What is our primary use case?
For CyberArk Identity, a typical scenario involves using it with a federation, like Active Directory or Azure AD, to manage user identities. Since CyberArk Identity is a SaaS offering (not installable on-premise), identity connectors bridge the gap between the customer's directory (Azure AD or Active Directory) and CyberArk Identity.
These connectors essentially synchronize the two systems. For example, disabling an account in the customer's directory (either Azure AD or Active Directory) automatically disables the corresponding account in CyberArk Identity if the identity connector is present.
However, if you manage accounts manually within CyberArk Identity, you don't necessarily need a connector. This specific connector is called the CyberArk Identity Connector.
We can manage user access and permissions through CyberArk Identity. To fully manage it, we need a connector and whatever changes we want to make to user access or entitlements, if we do it in the CyberArk Identity end, the same will reflect in the customer's AD (Active Directory) also if you have the Identity Connector.
We use CyberArk Identity for multiple applications, like, for a single sign-on across multiple applications.
Some customers use it for managing server privileges through the SaaS version. In this case, CyberArk Identity facilitates the connection by federating the customer's Active Directory or Azure AD with the CyberArk SaaS environment. However, they only utilize a few features of CyberArk Identity, not its full potential.
What is most valuable?
I like the RBAC (Role-Based Access Control). This feature is quite common in other identity tools as well. It basically involves defining various roles, and then simply assigning those roles to users.
That's the RBAC feature that I find most valuable for security.
Moreover, CyberArk Identity offers multi-factor authentication, but I haven't configured this feature yet.
For instance, if the customer wants multi-factor authentication (MFA) or single sign-on (SSO), they usually prefer their own Azure MFA or Azure AD as a base or anything that is already integrated with their environment, so they don't have to subscribe to CyberArk SSO. But it's possible.
What needs improvement?
CyberArk Identity could improve by allowing federation directly or seamlessly, without the need for an Identity Connector. Instead of building separate Azure Connectors, if they could just federate, that would be nice.
However, for this kind of feature to work, the customer's environment would need specific configurations.
Basically, they could improve the federation capabilities to handle multiple domains separately, instead of just one. Right now, if you're working with one domain, it's okay. But for multiple domains, it becomes a bit complicated.
In the on-premises version, you can curate more than one domain seamlessly. However, the SaaS version of CyberArk Identity requires more configuration.
Moreover, CyberArk Identity is relatively new. They haven't been in the market for more than two or three years. They're still under development and not yet a fully-fledged product.
They're constantly adding features, but they haven't yet achieved complete account management capabilities for all types of accounts, which is likely due to their competition.
So, while they are actively promoting it, not many customers are using CyberArk Identity yet.
For how long have I used the solution?
I have been using it for two years. CyberArk Identity is a relatively new offering specifically designed for the SaaS environment, their cloud offering.
CyberArk also offers a self-hosted version and the SaaS option. So, if customers choose a SaaS environment, then CyberArk Identity comes into play for identity and access management (IAM).
CyberArk is now pushing CyberArk Identity because it can manage various other aspects, including directories, which is why they are actively promoting it.
Buyer's Guide
Idira Identity
August 2026
Learn what your peers think about Idira Identity. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,549 professionals have used our research since 2012.
What do I think about the stability of the solution?
The SaaS version is quite stable. It's a stable version because they are promoting it heavily and even proposing migration from self-hosted on-premises versions to the SaaS version. So, it's quite reliable. However, as with any cloud service, there's always a possibility of issues.
The only thing to consider is the number of zones in different regions. For example, in the US, UK, or Asia-Pacific regions, they should have more zones for the vault or cloud components. In the UK, for instance, they only have two or three zones.
So, the overall stability is good. However, I would like to see them offer a solution where high-volume customers using their SaaS service can have a customized dashboard showing real-time availability (what's up and what's down).
Currently, customers have to manually select their instance and check its status. If we could get a real-time status of the running services and components, that would be nice.
In terms of stability, CyberArk Identity has a high SLA (Service Level Agreement); an SLA of 99.9%. So, it should be reliable.
What do I think about the scalability of the solution?
I would rate the scalability an eight out of ten. It's close to ten, but it's not quite perfect. There's a slight complexity because, for some license increases, you need purchase orders (POs) and approvals.
However, technically, it's very simple. They just need End-to-End Orchestration (EON) for the license, which means something is added on their back end in the SaaS offering. The customer doesn't have to do anything. You just pay the money, and they attach the license.
So, it's scalable vertically or horizontally. If you need more storage space for recordings (because CyberArk has a recording feature), or if you want to keep the audit logs longer than a year, they can do that too, and it's not that expensive.
Considering everything, I'd rate its overall scalability an eight out of ten.
Basically, it can be used by all sizes of companies because the licensing is flexible. It can be for 50 users, 100 users, 4,000 users, 12,000 users, even 20,000 users. So, it's good for modularizing or setting up for small enterprises, and it's also suitable for medium and large enterprises.
How are customer service and support?
There is room for improvement in customer service and support. Since I started with CyberArk products about seven years ago, the support hasn't significantly improved. They haven't necessarily enhanced the organization, updates, or handovers, which should be addressed.
How was the initial setup?
Since this is a SaaS (Software-as-a-Service) offering, the vendor handles most of the things, around 75%.
CyberArk does have good documentation, but there is room for improvement, maybe about 5%.
The documentation could be more specific about the changes needed to achieve specific goals.
For example, in my recent project, we encountered an issue. User accounts and groups weren't showing up in CyberArk Identity when trying to pull them from the customer directory. We had to troubleshoot extensively, and the documentation didn't provide the necessary guidance. Thankfully, with CyberArk's help, we resolved the issue.
So, an improvement they could make is to clarify in the documentation the specific configuration changes needed for different customer goals. For instance, pulling user accounts, security groups, and user server security groups requires specific configurations that weren't clearly outlined in the documentation. This is the 5% area they can improve on.
Integrating CyberArk Identity with other IT infrastructure is not simple, it is a bit complex. You need to bring multiple domains together and ensure various networks connect.
It's not just about the cloud environment; you also need firewalls and configurations, making it a management challenge. So, it's not easy, but it is not overly complex either, maybe moderate with some complexities.
It's a one-time setup. If you do it correctly the first time, then it runs smoothly.
What's my experience with pricing, setup cost, and licensing?
It's not that affordable compared to Delinea or other products. They're less expensive and allow more customization. For the cost, it is expensive.
It's like choosing between Volkswagen and Mercedes-Benz. Both might have good safety features, but Mercedes offers more features and is considered bulletproof initially. They have standard pricing, so you get everything. It's like choosing a car you don't need daily protection for versus one that requires constant defense.
So, there's still value in CyberArk, and they are improving.
What other advice do I have?
Overall, I would rate the solution a seven out of ten because there is still room for improvement.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner