We performed a comparison between CyberArk Privileged Access Manager, SailPoint IdentityIQ, and SAP Identity Management based on real PeerSpot user reviews.
Find out what your peers are saying about CyberArk, Delinea, BeyondTrust and others in Privileged Access Management (PAM)."AIM has been a great help in automating password retrieval which removes the need for hard-coded credentials."
"On the customer accounts side, our account managers are responsive. If you ask them, they will get you whomever you need."
"For a while, there were individual IDs having privileged access. We wanted to restrict that. We implemented the solution so that it can be more of internal control. We can have session recordings happening and reduce our attacks."
"We are able to rotate privileged user passwords to eliminate fraudulent use."
"The ability to develop and deploy applications with no stored secrets is very valuable."
"Creating policies and the password rotation feature have been valuable. We don't have to memorize our password for the ADM account."
"Its' quite stable."
"All of the features of CyberArk Privileged Access Manager are valuable."
"User provisioning and the role management features are good."
"A feature of SailPoint IdentityIQ that I like best is that it has good integration with other platforms. My company is using ADP here in Brazil, and SailPoint IdentityIQ works very, very well with it. My company is also using the solution for governance evaluation, segregation, and other access tests. For my company, SailPoint IdentityIQ is a very important solution, especially because it's automated, and there's a huge audit and risk issue here in Brazil."
"It is a scalable product."
"The tool is quite stable and user-friendly."
"The initial setup isn't so difficult."
"The solution is pretty stable and simple to use."
"What I like most about SailPoint IdentityIQ is that it's simple to use and easy to configure and deploy."
"The basic concept is most valuable. I like how they have designed the solution. They create an Identity Cube, and then they do all the processes and configuration around the Identity Cube."
"The setup process is straightforward."
"The most valuable feature is the user experience for managing information."
"What I found most valuable in SAP Identity Management is process automation. The solution also gives transparency about what is happening and why which I find beneficial. Another feature I found valuable in SAP Identity Management is integration. It has very good integration."
"What's most valuable in SAP Identity Management is that it's easily an out-of-the-box solution for connectivity with SAP applications. We do not have to do any customizations, and this makes the solution very compatible with most SAP applications. SAP Identity Management is also very user-friendly."
"What I like about SAP Identity Management is that it's stable for experienced users and suitable for access management, not just for SAP accounts, but for Active Directory, including file sharing and process sharing."
"It provides basic automatic user administration and role provisioning to save time."
"The most valuable features of SAP Identity Management are business roles and automated user provisioning."
"Rather than implement a basic SSO, this solution assisted us with setting up two-factor authentication."
"There is a lot of room for improvement in the report section. I also work on other tools, such as Thycotic, which allows you to create customized reports for your organization's needs. In CyberArk, there are limited reports, whereas in Thycotic or some of the other PAM tools, because the database is different, you can customize the report based on your needs through SQL queries."
"Many of the infrastructure folks who use the product dislike it because it complicates their workflow. They get a little less control, and they have to go through a specific solution. It proactively logs in for them, which obfuscates some of the issues that they may be troubleshooting."
"It should be easy to use for non-technical people. Its interface can be a bit difficult. Some parts of its interface are not very intuitive. Some of the controls are hidden, and instead of having a screen with all the controls for that account on it, you have to use menus and other similar things."
"The PTA could be improved. Currently, companies often have multiple domains and sometimes it's difficult to implement CyberArk in this kind of infrastructure. For example, you can add CPM (Central Policy Manager) and PSM (Privileged Session Manager and PVWA (Password Vault Web Access) for access, but if you want to add PTA (Privileged Threat Analysis) to scan Vault logs, it is difficult because this component may be adding multiple domain environments."
"CyberArk has to continue to evolve with that threat landscape to make sure that they're still protecting those credentials that are owned by those that have privileged accounts in the firms."
"I would love them to improve their UI customizing features."
"They can do a better job in the PSM space."
"We need a bit more education for our user community because they are not using it to its capabilities."
"The mover process for this solution could be improved."
"The UI is complex."
"Needs to focus on automation wherein provisioning of work can be improved and access certification should be automated without the intervention from a manager for approval."
"What it doesn't do is provide notice in the event of a vulnerability or offense from the security."
"The solution, in general, is quite expensive."
"The interface should be simple and easier to use."
"In the past, we had a lot of problems with SailPoint IdentityIQ, particularly in providing access and provisioning. There were some gaps in the operation of the solution because they were manual rather than automated, and the users and administrators were given access directly via Active Directory, and it wasn't appropriate for us at the time to use. In terms of integration, we could provide a more automated solution after a minimum number of years, but not in the SailPoint IdentityIQ platform, but there were problems in the registration, for example, with putting information inside ADP, but in general, we were able to solve those problems, and after implementing SailPoint IdentityIQ we had increased evaluations."
"It allowed to implement the automated processes when a new employee is hired. It allows to have a main central process for new hires."
"I find SAP Identity Management complicated to use. Maintaining it is also complex."
"SAP Identity Management can improve risk analysis and authority checks."
"A lack of startup connectors to different systems, and could have better connectors for SAP IDM."
"Research and marketing need to be improved."
"What needs improvement in SAP Identity Management is its compatibility with third-party applications. We'd like to get connectors or plugin settings to make it easier to manage other applications, whether SAP or non SAP applications. As SAP Identity Management is not compatible with non SAP applications, some of the clients are looking for other IDM applications such as SalePoint and Saviynt, so this is an issue we've observed in the solution."
"One of the areas for improvement in the solution is its user interface which needs to be up-to-date and fancier, in particular, have better visualization in terms of the tabs and buttons. The user interface of SAP Identity Management should be improved based on the latest trends."
"The pricing could be better."
"I have encountered issues with the host authentication feature."
More CyberArk Privileged Access Manager Pricing and Cost Advice →