No more typing reviews! Try our Samantha, our new voice AI agent.

CyberArk Privileged Access Manager vs ForgeRock vs SailPoint Identity Security Cloud comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.6
CyberArk enhances security, reduces risks and costs, improves efficiency, and streamlines workflows, but ROI remains difficult to quantify.
Sentiment score
5.2
ForgeRock enhanced market efficiency, security, and customer trust, reducing staffing needs and improving time to market without exact ROI figures.
Sentiment score
7.1
SailPoint Identity Security Cloud reduces costs, automates access, enhances productivity, and achieves ROI within 14 to 18 months.
The return on investment lies in improved security infrastructure, addressing over-privileged access, and reducing the risk of credential compromise, which is a major source of data breaches.
Cyber Security Engineer at Isolutions Associates Ltd (ISOLS)
The end users have the authority to reconcile the password or verify it before using session isolation, which is one of the unique features that can be enabled through Privileged Session Manager, preventing any attacks from happening within the organization when connected with sessions through CyberArk Privileged Access Manager.
Senior Engineer at a tech vendor with 1,001-5,000 employees
CyberArk Privileged Access Manager has helped customers save on costs primarily by reducing the number of engineering and information security personnel.
Head of Sales Services Department at a comms service provider with 51-200 employees
On a B2B level, it opened up the market for TomTom to sell its services in a more efficient way to car companies.
Principal Consultant at Road2Value
We can use a Linux image from ForgeRock with different systems, applications, websites, and mobile apps to create various types of access for users.
Assistant Architect at a energy/utilities company with 501-1,000 employees
I can definitely see that fewer employees are needed compared to using different SaaS applications.
Identity and Access Management Specialist at a university with 10,001+ employees
 

Customer Service

Sentiment score
6.5
CyberArk Privileged Access Manager's customer service is knowledgeable but experiences delays and inconsistency in response times.
Sentiment score
5.8
ForgeRock customer service is flexible and responsive, but improvements are needed for professional services and ticket resolution speed.
Sentiment score
5.3
SailPoint Identity Security Cloud offers praised support with weekend availability, though regional and language challenges may occur.
CyberArk has been exceptional in coming back to us with immediate responses.
IT Cyber Security Lead at a mining and metals company with 1,001-5,000 employees
It could be forever until you talk to someone who knows what they are doing.
Senior PAM Consultant at iC Consult GmbH
Based on the issue resolution and support quality, I rate the support 10 out of 10.
Operation Specialists at a tech vendor with 10,001+ employees
The support portals offer comprehensive documentation, troubleshooting guides, and community forums that have been helpful for resolving common issues independently.
Software Engineer at a financial services firm with 10,001+ employees
For standard support tickets, response times were very decent, and the support team was helpful in identifying configuration issues, especially with authentication trees, token settings, and directory replications.
Identity and Access Management Specialist at a university with 10,001+ employees
The customer support is very flexible and supportive, particularly in the area of automation and customer deployments.
Cybersecurity Consultant at CyberBackbone
SailPoint's team consists of specialists who handle tickets without needing to depend on other teams.
Technical Support Analyst at CLSA
Sometimes, the support is slow, and they often suggest resorting to expert services.
Vice President Sales at a tech vendor with 1-10 employees
Technical support is very good.
Senior Manager Cybersecurity at LTI - Larsen & Toubro Infotech
 

Scalability Issues

Sentiment score
7.6
CyberArk Privileged Access Manager is scalable, supports diverse environments, but scaling decisions depend on licensing and proper planning.
Sentiment score
7.3
ForgeRock offers scalable solutions for diverse enterprises, supporting seamless expansion, efficient administration, and integration across multiple environments.
Sentiment score
7.1
SailPoint Identity Security Cloud is scalable, supporting millions of identities, though may require extra resources and faces Java memory challenges.
The CPM can reportedly handle up to 50,000 accounts independently without issue.
Privileged Access Management Engineer at a hospitality company with 10,001+ employees
I would rate it a ten out of ten for scalability.
IT Cyber Security Lead at a mining and metals company with 1,001-5,000 employees
They had 40,000 passwords in this one safe, and it was saving the last ten iterations of each password object. That means they had 400,000 password objects in this safe. They exceeded the limit.
Senior PAM Consultant at iC Consult GmbH
The access management layer is stateless, so I can scale horizontally by adding more nodes behind a load balancer as traffic increases.
Identity and Access Management Specialist at a university with 10,001+ employees
The platform provides flexible authentication trees, enabling us to design custom MFA flows tailored for different user groups and risk profiles.
Software Engineer at a financial services firm with 10,001+ employees
We scaled up with ForgeRock. My team received an award for implementing it for a 60 million customer base, which was the largest implementation at that time.
Principal Consultant at Road2Value
The solution scales well as long as we provide the necessary resources.
Vice President Sales at a tech vendor with 1-10 employees
The solution is scalable and can be upgraded to accommodate increased user counts.
Technical Project Manager & Senior Security Architect at Tech Mahindra Limited
SailPoint is scalable, though challenges exist in terms of workflow and user interface design.
Technical Support Analyst at CLSA
 

Stability Issues

Sentiment score
7.7
CyberArk Privileged Access Manager is highly reliable and stable, with minor issues mainly from older versions or configurations.
Sentiment score
7.3
ForgeRock is stable and reliable, though customization affects stability, with users rating it seven to nine out of ten.
Sentiment score
7.9
SailPoint Identity Security Cloud is stable, with high reliability ratings, minor issues, and seamless integration fostering user satisfaction.
Proper fine-tuning and expertise ensure the product performs well.
Cybersecurity Specialist at a comms service provider with 5,001-10,000 employees
Overall, the stability of the solution is high.
Senior Cybersecurity Manager at a financial services firm with 10,001+ employees
It has a large customer base and positive feedback within my network.
Senior Manager at a energy/utilities company with 1,001-5,000 employees
ForgeRock supports integration with legacy systems in our organization by offering a wide range of connectors and APIs.
Software Engineer at a financial services firm with 10,001+ employees
ForgeRock is very stable because it manages access, authentication, and authorization effectively.
Assistant Architect at a energy/utilities company with 501-1,000 employees
IdentityIQ deserves a rating of 12 out of ten for stability.
Vice President Sales at a tech vendor with 1-10 employees
The version I use now is very stable, especially compared to previous versions like eight point zero and eight point one.
Specialist Consultant at a financial services firm with 10,001+ employees
 

Room For Improvement

CyberArk Privileged Access Manager needs improved navigation, reporting, automation, integration, platform compatibility, and pricing for enhanced user satisfaction.
ForgeRock users suggest improving documentation, UI, DevOps support, onboarding, and training for better customization and admin experience.
SailPoint Identity Security Cloud is costly, complex, and lacks user-friendliness, necessitating better automation, support, customization, and integration.
They want everything to be on the cloud, but even in the SaaS version of CyberArk Privileged Access Manager, they need to deploy some servers on-premises.
Presales Engineer at a computer software company with 201-500 employees
We cannot generate a plug-in for web-based applications.
Contractor at a pharma/biotech company with 5,001-10,000 employees
If they want clients to move to the cloud, they need to support them in real-time.
Senior Manager at a consultancy with 11-50 employees
ForgeRock needs to focus on low-code, no-code solutions that allow for drag-and-drop functionality with good orchestration.
CIAM Engineer at a tech vendor with 10,001+ employees
It would be better if they were available for support whenever the customer needs it, especially during migration or go-live time periods.
IAM Solution Architect at a tech services company with 1-10 employees
The main area is complexity. ForgeRock is extremely flexible, but the learning curve can be steep.
Identity and Access Management Specialist at a university with 10,001+ employees
SailPoint lacks some features like privileged account management and access management features found in products like Okta.
Technical Project Manager & Senior Security Architect at Tech Mahindra Limited
I find raising a ticket to be too complex, which could be improved for better user-friendliness.
Technical Support Analyst at CLSA
We have also put our enhancement request, and the SailPoint team has accepted that the feature is not available and plans to include it going forward.
Senior Manager Cybersecurity at LTI - Larsen & Toubro Infotech
 

Setup Cost

CyberArk Privileged Access Manager is costly but valued for features and security, deemed worthwhile for large implementations.
ForgeRock offers flexible pricing with community and enterprise options, seen as fair, supporting various features and open-source choices.
SailPoint Identity Security Cloud is costly, with varying prices and separate fees, but offers discounts for long-term plans.
CyberArk is expensive compared to other products I know.
Cybersecurity Specialist at a comms service provider with 5,001-10,000 employees
CyberArk is comparatively expensive compared to other PAM solutions, such as Delinea, especially during renewal.
Presales Engineer at a computer software company with 201-500 employees
CyberArk's SaaS solution is particularly expensive.
Senior Manager at a energy/utilities company with 1,001-5,000 employees
The pricing, setup cost, and licensing are very straightforward, which is a good success.
Cybersecurity Consultant at CyberBackbone
One has to spend considerable time trying to understand the different modules and different needs for those modules on the licensing front.
Principal Consultant at Road2Value
SailPoint is cheaper than ServiceNow, which is very expensive.
Technical Support Analyst at CLSA
The pricing of SailPoint could be better.
Vice President Sales at a tech vendor with 1-10 employees
The costs are slightly higher than SailPoint IQ due to included charges for maintenance.
Technical Project Manager & Senior Security Architect at Tech Mahindra Limited
 

Valuable Features

CyberArk Privileged Access Manager enhances security and efficiency with robust features, seamless integrations, and user-friendly, scalable architecture.
ForgeRock offers flexible authentication, scalability, and DevOps support with strong API integration, enhancing security and operational efficiency.
SailPoint Identity Security Cloud offers intuitive UI, fast deployment, extensive connectors, and strong compliance with AI-enhanced automated identity management.
CyberArk Privileged Access Manager helps ensure data privacy because we now know who is using which credentials and at what time.
Senior Cybersecurity Manager at a financial services firm with 10,001+ employees
It keeps a record of activities, allowing me to easily fetch screen recordings to detect any misuse and see who did what and what happened.
Senior Manager at a consultancy with 11-50 employees
It can integrate with Splunk, SNMP, and other solutions and technologies.
Technical Support Analyst at Capgemini
Centralized management makes the biggest difference because it allows us to define, update, and enforce security and compliance rules from a single location.
Software Engineer at a financial services firm with 10,001+ employees
ForgeRock positively impacts our organization as we manage a large number of users with ease, providing a standard IAM solution that simplifies our processes.
CIAM Engineer at a tech vendor with 10,001+ employees
ForgeRock has positively impacted my organization by allowing us to migrate from the older system to the newer ForgeRock component, enabling us to go live with many products across geographies, enhancing security as it is all cloud-based, and with the company taking care of availability, it has reduced costs for the company.
IAM CONSULTANT at a tech services company with 10,001+ employees
The automation of provisioning and deprovisioning, managing contractors, temporary users, and the overall automation factor is fantastic.
Vice President Sales at a tech vendor with 1-10 employees
The solution can be customized to adapt the workflow to our industry, offering considerable flexibility.
Specialist Consultant at a financial services firm with 10,001+ employees
From a project management point of view, the tool supports audit success with features to segregate permanent and contractor employees, integrate with HR systems, and indicate other sources for contractors.
Senior Manager Cybersecurity at LTI - Larsen & Toubro Infotech
 

Featured Reviews

Atul-Gujar - PeerSpot reviewer
CyberArk manager at a comms service provider with 10,001+ employees
Secures critical infrastructures with essential user session audit records
A potential area for improvement is enhancing support for cluster environments and distributed Vaults. Clients in multiple countries that need central access have different challenges that require better solutions from CyberArk. For financial services, CyberArk can improve incident response by ensuring fast support for critical priority tickets to meet compliance requirements. Providing more documentation on CyberArk is recommended for new team members to enhance their troubleshooting capabilities. I understand it's up to the client, but 99% fail to change the demo key, so it's crucial for CyberArk to emphasize changing the key and documenting it as part of the installation process.
SR
Software Engineer at a financial services firm with 10,001+ employees
Centralized access control has improved secure onboarding and supports strict compliance
I wish we had used ForgeRock's adaptive risk-based authentication, which allows dynamic adjustment of authentication requirements based on user behavior. This could have helped us further strengthen our security. Another hidden gem is the built-in support for custom authentication modules and scripting, which gives a great deal of flexibility to tailor authentication flows. The self-service capabilities for password resets and account recovery have been very helpful in reducing support overhead and improving user experience. Discovering and utilizing these features would have definitely made our integration even smoother and would have provided additional value for both our users and our security team. One area of improvement would be the user interface for policy and workflow configuration, which can become complex and sometimes unintuitive, especially for new administrators. A more streamlined and user-friendly UI would help reduce the learning curve. Enhanced out-of-the-box analytics and reporting would also be valuable, as our current options often require custom development or integration with external tools. While extensibility is a strength, documentation for advanced customizations and integrations could be more comprehensive and easier to follow. Improved support for seamless upgrades and backward compatibility would also help minimize downtime. In terms of performance, optimizing the platform for high concurrency environments would be beneficial, especially for organizations with large user bases or peak usage periods. Enhanced scalability features such as more granular or horizontal scaling options would provide better support for distributed deployments. For integrations, having more pre-built connectors and easy integration with modern cloud-native services would accelerate adoption. Improved monitoring and real-time health dashboards would help proactively identify and resolve performance bottlenecks.
ND
Principle at a manufacturing company with 10,001+ employees
User access management excels but needs enhancements with integration capabilities
I was aware of that because I used to manage these solutions earlier on, but it was purchased by the Procurement team, so I was not involved in any of those.There are certain details I may not be able to disclose currently, but we can speak in general about a number of products and tools that are ongoing. I have not been using access management controls here, so I don't have the latest features or details or hands-on experience in that space. I cannot share all the details about the improvements in security operations since we were exploring some products, but I'm familiar with Saviynt as I was one of their partners for other solutions, and currently, I cannot disclose a lot of performance related to my current roles.
report
Use our free recommendation engine to learn which Access Management solutions are best for your needs.
885,728 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
10%
Computer Software Company
8%
Government
5%
Financial Services Firm
20%
Manufacturing Company
8%
Computer Software Company
7%
Insurance Company
6%
Financial Services Firm
16%
Manufacturing Company
10%
Computer Software Company
8%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise174
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise5
Large Enterprise18
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise8
Large Enterprise42
 

Questions from the Community

How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If the...
What is your experience regarding pricing and costs for ForgeRock?
The pricing, setup cost, and licensing are very straightforward, which is a good success. I appreciate that it is ver...
What needs improvement with ForgeRock?
There are some areas I want ForgeRock to improve. These areas include policy configuration, documentation clarity, UI...
What is your primary use case for ForgeRock?
I am using ForgeRock for standard support, policy configurations, and documentation clarity. The pricing, setup cost,...
What is your experience regarding pricing and costs for SailPoint IdentityIQ?
The product is expensive. People need to opt for a licensing plan for one year or three years.
What advice do you have for others considering SailPoint IdentityIQ?
You can use SailPoint Atlas to take identity security to the next level. In SailPoint IIQ, writing a custom connector...
What do you like most about SailPoint IdentityNow?
It significantly reduces the workload for certification processes.
 

Also Known As

CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
ForgeRock Identity Platform, ForgeRock OpenIDM
IdentityIQ, IdentityNow, Cloud Infrastructure Entitlement Management, Intello
 

Overview

 

Sample Customers

Rockwell Automation
Geico, Thomson Reuters, Salesforce, McKesson, Trinet, SKY, BNP Paribas, Deloitte, Capgemini, North Western University
Adobe, AXA Technology Services, Cuna Mutual Group, Equifax, ING Direct, Orrstown Bank, Rockwell Automation, SallieMae, Spirit Aerosystems, TEL
Find out what your peers are saying about Microsoft, Okta, Cisco and others in Access Management. Updated: March 2026.
885,728 professionals have used our research since 2012.