CyberArk Privileged Access Manager vs SailPoint Identity Security Cloud comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 3, 2022
 

Categories and Ranking

CyberArk Privileged Access ...
Average Rating
8.8
Number of Reviews
144
Ranking in other categories
User Activity Monitoring (1st), Privileged Access Management (PAM) (1st)
SailPoint Identity Security...
Average Rating
8.2
Number of Reviews
62
Ranking in other categories
User Provisioning Software (1st), Identity Management (IM) (2nd), Identity and Access Management as a Service (IDaaS) (IAMaaS) (3rd), Cloud Infrastructure Entitlement Management (CIEM) (1st)
 

Mindshare comparison

As of June 2024, in the Privileged Access Management (PAM) category, the mindshare of CyberArk Privileged Access Manager is 22.2%, down from 22.6% compared to the previous year. The mindshare of SailPoint Identity Security Cloud is 3.1%, up from 2.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Privileged Access Management (PAM)
Unique Categories:
User Activity Monitoring
22.2%
User Provisioning Software
33.5%
Identity Management (IM)
22.3%
 

Featured Reviews

PG
Aug 21, 2023
Good security, seamless integration, and real time monitoring capabilities
In a large financial institution, CyberArk Privileged Access Management (PAM) plays a pivotal role in ensuring the security and integrity of sensitive financial data. With numerous systems, applications, and databases holding critical client information and transaction data, the institution faced…
SC
Sep 5, 2022
Scalable access governance system that removes manual approvals and makes teams more productive
We use this solution for identity governance and to understand who has access to what and whether that access should be granted or not. We also use it for access to recertification automation which provides a complete report of who has what access in the organization at the press of a button. We…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We are able to centrally manage credentials, touch applications, and rotate passwords."
"Because we now have the ability to grant access to management utilities like DNS Manager, Sequel Studio, and MMC, in a secure fashion, without system admins being required to continually reenter various passwords that are stored who knows where, it has really made the system admin's job much easier. It has made the PSM's job much easier. It has made the auditor's job and the security team's job and the access manager's job significantly easier, because we're able to move much more quickly toward a role-based access management system, and that is really streamlining the whole onboarding/offboarding management process."
"I found it valuable that CyberArk Privileged Access Manager can be integrated with PTA (privileged threat analytics), and this means that it will tell you if there's a risk to the logins and signs of risk and if risky behavior is observed. It's a good feature. Another good feature is the CPM (central password manager) because it helps you rotate the passwords automatically without involving the admins. It can go and update the scheduled tasks and the services. At the same time, if there's an application where it cannot do all of these, CPM will trigger an automatic email to the application owners, telling them that they should go ahead and change the password. This allows you to manage the account password that CyberArk cannot manage, which helps mitigate the risk of old passwords, where the password gets compromised, and also allows you to manage the security of the domain."
"CyberArk has the ability to change the credentials on every platform."
"The key aspects of privileged access management are being able rotate passwords, make sure someone is accountable, and tie it back to a user (when the system is being used)."
"The solution is scalable."
"CyberArk has helped us to identify, store, protect, and monitor the usage of privileged accounts."
"The product is for hardening access and making the organization more secure, therefore reducing chances of a breach."
"The most powerful feature of the solution is its platform-based approach. Unlike other solutions, this tool offers a high level of customization. It is an open and flexible platform, allowing users to tailor it to their needs. This ability to customize and adapt the solution to individual requirements makes the solution stand out as a powerful product."
"IdentityIQ's best features are the hassle-free user experience and security."
"This solution is easy to configure."
"The tool is quite stable and user-friendly."
"The initial setup isn't so difficult."
"The solution is pretty stable and simple to use."
"The solution is one of the main security products you need to control access and have visibility into what's happening in your organization. It helps with managing access to applications, ensuring governance, and obtaining certifications."
"Provides good authorization and authentication system functionality."
 

Cons

"They can do a better job in the PSM space."
"Performance of PIM could be better and intended for usability as well as security."
"This is probably a common thing, but they do ask for a lot of log files, a lot of information. They ask you to provide a lot of information to them before they're willing to give you anything at all upfront. It would be better if they were a little more give-and-take upfront: "Why don't you try these couple of things while we take your log files and stuff and go research them?" A little bit of that might be more helpful."
"The interface on version 9 looks old."
"CyberArk PAM is a very broad product as everyone's requirements for implementation are different. In our particular case, the initial implementation was planned and developed by people who didn't know our specific network requirements, so the initial implementation needed to be tweaked over time. While this is normal, at the time all these "major" changes required CyberArk professional services to come in-plant and "assist" with the changes."
"Areas the product could be improved are in some of the reporting capabilities and how the reports are configured."
"Tech support staff can be more proactive."
"Integration with the ticketing system should allow any number of fields to be used for validation before allowing a user to be evaluated and able to access a server."
"The connectors are far too manual. This needs to be automated a bit."
"The advanced provisioning features require more improvement."
"I would like to see more Cloud management from this product."
"Regarding the scope for improvement in the solution, reporting is an area that can be a bit more UI-oriented."
"It is not readily available and cannot be downloaded from the net."
"SailPoint IdentityIQ could be cheaper."
"Scalability is hard, especially when you are doing it in real time."
"The UI is complex."
 

Pricing and Cost Advice

"I believe that this solution is priced well. It's the market leader and I think that it's the best solution."
"If you are looking at implementing this solution, buy the training and go to it."
"No, I do not have any advice on the price of the product."
"The cost is high compared to other products."
"I do not have any opinions to add about the pricing of the product."
"The price of CyberArk Privileged Access Manager is expensive. There are no other fees other than the standard licensing fees."
"I haven't seen the numbers. I know it is not cheap, but I don't know what it is. I would rate it a six out of ten in terms of pricing. It is definitely more expensive than the other product, but it also provides more functionality, and it is modular too. So, we pay for the functionality we're actually going to use, and that's nice."
"The solution is very expensive and requires a license. We pay for an enterprise license."
"The product is expensive. People need to opt for a licensing plan for one year or three years."
"The licensing fees are on a yearly basis."
"SailPoint is higher in price as compared to Saviynt. The initial cost of SailPoint is very high. There are additional costs to the standard licensing fees."
"Usually, the cost of deploying about 5,000 licenses or 5,000 users, would be the equivalent to the cost of the license, which would be reaching up to around $90,000."
"It's all competitive. Initially, the prices look a bit higher, but once it gets into a competitive situation, they meet the market. I'd rate it an eight out of ten in terms of pricing. It tends to be more expensive, but it works."
"SailPoint IdentityIQ is too expensive for small and medium companies. It is an expensive product."
"SailPoint IIQ is the best of best. That is reflected in the pricing of the solution. The pricing is based on the number of identities."
"You do pay one price for the license but that price depends on what you choose to include as far as the optional modules go."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Answers from the Community

NC
Dec 1, 2021
Dec 1, 2021
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the management of user identities, systems, data, and cloud services. It works great for Identity Access Management, specifically for cleaning up inactive and orphaned accounts. It has the joiner-mover-lea...
See 2 answers
Nov 17, 2021
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the management of user identities, systems, data, and cloud services. It works great for Identity Access Management, specifically for cleaning up inactive and orphaned accounts. It has the joiner-mover-leaver feature. One of the features we like is the large availability of connectors for different applications and platforms. You can also recertify an account, which is very useful. It is well suited for large companies with lots of users and applications. However, for small companies, it might be a bit of an overkill. Sailpoint has a steep learning curve, so it is not for inexperienced users. Moreover, it doesn’t offer a lot of supporting documentation. It also doesn’t integrate well with other solutions. We chose CyberArk despite the cost because it works great for password management. CyberArk helps manage privileged accounts and service accounts, for example, when users need to connect remotely into systems. It is especially useful for IT staff to access their privileged accounts without having to remember the passwords every time - individually and even as a group. What we like the most about CyberArk is the ease of use and effectiveness in managing privileged accounts. For instance, it automatically changes the passwords for privileged accounts and reconciles and verifies passwords. New users can obtain secure credentials with minimal time and effort. The initial cost is high, which can be a bit of a stretch for small organizations. It also has high requirements for the initial setup and is difficult to customize. The performance could be faster. Conclusions While Sailpoint IdentityIQ is a very good privileged account solution, CyberArk is better suited for us because of its ease of use and efficiency in password management.
DM
Dec 1, 2021
The two products are actually complimentary. Both companies have been very good about staying in their lanes and are their respective market leaders. CyberArk's PAM solution is aimed at protecting privileged accounts by providing features like vaulting, credential rotation, session monitoring and recording. They also have solutions for DevOps and Secrets management. SailPoint is an Identity Governance solution and actually manages CyberArk as an application the same way it manages accounts and privileges in SAP, AD, AAD and over 100 more applications. For CyberArk, it can add/change/delete users as well as create safes and assign users to those safes. At a user account certification time, it will show the CyberArk users and their associated privileges and allow the user's manager or other appropriate people to approve or revoke the privileged access.  SailPoint creates an Identity warehouse so that a user's accounts and entitlements are gathered, managed and reported on in a centralized manner. See Youtube for a quick explanation - SailPoint Identity Governance Integrates with CyberAek Privileged Access Security.  SailPoint does not provide the vault and session management functions that CyberArk does.
 

Top Industries

By visitors reading reviews
Educational Organization
31%
Computer Software Company
12%
Financial Services Firm
11%
Manufacturing Company
5%
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
9%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
CyberArk Privileged Access Manager comes at a high cost. But the solution is worth its price.
What do you like most about SailPoint IdentityIQ?
The first valuable feature of the solution is its interface. The second feature of the solution is the level of flexibility it provides.
What is your experience regarding pricing and costs for SailPoint IdentityIQ?
The product is expensive. People need to opt for a licensing plan for one year or three years.
What needs improvement with SailPoint IdentityIQ?
Regarding the scope for improvement in the solution, reporting is an area that can be a bit more UI-oriented. Apart from that, it's a very good product, and I do not have any complaints about it.
 

Also Known As

CyberArk Privileged Access Security
IdentityIQ, IdentityNow, Cloud Infrastructure Entitlement Management
 

Overview

 

Sample Customers

Rockwell Automation
Adobe, AXA Technology Services, Cuna Mutual Group, Equifax, ING Direct, Orrstown Bank, Rockwell Automation, SallieMae, Spirit Aerosystems, TEL
Find out what your peers are saying about CyberArk, Delinea, BeyondTrust and others in Privileged Access Management (PAM). Updated: June 2024.
787,779 professionals have used our research since 2012.