No more typing reviews! Try our Samantha, our new voice AI agent.

IBM Resource Access Control Facility vs Idira Privileged Access Manager comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Resource Access Control...
Ranking in Mainframe Security
5th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
3
Ranking in other categories
No ranking in other categories
Idira Privileged Access Man...
Ranking in Mainframe Security
1st
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (2nd), Privileged Access Management (PAM) (1st), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

As of September 2026, in the Mainframe Security category, the mindshare of IBM Resource Access Control Facility is 10.7%, down from 15.1% compared to the previous year. The mindshare of Idira Privileged Access Manager is 5.9%, up from 4.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Mainframe Security Mindshare Distribution
ProductMindshare (%)
Idira Privileged Access Manager5.9%
IBM Resource Access Control Facility10.7%
Other83.4%
Mainframe Security
 

Featured Reviews

KC
Senior systems engineer at Unum
We're able to do role-based security so when new people join the company we're able to quickly add them to the proper security through role-based security groups.
It's completely secure. That's the best answer I can give you. We're able to do role-based security so when new people join the company we're able to quickly add them to the proper security through role-based security groups. Our resources are secured with this product I would welcome something…
Singaravelu C - PeerSpot reviewer
CyberArk Engineer at Tata Consultancy
Provides full visibility into user activity and ensures secure end-to-end access across critical systems
In CyberArk Privileged Access Manager, I see room for improvement as I am working in the on-premises networks, and now we are also having the cloud-based PAM. So there, everything is maintained by the CyberArk Privileged Access Manager team, and we are only maintaining the PSM servers. So it is already upgraded from the on-premises network to the cloud network. If you ask me what we can implement beyond that, I just need a few minutes to think about what new things, because it is already an end-to-end security on-premises itself. Now, when it comes to PCloud, Privileged Cloud, it is more secure than the on-premises networks because most of the things are handled using the cloud itself. So it is an already upgraded version; we do not need to implement something new. But if you think in that way, we can have a chance to implement our things. If anything could be improved in CyberArk Privileged Access Manager, I think we could build a small agent AI in my team, we could give access to these logs—the Vault logs, PSM logs, and CPM logs. Whenever the system is going down, the AI will automatically check. If we actually implement agent AI in CyberArk Privileged Access Manager, it will check the logs, and if any errors are coming, it automatically triggers alerts and gives the solution. That is the best improvement I can think of because these days, most things are done by agent AI. So if we also implement this agent AI in CyberArk Privileged Access Manager, we can add more features.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's completely secure."
"Technical support is exceptional."
"Perfectly integrated with the z/OS operating system and all the other products in the IBM z/OS family."
"We chose CyberArk because of its great functionalities, the ability to be deployed granularly at a different scale for each function, and the ability to be deployed in a distributed infrastructure."
"Right off the bat, the most valuable feature is the DNA scan. It gives us the ability to scan our environment and find the accounts that we're going to need to take under control."
"The benefit is knowing where your accesses are, who has access to what, and it provides improved security around having your credentials locked down and rotated regularly."
"Thus far I can say technical support is excellent. We haven't had any issues or difficulties."
"The solution is very complete; it has the most features on the market, session monitoring is excellent and may be the solution's most valuable aspect, and it offers very good password protection with great integration with many products."
"We found the initial setup to be easy."
"I would recommend CyberArk Privileged Access Manager because it is a leading solution for privileged access management."
"We have the identity provider for all the authentication processes. However, sometimes, we need access to different applications for customers or clients that are not integrated into the identity provider. For these, we need to store a password to gain access. For example, we use the CyberArk Password Vault for third-party services. This vault needs to be shared with many people in our company."
 

Cons

"I would like the generation of RACF on-screen listings and reports to be more flexible."
"I would welcome something that is more easily integrated with distributor platforms."
"The way to pull security logs could be better."
"CyberArk's license is too expensive. I rate it seven out of 10 for affordability."
"The documentation is rather basic and it is missing many use cases."
"Areas of CyberArk Privileged Access Manager that can be improved include offering clearer configuration options."
"CyberArk has a lot on the privileged access side but they have to concentrate more on the application side as well."
"Sometimes the infrastructure team is hesitant to provide more resources."
"CyberArk lacks the following functions for a better IAM like solution: - Provision accounts for systems and directories. - Create access to the systems. - Monitor if any new account has been created into the system. - Better GUI for the end-user and also for administrators."
"Regarding technical support from CyberArk, while L2 and L3 teams are effective, L1 support requires improvement due to longer response times in critical situations."
"The major pain point that we have is the capacity of CyberArk due to the sheer volume of NPAs that we are managing. We are a large organization and we have hundreds of thousands of non-personal accounts to manage. We have already found out that there are certain capacity limitations within CyberArk that might introduce performance issues. From my perspective, something that would be valuable would be if the vault could hold more passwords and be more scalable."
 

Pricing and Cost Advice

Information not available
"Although CyberArk Privileged Access Management is expensive, its protection capabilities outweigh the cost."
"CyberArk Enterprise Password Vault's pricing is reasonable."
"The price of this solution is quite reasonable."
"I focus more on the technical side, but I hear customers say that if CyberArk was more affordable, they might have acquired more licenses. Some clients consider alternative solutions due to pricing concerns."
"With reducing the privileged account access, there has been a huge improvement. They are now bringing more accounts on a little at a time."
"I would rate CyberArk's pricing a nine out of ten, with one being cheap and ten being expensive. It's one of the most expensive solutions in the market, but it's worth it."
"My company always complains about the cost of CyberArk Privileged Access Manager because it's too high."
"Pricing and licensing depend on the environment."
report
Use our free recommendation engine to learn which Mainframe Security solutions are best for your needs.
913,654 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Government
15%
Manufacturing Company
11%
Outsourcing Company
7%
Outsourcing Company
12%
Financial Services Firm
11%
Manufacturing Company
9%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise175
 

Questions from the Community

Ask a question
Earn 20 points
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What needs improvement with CyberArk Privileged Access Manager?
I believe account discovery and rolling support need to be improved. Account discovery is important when integrating with other systems, as other PAM solutions can perform account discovery and onb...
 

Also Known As

IBM RACF
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

Information Not Available
Rockwell Automation
Find out what your peers are saying about IBM Resource Access Control Facility vs. Idira Privileged Access Manager and other solutions. Updated: September 2026.
913,654 professionals have used our research since 2012.