

Find out in this report how the two Access Management solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
On a B2B level, it opened up the market for TomTom to sell its services in a more efficient way to car companies.
We can use a Linux image from ForgeRock with different systems, applications, websites, and mobile apps to create various types of access for users.
I can definitely see that fewer employees are needed compared to using different SaaS applications.
I can definitely say that it saved us time, and a lot of it. Probably months worth of time in engineering and IT support.
The onboarding of temporary privileged access accelerated significantly, allowing us to release consultants much faster than before, saving considerable money.
We need fewer employees now because StrongDM saves our time by eliminating manual work.
The support portals offer comprehensive documentation, troubleshooting guides, and community forums that have been helpful for resolving common issues independently.
For standard support tickets, response times were very decent, and the support team was helpful in identifying configuration issues, especially with authentication trees, token settings, and directory replications.
The team is very responsive and takes a sense of ownership and accountability.
They responded quickly to issues and were readily available for calls rather than waiting for email confirmations.
The technical support is responsive and knowledgeable.
They also have very good documentation, where they often ask us to refer to a particular document but can provide excellent on-call support.
The access management layer is stateless, so I can scale horizontally by adding more nodes behind a load balancer as traffic increases.
The platform provides flexible authentication trees, enabling us to design custom MFA flows tailored for different user groups and risk profiles.
We scaled up with ForgeRock. My team received an award for implementing it for a 60 million customer base, which was the largest implementation at that time.
If a larger organization such as Microsoft or Dell adopted it, there would be more privileged accounts, showing the product's potential to grow if issues in maintenance and crashing are resolved.
StrongDM's scalability is impressive; it is highly available, and we never perceived any latency issues.
StrongDM has very large and good scalability, capable of providing a million data in a second, showcasing its great scalability.
ForgeRock supports integration with legacy systems in our organization by offering a wide range of connectors and APIs.
ForgeRock is very stable because it manages access, authentication, and authorization effectively.
The gateway sometimes crashes, and you are unable to retrieve passwords.
StrongDM is very stable; I cannot recall experiencing a glitch.
I rate the stability of the product five out of ten because crashes sometimes happen when we are working on it.
ForgeRock needs to focus on low-code, no-code solutions that allow for drag-and-drop functionality with good orchestration.
It would be better if they were available for support whenever the customer needs it, especially during migration or go-live time periods.
The main area is complexity. ForgeRock is extremely flexible, but the learning curve can be steep.
StrongDM has limited MFA and passwordless options, relying heavily on time-based one-time passwords (OTP) or Duo, lacking support for true passwordless setups like biometrics or hardware YubiKeys, and it does not support per-session MFA.
It would be beneficial to have better control and alignment between frequent updates and improved communication regarding possible negative effects on existing customer bases.
It is difficult to find documentation or materials to review how it works, and there is less product material available in the market.
One has to spend considerable time trying to understand the different modules and different needs for those modules on the licensing front.
The setup cost was free, with technical staff aiding our onboarding, requiring us only to cover the license fee.
It was mentioned that while the product is rapidly gaining features, it might become cost-prohibitive for wider usage.
My thoughts on the pricing of StrongDM is that it is expensive.
Centralized management makes the biggest difference because it allows us to define, update, and enforce security and compliance rules from a single location.
ForgeRock positively impacts our organization as we manage a large number of users with ease, providing a standard IAM solution that simplifies our processes.
ForgeRock has positively impacted my organization by allowing us to migrate from the older system to the newer ForgeRock component, enabling us to go live with many products across geographies, enhancing security as it is all cloud-based, and with the company taking care of availability, it has reduced costs for the company.
One of the most powerful tools in StrongDM is audit logging.
Just-in-Time Access is the primary feature that works well and makes life easier for us here at LivePerson.
The best features for us are the centralized access control and the detailed audit logging, which allow us to provide temporary privileged access without managing VPNs ourselves.
| Product | Mindshare (%) |
|---|---|
| ForgeRock | 4.0% |
| StrongDM | 0.8% |
| Other | 95.2% |
| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 5 |
| Large Enterprise | 18 |
| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 3 |
| Large Enterprise | 9 |
ForgeRock offers robust integration, customization, and identity management with support for SAML, OAuth 2.0, and DevOps readiness, ensuring enhanced security and scalability.
ForgeRock stands out in identity and access management featuring flexible authentication flows, risk-based authentication, centralized policy management, and comprehensive data protection. Its open-source foundation and cloud capabilities allow versatility and ease of use. While it provides excellent user path orchestration through the Journey feature, challenges exist in integration support and user-friendly customization. Improved documentation and streamlined interfaces are necessary to overcome deployment complexities. Additionally, the cost and support model may be burdensome for smaller organizations.
What are the key features?ForgeRock is widely utilized in industries like telecommunications, insurance, and open banking for secure user authentication and access management. It supports microservice authentications, customer identity management, single sign-on, and multi-factor authentication, integrating effectively with existing infrastructures to enhance security and user experience.
StrongDM streamlines secure, password-less access, reducing attack surfaces with its zero trust approach. It integrates smoothly with existing systems supporting IP whitelisting and excels in managing runtime features while offering comprehensive audit logging and seamless resource access.
StrongDM provides organizations with enhanced security through features like password rotation and efficient management of access to resources such as EC2 instances, Kubernetes clusters, and databases. Its integration capabilities are complemented by cost-effectiveness compared to competitors like CyberArk. Companies utilize StrongDM for controlling access in dynamic environments, benefiting from audit logging for detailed movement tracking. While users appreciate its efficiency, they also seek improvements in update control and better accompanying documentation. Some express the need for a cloud-native option to address diverse demands, as the current setup can be challenging without comprehensive materials. Flexibility and more traditional PAM features are in demand.
What are StrongDM's key features?In industries managing sensitive data or requiring regulated access, StrongDM is crucial for securing cloud private networks and managing user access to databases and hosts. DevOps teams benefit from its ability to protect connectivity to backend servers, ensuring identity and access management remains robust and adaptable for companies dealing with frequent changes or expansions.
We monitor all Access Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.