No more typing reviews! Try our Samantha, our new voice AI agent.

IBM Security Secret Server vs Idira Privileged Access Manager comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Security Secret Server
Ranking in Privileged Access Management (PAM)
20th
Average Rating
8.2
Reviews Sentiment
5.7
Number of Reviews
8
Ranking in other categories
No ranking in other categories
Idira Privileged Access Man...
Ranking in Privileged Access Management (PAM)
1st
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (2nd), Mainframe Security (1st), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

As of September 2026, in the Privileged Access Management (PAM) category, the mindshare of IBM Security Secret Server is 1.4%, up from 1.0% compared to the previous year. The mindshare of Idira Privileged Access Manager is 8.6%, down from 16.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
Idira Privileged Access Manager8.6%
IBM Security Secret Server1.4%
Other90.0%
Privileged Access Management (PAM)
 

Featured Reviews

AsifIqbal - PeerSpot reviewer
Chief Information Security Officer at a insurance company with 501-1,000 employees
Privileged access monitoring has strengthened identity control and improved security posture
I find the monitoring and recording parts of IBM Security Secret Server to be the most valuable features. Password vaulting is somewhat typical, but I rate monitoring and recording as very good features, along with ease of deployment. The reporting tools in IBM Security Secret Server have helped me identify vulnerabilities. From the monitoring part, you can somewhat cover the identity vulnerability aspect. However, for identity vulnerability, I think the best approach is to use IAM rather than PAM. It is easy to integrate IBM Security Secret Server with cybersecurity frameworks, which is a very important aspect. When we are improving our attack surface, identity is the most important thing that we need to cover, and PAM will play a very crucial role in improving our cybersecurity framework and architecture. The main benefits that IBM Security Secret Server provides for me include complete control over the privileged identities, which are the main sources that can have the privilege to make numerous changes on the system. If we protect these identities through PAM and provide elevation on their accounts when required, then we can improve our security posture and infrastructure security.
Atul-Gujar - PeerSpot reviewer
CyberArk manager at a comms service provider with 10,001+ employees
Secures critical infrastructures with essential user session audit records
A potential area for improvement is enhancing support for cluster environments and distributed Vaults. Clients in multiple countries that need central access have different challenges that require better solutions from CyberArk. For financial services, CyberArk can improve incident response by ensuring fast support for critical priority tickets to meet compliance requirements. Providing more documentation on CyberArk is recommended for new team members to enhance their troubleshooting capabilities. I understand it's up to the client, but 99% fail to change the demo key, so it's crucial for CyberArk to emphasize changing the key and documenting it as part of the installation process.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"As a PAM solution, Secret Server performs all the use cases in our environment."
"The live recording is a very useful feature."
"This product has been able to cover most of the requests from our customers."
"Centralized Password Management: Our client has more than 400 geographical locations and approximately ten employees work at each location."
"The main benefits that IBM Security Secret Server provides for me include complete control over the privileged identities, which are the main sources that can have the privilege to make numerous changes on the system, and if we protect these identities through PAM and provide elevation on their accounts when required, then we can improve our security posture and infrastructure security."
"It is one of the most well-known names in this field."
"Access to privileged, shared credentials is simplified by optimizing the whole workflow and approval processes."
"One of the most valuable features is scalability, and how it allows you to scale it without affecting the underlying core components."
"Previously, we used to share passwords for service and normal admin accounts among team members. However, since we started managing it through the product, we've transitioned to individual admin accounts or implemented dual control for shared accounts. With dual control, exclusive checking and checkout options are available, and passwords are not stored in clear text anywhere in the credentials."
"Service count rotation is probably one of my favorite features... The ability to automatically rotate any password I need to really helps with the entire enterprise strategy that we're pushing right now."
"It has a centralized page where you can manage everything. This makes work easier. You don't have to remember different module URLs or browser applications. It is very easy to get all the secure identities of other environments into a single page, which is very important for us as it helps a lot in terms of operations, e.g., reduces management time. This is a single page where you can manage all accounts and onboard them to the CyberArk. You can then secure and see passwords from everywhere. So, there is a single pane of glass where you can manage all the identities across environments as well as across different types of identities."
"Password Vault is probably the top product in that space, and it's a monster to implement, but CyberArk is great at what they do."
"CyberArk is the best out there."
"There are no issues with scalability, and our clients are very happy to use the product."
"We know when passwords will be expiring so we can force users to change their passwords, as well as requiring specific password requirements for length, complexity, etc."
"It takes away all ambiguity around "known" admin accounts."
 

Cons

"The newer interface is more difficult to use than the previous one, and consequently, new users might need more training."
"I mention that password vaulting and password rotation in IBM Security Secret Server are basically the same thing, and it becomes somewhat complex when integrating a different system with them because it requires API development."
"It would be preferable if the full proxy was included in the IBM Security Secret Server."
"Unfortunately, the technical support is not very responsive because we purchased it from IBM; however, the actual support comes from Thycotic."
"What needs improvement in IBM Security Secret Server is support. The local partner provides good support, but IBM itself doesn't. Most of the time, the IBM support team does not aggressively resolve issues reported through chat or the IBM website."
"Although much has improved in last two years, the GUI for IBM products can be improved."
"The nonclustered index is working in an area with a problem that needs improvement."
"If you have a hosted PIM in your local environment and you plan to migrate it to some cloud-based environment, then migration will become a painful task."
"Areas the product could be improved are in some of the reporting capabilities and how the reports are configured."
"I believe account discovery and rolling support need to be improved."
"There are upwards of six components you need to set it up. And you might need anywhere from two to five servers. It takes some work to set that up, especially in a larger environment."
"They are sometimes not flexible with things. For instance, from one day to another, there might be something that had been done years ago by CyberArk, then they say, "We do not support that." You then have to initiate a complaint and start working with them. Things might become complicated and months pass while you are working with them. Usually, they are good and fast, but sometimes they seem to be blocked with problems, e.g., you will suddenly be working with another team instead of the team that you were working with the day before."
"Initial setup was complex and time-consuming but the later versions are a lot faster to implement."
"I would like to see more integration with more tools, for more APIs."
"CyberArk Enterprise Password Vault's deployment is complex for resources with little experience. Tech support needs to be improved as well based on quality and knowledge."
"The initial setup was somewhat complex, but we received help from the product support team with the installation."
 

Pricing and Cost Advice

"My rating for the IBM Security Secret Server pricing is seven out of ten. It could be cheaper."
"I believe that we paid 35,000 or 40,000 US dollars for it."
"The price could be better. I think it's a good price for the on-premises environment and the high availability for enterprises the solution provides."
"It is in line with its competitors, but all such solutions cost too much money."
"Cost efficiency is the number one thing that can be improved in my mind. This would change lots of companies minds on purchasing the product."
"The price of CyberArk Privileged Access Manager is expensive. There are no other fees other than the standard licensing fees."
"I haven't seen the numbers. I know it is not cheap, but I don't know what it is. I would rate it a six out of ten in terms of pricing. It is definitely more expensive than the other product, but it also provides more functionality, and it is modular too. So, we pay for the functionality we're actually going to use, and that's nice."
"With the current model of licensing, for my use cases, sometimes it's hard to convince the management and get budget approvals for it. It's expensive and you're not getting anything new. It's just a control, but in terms of risk, you are covering a big impact on the company. Improvement in the licensing prices is something I would want to have."
"Pricing is a problem. CyberArk is expensive compared to other products I know. It is similar to buying a German car. It comes with all the bells and whistles, but some companies may find it too expensive."
"Payments have to be made on a yearly basis toward the licensing costs of the solution."
"It can be an expensive product."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
911,602 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Insurance Company
19%
Construction Company
12%
Outsourcing Company
10%
Performing Arts
7%
Financial Services Firm
12%
Outsourcing Company
10%
Manufacturing Company
9%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise2
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise175
 

Questions from the Community

What needs improvement with IBM Security Secret Server?
I believe there is not much that can be improved for IBM Security Secret Server. Providing local support and local vendor availability would be beneficial so we are not dependent on international s...
What is your primary use case for IBM Security Secret Server?
IBM Security Secret Server serves multiple use cases for us, including the monitoring of privileged users, as well as the recording and password vaulting of their accounts, passwords, and need-base...
What advice do you have for others considering IBM Security Secret Server?
I mention that password vaulting and password rotation in IBM Security Secret Server are basically the same thing, and it becomes somewhat complex when integrating a different system with them beca...
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What needs improvement with CyberArk Privileged Access Manager?
I believe account discovery and rolling support need to be improved. Account discovery is important when integrating with other systems, as other PAM solutions can perform account discovery and onb...
 

Also Known As

IBM Secret Server, Secret Server, IBM Security Privileged Identity Manager
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

Information Not Available
Rockwell Automation
Find out what your peers are saying about IBM Security Secret Server vs. Idira Privileged Access Manager and other solutions. Updated: August 2026.
911,602 professionals have used our research since 2012.