No more typing reviews! Try our Samantha, our new voice AI agent.

Idira Endpoint Privilege Manager vs VMware Carbon Black App Control comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Idira Endpoint Privilege Ma...
Ranking in Application Control
6th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
38
Ranking in other categories
Endpoint Compliance (5th), Privileged Access Management (PAM) (6th), Anti-Malware Tools (10th), Ransomware Protection (4th)
VMware Carbon Black App Con...
Ranking in Application Control
7th
Average Rating
9.2
Reviews Sentiment
6.8
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Application Control category, the mindshare of Idira Endpoint Privilege Manager is 9.6%, up from 4.7% compared to the previous year. The mindshare of VMware Carbon Black App Control is 9.7%, down from 15.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Control Mindshare Distribution
ProductMindshare (%)
Idira Endpoint Privilege Manager9.6%
VMware Carbon Black App Control9.7%
Other80.7%
Application Control
 

Featured Reviews

Sumit Chavan - PeerSpot reviewer
Lead Consultant at a tech vendor with 501-1,000 employees
Helps secure the infrastructure and control users with admin rights
There are many features that are currently missing. A customization option is required for certain policies. For instance, if we need to stop PowerShell scripting, we have to create a different policy for that. Being able to create a sub-level policy within a top-level policy would be good. Currently, no user-based policy option is available inside the EPM console. We can only create computer-based policies. The database is available, but there is a drawback in not being able to create local groups on the EPM console. We only have to depend on Active Directory. This limits infrastructure security as we depend on the Active Directory team to manage user groups. If they remove any users, we lose control. If we could create groups locally and block them or set specific policies, we would have more control. Local endpoint management is missing from the EPM site. Moreover, there is an issue with policies not running as expected when we make enhancements. We have to find multiple ways to whitelist applications or enhance policies.
AS
Security Administrator at EJADA
We can isolate problem machines and limit their access
We use App Control to scan the network for virtual machines that have unauthorized applications. We can isolate the problem VMs and control application access.  More than two years. I rate Carbon Black App Control 10 out of 10 for stability. I rate App Control six out of 10 for scalability.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product is very flexible"
"Our setup process is moving to the cloud, which is very good. It reduces complexity."
"We can do both server and endpoint protection."
"The solution is pretty mature and can accommodate our use cases quite well."
"CyberArk Endpoint Privilege Manager is entirely cloud-based, so no further upkeep is required."
"The most valuable feature of CyberArk Endpoint Privilege Manager is its ability to reset passwords every time that it is needed or periodically."
"CyberArk Endpoint Privilege Manager enhances computer security by providing minimal access, effectively preventing ransomware attacks."
"We were able to reduce the number of privileged accounts by 50%, which helped to simplify our privileged access management environment."
"All the functions within VMware Carbon Black App Control are valuable."
"It offers a sense of security where anything that comes in, regardless of what it is, unless you approve it manually, it's not going to run."
"Overall, this is a good product and one that I recommend."
"The visibility is valuable."
"I use the console to check for threats and I find it to be very user-friendly."
"The API integration is good."
"We have been dealing with VMware Carbon Black App Control for one year, and during this time we have already made sure that this is the best solution to protect our user machines and servers."
"The effectiveness of application whitelisting is very good."
 

Cons

"The solution is good but can be improved by allowing computers to be excluded from policies."
"Another enhancement needed is the scheduling of deployment, which I expect in future releases."
"CyberArk Endpoint Privilege Manager is not suitable for the current situation because when you compare it to OTP, OTP is the strongest password solution. You can use it as a one-time password, but you have to log into the password manager itself and if you don't change your password, it will be the weakest link in the security. In OTP, you don't have that weakest link."
"CyberArk Endpoint Privilege Manager could be improved by simplifying the administration process, specifically when setting up policies and applications."
"For an experienced system implementer it will take approximately one day. However, for somebody who is inexperienced it may take up to five days."
"The solution is very expensive."
"The solution can be complex to use at times."
"The CyberArk team is working on a feature to identify devices without the Endpoint Privilege Manager running, which is currently missing."
"The solution should have overhead in keeping lists of applications that you want don't want to run."
"I would like to see the addition of some more features that are in other, similar solutions."
"I rate App Control six out of 10 for scalability."
"Another issue is that even sometimes if you approve, for example, Adobe as a publisher, you say any product or anything that's from Adobe has to run. It generally runs, but especially in a large environment and with a lot of users, sometimes, due to some certification validation issues or some other issue, it might stop the process from running. Genuine processes like Adobe and Chrome can get blocked. so that needs to be improved."
"The reporting is not good and needs to be improved."
"Carbon Black does not use the database for identifying the file, the fields, or malware."
"Its setup is very complex, and it requires guidance from the support team, but it is well worth the effort."
"The initial setup is somewhat complex."
 

Pricing and Cost Advice

"We pay about $17 per user."
"The professional services for one eight-hour day would be $1,800."
"The tool's pricing is reasonable for customers."
"The price of CyberArk Endpoint Privilege Manager is expensive."
"The cost for CyberArk is very high."
"CyberArk Endpoint Privilege Manager has a very high price, so it's a one out of ten for me in terms of pricing."
"It's not at the lower end of the market. I think the price is reasonable considering the quality it delivers. It is a top-notch solution at a fair price point."
"Pricing depends on how many devices you use. Right now, on-premise, it costs us a little, but it's worth it. It seems like the cloud solution is much more expensive. We got this solution one year ago, and it's like we bought the solution, and now they are not going to support it on-premise anymore. We are in the implementation phase, and we missed this, and we already paid for the licenses. This is wasted time from my perspective, and CyberArk should be more customer-friendly."
"The pricing for this product is competitive and our customers who told us that often, Carbon Back is the cheaper solution."
"We pay a fee for support, which is renewed annually."
"Its price is reasonable and what is expected for these types of products."
report
Use our free recommendation engine to learn which Application Control solutions are best for your needs.
911,994 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
10%
Outsourcing Company
9%
Construction Company
8%
Financial Services Firm
22%
Computer Software Company
10%
Outsourcing Company
10%
Healthcare Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise19
By reviewers
Company SizeCount
Small Business4
Large Enterprise4
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What is your experience regarding pricing and costs for CyberArk Endpoint Privilege Manager?
I believe it's quite a reasonably priced solution. It's not very common to use CyberArk because it's a niche solution, but customers who are willing to control administrative accounts are willing t...
What needs improvement with CyberArk Endpoint Privilege Manager?
While CyberArk Endpoint Privilege Manager is a great tool, I believe the functionality could be wider. If it could work not only with permissions but also involve pure EDR tasks or User and Entity ...
Ask a question
Earn 20 points
 

Also Known As

Viewfinity
CB Protection, Carbon Black CB Protection
 

Overview

 

Sample Customers

Information Not Available
Kaas Tailored, Core-Mark, Indeed, Hologic, Landmark Credit Union, Project Worldwide
Find out what your peers are saying about Idira Endpoint Privilege Manager vs. VMware Carbon Black App Control and other solutions. Updated: August 2026.
911,994 professionals have used our research since 2012.