IkedeEbhole - PeerSpot reviewer
Pre sales Engineer (West Africa) at StarLink - Trusted Security Advisor
Real User
Top 20
A useful solution for privileged identity and application identity management
Pros and Cons
  • "It's a good solution, it works, and the bank is happy with it."
  • "The architecture needs to be improved."

What is our primary use case?

Our primary use case for his solution is privileged identity and application identity management, and we deploy the solution on-premises.

What is most valuable?

We have found the core features of the product most valuable, such as password management, session recording and vaulting.

What needs improvement?

The architecture needs to be improved. For example, the whole solution can come within a single software bundle instead of the distributed components we have for the on-premise deployments. I think there's room for improvements in that area because the competitors within that space have appliances and software that are just a single software. You don't have to split functionality across several servers like the current deployment.

For how long have I used the solution?

We have been using this solution for approximately five years.

Buyer's Guide
CyberArk Enterprise Password Vault
April 2024
Learn what your peers think about CyberArk Enterprise Password Vault. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,599 professionals have used our research since 2012.

What do I think about the scalability of the solution?

The solution is scalable. At the point of implementation, 300 users in our organization were using it, but that number may have increased.

How was the initial setup?

The initial setup is not very complex because of my experience and skills. Still, the end users are only in charge of the administrative aspects, but I think the set up is a bit complex for those who are not very savvy with the solution. Implementation took approximately two weeks.

What other advice do I have?

I rate the solution nine out of ten. The solution is good, but the main feature to be improved is having the product in a consolidated software bundle. So the moment we have PSM, it's a dedicated server. We can also have a PVWA in another server, so having a singular bundle is just like the cloud offering. The infrastructure is abstracted from the end user. So if we can have something like that for on-premises, that would simplify implementation. Regardless it's a good solution, it works, and the bank is happy with it. My recommendation to people considering implementing this product is to get the scoping appropriately done. It comes down to scoping the initial deployment, so it doesn't take forever. Still, if you're not scoping correctly, you could have a situation where people keep adding new accounts continuously, and your project never ends. Hence, scoping is kind of important.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Information Security Engineer II at a healthcare company with 1,001-5,000 employees
Real User
Stable and solid solution for managing passwords, and comes with auto password recycling and PSM features
Pros and Cons
  • "If properly set up, CyberArk Enterprise Password Vault has good stability, and is a very solid tool. It can run by itself. Its most valuable features are auto password recycling and PSM."
  • "What needs to be improved in CyberArk Enterprise Password Vault is their customer support, particularly in terms of responsiveness, willingness to help, and being more understanding. The initial setup and upgrade process for the solution is complex and can only be done by CyberArk, so this is another area for improvement."

What is our primary use case?

Our use case for CyberArk Enterprise Password Vault is managing privileged accounts. These are local accounts, e.g. local desktops, laptops, or servers. They have a built-in administration account, so part of the solution is to ensure that that account's username and password are stored in the vault and managed by CyberArk Enterprise Password Vault.

What is most valuable?

The most valuable feature of CyberArk Enterprise Password Vault is the auto password recycling feature, which works this way: previous accounts which are managed by this solution get their password reset every time, based on our given parameters, e.g. every two days, every five days, every week, etc. You give CyberArk Enterprise Password Vault the number of days that you want the passwords to be changed, so users won't need to have their passwords written somewhere. They can just log on to the solution and retrieve the password. They may even be able to remotely connect to the devices that they want to connect to via the PSM function of CyberArk Enterprise Password Vault.

What needs improvement?

What needs to be improved in CyberArk Enterprise Password Vault is their customer support, because as administrative engineers, since we're not experts in the solution, we have to rely on customer support.

Their customer support needs improvement in terms of being responsive and being understanding. They are knowledgeable, but responding and willingness to come and help knowing that it's their tool, rather than relying on the engineers from the customer side, e.g. our side, to do all the technical things.

The initial setup and upgrade process for CyberArk Enterprise Password Vault is complex and can only be done by CyberArk, so this is another area for improvement.

For how long have I used the solution?

My experience with CyberArk Enterprise Password Vault is almost three years.

What do I think about the stability of the solution?

CyberArk Enterprise Password Vault stability is good. If it's properly set up, it can just run by itself. It's a very solid tool, but it has to be properly set up because a simple misconfiguration can create a lot of pain. Once set up, it's really good.

How are customer service and support?

Customer support for this product still needs some improvement.

How was the initial setup?

The initial setup for CyberArk Enterprise Password Vault is another pain point, because the setup, including upgrading the solution, can only be done by CyberArk themselves. They have professional services involved to get an initial setup done, and to even do an upgrade, because of the complexity of the product itself.

What's my experience with pricing, setup cost, and licensing?

The SaaS version of CyberArk Enterprise Password Vault is very expensive, but the on-premises version is relative, e.g. depending on the size of the environment, it can be a bit pricey, but it's relatively okay compared to the others. It's their SaaS solution that's expensive.

What other advice do I have?

We're using version 11.1 of CyberArk Enterprise Password Vault.

It's probably not fair to judge CyberArk Enterprise Password Vault based on my overall experience with it, because the tool itself is brilliant, though it's a little bit complex in terms of how it is set up. The customer service could still be improved to meet the standards, but I'm giving CyberArk Enterprise Password Vault a score of seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
CyberArk Enterprise Password Vault
April 2024
Learn what your peers think about CyberArk Enterprise Password Vault. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,599 professionals have used our research since 2012.
Manager at a consultancy with 10,001+ employees
Real User
Good session management capabilities, and training available
Pros and Cons
  • "The most valuable feature is privileged session management."
  • "I would like to see a simplification of the product."

What is our primary use case?

We use CyberArk Enterprise Password Vault and we provide it to our customers.

We use this solution for password vaulting and session management.

What is most valuable?

The most valuable feature is privileged session management.

What needs improvement?

The installation process could be simplified.

I would like to see a simplification of the product.

For how long have I used the solution?

I have been dealing with CyberArk Enterprise Password Vault for ten years.

Depending on the needs of the client, it can be deployed both on-premises and in the cloud.

What do I think about the stability of the solution?

CyberArk Enterprise Password Vault is a stable solution.

What do I think about the scalability of the solution?

CyberArk Enterprise Password Vault is scalable.

Which solution did I use previously and why did I switch?

We use Teams for virtual meetings and storage, with SharePoint serving as the backend.

I've never liked the idea of using Zoom because the security was never great.

How was the initial setup?

The installation is not straightforward. It's complex. You would have to be very knowledgeable about the product to do this.

We need two to three administrators to maintain this solution.

What's my experience with pricing, setup cost, and licensing?

Licensing fees are paid on a yearly basis.

What other advice do I have?

Our laptops are containerized, we don't see what antivirus is on there. Our organization strips out all bloatware. If it is not sanctioned or proprietary, we don't use it.

Try to complete as much of the CyberArk training as possible.

 I would rate CyberArk Enterprise Password Vault a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Director / Engineer at Provincia
Real User
Enables users to connect to a target machine without the need to know the privileged accounts' password
Pros and Cons
  • "Our most valuable features would probably be key rotation, the SKM or SSH key manager, and account discovery."
  • "I think they can improve account onboarding. For instance, you have to use the Password Vault utility, whereas in Thycotic I think there is a feature in the user interface that allows you to upload your account with an Excel file. So I'd like to have a similar thing in CyberArk."

What is our primary use case?

I have worked as a CyberArk SME, team leader, project manager in the financial industry. I've managed both the implementation and configuration of enterprise CyberArk infrastructures.

How has it helped my organization?

As an end-user within the organization, I can't and I don't need to know the passwords of privileged accounts as CyberArk is taking care of the password/SSH Keys management on the target machines. The solution provides this security without changing the end-user experience because they are able to use the end-user tool like putty or remote desktop connection even without passing through the CyberArk interface

What is most valuable?

Our most valuable features would probably be password/key rotation, the SSH key manager, account discovery and quality of video recordings.

What needs improvement?

I think they can add a new feature for the account onboarding like I've seen for another PAM tool: for instance they should give to the CyberArk administrator the chance to upload the accounts via the PVWA using a txt or an xls file.

For how long have I used the solution?

We've been using this solution for five years.

How was the initial setup?

If you don't know the product well, it might not be easy to set up, because CyberArk has several modules. You need to study it before to start to implement this solution. It's not like other PAM tools e.g.Thycotic, which is easy to set up, as it's just a web server with a database.

The deployment itself can take between one and two work weeks. The project, or configuration documents, however, must take more time. You cannot think about the infrastructure in one week. You have to prepare all the documents, understand the infrastructure you want, etc. It's the project management that takes more time.

What other advice do I have?

You have to analyze the target hosts that you have in your organization and understand what is the scope of your project. You have to make a very clear plan for the project and CyberArk infrastructure sizing. Then you have to do a very good job with the project management and collaborate with the privileged accounts stakeholders. With all that in mind, you can go ahead with CyberArk.

Be careful with the configuration. When you make changes and so on, be very careful to understand what you are doing. Plan and test what you are doing in a test environment before switching to production.

I would rate CyberArk as nine out of ten. Ten means that it's the best solution on the market and no one else compares to it.  However, before giving them a ten, they should do something related to the Password Vault utility. Maybe they should add some other features too. For me, it is one of the best tools on the market, so nine is enough for now.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PAM Architect at a tech services company with 11-50 employees
MSP
Top 10
Stable, good support, and secures each password with individual encryption
Pros and Cons
  • "CyberArk probably has probably the best vault on the market because of the multiple layered security and each password getting its own encryption."
  • "CyberArk has two disadvantages; the first is that it's insanely expensive and the other is it's very complex."

What is our primary use case?

I'm an integrator and we identify and provide performance discovery, and we select the best product for our clients.

We have users that are administrators in the environment, and we convert them into a shared account model. Many of the organizations have two accounts. One is a regular user account and the other gives them administrative rights.

CyberArk allows for a higher degree of segregation of duties, although CyberArk itself doesn't do that. You have to have knowledge of role-based access control and least privilege principles. It supports it, but you have to implement it.

There is also service recording, service accounts on Windows Systems, and Linux systems, to rotate their passwords.

You will find service accounts with passwords that are 5,000 to 8,000 days old, but not with CyberArk. It creates a very strong service to prevent attacks. 

When passwords don't change it makes them very vulnerable and allows attackers significant lateral mobility within an organization. It gives them the necessary time to scout the environment and choose what their attack will be, whether it's going to be a ransomware attack or a data exfiltration attack or if it's going to go in to cause defamation to the company like creating a denial of service to clients. Also, hacking their Facebook page or their Twitter page are common attacks.

What is most valuable?

CyberArk probably has probably the best vault on the market because of the multiple layered security and each password getting its own encryption. Each password gets individual encryption. By the time you are able to crack one of the passwords, it's already been changed a dozen times.

The attack surface on a CyberArk Vault is very nominal and in addition, CyberArk also has its own on-staff hackers where companies actually hire them to perform penetration testing, but within, inside the environment.

What needs improvement?

CyberArk has two disadvantages; the first is that it's insanely expensive and the other is it's very complex. 

That's the downside because CyberArk was not built organically. It was built systematically.

They're not built into the product. You have to shoehorn things in. You have to create programmatic interfaces to make things work, but that's why I said it's the most complex product.

CyberArk is still in the model of managing accounts and passwords. When you're logged in as a domain admin, you're leaving footprints everywhere you go. These footprints can be picked up and replicated. So, I think CyberArk is behind the curve in that area.

Customers are already having an issue with the cost of CyberArk and then you have to add another $100,000.00 to the bill for other application accounts.

I would like to see a more streamlined and built-in programmatic onboarding and offboarding process. Something a little bit less complex than what they're currently doing.

The price is the problem and also the architecture can be daunting because CyberArk really strongly encourages having hardware vaults. Most corporations are totally virtualized.

I use virtualized vaults on everything including the high availability configuration.

For how long have I used the solution?

I started using Cyber-Ark Enterprise Password Vault when they were on version five or six, they are now on 11.5 or 11.6. I have been using this solution for a total of 15 years.

What do I think about the stability of the solution?

CyberArk is very stable.

If there is a problem, or if a problem does occur, unless you know exactly what to do and how to diagnose it, you may not be able to find it because there are so many moving parts. However, a good administrator can usually diagnose a problem fairly rapidly.

They determine the root cause by performing a root cause analysis. Also, you should inform CyberArk because sometimes a fix might be required. CyberArk stopped performing single sign-on.

What do I think about the scalability of the solution?

CyberArk is very scalable. It's one of the things that I love and it's also one of the things that I hate about CyberArk.

For example, it's a standalone vault that is practically uncrackable. If you want to do a password rotation you need to have a central password manager. It's called a CPM.

If you want session recordings you have to have a PSM. They can be run on the same server, but eventually, the performance is going to be an extensive task. 

A CPM is performing verification on passwords continuously, and to start stacking server roles on top of each other. 

If you're a semi-vault in a small environment, with one server running CPM, PSM, and PDWA all on one box, it would be no problem with less than 10 administrators and only 70 servers.

With other small or larger organizations that have hundreds of servers rendering that capability or that flexibility, you would have to have a dedicated CPM and dedicated PDWAs, which is the administrator web interface.

For a medium-sized company where you want to do a session recording for all the administrator access, it will cause a problem. It will require multiple PSM servers and if you don't have a good administrator who documents the build process well, or they don't update it, then the problem shows when you build a new PSM. If they don't add all the applications to it then you're going to get an intermittent error across the low-balanced PFMs, where eight of the ten work, but two of them don't because they didn't install the SFQL agent. It's a very complex program, albeit very scalable.

If you're a multinational corporation, you can have your vault in one location and have PSMs distributed where the systems are in the data centers. Then, the PDWAs and the CPMs would be in the data centers and you would have the PDWAs where the user populations are. Rather than having one single appliance or one single box that does everything, you end up having boxes distributed all over. This means that they have to do synchronization and it works out very well most times.

We have small to large company clients. We have clients that have tens of thousands of administrative accounts and 1000 or so servers, to clients as small as having 70 servers with maybe only 750 to 1500 accounts.

How are customer service and technical support?

Technical support is awesome!

CyberArk has excellent technical support. They may not be timely. They're not quick, but they're great.

I would rate the technical support a ten out of ten.

You have to follow the ticket creation process, which is in your benefit because you need screenshots and logs to be able to diagnose the problem. If you do that, then CyberArk comes back with some incredible support help and in most times it's something that I would have never been able to figure out because the product is very complex and it has a lot of moving parts.

Which solution did I use previously and why did I switch?

I have not used any other solution previously. CyberArk is what I learned first.

How was the initial setup?

The initial setup was very complex. There are a lot of moving parts. The skillsets for some of the advanced features require administrators to know how to program in specific APIs. 

The complexity to implement is very high. On a scale of one to 10, it's a 9.5.

What's my experience with pricing, setup cost, and licensing?

CyberArk is very expensive and there are additional fees for add-ons.

What other advice do I have?

CyberArk Password Vault is probably the top vault on the market and Thycotic would be a close second.

CyberArk is not always suited for our clients but it is the best solution. Eight out of 10 organizations don't implement it. Just because you know CyberArk doesn't mean you understand it.

The SaaS solution is sound but the on-premises is primarily what I have worked on. I am CyberArk certified. When I started off several years ago, I got my CIS as PE. I was put into a security group in EDS. 

Network admins who work for the company have to be administrators, with high skill levels. 

Before implementing CyberArk, I would say do a very aggressive use case creation of everything that you're expecting the vault to do. The security architecture should be able to create high-level bulleted use cases. Security administration should be able to take it down to the next level of detail.

They will have to add Conjure, which is another license for CyberArk.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Manager at a financial services firm with 5,001-10,000 employees
Real User
Super stable and easy to scale
Pros and Cons
  • "Super stable and easy to scale"

    What is our primary use case?

    Our clients primarily use the CyberArk Password Vault for password rotation and password management.

    What is most valuable?

    The feature I find most valuable is the password credential rotation.

    What needs improvement?

    With regards to potential improvements for the CyberArk product, I find the product quite expensive and I would like to see the cost reduced. 

    For how long have I used the solution?

    I have been using CyberArk Password Vault for 8 years. 

    What do I think about the stability of the solution?

    CyberArk Password Vault is super stable once you are on a tried and true platform version. 

    What do I think about the scalability of the solution?

    The product is also easy to scale. 

    How are customer service and support?

    I have utilized CyberArk technical support for issues and this was very straightforward to work with. The response time was a little slow. 

    Which solution did I use previously and why did I switch?

    I have previously deployed and installed Thycotic as an alternate password vault solution, but I find CyberArk to be much better.

    How was the initial setup?

    With installation of CyberArk Password Vault, there are some complexities to setting it up, I would say it is not straight forward to setup. 

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Senior Presale - BU Information Security at a tech services company with 51-200 employees
    Real User
    Feature-rich, good performance, scalable, and has a user-friendly interface
    Pros and Cons
    • "It's a highly flexible solution that can adapt to each customer's needs."
    • "The initial setup could be simpler but it may not be as effective."

    What is our primary use case?

    We implement this solution for our customers. We are system integrators, not end-users.

    The main use case is for secure access, and monitoring the access by IT administrators.

    What is most valuable?

    I like the performance of CyberArk Enterprise Password Vault.

    Definitely, it's a reliable solution.

    It has a wide range of features. They are probably the widest range of features on the market. It is the main reason customers usually select this product.

    This solution works very well, and the feedback from our customers is very good.

    Integration is one of the strongest capabilities of this solution. There are hundreds of integrations that are ready to use. It is continuously growing, which is one of its strengths.

    The interface is really user-friendly.

    It's a highly flexible solution that can adapt to each customer's needs.

    Another strength, for both performance and the security levels, is the segregation of the different rules of the solution.

    What needs improvement?

    The initial setup could be simpler but it may not be as effective.

    For how long have I used the solution?

    I've been using CyberArk Enterprise Password Vault for three years, and the company began using it in 2003.

    This solution is used mainly on-premises, but the trend is to go with hybrid and cloud deployment for new projects.

    What do I think about the stability of the solution?

    CyberArk Enterprise Password Vault is a stable product.

    What do I think about the scalability of the solution?

    CyberArk Enterprise Password Vault is easy to scale.

    How are customer service and support?

    I have not contacted technical support. I deal in the presales department. I don't manage the technical aspects of delivery and support.

    How was the initial setup?

    We needed to build a specific project that is tailored for each customer. It requires a bit of design with the first part of the project, which is a benefit because the solution has high performance and is built on the needs of the customer. 

    There is a bit of a setup initially, but it provides them with a good result for the project.

    What's my experience with pricing, setup cost, and licensing?

    It's an affordable platform.

    It is not the cheapest solution available on the market, but if you want a good project, you need to have the value of the solution you are selecting. 

    In my opinion, it is a good compromise between the cost and the benefits. I think the price is fair.

    What other advice do I have?

    I would definitely recommend this solution to others who are interested in using it.

    I do not have visibility with other solutions that may be better or more up-to-date.

    I would rate CyberArk Enterprise Password Vault a ten out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    System Administrator at Porto Editora
    Real User
    Passwords are stored securely within the vault and eliminates the need for users to store passwords in less secure locations
    Pros and Cons
    • "The password protection itself is the most important feature. It's something we didn't have before."
    • "The session monitoring and recording feature is also a good feature feature, but we're currently experiencing an issue with session monitoring not working correctly. We're working with CyberArk to resolve it. We aren't able to view active sessions or historical recordings of sessions."

    What is our primary use case?

    Primarily, I import accounts from our critical systems.  

    How has it helped my organization?

    Knowing that our passwords are stored securely within the vault has been a big improvement. It eliminates the need for users to store passwords in less secure locations.

    We want to integrate it with our IT service management platform and our SOC solution, but that's a future project.

    What is most valuable?

    The password protection itself is the most important feature. It's something we didn't have before.

    Moreover, the interface is intuitive. It is clear and user-friendly. 

    What needs improvement?

    The session monitoring and recording feature is also a good feature feature, but we're currently experiencing an issue with session monitoring not working correctly. We're working with CyberArk to resolve it.

    We aren't able to view active sessions or historical recordings of sessions.

    It is complex, which is something I know CyberArk is working on. They're trying to simplify certain administration tasks because a common critique is the level of complexity. But overall, we can do everything we need with it.

    So, CyberArk could still focus on making it more user-friendly.

    For how long have I used the solution?

    I have been using it for a year. 

    What do I think about the scalability of the solution?

    So far, we haven't had any scalability problems.

    We have around 50 licensed users – primarily administrators. We currently manage about 5,000 accounts with CyberArk.

    How are customer service and support?

    Sometimes, the initial response time is a bit slow, but once the customer service and support take on a case, they resolve issues quickly.

    How would you rate customer service and support?

    Positive

    What about the implementation team?

    CyberArk handled the primary setup tasks. We worked with a partner to implement additional components and now have the knowledge to manage the solution ourselves.

    The implementation process took around eight months. 

    What was our ROI?

    There has been an ROI. 

    We expect to see a full return on investment within the next three years. This was part of our long-term security plan.

    What's my experience with pricing, setup cost, and licensing?

    It is expensive, but the cost is justified considering the security it provides. Compared to other solutions, it is costly. We have not tried other solutions, but the price is high. 

    We only license Password Vault.

    Which other solutions did I evaluate?

    My company evaluated another solution like Delinea but preferred CyberArk due to its robustness and flexibility.

    I like its flexibility, while adding some complexity, allows us to fully customize the solution to our needs.

    One of the main advantages is the way we can connect from outside. We use a portal that provides secure access to our systems without needing a VPN. We just scan a QR code, and we're connected. We do not need to use a password and we are in through the QR code scan. 

    What other advice do I have?

    I would recommend using it. Overall, I would rate the solution a nine out of ten.

    It's a very complete solution for what we need.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Download our free CyberArk Enterprise Password Vault Report and get advice and tips from experienced pros sharing their opinions.
    Updated: April 2024
    Buyer's Guide
    Download our free CyberArk Enterprise Password Vault Report and get advice and tips from experienced pros sharing their opinions.