Try our new research platform with insights from 80,000+ expert users

CyberArk Privileged Access Manager vs One Identity Manager comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.0
CyberArk Privileged Access Manager enhances security, reduces costs, and improves efficiency by automating password management and streamlining workflows.
Sentiment score
7.7
One Identity Manager improves productivity and efficiency with automation, reducing costs and resources by 30-40% annually.
The return on investment lies in improved security infrastructure, addressing over-privileged access, and reducing the risk of credential compromise, which is a major source of data breaches.
The end users have the authority to reconcile the password or verify it before using session isolation, which is one of the unique features that can be enabled through Privileged Session Manager, preventing any attacks from happening within the organization when connected with sessions through CyberArk Privileged Access Manager.
CyberArk Privileged Access Manager has helped customers save on costs primarily by reducing the number of engineering and information security personnel.
Without it, we would need thousands of additional people.
If you do not see it as purely an Identity Management tool but as a possibility to automate processes in the company, it provides a huge amount of value.
One Identity Manager saved us approximately thirty to forty percent in terms of time, money, and resources compared to our pre-deployment setup.
 

Customer Service

Sentiment score
6.5
CyberArk's support is mixed; effective higher-tier levels, but needs better coordination and consistency for complex issues.
Sentiment score
6.9
One Identity Manager's support is praised for responsiveness, with suggestions for quicker responses and deeper knowledge at initial levels.
CyberArk has been exceptional in coming back to us with immediate responses.
It could be forever until you talk to someone who knows what they are doing.
They are helpful, but complex issues can take a long time to resolve, which can delay solutions for urgent customer issues.
If you have outages or critical production problems, you can count on the manufacturer to help resolve the situation.
If I raised a request while they were active, I received responses within an hour.
After submission, they contact the product team, which often takes one or two months to respond.
 

Scalability Issues

Sentiment score
7.7
CyberArk Privileged Access Manager is scalable, supports diverse deployments, and efficiently handles thousands of users, despite planning requirements.
Sentiment score
7.4
One Identity Manager scales well, supporting growth, though performance may dip with complex setups and database management is crucial.
The CPM can reportedly handle up to 50,000 accounts independently without issue.
I would rate it a ten out of ten for scalability.
They had 40,000 passwords in this one safe, and it was saving the last ten iterations of each password object. That means they had 400,000 password objects in this safe. They exceeded the limit.
We could handle about 1,00,000 records for different users.
I would rate its scalability as strong since we have not experienced any significant challenges.
We are hosting it centrally in Switzerland.
 

Stability Issues

Sentiment score
7.8
CyberArk Privileged Access Manager is highly stable, reliable, with minimal issues, and excels in performance and disaster recovery.
Sentiment score
7.4
Users rate One Identity Manager highly for stability, despite occasional bugs, with significant improvements in versions eight and nine.
Proper fine-tuning and expertise ensure the product performs well.
Overall, the stability of the solution is high.
It has a large customer base and positive feedback within my network.
I would rate it a nine out of ten for stability.
Specifically affecting the test and development environments, not the production environment.
One Identity Manager has improved in terms of performance and added functionality.
 

Room For Improvement

Users recommend enhancing CyberArk's interface, integration, documentation, customization, costs, support, performance, and training for improved experience.
One Identity Manager needs better performance, user-friendly design, comprehensive documentation, and improved cloud integration and reporting features.
They want everything to be on the cloud, but even in the SaaS version of CyberArk Privileged Access Manager, they need to deploy some servers on-premises.
We cannot generate a plug-in for web-based applications.
If they want clients to move to the cloud, they need to support them in real-time.
This lack of 24-hour support is problematic from a testing and development standpoint.
It is crucial for them to expand their support team to match their product's success.
In terms of providing a single platform for enterprise-level administration and governance of users, data, and privileged accounts, One Identity is not yet there.
 

Setup Cost

CyberArk Privileged Access Manager is costly yet favored for its robust security and market-leading capabilities, justifying the expense.
One Identity Manager's pricing is competitive, especially for large enterprises, but varies based on deployment and features.
CyberArk is expensive compared to other products I know.
CyberArk is comparatively expensive compared to other PAM solutions, such as Delinea, especially during renewal.
CyberArk's SaaS solution is particularly expensive.
On-premises might incur higher costs.
We have a good enterprise license agreement, and we are very happy with what we get for the price we pay for it.
On-premises, it is cheap.
 

Valuable Features

CyberArk Privileged Access Manager offers secure, versatile management for privileged accounts with automation, integration, and a user-friendly interface.
One Identity Manager excels in customization, SAP integration, and identity governance with automation, user-friendly interface, and extensive connectors.
CyberArk Privileged Access Manager helps ensure data privacy because we now know who is using which credentials and at what time.
It keeps a record of activities, allowing me to easily fetch screen recordings to detect any misuse and see who did what and what happened.
It can integrate with Splunk, SNMP, and other solutions and technologies.
It ensures high security through multiple approval processes, preventing unauthorized access and enhancing compliance by providing time-based access for privileged accounts with proper audit trails.
It continuously monitors user behavior in real-time, triggering automated responses, and manages secure access for both on-premises and cloud applications using protocols such as SAML.
Once you have some experience, it demonstrates best practices and guides you on the correct way to use the tool.
 

Categories and Ranking

CyberArk Privileged Access ...
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
223
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (2nd), Privileged Access Management (PAM) (1st), Mainframe Security (2nd), Operational Technology (OT) Security (3rd)
One Identity Manager
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
119
Ranking in other categories
User Provisioning Software (1st), Identity Management (IM) (3rd)
 

Mindshare comparison

While both are Identity and Access Management solutions, they serve different purposes. CyberArk Privileged Access Manager is designed for Privileged Access Management (PAM) and holds a mindshare of 18.0%, down 22.6% compared to last year.
One Identity Manager, on the other hand, focuses on Identity Management (IM), holds 6.3% mindshare, down 6.8% since last year.
Privileged Access Management (PAM)
Identity Management (IM)
 

Featured Reviews

Abdul Durrani - PeerSpot reviewer
Enables granular and secure access with just-in-time access and Zero Trust model
CyberArk provides a good amount of control over access types. However, as a future enhancement, having additional features for cross-platform integration would be beneficial. It would be good to have integrations with other tools and firewalls, such as Zscaler and CrowdStrike. Although I am not fully aware of recent updates, more cross-platform integration would be valuable. A SOC analyst would like to have centralized access in terms of information flowing in even for privileged access management. They would like to have control over everything instead of opening four to five tabs for different sorts of information. Cross-platform integration would help with that. Customers also want CyberArk's pricing to be better so that they can implement it further and have more licenses. Implementing a privileged access management solution can be challenging. It would be great if CyberArk could provide recommendations based on the compliance standards of an organization. It would help system admins ensure that all the required ports are closed and the systems are being managed properly. If any system is not being used anymore, any ports opened for that system need to be closed. Having such recommendations would be helpful.
Ranjan Mishra - PeerSpot reviewer
Enables our organization to manage accounts across multiple target systems from a central identity management solution
The One Identity Manager web portal needs simplification. While a new Angular portal was introduced with version 8.2, the knowledge base lacks sufficient information and resources. Even with an Angular developer or a One Identity specialist, a knowledge gap exists due to the combination of AngularJS and One Identity schema expertise required. This makes it difficult to find resources that can effectively utilize the portal, highlighting the need for a more user-friendly interface. One Identity Manager currently offers Long Term Support only for version 9.0. All other versions have a two-year lifecycle with extended support. For organizations managing a complex environment with numerous connected systems, users, and assignments, upgrading every two years is impractical. Extending support for regular versions by one or two years would benefit clients in this situation.
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
857,028 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
27%
Financial Services Firm
13%
Computer Software Company
12%
Manufacturing Company
6%
Computer Software Company
18%
Financial Services Firm
15%
Manufacturing Company
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
The pricing for CyberArk Privileged Access Manager is quite expensive, and the pricing varies from region to region. In APAC, CyberArk Privileged Access Manager can be obtained for less than in Nor...
What do you like most about One Identity Manager?
The One Identity birthright process has helped generate user accounts more accurately and quickly.
What is your experience regarding pricing and costs for One Identity Manager?
One Identity Manager is positioned as a premium product. It falls between middle and high in terms of cost, approximately a six to seven if ten is expensive.
What needs improvement with One Identity Manager?
The user experience has been a concern in the past, particularly with the web interface, but improvements are expected with the transition to Angular. The support from One Identity is very poor. Th...
 

Also Known As

CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
Quest One Identity Manager
 

Overview

 

Sample Customers

Rockwell Automation
Texas A&M, Sky Media, BHF Bank, Swiss Post, Union Investment, Wayne State University. More at OneIdentity.com/casestudies
Find out what your peers are saying about CyberArk, Delinea, One Identity and others in Privileged Access Management (PAM). Updated: June 2025.
857,028 professionals have used our research since 2012.