No more typing reviews! Try our Samantha, our new voice AI agent.

Idira Endpoint Privilege Manager vs KeeperPAM comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Idira Endpoint Privilege Ma...
Ranking in Privileged Access Management (PAM)
6th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
38
Ranking in other categories
Endpoint Compliance (5th), Anti-Malware Tools (10th), Application Control (6th), Ransomware Protection (4th)
KeeperPAM
Ranking in Privileged Access Management (PAM)
27th
Average Rating
8.0
Number of Reviews
1
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Privileged Access Management (PAM) category, the mindshare of Idira Endpoint Privilege Manager is 2.5%, down from 3.2% compared to the previous year. The mindshare of KeeperPAM is 1.5%, up from 0.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
Idira Endpoint Privilege Manager2.5%
KeeperPAM1.5%
Other96.0%
Privileged Access Management (PAM)
 

Featured Reviews

Sumit Chavan - PeerSpot reviewer
Lead Consultant at a tech vendor with 501-1,000 employees
Helps secure the infrastructure and control users with admin rights
There are many features that are currently missing. A customization option is required for certain policies. For instance, if we need to stop PowerShell scripting, we have to create a different policy for that. Being able to create a sub-level policy within a top-level policy would be good. Currently, no user-based policy option is available inside the EPM console. We can only create computer-based policies. The database is available, but there is a drawback in not being able to create local groups on the EPM console. We only have to depend on Active Directory. This limits infrastructure security as we depend on the Active Directory team to manage user groups. If they remove any users, we lose control. If we could create groups locally and block them or set specific policies, we would have more control. Local endpoint management is missing from the EPM site. Moreover, there is an issue with policies not running as expected when we make enhancements. We have to find multiple ways to whitelist applications or enhance policies.
Mahesh-Subramanian - PeerSpot reviewer
Vice President at Chargebacks911
Offers security audit that shows us how many passwords are weak and how often they're being changed
There are a couple of things. One is the BreachWatch feature. It's one of the most useful things because it shows us who on our team has weak or compromised passwords. So, it checks the passwords and helps improve them. There's also a security audit that shows us how many passwords are weak and how often they're being changed. Some people haven't changed their passwords for months, even though applications force them to change every 45 or 90 days. So you can catch those issues and warn them. Most applications allow for rotation, but some don't. I've seen people use the same password for years. At least Keeper tells us these passwords haven't been rotated, and we can warn them to change them manually since we can't force people to change the password.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"There are many valuable aspects of the product, but the most common feature is working with the privileges. The controls of CyberArk Endpoint Privilege Manager influence the visibility into endpoints for my customers. It allows them to granularly manage controls to prevent some malicious activities on the endpoint machine."
"The stability of CyberArk Endpoint Privilege Manager is excellent, with an uptime of 99.99 percent."
"The most valuable feature is the ability to control users with admin rights. Even if developers and senior folks maintain their admin rights, we can still manage their activities."
"CyberArk Endpoint Privilege Manager has had a positive impact on my customers' security posture."
"The tool is an endpoint management system. It monitors everything a standard user does and helps elevate privileges when necessary for advanced users. It keeps an auditable trail of all activities. Practically, it stops and blocks potentially hazardous user behavior, whether intentional or unintentional. Certain companies must use endpoint management software because of national or international rules or ISO norms."
"In terms of ROI, deploying CyberArk Endpoint Privilege Manager has secured the infrastructure, which saves money, time, and resources."
"Their customer support was excellent."
"CyberArk Endpoint Privilege Manager (EPM) 's most valuable feature is its ability to manage user application privileges and protect against ransomware attacks by controlling access to specific files and applications."
"BreachWatch feature is one of the most useful things because it shows us who on our team has weak or compromised passwords."
 

Cons

"If you do not have certification, you cannot send a ticket; this makes dealing with technical support difficult."
"Performance could be better. We have a couple of problems with CyberArk right now. One of the problems is performance in our environment. Support also takes a long time to respond. If the user already has local admin rights, then I can't collect any events in the console from this device. There are also some options in CyberArk that are not working properly, and are not helpful in this case. I can't collect any information to create a proper policy for the device. I have to investigate everything manually, or even disable the local admin from the device. I can collect the events only after this, and it's very time consuming. In my case, it's a waste of resources."
"The solution is good but can be improved by allowing computers to be excluded from policies."
"A customization option is required for certain policies. For instance, if we need to stop PowerShell scripting, we have to create a different policy for that. Being able to create a sub-level policy within a top-level policy would be good."
"CyberArk Endpoint Privilege Manager can be better by making its UI more consistent."
"We have had some major issues with the tool, but we have worked with the R&D teams and we have worked with support. There is room for improvement, especially on response times. But they're working on it and they're doing the best they can."
"The solution's pricing could be better."
"The CyberArk team is working on a feature to identify devices without the Endpoint Privilege Manager running, which is currently missing."
"The final implementation was challenging because we had to roll it out to three different departments within the same umbrella, each with its own domains."
 

Pricing and Cost Advice

"The professional services for one eight-hour day would be $1,800."
"I think that it was in the range of $200,000 that had to get approved."
"I believe it's quite a reasonably priced solution. It's not very common to use CyberArk because it's a niche solution, but customers who are willing to control administrative accounts are willing to pay this money."
"It is an expensive solution."
"licensing for this solution is based on the number of APV (privileged users), and the number of sessions that you want to record."
"We pay about $17 per user."
"The tool is priced high. I would rate its pricing an eight out of ten."
"The tool is a bit pricey compared to its competitors. My company does work with competitors, but I don't have hands-on experience with other software. I've just done some comparisons."
"It's good value for money."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Outsourcing Company
11%
Manufacturing Company
10%
Construction Company
8%
Manufacturing Company
14%
Financial Services Firm
14%
Energy/Utilities Company
7%
Media Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise19
No data available
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What is your experience regarding pricing and costs for CyberArk Endpoint Privilege Manager?
I believe it's quite a reasonably priced solution. It's not very common to use CyberArk because it's a niche solution, but customers who are willing to control administrative accounts are willing t...
What needs improvement with CyberArk Endpoint Privilege Manager?
While CyberArk Endpoint Privilege Manager is a great tool, I believe the functionality could be wider. If it could work not only with permissions but also involve pure EDR tasks or User and Entity ...
Ask a question
Earn 20 points
 

Also Known As

Viewfinity
No data available
 

Overview

Find out what your peers are saying about Idira by Palo Alto Networks, One Identity, Okta and others in Privileged Access Management (PAM). Updated: August 2026.
913,683 professionals have used our research since 2012.