Try our new research platform with insights from 80,000+ expert users

ForgeRock vs Ping Identity Platform vs SailPoint Identity Security Cloud comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Access Management
Authentication Systems
User Provisioning Software
 

Featured Reviews

Trisha Bhola - PeerSpot reviewer
It's easier to customize and maintain our code
I worked on two different projects based on ForgeRock, and both are automated deployments. One is a UI-based deployment. It's an automated process using some scripts. The deployments are done through Octopus, so it's also automated. We first deploy the essential components of AM and then implement additional configurations like Amster Imports. After that, we import all the SAML Federation data and add some certificates. We have two teams of five and three team members working on the different deployment processes. One is working on the dev side, another is looking at the higher environment, and one is managing the data. In another project, I'm the only developer. We also deploy on the dev environments so that anyone can test new features, configurations, and client requirements. They can test it on the dev environment, but a team of four people manages higher environments. The Access Management component involves the most customization, which takes around 15 to 20 minutes because of the need to import the Amster configuration. If another deployment is simultaneously happening, it may be a little slower and take around 30 minutes. The other components, like the user data stores, take about five to seven minutes. It's another five to 10 minutes for Identity Management. After deployment, the maintenance is mostly checking for security vulnerabilities. If ForgeRock shares security vulnerabilities or advisories, we check to see if there is something inside we need to maintain. Other than that, we just install updates when they add features each month.
Dilip Reddy - PeerSpot reviewer
Easy to use but requires improvements in the area of stability
In my company, we have worked on authorization, and I know that there are different types of grants. We have worked on the authorization code, client credentials, and ROPC grant. There are two types of tokens, like the JWT token and internally managed reference tokens. JWT tokens are useful for finding information related to the claim requests. Internally managed reference tokens are useful for dealing with visual data and information. For the clients to fit the user information, they need to do additional work to fit all the user info into the site, which is to define and validate the token issue and provide the request for VPNs. I worked on the key differences between the authorization code and implicit grant. In the authorization code type, you will have the authorization code issued initially to the client, and the client has to exchange it with the authorization server, like using a DAC channel to get the access token. In implicit grants, tokens are issued right away if the application is a single-page application. We can either use the authorization code or an implicit grant.
Praveen Jalumuru - PeerSpot reviewer
Enhanced automation and AI-driven integration offer significant time savings
The most valuable features include its ability to integrate with AI and machine learning, the automation of reports, and the built-in connectors that enable easy connection with both legacy and cloud-based applications. Its code-less drag-and-drop functionality allows for easier adjustments, and it provides strong support with reduced SLAs compared to SailPoint IQ.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It works very well, especially in Identity and Access Management. It helps detect anomalies in user behavior patterns."
"I like the way it is handling authentication and authorization."
"Even though we have very small business interests with them today, they see that we plan on growing drastically over the next two years. Therefore, we have excellent support and we are now at a point where we are not calling tech support. We pick up a phone and call the Account Manager and they'll get everything resolved for us. We don't have to queue along with everybody else and go through a long process."
"This is a stable solution. When you do experience any issues, you will see it in your DB logs or audit logs so you can easily reach a conclusion of might be causing it."
"ForgeRock has CIAM, which other products didn't have, and they have DevOps ready."
"The product is easy to use in a development environment."
"We have found the identity and access management tools in the solution to be particularly useful for our organization."
"In terms of the tool's operational efficiency, ForgeRock Access Management is used in a lot of environments, different regions, and in different stages of production environments."
"The product's most valuable features include its cloud-based capabilities for handling cloud applications and providing authentication and authorization through OIDC and SAML. It also supports integrations needed for both local and internal applications, including legacy applications requiring web server access."
"It offers robust features and customization options that justify the cost."
"I work on the application onboarding process because we have multiple customers and get data from different sources."
"I would recommend PingFederate as an IAM solution for its no-code environment, single sign-on, multi-factor authentication, bidirectional services, and advanced features."
"The solution is stable. We haven't experienced any bugs or glitches."
"I like the self-service feature. The 502 and UBP systems are also excellent. PingID's ability to authenticate with SSH, RDP, and Windows login is pretty handy. It covers the entire spectrum of use."
"The solution has a smooth and configurable user interface for single sign-on capabilities."
"From a security perspective, I highly value the product's biometric authentication methods such as FIDO, FaceID, YubiKey, and the mobile app."
"Access certification and provisioning are two of the solutions most valuable features."
"Great product to manage the access control of users."
"I find the built-in connectors, lifecycle management, certification, and recertification features to be the most valuable."
"SailPoint has allowed us to ensure the right people have the right access and to the rights things."
"We are happy with the SailPoint IdentityIQ’s stability."
"The solution is stable and reliable."
"We like the integration with other systems."
"Has a great certification module with intuitive options."
 

Cons

"We would like this solution to be developed for use with mobile applications."
"The solution could improve by adding more advertising and marketing."
"The solution requires more simplified customization. However, part of the problem is my clients determining their own preferences. Technology can help and do many things, but you have to define your own policies to ensure that the solution or service works within those parameters. Helping customers understand their business and different processes is another issue not relating to the functionality of this solution."
"The only problem with ForgeRock is that it is derived from an open-source product, so sometimes it's a bit unstable."
"In an upcoming release, the solution could improve by limiting the need to do customizations."
"I find that it's quite expensive for just an open-source system. Support is quite expensive."
"I don't think ForgeRock directly supports integrations with Slack, making it an area where improvements are required."
"The solution's deployment should be made easier."
"The product is not customizable."
"In the beginning, the initial setup was very complex."
"PingID's device management portal should be more easily accessible via a link. They provide no link to the portal like they do for the service. The passwordless functionality could be more comprehensive. You can't filter based on hardware devices. Having that filtering option would be great. Device authentication would be a great feature."
"I think that the connection with like Microsoft Word, especially for Office 365, is a weak point that could be improved."
"The product's community has certain shortcomings that require improvement."
"Notifications and monitoring are two areas with shortcomings in the solution that need improvement."
"PingID classifies the type of environment into internal and external, which is an area for improvement because you need to take additional steps to trust internal and external users."
"One significant challenge was ensuring smooth user migration during system upgrades in Ping."
"Regarding the scope for improvement in the solution, reporting is an area that can be a bit more UI-oriented."
"The price of IdentityIQ could be lower. There are additional costs when you buy the licenses, and they force the customers to pay for them."
"When it comes to queries and analysis, I find the reporting module to be very low, very simple."
"The product has poor reporting and analytic capabilities. Reports are not easy to use and its analytic capabilities are limited."
"The UI of the solution could be more customizable so we could change the workflows to suit our needs."
"The workflow and user interface of SailPoint are not as smooth as ServiceNow's."
"SailPoint IdentityIQ has a primitive AI engine."
"If you compare Saviynt and Okta Workforce Identity versus SailPoint IdentityIQ, SailPoint IdentityIQ needs to improve its UI."
 

Pricing and Cost Advice

"ForgeRock is an expensive solution."
"ForgeRock's pricing is more competitive than other products."
"Its price is comparable to other products in the market."
"The license is purchased annually per user. However, you can negotiate if you are signing for a longer period of time. When comparing this solution to others on the market it is priced fair, it is not at the top of the price range or at the bottom end."
"The pricing of the solution is fair but I do not have the full details."
"It's a bit pricey and could be more competitive."
"We have multiple clients we are looking at right now. We are at a very small number, however, the idea and the goal is to grow. We are looking at about $100,000 and $50,000 a minimum a month cost. That'd be minimum maybe in a couple of years."
"Its licensing is on a yearly basis, but it also depends on the contract that you have with the vendor. They have multiple types of contracts. There are additional costs to the standard licensing fees. If you need some of the features, you have to pay more."
"PingID pricing is a ten out of ten because it's a little bit cheaper than other tools, such as Okta and ForgeRock, and supports multiple tools."
"The platform's value justifies the pricing, especially considering its security features and scalability."
"Ping Identity Platform is not very expensive."
"PingID's pricing is pretty competitive."
"The product is costly."
"The tool is quite affordable."
"The pricing is neither too expensive nor too cheap."
"Compared to some SaaS-based solutions, the platform is relatively cost-effective."
"SailPoint IdentityIQ is too expensive for small and medium companies. It is an expensive product."
"You are able to get discounts if you plan to use the tool for the long-term i.e. discounts for 5+ years of usage."
"The licensing fees are on a yearly basis."
"The product is expensive. People need to opt for a licensing plan for one year or three years."
"In terms of pricing, SailPoint IdentityIQ is affordable. It's not cheap, and it's not expensive, so the solution is in the middle, price-wise. It also didn't have additional costs, even if my company had different teams that took care of auditing and provisioning and projects that used SailPoint IdentityIQ."
"As per my knowledge, it runs on a paid partnership model, but I am not sure about it."
"The pricing is a little bit higher than other tools."
"It is a costly solution. Its cost, for sure, should be reduced."
report
Use our free recommendation engine to learn which Access Management solutions are best for your needs.
850,043 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
24%
Computer Software Company
12%
Insurance Company
7%
Manufacturing Company
7%
Financial Services Firm
26%
Computer Software Company
10%
Manufacturing Company
9%
Insurance Company
6%
Financial Services Firm
18%
Computer Software Company
14%
Manufacturing Company
10%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about ForgeRock?
The most valuable features of ForgeRock are social login and data protection.
What is your experience regarding pricing and costs for ForgeRock?
Our company was considering switching back to Keycloak from ForgeRock, so as to not pay any license fees. ForgeRock a...
What needs improvement with ForgeRock?
In the past, I saw that Splunk was integrated with a testing portal, and then it was integrated with Slack. I don't t...
What do you like most about PingID?
The mobile biometric authentication option improved user experience. It's always about security because, with two-fac...
What is your experience regarding pricing and costs for PingID?
The pricing is neither too expensive nor too cheap.
What needs improvement with PingID?
The management console needs to be improved. PingID should revise it.
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to m...
What is your experience regarding pricing and costs for SailPoint IdentityIQ?
The product is expensive. People need to opt for a licensing plan for one year or three years.
What advice do you have for others considering SailPoint IdentityIQ?
You can use SailPoint Atlas to take identity security to the next level. In SailPoint IIQ, writing a custom connector...
 

Also Known As

ForgeRock Identity Platform, ForgeRock OpenIDM
Ping Identity (ID), PingFederate, PingAccess, PingOne, PingDataGovernance, PingDirectory, OpenDJ
IdentityIQ, IdentityNow, Cloud Infrastructure Entitlement Management, Intello
 

Overview

 

Sample Customers

Geico, Thomson Reuters, Salesforce, McKesson, Trinet, SKY, BNP Paribas, Deloitte, Capgemini, North Western University
Equinix, Land O'Lakes, CDPHP, Box, International SOS, Opower, VSP, Chevron, Truist, Academy of Art University, Northern Air Cargo, Repsol
Adobe, AXA Technology Services, Cuna Mutual Group, Equifax, ING Direct, Orrstown Bank, Rockwell Automation, SallieMae, Spirit Aerosystems, TEL
Find out what your peers are saying about Microsoft, Ping Identity, Okta and others in Access Management. Updated: April 2025.
850,043 professionals have used our research since 2012.