No more typing reviews! Try our Samantha, our new voice AI agent.

Idira Endpoint Privilege Manager vs VMware Carbon Black App Control comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Idira Endpoint Privilege Ma...
Ranking in Application Control
5th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
38
Ranking in other categories
Endpoint Compliance (5th), Privileged Access Management (PAM) (5th), Anti-Malware Tools (11th), Ransomware Protection (6th)
VMware Carbon Black App Con...
Ranking in Application Control
7th
Average Rating
9.2
Reviews Sentiment
6.8
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Application Control category, the mindshare of Idira Endpoint Privilege Manager is 9.0%, up from 3.5% compared to the previous year. The mindshare of VMware Carbon Black App Control is 10.3%, down from 22.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Control Mindshare Distribution
ProductMindshare (%)
CyberArk Endpoint Privilege Manager9.0%
VMware Carbon Black App Control10.3%
Other80.7%
Application Control
 

Featured Reviews

DR
Commercial and Technical Professional Manager at Evolution Technologies Group
Strengthening financial services infrastructure by safeguarding and integrating with ecosystems
We use CyberArk Endpoint Privilege Manager to complement a privilege access management solution in order to avoid golden ticket attacks and strengthen services against attacks. It serves as a complement to our asset management solution. The architecture of CyberArk Endpoint Privilege Manager is beneficial for integrating with all customer ecosystems; it's easy to deploy, and achieving that level of integration and control is more challenging with other solutions. The ability of CyberArk Endpoint Privilege Manager to safeguard our financial services infrastructure is very important, as we need to record actions on privileges in our information systems. Regarding the granularity of the managed controls in CyberArk Endpoint Privilege Manager, we have different levels of features to define compensations and capabilities, which help us verify configurations and access, ultimately keeping the safety of rights intact. Our initial challenge with CyberArk Endpoint Privilege Manager is to comply with Colombian regulations in the financial sector, particularly identifying users and managing password changes and rotations. We needed to certify the identities and provide necessary information for government investigations, if required. CyberArk Endpoint Privilege Manager is very important for helping our organization meet compliance and regulatory requirements. We have to comply with international regulations such as SOC, but also with local regulations unique to the financial sector, which is crucial for us due to the high risks involved. CyberArk Endpoint Privilege Manager helped us reduce the time for regulatory processes to approximately two to four months, completing the solution and training. CyberArk Endpoint Privilege Manager has helped us reduce the mean time to detect within our organization. That's our main goal. Regarding MTTD, the solution provides enough information to enhance our overall detection process. We have an 85% improvement in MTTD. CyberArk Endpoint Privilege Manager helps ensure data privacy through strategies that manage information in real-time. CyberArk Endpoint Privilege Manager helps save costs by avoiding risks and future expenses associated with security incidents. It's essential to communicate the value of CyberArk Endpoint Privilege Manager to users, as its controls help improve system security. My role at the company involves service and sales activities.
AS
Security Administrator at EJADA
We can isolate problem machines and limit their access
We use App Control to scan the network for virtual machines that have unauthorized applications. We can isolate the problem VMs and control application access.  More than two years. I rate Carbon Black App Control 10 out of 10 for stability. I rate App Control six out of 10 for scalability.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The stability of CyberArk Endpoint Privilege Manager is excellent, with an uptime of 99.99 percent."
"The most valuable feature of the solution is its performance."
"What sets CyberArk apart is its continuous innovation, staying ahead of the competition."
"This is the number one product for privilege account security."
"The solution is pretty mature and can accommodate our use cases quite well."
"The biggest benefit of CyberArk EPM for our customers is control over privileged access for endpoints. Endpoints are often the starting point for attackers to enter and move within a network. CyberArk EPM bridges the gap between security and operations teams. Operations teams are happy because work isn't stopped due to admin rights issues, while security teams are satisfied that full admin rights aren't given to all users."
"The tool is an endpoint management system. It monitors everything a standard user does and helps elevate privileges when necessary for advanced users. It keeps an auditable trail of all activities. Practically, it stops and blocks potentially hazardous user behavior, whether intentional or unintentional. Certain companies must use endpoint management software because of national or international rules or ISO norms."
"There are many valuable aspects of the product, but the most common feature is working with the privileges. The controls of CyberArk Endpoint Privilege Manager influence the visibility into endpoints for my customers. It allows them to granularly manage controls to prevent some malicious activities on the endpoint machine."
"It offers a sense of security where anything that comes in, regardless of what it is, unless you approve it manually, it's not going to run."
"Carbon Black offers a total lockdown solution; it shows us the attacks that are being attempted against our infrastructure and how we are being protected."
"The effectiveness of application whitelisting is very good."
"The visibility, reporting, and the ability to stop or prevent malicious or undesired applications from being installed are the most valuable features."
"All the functions within VMware Carbon Black App Control are valuable."
"I use the console to check for threats and I find it to be very user-friendly."
"If any malicious activity, like VAT viruses, anything RNE, ZOD malware, or something similar, comes in we know that unless we approve it, it's going to be blocked."
"All the functions within VMware Carbon Black App Control are valuable."
 

Cons

"CyberArk meets clients' need very spot-on. It covers everything customers ask for. As for improvements, honestly, the feedback's been really positive. I haven't heard any specific areas that need work."
"It cannot be on-prem. It is only cloud-based. Sometimes, that's a restriction in terms of usage."
"Compared to other tools like Linux, this solution isn't as user-friendly."
"CyberArk Endpoint Privilege Manager could be improved by simplifying the administration process, specifically when setting up policies and applications."
"Performance could be better. We have a couple of problems with CyberArk right now. One of the problems is performance in our environment. Support also takes a long time to respond. If the user already has local admin rights, then I can't collect any events in the console from this device. There are also some options in CyberArk that are not working properly, and are not helpful in this case. I can't collect any information to create a proper policy for the device. I have to investigate everything manually, or even disable the local admin from the device. I can collect the events only after this, and it's very time consuming. In my case, it's a waste of resources."
"The CyberArk team is working on a feature to identify devices without the Endpoint Privilege Manager running, which is currently missing."
"CyberArk should consider whitelisting important applications like PowerShell and DLL that are currently not allowed due to some malicious content."
"CyberArk Endpoint Privilege Manager is not suitable for the current situation because when you compare it to OTP, OTP is the strongest password solution."
"Another issue is that even sometimes if you approve, for example, Adobe as a publisher, you say any product or anything that's from Adobe has to run. It generally runs, but especially in a large environment and with a lot of users, sometimes, due to some certification validation issues or some other issue, it might stop the process from running. Genuine processes like Adobe and Chrome can get blocked. so that needs to be improved."
"The reporting is not good and needs to be improved."
"Its setup is very complex, and it requires guidance from the support team, but it is well worth the effort."
"The initial setup is somewhat complex."
"Carbon Black does not use the database for identifying the file, the fields, or malware."
"I rate App Control six out of 10 for scalability."
"Another issue is that even sometimes if you approve, for example, Adobe as a publisher, you say any product or anything that's from Adobe has to run. It generally runs, but especially in a large environment and with a lot of users, sometimes, due to some certification validation issues or some other issue, it might stop the process from running."
"The initial setup is somewhat complex."
 

Pricing and Cost Advice

"The tool's pricing is reasonable for customers."
"The cost for CyberArk is very high."
"CyberArk Endpoint Privilege Manager is slightly expensive, but costs can be negotiated to become more competitive."
"I think that it was in the range of $200,000 that had to get approved."
"CyberArk Endpoint Privilege Manager has a very high price, so it's a one out of ten for me in terms of pricing."
"Although I do not deal directly with the pricing, CyberArk Endpoint Privilege Manager is costly compared to other solutions. However, it offers beneficial features."
"We pay about $17 per user."
"It's not at the lower end of the market. I think the price is reasonable considering the quality it delivers. It is a top-notch solution at a fair price point."
"We pay a fee for support, which is renewed annually."
"Its price is reasonable and what is expected for these types of products."
"The pricing for this product is competitive and our customers who told us that often, Carbon Back is the cheaper solution."
report
Use our free recommendation engine to learn which Application Control solutions are best for your needs.
896,692 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Manufacturing Company
11%
Computer Software Company
7%
Government
7%
Financial Services Firm
23%
Computer Software Company
9%
Government
8%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise19
By reviewers
Company SizeCount
Small Business4
Large Enterprise4
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What is your experience regarding pricing and costs for CyberArk Endpoint Privilege Manager?
I believe it's quite a reasonably priced solution. It's not very common to use CyberArk because it's a niche solution, but customers who are willing to control administrative accounts are willing t...
What needs improvement with CyberArk Endpoint Privilege Manager?
While CyberArk Endpoint Privilege Manager is a great tool, I believe the functionality could be wider. If it could work not only with permissions but also involve pure EDR tasks or User and Entity ...
Ask a question
Earn 20 points
 

Also Known As

Viewfinity
CB Protection, Carbon Black CB Protection
 

Overview

 

Sample Customers

Information Not Available
Kaas Tailored, Core-Mark, Indeed, Hologic, Landmark Credit Union, Project Worldwide
Find out what your peers are saying about Idira Endpoint Privilege Manager vs. VMware Carbon Black App Control and other solutions. Updated: April 2026.
896,692 professionals have used our research since 2012.