Try our new research platform with insights from 80,000+ expert users

CyberArk Privileged Access Manager vs ForgeRock vs SailPoint Identity Security Cloud comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Featured Reviews

Abdul Durrani - PeerSpot reviewer
Enables granular and secure access with just-in-time access and Zero Trust model
CyberArk provides a good amount of control over access types. However, as a future enhancement, having additional features for cross-platform integration would be beneficial. It would be good to have integrations with other tools and firewalls, such as Zscaler and CrowdStrike. Although I am not fully aware of recent updates, more cross-platform integration would be valuable. A SOC analyst would like to have centralized access in terms of information flowing in even for privileged access management. They would like to have control over everything instead of opening four to five tabs for different sorts of information. Cross-platform integration would help with that. Customers also want CyberArk's pricing to be better so that they can implement it further and have more licenses. Implementing a privileged access management solution can be challenging. It would be great if CyberArk could provide recommendations based on the compliance standards of an organization. It would help system admins ensure that all the required ports are closed and the systems are being managed properly. If any system is not being used anymore, any ports opened for that system need to be closed. Having such recommendations would be helpful.
Ahmet Murat Ülker - PeerSpot reviewer
Easy to use, but customizations can be complicated to handle
I would suggest others use the product after asking them to consider their use cases. SSO may be a use case for some, and using the product as an IDM tool may be a use case. At the moment, my company is not deploying all the components of ForgeRock itself. My company uses ForgeRock for OAuth 2.0. For example, my company is not deploying the IDM and identity gateway components. You should consider your use case and select the required components for that use case. My company does not use the SSO features of the tool. My company uses SSO to access ForgeRock's AM Console for individual users. My company does not use single sign on features of the product and instead, we use Auth0. I rate the tool a seven or eight out of ten.
Mitch MO - PeerSpot reviewer
Adapts workflows with industry-specific flexibility for big companies
We find flexibility to be one of the most valuable features. The solution can be customized to adapt the workflow to our industry, offering considerable flexibility. Additionally, it is considered a good solution for large companies due to its scalability and ability to cater to the needs of many customers. It has also enhanced security and provided significant flexibility for our specifications module.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product has allowed us to improve both the management and access to privileged credentials, while also creating a full audit trail of all activities happening within isolated sessions of all tasks and activities taking place within the solution."
"Their legacy of more than 20 years is very valuable. It brings a lot of stability to the product and a wide variety of integration with the ecosystem. Because of these factors, it has also been very successful in deployment. So, the legacy and integration with other technologies make the PAM platform very stable and strong. In terms of features, most of the other vendors are still focusing just on the privileged access management or session recording, but CyberArk has incorporated artificial intelligence to make PAM a more proactive system. They have implemented threat analytics into this, and there is also a lot of focus on domain controller production, Windows Server protection, and stuff like that. They have also further advanced it with the security on the cloud and DevOps systems. They have a bundle licensing model, which really helps. They don't have a complex licensing model. Even though in our market, people say CyberArk is expensive as compared to some of the other products, but in terms of overall value and as a bundling solution, it is an affordable and highly scalable product."
"It is a robust product."
"The most valuable feature of CyberArk Privileged Access Manager is the vault. I am satisfied with the interface and the documentation."
"It's a highly flexible solution that can adapt to each customer's needs."
"The accounts are maintained automatically. Hence, resource and administration costs are less."
"DVR like video recording and text-based recording for easier audits."
"Session monitoring includes recordings of all activities performed."
"ForgeRock has CIAM, which other products didn't have, and they have DevOps ready."
"The support is good and prompt."
"We create and define the permissions and configurations for the users."
"The solution is very scalable. We have a lot of users that have been increasing over the years that we have been using it. We have approximately 20,000 users."
"The solution's most valuable feature is the authentication for the consumers. The integration with other third-party applications is excellent."
"Easy to customize and adaptable to any environment."
"I like the way it is handling authentication and authorization."
"Even though we have very small business interests with them today, they see that we plan on growing drastically over the next two years. Therefore, we have excellent support and we are now at a point where we are not calling tech support. We pick up a phone and call the Account Manager and they'll get everything resolved for us. We don't have to queue along with everybody else and go through a long process."
"Access certification and provisioning are two of the solutions most valuable features."
"Great product to manage the access control of users."
"It is simple and easy to implement."
"Security and administration for any new/current access."
"SailPoint IdentityIQ has a good and straightforward user interface. They also have a lot of resources and documentation available to understand the process."
"SailPoint has an edge in terms of security since administrators have limited access, unlike ServiceNow where you can change everything."
"It significantly reduces the workload for certification processes."
"The big one now is that they're adding AI and machine learning to figure out automated approvals and make recommendations to their reviewers. So, if I bring up Doug McPherson and it says he has access to this application, the system will make a review based on peer group analysis. That's one of the biggest new things. The problem used to be that people would get everything loaded on, and they created too much work for themselves. Now, they can use these policies and start to let the machine pick the less risky things."
 

Cons

"They can do a better job in the PSM space."
"To get it to a ten it should give other possibilities to select if you could follow the keystrokes. It should have a flexibility with things where people can use it a lot faster."
"The solution is too big and complex for any businesses that are small or medium-sized. They should offer a more compact version or make a solution better suited to smaller businesses."
"CyberArk Enterprise Password Vault can improve the distributive vault feature. Distributing the vault in multiple areas and multiple data centers should improve."
"The product is complex and requires extensive configuration."
"I would like to see an easier way to define delegated roles within the administration of the core product."
"The current interface doesn't scale that well, and has some screens still in the old layout."
"We need a bit more education for our user community because they are not using it to its capabilities."
"The only problem with ForgeRock is that it is derived from an open-source product, so sometimes it's a bit unstable."
"We're worried about the scaling. We're told it will be okay and there won't be issues, however, I'm not 100% convinced."
"We raised tickets asking for improvements, but sometimes we don't get the proper solution. They are responding, but the ticket is open for weeks and weeks. For some issues, we don't get a satisfactory solution or the solution doesn't work."
"Lacks simplified documentation within the tool that requires use of a separate portal."
"The product's support services in the French language are not free."
"As with any complex software platform, there is a learning curve to using ForgeRock, and it may require specialized expertise to implement and manage effectively."
"Automatic Deployment needs improvement. it could be made easier."
"The solution's documentation is not very good, and they do not give more details."
"The report functionality and dashboard of the access manager could be improved."
"The advanced provisioning features require more improvement."
"I think that the onboarding framework could be improved."
"It is not readily available and cannot be downloaded from the net."
"I would like for the next release to have a more user-friendly interface."
"There are various functions that don't work in IdentityIQ, including the access request reminder, which doesn't go to the approvals in the proper format, so it's hard for users to read."
"Some setups should be done in the interface and in the code, and could be made simpler."
"We faced some issues while integrating the solution with a third-party tool."
 

Pricing and Cost Advice

"The price of CyberArk Privileged Access Manager could be less expensive."
"The solution is cost-effective for the features."
"From a client perspective, CyberArk's pricing is fair but there is a significant increase each year. They should limit the price increase because this could potentially drive customers to other partners. Price changes should be at defined intervals. There should not be sudden jumps."
"This solution is expensive."
"I'm aware that the organization had purchased licensing for almost all of CyberArk's solutions including licensing for PTA, EPM, and the Application Identity Manager. But when it comes to PSM, this is one of the components where there's an additional charge for any extra PSMs that you want to deploy. I believe that there's some rider where the vendor has a bit of leeway to, at times, charge a premium on whatever additional services you may require above the board."
"The pricing is slightly higher compared to other solutions, but it is reasonable because there are better security features."
"I believe that this solution is priced well. It's the market leader and I think that it's the best solution."
"No, I do not have any advice on the price of the product."
"Its price is comparable to other products in the market."
"It's a bit pricey and could be more competitive."
"Its licensing is on a yearly basis, but it also depends on the contract that you have with the vendor. They have multiple types of contracts. There are additional costs to the standard licensing fees. If you need some of the features, you have to pay more."
"ForgeRock's pricing is more competitive than other products."
"The license is purchased annually per user. However, you can negotiate if you are signing for a longer period of time. When comparing this solution to others on the market it is priced fair, it is not at the top of the price range or at the bottom end."
"We have multiple clients we are looking at right now. We are at a very small number, however, the idea and the goal is to grow. We are looking at about $100,000 and $50,000 a minimum a month cost. That'd be minimum maybe in a couple of years."
"The pricing of the solution is fair but I do not have the full details."
"ForgeRock is an expensive solution."
"In terms of pricing, SailPoint IdentityIQ is affordable. It's not cheap, and it's not expensive, so the solution is in the middle, price-wise. It also didn't have additional costs, even if my company had different teams that took care of auditing and provisioning and projects that used SailPoint IdentityIQ."
"SailPoint is expensive compared to its competitors. It's one of the most expensive products, so I'd rate it as one out of five, cost-wise."
"It's difficult to say that the solution saved costs because it is quite expensive."
"It is a costly solution. Its cost, for sure, should be reduced."
"It's all competitive. Initially, the prices look a bit higher, but once it gets into a competitive situation, they meet the market. I'd rate it an eight out of ten in terms of pricing. It tends to be more expensive, but it works."
"As per my knowledge, it runs on a paid partnership model, but I am not sure about it."
"We pay an annual licensing cost for SailPoint IdentityIQ."
"This is an expensive solution. I would rate it a two and a half out of five for pricing."
report
Use our free recommendation engine to learn which Access Management solutions are best for your needs.
865,140 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
15%
Manufacturing Company
9%
Government
7%
Financial Services Firm
23%
Computer Software Company
12%
Manufacturing Company
7%
Government
6%
Financial Services Firm
16%
Computer Software Company
13%
Manufacturing Company
10%
Healthcare Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What do you like most about ForgeRock?
The most valuable features of ForgeRock are social login and data protection.
What is your experience regarding pricing and costs for ForgeRock?
Our company was considering switching back to Keycloak from ForgeRock, so as to not pay any license fees. ForgeRock a...
What needs improvement with ForgeRock?
In the past, I saw that Splunk was integrated with a testing portal, and then it was integrated with Slack. I don't t...
What is your experience regarding pricing and costs for SailPoint IdentityIQ?
The product is expensive. People need to opt for a licensing plan for one year or three years.
What advice do you have for others considering SailPoint IdentityIQ?
You can use SailPoint Atlas to take identity security to the next level. In SailPoint IIQ, writing a custom connector...
What do you like most about SailPoint IdentityNow?
It significantly reduces the workload for certification processes.
 

Also Known As

CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
ForgeRock Identity Platform, ForgeRock OpenIDM
IdentityIQ, IdentityNow, Cloud Infrastructure Entitlement Management, Intello
 

Overview

 

Sample Customers

Rockwell Automation
Geico, Thomson Reuters, Salesforce, McKesson, Trinet, SKY, BNP Paribas, Deloitte, Capgemini, North Western University
Adobe, AXA Technology Services, Cuna Mutual Group, Equifax, ING Direct, Orrstown Bank, Rockwell Automation, SallieMae, Spirit Aerosystems, TEL
Find out what your peers are saying about Microsoft, Auth0, Ping Identity and others in Access Management. Updated: July 2025.
865,140 professionals have used our research since 2012.