Try our new research platform with insights from 80,000+ expert users

CyberArk Privileged Access Manager vs ForgeRock vs Ping Identity Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Featured Reviews

Abdul Durrani - PeerSpot reviewer
Enables granular and secure access with just-in-time access and Zero Trust model
CyberArk provides a good amount of control over access types. However, as a future enhancement, having additional features for cross-platform integration would be beneficial. It would be good to have integrations with other tools and firewalls, such as Zscaler and CrowdStrike. Although I am not fully aware of recent updates, more cross-platform integration would be valuable. A SOC analyst would like to have centralized access in terms of information flowing in even for privileged access management. They would like to have control over everything instead of opening four to five tabs for different sorts of information. Cross-platform integration would help with that. Customers also want CyberArk's pricing to be better so that they can implement it further and have more licenses. Implementing a privileged access management solution can be challenging. It would be great if CyberArk could provide recommendations based on the compliance standards of an organization. It would help system admins ensure that all the required ports are closed and the systems are being managed properly. If any system is not being used anymore, any ports opened for that system need to be closed. Having such recommendations would be helpful.
Ahmet Murat Ülker - PeerSpot reviewer
Easy to use, but customizations can be complicated to handle
I would suggest others use the product after asking them to consider their use cases. SSO may be a use case for some, and using the product as an IDM tool may be a use case. At the moment, my company is not deploying all the components of ForgeRock itself. My company uses ForgeRock for OAuth 2.0. For example, my company is not deploying the IDM and identity gateway components. You should consider your use case and select the required components for that use case. My company does not use the SSO features of the tool. My company uses SSO to access ForgeRock's AM Console for individual users. My company does not use single sign on features of the product and instead, we use Auth0. I rate the tool a seven or eight out of ten.
MAHESHKUMAR7 - PeerSpot reviewer
Offers multi-factor authentication and application support side of PingFederate but application only supports specific protocols
A lot of teams work with technical support, but I work with it for user issues only. You might need support with things like application swaps, application names, and application URLs. I didn't know where to find those in Ping Identity, so I contacted technical support for those issues. The support team is very clever and active. They provide end-to-end support once an issue is created. I have worked with most of the support team. I also work with the support team because I work with the operations team. I provide 24/7 support to production and non-production environments. I coordinate with application and network teams to troubleshoot critical tickets and issues related to Ping Identity solutions.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The implementation of the PSM proxy has reduced the specific risk of "insider attacks" on our domain controllers and SLDAP servers by eliminating direct user login by an open secure connection on the user's behalf without ever revealing the privileged credentials."
"Allows secure, logged access to highly sensitive servers and services."
"CyberArk Privileged Access Manager's main benefit is it provides secure access to our servers. There are features to capture the user activity, it provides video recording processing. If the users are logged in to the server, we can see what activities they are performing. It's a very nice tool for Privileged Access Management. They have plenty of useful services and the solution has fulfilled our needs."
"It has the ability to scale out. We have scaled out quite a bit with our product and use of it to get to multiple locations and businesses, so it has the breadth to do that."
"Our go-to solution for securing against the pass the hash attack vector and auditing privileged account usage."
"CyberArk's GUI is user friendly."
"We also use CyberArk’s Secrets Manager. Because AWS is the biggest area for us, we have accounts in AWS that are being rotated by CyberArk. We also have a manual process for the most sensitive of our AWS accounts, like root accounts. We've used Secrets Manager on those and that has resulted in a significant risk reduction, as well."
"The features that are most effective, like every PAM solution, include monitoring and password rotations."
"Easy to customize and adaptable to any environment."
"ForgeRock is an extensive product with many functionalities and capabilities, much more than many other tools combined."
"The product is easy to use in a development environment."
"The product is easy to set up."
"Easy to navigate, handle and manage the applications."
"The support is good and prompt."
"The solution integrates well and it is important for them to keep up with the current trends in the market quickly enough, and they have been doing a good job at it."
"I like the intelligent authentication feature."
"What I like best about PingID is that it's very user-friendly. PingID is well-built as a developer tool and regularly upgrades and updates via patches. I also like that PingID has clear documents that will help you integrate it with other solutions."
"We use the product to run different reports."
"The most valuable feature is multifactor authentication."
"It provides ease of connecting all our devices."
"It gets a mobility portal in place in conjunction with Office 365. It provides very good possibilities and it's much better than other technology that we have used before which was unstable and slower."
"It is a scalable solution."
"PingFederate gives you granular control over the settings. There are many options for fine-tuning policies."
"It is a stable solution. Stability-wise, I rate the solution a ten out of ten."
 

Cons

"Transitioning from a traditional on-premises deployment to the privileged cloud has resulted in losing access to many logs and administrative tools typically available on the back end."
"Initially, there was a lot of hiccups, because there were a lot of transitions due to manual installations."
"We would, of course, always prefer it if the pricing was cheaper."
"New functionalities and discovered bugs take longer to patch. We would greatly appreciate quicker development of security patches and bug corrections."
"Integration with the ticketing system should allow any number of fields to be used for validation before allowing a user to be evaluated and able to access a server."
"Their support can be better. Their SLA timings are higher than others."
"The current user interface is a little dated. However, I hear there are changes coming in the next version."
"The major pain point that we have is the capacity of CyberArk due to the sheer volume of NPAs that we are managing. We are a large organization and we have hundreds of thousands of non-personal accounts to manage. We have already found out that there are certain capacity limitations within CyberArk that might introduce performance issues. From my perspective, something that would be valuable would be if the vault could hold more passwords and be more scalable."
"As with any complex software platform, there is a learning curve to using ForgeRock, and it may require specialized expertise to implement and manage effectively."
"Lacks simplified documentation within the tool that requires use of a separate portal."
"In an upcoming release, the solution could improve by limiting the need to do customizations."
"The solution requires more simplified customization. However, part of the problem is my clients determining their own preferences. Technology can help and do many things, but you have to define your own policies to ensure that the solution or service works within those parameters. Helping customers understand their business and different processes is another issue not relating to the functionality of this solution."
"The user interface could be improved as it is cumbersome and outdated. It doesn't have a responsive UI."
"We would like this solution to be developed for use with mobile applications."
"They should improve the solution by include reporting."
"We raised tickets asking for improvements, but sometimes we don't get the proper solution. They are responding, but the ticket is open for weeks and weeks. For some issues, we don't get a satisfactory solution or the solution doesn't work."
"In Ping Identity, we have had some issues. We've worked with logging and troubleshooting, including some firewall and security issues."
"They could enhance the product's device tracking for better zero-trust security would be beneficial. Currently, it tracks IPs well but lacks detailed device information, which is crucial from a security standpoint."
"The product's community has certain shortcomings that require improvement."
"The product is not customizable."
"I think that the connection with like Microsoft Word, especially for Office 365, is a weak point that could be improved."
"We have encountered instances where it is not easy to do authentication."
"PingID would benefit from a better user interface for integration."
"Ping Identity Platform must improve its UI since its management console is complicated."
 

Pricing and Cost Advice

"I would rate CyberArk's pricing a nine out of ten, with one being cheap and ten being expensive. It's one of the most expensive solutions in the market, but it's worth it."
"This solution is expensive."
"I rate the tool's pricing an eight out of ten."
"I believe that this solution is priced well. It's the market leader and I think that it's the best solution."
"Its price is high. I have also worked with Delinea. CyberArk is comparatively expensive compared to other PAM solutions, such as Delinea, especially during renewal."
"It is in line with its competitors, but all such solutions cost too much money."
"It costs us around $200 per user."
"CyberArk Privileged Access Manager is on the expensive side. It is very expensive."
"It's a bit pricey and could be more competitive."
"Its price is comparable to other products in the market."
"We have multiple clients we are looking at right now. We are at a very small number, however, the idea and the goal is to grow. We are looking at about $100,000 and $50,000 a minimum a month cost. That'd be minimum maybe in a couple of years."
"The pricing of the solution is fair but I do not have the full details."
"The license is purchased annually per user. However, you can negotiate if you are signing for a longer period of time. When comparing this solution to others on the market it is priced fair, it is not at the top of the price range or at the bottom end."
"ForgeRock is an expensive solution."
"Its licensing is on a yearly basis, but it also depends on the contract that you have with the vendor. They have multiple types of contracts. There are additional costs to the standard licensing fees. If you need some of the features, you have to pay more."
"ForgeRock's pricing is more competitive than other products."
"Ping Identity Platform is not an expensive solution."
"The pricing is neither too expensive nor too cheap."
"PingID pricing is a ten out of ten because it's a little bit cheaper than other tools, such as Okta and ForgeRock, and supports multiple tools."
"The tool is quite affordable."
"Compared to some SaaS-based solutions, the platform is relatively cost-effective."
"The platform's value justifies the pricing, especially considering its security features and scalability."
"Ping offers flexible pricing that's not standardized."
"PingID's pricing is pretty competitive."
report
Use our free recommendation engine to learn which Access Management solutions are best for your needs.
865,140 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
15%
Manufacturing Company
9%
Government
7%
Financial Services Firm
23%
Computer Software Company
12%
Manufacturing Company
7%
Government
6%
Financial Services Firm
24%
Computer Software Company
10%
Manufacturing Company
9%
Retailer
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What do you like most about ForgeRock?
The most valuable features of ForgeRock are social login and data protection.
What is your experience regarding pricing and costs for ForgeRock?
Our company was considering switching back to Keycloak from ForgeRock, so as to not pay any license fees. ForgeRock a...
What needs improvement with ForgeRock?
In the past, I saw that Splunk was integrated with a testing portal, and then it was integrated with Slack. I don't t...
What do you like most about PingID?
The mobile biometric authentication option improved user experience. It's always about security because, with two-fac...
What is your experience regarding pricing and costs for PingID?
The pricing is neither too expensive nor too cheap.
What needs improvement with PingID?
The management console needs to be improved. PingID should revise it.
 

Also Known As

CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
ForgeRock Identity Platform, ForgeRock OpenIDM
Ping Identity (ID), PingFederate, PingAccess, PingOne, PingDataGovernance, PingDirectory, OpenDJ
 

Overview

 

Sample Customers

Rockwell Automation
Geico, Thomson Reuters, Salesforce, McKesson, Trinet, SKY, BNP Paribas, Deloitte, Capgemini, North Western University
Equinix, Land O'Lakes, CDPHP, Box, International SOS, Opower, VSP, Chevron, Truist, Academy of Art University, Northern Air Cargo, Repsol
Find out what your peers are saying about Microsoft, Auth0, Ping Identity and others in Access Management. Updated: July 2025.
865,140 professionals have used our research since 2012.