as fair, supporting various features and open-source choices.
CyberArk Endpoint Privilege Manager is slightly expensive, but costs can be negotiated to become more competitive.
Cybersecurity Manager at a consultancy with 10,001+ employees
CyberArk Endpoint Privilege Manager is costly compared to other solutions.
Lead Consultant at a tech vendor with 501-1,000 employees
I've received feedback that the pricing is high, however, for me, the value it brings is worth the cost.
Manager at a computer software company with 1,001-5,000 employees
The pricing, setup cost, and licensing are very straightforward, which is a good success.
Cybersecurity Consultant at Nnamdi Azikiwe University
One has to spend considerable time trying to understand the different modules and different needs for those modules on the licensing front.
Principal Consultant at Road2Value
 

Valuable Features

CyberArk Endpoint Privilege Manager enhances security by managing privileges, integrating seamlessly, and preventing ransomware while ensuring regulatory compliance.
ForgeRock offers flexible authentication, scalability, and DevOps support with strong API integration, enhancing security and operational efficiency.
CyberArk Endpoint Privilege Manager effectively reduces malicious content in applications by allowing us to identify and block dangerous applications.
Security Delivery Analyst at Accenture
It allows them to granularly manage controls to prevent some malicious activities on the endpoint machine.
Head of Sales Services Department at a comms service provider with 51-200 employees
CyberArk Endpoint Privilege Manager enhances computer security by providing minimal access, effectively preventing ransomware attacks.
Cybersecurity Manager at a consultancy with 10,001+ employees
Centralized management makes the biggest difference because it allows us to define, update, and enforce security and compliance rules from a single location.
Software Engineer at a financial services firm with 10,001+ employees
ForgeRock positively impacts our organization as we manage a large number of users with ease, providing a standard IAM solution that simplifies our processes.
CIAM Engineer at a tech vendor with 10,001+ employees
ForgeRock has positively impacted my organization by allowing us to migrate from the older system to the newer ForgeRock component, enabling us to go live with many products across geographies, enhancing security as it is all cloud-based, and with the company taking care of availability, it has reduced costs for the company.
IAM CONSULTANT at a tech services company with 10,001+ employees
 

Categories and Ranking

CyberArk Endpoint Privilege...
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
38
Ranking in other categories
Endpoint Compliance (5th), Privileged Access Management (PAM) (4th), Anti-Malware Tools (5th), Application Control (3rd), Ransomware Protection (3rd)
ForgeRock
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
38
Ranking in other categories
Identity Management (IM) (9th), Access Management (8th), Customer Identity and Access Management (CIAM) (4th)
 

Mindshare comparison

While both are Identity and Access Management solutions, they serve different purposes. CyberArk Endpoint Privilege Manager is designed for Privileged Access Management (PAM) and holds a mindshare of 2.4%, down 3.6% compared to last year.
ForgeRock, on the other hand, focuses on Access Management, holds 4.5% mindshare, down 6.6% since last year.
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
CyberArk Endpoint Privilege Manager2.4%
CyberArk Privileged Access Manager10.4%
Delinea Secret Server4.5%
Other82.7%
Privileged Access Management (PAM)
Access Management Mindshare Distribution
ProductMindshare (%)
ForgeRock4.5%
Microsoft Entra ID12.9%
Okta Platform11.4%
Other71.2%
Access Management
 

Featured Reviews

DR
Commercial and Technical Professional Manager at Evolution Technologies Group
Strengthening financial services infrastructure by safeguarding and integrating with ecosystems
We use CyberArk Endpoint Privilege Manager to complement a privilege access management solution in order to avoid golden ticket attacks and strengthen services against attacks. It serves as a complement to our asset management solution. The architecture of CyberArk Endpoint Privilege Manager is beneficial for integrating with all customer ecosystems; it's easy to deploy, and achieving that level of integration and control is more challenging with other solutions. The ability of CyberArk Endpoint Privilege Manager to safeguard our financial services infrastructure is very important, as we need to record actions on privileges in our information systems. Regarding the granularity of the managed controls in CyberArk Endpoint Privilege Manager, we have different levels of features to define compensations and capabilities, which help us verify configurations and access, ultimately keeping the safety of rights intact. Our initial challenge with CyberArk Endpoint Privilege Manager is to comply with Colombian regulations in the financial sector, particularly identifying users and managing password changes and rotations. We needed to certify the identities and provide necessary information for government investigations, if required. CyberArk Endpoint Privilege Manager is very important for helping our organization meet compliance and regulatory requirements. We have to comply with international regulations such as SOC, but also with local regulations unique to the financial sector, which is crucial for us due to the high risks involved. CyberArk Endpoint Privilege Manager helped us reduce the time for regulatory processes to approximately two to four months, completing the solution and training. CyberArk Endpoint Privilege Manager has helped us reduce the mean time to detect within our organization. That's our main goal. Regarding MTTD, the solution provides enough information to enhance our overall detection process. We have an 85% improvement in MTTD. CyberArk Endpoint Privilege Manager helps ensure data privacy through strategies that manage information in real-time. CyberArk Endpoint Privilege Manager helps save costs by avoiding risks and future expenses associated with security incidents. It's essential to communicate the value of CyberArk Endpoint Privilege Manager to users, as its controls help improve system security. My role at the company involves service and sales activities.
SR
Software Engineer at a financial services firm with 10,001+ employees
Centralized access control has improved secure onboarding and supports strict compliance
I wish we had used ForgeRock's adaptive risk-based authentication, which allows dynamic adjustment of authentication requirements based on user behavior. This could have helped us further strengthen our security. Another hidden gem is the built-in support for custom authentication modules and scripting, which gives a great deal of flexibility to tailor authentication flows. The self-service capabilities for password resets and account recovery have been very helpful in reducing support overhead and improving user experience. Discovering and utilizing these features would have definitely made our integration even smoother and would have provided additional value for both our users and our security team. One area of improvement would be the user interface for policy and workflow configuration, which can become complex and sometimes unintuitive, especially for new administrators. A more streamlined and user-friendly UI would help reduce the learning curve. Enhanced out-of-the-box analytics and reporting would also be valuable, as our current options often require custom development or integration with external tools. While extensibility is a strength, documentation for advanced customizations and integrations could be more comprehensive and easier to follow. Improved support for seamless upgrades and backward compatibility would also help minimize downtime. In terms of performance, optimizing the platform for high concurrency environments would be beneficial, especially for organizations with large user bases or peak usage periods. Enhanced scalability features such as more granular or horizontal scaling options would provide better support for distributed deployments. For integrations, having more pre-built connectors and easy integration with modern cloud-native services would accelerate adoption. Improved monitoring and real-time health dashboards would help proactively identify and resolve performance bottlenecks.
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
893,311 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Manufacturing Company
11%
Computer Software Company
7%
Government
7%
Financial Services Firm
20%
Computer Software Company
6%
Manufacturing Company
6%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise18
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise5
Large Enterprise18
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What do you like most about CyberArk Endpoint Privilege Manager?
The most valuable feature of the solution is its performance.
What is your experience regarding pricing and costs for CyberArk Endpoint Privilege Manager?
I believe it's quite a reasonably priced solution. It's not very common to use CyberArk because it's a niche solution, but customers who are willing to control administrative accounts are willing t...
What is your experience regarding pricing and costs for ForgeRock?
The pricing, setup cost, and licensing are very straightforward, which is a good success. I appreciate that it is very straightforward and helpful.
What needs improvement with ForgeRock?
There are some areas I want ForgeRock to improve. These areas include policy configuration, documentation clarity, UI complexity, and debugging token flow. I want ForgeRock to improve in documentat...
What is your primary use case for ForgeRock?
I am using ForgeRock for standard support, policy configurations, and documentation clarity. The pricing, setup cost, and licensing are very straightforward, which is a good success. I appreciate t...
 

Also Known As

Viewfinity
ForgeRock Identity Platform, ForgeRock OpenIDM
 

Overview

 

Sample Customers

Information Not Available
Geico, Thomson Reuters, Salesforce, McKesson, Trinet, SKY, BNP Paribas, Deloitte, Capgemini, North Western University
Find out what your peers are saying about CyberArk, One Identity, Okta and others in Privileged Access Management (PAM). Updated: April 2026.
893,311 professionals have used our research since 2012.