Try our new research platform with insights from 80,000+ expert users

CyberArk Privileged Access Manager vs ForgeRock vs SailPoint Identity Security Cloud comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Featured Reviews

Abdul Durrani - PeerSpot reviewer
Enables granular and secure access with just-in-time access and Zero Trust model
CyberArk provides a good amount of control over access types. However, as a future enhancement, having additional features for cross-platform integration would be beneficial. It would be good to have integrations with other tools and firewalls, such as Zscaler and CrowdStrike. Although I am not fully aware of recent updates, more cross-platform integration would be valuable. A SOC analyst would like to have centralized access in terms of information flowing in even for privileged access management. They would like to have control over everything instead of opening four to five tabs for different sorts of information. Cross-platform integration would help with that. Customers also want CyberArk's pricing to be better so that they can implement it further and have more licenses. Implementing a privileged access management solution can be challenging. It would be great if CyberArk could provide recommendations based on the compliance standards of an organization. It would help system admins ensure that all the required ports are closed and the systems are being managed properly. If any system is not being used anymore, any ports opened for that system need to be closed. Having such recommendations would be helpful.
Trisha Bhola - PeerSpot reviewer
It's easier to customize and maintain our code
I worked on two different projects based on ForgeRock, and both are automated deployments. One is a UI-based deployment. It's an automated process using some scripts. The deployments are done through Octopus, so it's also automated. We first deploy the essential components of AM and then implement additional configurations like Amster Imports. After that, we import all the SAML Federation data and add some certificates. We have two teams of five and three team members working on the different deployment processes. One is working on the dev side, another is looking at the higher environment, and one is managing the data. In another project, I'm the only developer. We also deploy on the dev environments so that anyone can test new features, configurations, and client requirements. They can test it on the dev environment, but a team of four people manages higher environments. The Access Management component involves the most customization, which takes around 15 to 20 minutes because of the need to import the Amster configuration. If another deployment is simultaneously happening, it may be a little slower and take around 30 minutes. The other components, like the user data stores, take about five to seven minutes. It's another five to 10 minutes for Identity Management. After deployment, the maintenance is mostly checking for security vulnerabilities. If ForgeRock shares security vulnerabilities or advisories, we check to see if there is something inside we need to maintain. Other than that, we just install updates when they add features each month.
Quach Van Lam - PeerSpot reviewer
Flexible, easy to customize, and not too difficult to set up
The initial setup isn't so difficult. The product can be flexible in the build. You can easily customize the workflows. We can set everything up on the cloud, which makes things very easy. It can easily adapt to the PoC requirement and the set requirements on the app's online version.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a leading solution and one of the best SaaS solutions in the market."
"For me, CyberArk Privileged Access Manager's most valuable features are password and session management."
"Securely protects our TAP/NUID and privileged access accounts within the company."
"It's secure and reliable. I especially appreciate that it's locked down and only allows access to authorized components."
"I love the ability to customize the passwords: the forbidden characters, the length of the password, the number of capital, lowercase, and special characters. You can customize the password so that it tailor fits, for example, mainframes that can't have more than eight characters. You can say, "I want a random password that doesn't have these special characters, but it is exactly eight characters," so that it doesn't throw errors."
"It provides an accountability to the individuals who are using it, knowing that it is audited and tracked."
"The automatic change of the password and Privileged Session Manager (PSM) are the most valuable features. With Privileged Session Manager, you can control the password management in a centralized way. You can activate these features in a session; the session isolation and recording. You apply the full intermediation principle. So, you must pass through CyberArk PAM to get access to the target system. You don't need to know the password, and everything that you do is registered and auditable. In this case, no one gets to touch the password directly. Also, you can implement detection and response behavior in case of a breach."
"DVR like video recording and text-based recording for easier audits."
"Easy to customize and adaptable to any environment."
"The support is good and prompt."
"The solution is very scalable. We have a lot of users that have been increasing over the years that we have been using it. We have approximately 20,000 users."
"The product is easy to use in a development environment."
"I like the intelligent authentication feature."
"This is a stable solution. When you do experience any issues, you will see it in your DB logs or audit logs so you can easily reach a conclusion of might be causing it."
"Even though we have very small business interests with them today, they see that we plan on growing drastically over the next two years. Therefore, we have excellent support and we are now at a point where we are not calling tech support. We pick up a phone and call the Account Manager and they'll get everything resolved for us. We don't have to queue along with everybody else and go through a long process."
"The product is easy to set up."
"SailPoint IdentityIQ has more enriched out-of-box connectors than the others."
"The solution is one of the main security products you need to control access and have visibility into what's happening in your organization. It helps with managing access to applications, ensuring governance, and obtaining certifications."
"Provides functionalities for various stages, such as joiner, mover, and leaver"
"​The Certification and Provisioning features are most valuable."
"The customer service is excellent, with quick response times and comprehensive support from the SailPoint team."
"Good life cycle management, segregation of duties, and analytics features."
"What I like most about SailPoint IdentityIQ is that it's simple to use and easy to configure and deploy."
"User provisioning and the role management features are good."
 

Cons

"I would prefer that this is a fully-managed service, rather than have to manage the software ourselves and keep it up to date."
"CyberArk PAM is a very broad product as everyone's requirements for implementation are different. In our particular case, the initial implementation was planned and developed by people who didn't know our specific network requirements, so the initial implementation needed to be tweaked over time. While this is normal, at the time all these "major" changes required CyberArk professional services to come in-plant and "assist" with the changes."
"One of our current issues is a publishing issue. If we whitelist Google Chrome, all the events of Google Chrome should be gone. It is not happening."
"Integration with the ticketing system should allow any number of fields to be used for validation before allowing a user to be evaluated and able to access a server."
"The product is very vaulting-focused. I'd love to see it expanding its capabilities a bit further into areas like just-in-time elevation, and access with non-vaulted credentials."
"I would like to see an easier way to define delegated roles within the administration of the core product."
"One area for improvement is the user interface. It needs significant enhancements."
"The graphical user interface could be simplified and harmonized for better usability. It should be consistent. Its GUI is very confusing."
"The only problem with ForgeRock is that it is derived from an open-source product, so sometimes it's a bit unstable."
"I think the upgrade process is sometimes a little complicated and there are failures that occur."
"In an upcoming release, the solution could improve by limiting the need to do customizations."
"Automatic Deployment needs improvement. it could be made easier."
"I don't think ForgeRock directly supports integrations with Slack, making it an area where improvements are required."
"The user interface could be improved as it is cumbersome and outdated. It doesn't have a responsive UI."
"It should be a little bit easier to implement. It is user-friendly, but there is always scope for improvement."
"It should have a better user interface. Its flexibility should also be improved. It is not about simplifying; it is more about flexibility. Each company has its own requirements, and ForgeRock can provide more flexibility in terms of the use of existing modules to implement features for the customers."
"Scalability is hard, especially when you are doing it in real time."
"The user interface is not very user-friendly."
"The cost can be prohibitive for middle-tier companies."
"There's a lot of customization required to improve the user experience."
"The interface can improve, and the product could become a little cheaper."
"SailPoint lacks some features like privileged account management and access management features found in products like Okta."
"The solution's technical support team's response time and skills need improvement since it is an area where there are shortcomings."
"The interface should be simple and easier to use."
 

Pricing and Cost Advice

"Pricing is a problem. CyberArk is expensive compared to other products I know. It is similar to buying a German car. It comes with all the bells and whistles, but some companies may find it too expensive."
"They have two types of licensing: purchase and subscription. You have to pay for each admin user, such as Microsoft admin, mail admin, database admin, etc."
"I would rate the tool’s pricing a six out of ten."
"The solution is available at a high price"
"If you are looking at implementing this solution, buy the training and go to it."
"Quite expensive"
"Although CyberArk Privileged Access Management is expensive, its protection capabilities outweigh the cost."
"There are additional features added to our CyberArk Privileged Access Manager license. For example, features that allow us to integrate into various kinds of platforms."
"The pricing of the solution is fair but I do not have the full details."
"The license is purchased annually per user. However, you can negotiate if you are signing for a longer period of time. When comparing this solution to others on the market it is priced fair, it is not at the top of the price range or at the bottom end."
"ForgeRock is an expensive solution."
"Its price is comparable to other products in the market."
"It's a bit pricey and could be more competitive."
"ForgeRock's pricing is more competitive than other products."
"We have multiple clients we are looking at right now. We are at a very small number, however, the idea and the goal is to grow. We are looking at about $100,000 and $50,000 a minimum a month cost. That'd be minimum maybe in a couple of years."
"Its licensing is on a yearly basis, but it also depends on the contract that you have with the vendor. They have multiple types of contracts. There are additional costs to the standard licensing fees. If you need some of the features, you have to pay more."
"I rate the solution a seven on a scale where one is cheap and ten is too expensive. In short, the solution falls under the higher side of pricing."
"It is a costly solution. Its cost, for sure, should be reduced."
"SailPoint IIQ is the best of best. That is reflected in the pricing of the solution. The pricing is based on the number of identities."
"You are able to get discounts if you plan to use the tool for the long-term i.e. discounts for 5+ years of usage."
"The price of the solution could improve, it is not priced well for smaller businesses to afford."
"The pricing is a little bit higher than other tools."
"It's all competitive. Initially, the prices look a bit higher, but once it gets into a competitive situation, they meet the market. I'd rate it an eight out of ten in terms of pricing. It tends to be more expensive, but it works."
"The licensing fees are on a yearly basis."
report
Use our free recommendation engine to learn which Access Management solutions are best for your needs.
851,823 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
33%
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
6%
Financial Services Firm
24%
Computer Software Company
12%
Insurance Company
7%
Manufacturing Company
7%
Financial Services Firm
18%
Computer Software Company
14%
Manufacturing Company
10%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
With the current model of licensing, for my use cases, sometimes it's hard to convince the management and get budget ...
What do you like most about ForgeRock?
The most valuable features of ForgeRock are social login and data protection.
What is your experience regarding pricing and costs for ForgeRock?
Our company was considering switching back to Keycloak from ForgeRock, so as to not pay any license fees. ForgeRock a...
What needs improvement with ForgeRock?
In the past, I saw that Splunk was integrated with a testing portal, and then it was integrated with Slack. I don't t...
What is your experience regarding pricing and costs for SailPoint IdentityIQ?
The product is expensive. People need to opt for a licensing plan for one year or three years.
What advice do you have for others considering SailPoint IdentityIQ?
You can use SailPoint Atlas to take identity security to the next level. In SailPoint IIQ, writing a custom connector...
What do you like most about SailPoint IdentityNow?
It significantly reduces the workload for certification processes.
 

Also Known As

CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
ForgeRock Identity Platform, ForgeRock OpenIDM
IdentityIQ, IdentityNow, Cloud Infrastructure Entitlement Management, Intello
 

Overview

 

Sample Customers

Rockwell Automation
Geico, Thomson Reuters, Salesforce, McKesson, Trinet, SKY, BNP Paribas, Deloitte, Capgemini, North Western University
Adobe, AXA Technology Services, Cuna Mutual Group, Equifax, ING Direct, Orrstown Bank, Rockwell Automation, SallieMae, Spirit Aerosystems, TEL
Find out what your peers are saying about Microsoft, Ping Identity, Okta and others in Access Management. Updated: May 2025.
851,823 professionals have used our research since 2012.