We use it for Cisco device TACACS authentication and .1X security.
Network Engineer at a financial services firm with 201-500 employees
Helps to ensure that we're secure and no unauthorized devices are accessing the network
Pros and Cons
- "TACACS and .1X security are the most valuable features. TACACS acts for user control, so no one can authenticate to our network devices, and .1X is to validate that unauthorized devices are plugged into our network."
- "Its user interface could be better. It's not bad. They've just redesigned the whole user interface. It's not terribly difficult. The drop-down menus are easy to use. However, when you're looking for some things in the user interface, it takes a minute to find where you were prior."
What is our primary use case?
How has it helped my organization?
We have a better state of mind that we're secure, and we don't have unauthorized devices accessing the network. In a financial institution, we want to keep everything as secure as possible. We don't want anything plugged in.
It has helped to consolidate tools. We had arpwatch monitoring, which we no longer have to use, and then TACACS is securing the network. We didn't have a tool before, so that added a layer of security for us.
It has improved our cybersecurity resilience. We have authentication logging for everything that's authenticated or denied. We use a Splunk forwarder. We get notifications if something is denied for authentication.
What is most valuable?
TACACS and .1X security are the most valuable features. TACACS acts for user control, so no one can authenticate to our network devices, and .1X is to validate that unauthorized devices are plugged into our network.
What needs improvement?
Its user interface could be better. It's not bad. They've just redesigned the whole user interface. It's not terribly difficult. The drop-down menus are easy to use. However, when you're looking for some things in the user interface, it takes a minute to find where you were prior.
Buyer's Guide
Cisco Identity Services Engine (ISE)
September 2026
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,924 professionals have used our research since 2012.
For how long have I used the solution?
I've been using Cisco ISE for a year.
What do I think about the stability of the solution?
Its stability is great.
What do I think about the scalability of the solution?
Its scalability is also great. We have 350 users.
How are customer service and support?
Their support is excellent. I've opened two support tickets so far, and they were able to remediate the issue within a few hours.
How was the initial setup?
It's fairly difficult. We have third-party support to assist with the setup.
Our setup is on-prem and virtual in Azure.
What about the implementation team?
It was a third-party support, not a reseller.
What other advice do I have?
It's a very good tool for security. It's a lot of work to initially set up, but once it's set up, it's pretty easy to use.
It hasn't yet saved the time of our IT staff. It's still fairly new, so we haven't had much time to use the product fully. It has only been a year since we started using it, so it's still pretty new.
Overall, I'd rate Cisco ISE a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a energy/utilities company with 1,001-5,000 employees
Enhances security, protects us at the access layer, and helps to enforce policies dynamically
Pros and Cons
- "With NAC, the profiling feature is valuable. We're able to see what we have out there in the network and dynamically assign policies to it. We can then use that to enforce TrustSec policy or anything else with NAC."
- "There should be more visibility into TrustSec policy actions. When TrustSec blocks something or makes any kind of changes to the network, we don't always see that. We have to log into the switch itself, or we have to get some type of Syslog parsing to do that."
What is our primary use case?
We use it for NAC and wireless, and for our TrustSec policy. These are the three primary use cases we have so far.
How has it helped my organization?
It's a network access control solution for us. Previous to Cisco ISE, we didn't have one, so, from a security standpoint, it increased our security visibly.
It has enhanced our security. We have a solution now that can protect us at the access layer, which we didn't have before.
It has helped to consolidate any tools or applications. We only have to use one product for RADIUS, TACACS, and authentication servers. NAC and other things are consolidated into one system, which is nice.
It has helped our organization improve its cybersecurity resilience. The security at the access layer through NAC has been nice, and then the ability to enforce policies dynamically using profiling and NAC and TrustSec is good.
What is most valuable?
With NAC, the profiling feature is valuable. We're able to see what we have out there in the network and dynamically assign policies to it. We can then use that to enforce TrustSec policy or anything else with NAC.
What needs improvement?
There should be more visibility into TrustSec policy actions. When TrustSec blocks something or makes any kind of changes to the network, we don't always see that. We have to log into the switch itself, or we have to get some type of Syslog parsing to do that. Cisco DNA Center may do it, but it would be better if that was integrated into Cisco ISE.
In terms of securing our infrastructure from end to end so we can detect and remediate threats, it's a little bit difficult in terms of visibility, but, generally, we would just go through the logs and see if there's a problem or not.
For how long have I used the solution?
I've been working in this organization for three to four years, and they have been using it prior to my joining.
What do I think about the stability of the solution?
It's very stable for us.
What do I think about the scalability of the solution?
It isn't something we have had to deal with.
How are customer service and support?
They're pretty good. Compared to others, Cisco is probably above average. With Cisco TAC, usually, if the first level doesn't resolve it, you can get up to a higher level within a day or two, which is better than a lot of other vendors we've been working with lately, such as Palo Alto. Cisco tech support is doing pretty well. I'd rate them a seven out of ten. Being able to access higher-level engineers and escalate things more quickly is always going to improve any case.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Before Cisco ISE, we didn't have a similar solution.
How was the initial setup?
It was implemented before I joined, but it was probably phased. It was first for wireless and then became more of a NAC thing. It was a long process. It was somewhat difficult just because of how much was required of it. I don't think it was particularly painful.
What was our ROI?
We get a return on investment from it. It's a solution that's often required for IT insurance, etc. It's definitely needed but do we need to have one from Cisco? I don't know, but there's definitely an ROI there.
What other advice do I have?
To someone researching this solution who wants to improve cybersecurity in their organization, I'd say that make sure you know what you're getting into. Understand and have a good plan going into it and have operational support for not just networking, but also help desk and other IT teams before deploying this solution.
I don't know if Cisco ISE has saved us any time because it's an enhancement to our security that we didn't have before. It probably takes a little more time than not having it. Having no security is super easy because you don't have to worry about anything, but if you have any security product, you have to do work to support that.
Overall, I'd rate Cisco ISE an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco Identity Services Engine (ISE)
September 2026
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,924 professionals have used our research since 2012.
Network Engineer at a hospitality company with 10,001+ employees
Video Review
Helped us get away from pre-shared keys, and allows us to see what's connected to the network
Pros and Cons
- "[One of the most valuable features] is just the ease of use. It's pretty simple to set up certs that we can add to our clients to make sure that they connect properly, [as is] whitelisting Mac addresses."
- "It works so well we haven't had to reach out too much."
- "Automation [is an area for improvement]. It seems like everywhere I look, automation is super important. Automation and integrations. That's the area it could be improved..."
- "Automation and integrations are the areas it could be improved, as we get more and more away from a lot of human involvement and into machine learning and just trusting that these systems could automatically help us."
What is our primary use case?
One of our use cases is using it for authentication for the wireless. Our internal corporate network is using the Cisco ISE server to authenticate clients and make sure that we have the right clients on the wireless side, as well as on the wired side. We just introduced that about a year ago to make sure all our wired clients are our clients and not some "rando" plugging into the network.
How has it helped my organization?
Definitely, getting away from pre-shared keys has been the biggest key. It is allowing users to connect to the internal network, the employee's network, from anywhere, across the entire US. It is allowing that ease of use.
It's also allowing us to see what's connected to the network. We can see that there are only really clients. We can see what's connected on the wired side and what's getting blocked, and understand [things] from our users. "Okay, that's getting plugged in. What do you guys use this for?" It's adding a layer of defense that's super important to our organization.
I don't think we've gotten away from trust completely, but it has helped a lot. It's allowed, on the server side and on the infrastructure side, to allow certain clients. We don't have to trust the client necessarily. We know that that's a corporate client and we don't have to play any guessing games. The corporate client that we want on that specific network is going to have the right cert and the right thing. It allows access control without a lot of human involvement.
It's helped significantly. We have fewer IoT devices on internal networks and that's the key. Your clients have the right firewall protections and the right anti-virus. Those are on the internal network so you're not putting stuff [on it] that you don't know whether it has a security vulnerability or if it's easily hacked. You're allowing those to be in separated networks that silo them off with a PSK. And you're keeping the internal network to clients that you know are protected.
What is most valuable?
[One of the most valuable features] is just the ease of use. It's pretty simple to set up certs that we can add to our clients to make sure that they connect properly, [as is] whitelisting Mac addresses.
It also integrates really well with some of our other services like ServiceNow. A ticket comes in and then, boom, it's automatically going to the ISE, and then ISE is allowing that client with that Mac address to get on the network easily.
[In addition, regarding establishing trust for every access request, no matter where it comes from] it does the job. It's a perfect solution in order to manage a large corporate network.
It allows that access control [for a distributed network]. That's super significant. It allows you to segment things and allows only certain devices to access the network.
What needs improvement?
Automation [is an area for improvement]. It seems like everywhere I look, automation is super important. Automation and integrations. That's the area it could be improved, as we get more and more away from a lot of human involvement and [into] machine learning and just trusting that these systems could automatically help us.
For how long have I used the solution?
My name is Edward Martinez. Network engineer. Our company has about 5,000 employees, and we're in the beverage industry.
[I've been using Cisco ISE (Identity Services Engine)] ever since I started. That was one of the main services that I had to understand and get involved with as soon as I started at our company.
What do I think about the stability of the solution?
I haven't had many issues in terms of its stability. It doesn't really ever go down. Anytime we ever have any issues with it, it's usually human error.
How are customer service and support?
In the past, I've always had pretty good support from Cisco. Their TAC is really good. They're pretty straightforward. I haven't had many experiences with ISE, honestly. It works so well we haven't had to reach out too much.
I would rate their support about a nine out of 10. It works most of the time. It depends on the engineer you run into. It depends on the people you deal with.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
[The main challenge] was authentication and not using PSK, traditional pre-shared keys. They wanted to get away from pre-shared keys; people share them. They wanted something that would allow clients to just connect automatically, not have a pre-shared key, and be secure. That's the most important part, making sure that the right clients are getting on our internal corporate network.
[Our company] was just using PSK and that solution was really built around access control of our corporate networks. They were using PSKs at every site and rotating those PSKs, or had site-specific PSKs. Now, when somebody comes into the office, they can just connect to the employees' network automatically, and it's the same across the board at every site.
It was this idea that we needed to simplify things. We needed to make it easier on our users to go into an office and connect to the internet and not have to ask an IT guy there or make a ticket. That was the important part.
How was the initial setup?
I've just been involved with the secondary deployment, using the ISE on our wired ports.
It was pretty straightforward. It was funny. We did it during COVID so it was really easy when nobody was in the office to implement the solution. It kind of worked out that way, when there was nobody in the office.
But otherwise, people have started to come back and we haven't had really many issues in terms of authentication. It's really easy. People have wired in and if their client has the right cert, it's been a breeze. They've been authenticated and it takes a minimal amount of time.
What about the implementation team?
We have an operations partner that we deal with pretty often. It's an Austrian company, NTS. They work with Cisco a lot on our solutions and, obviously, we're evaluating it with them and then making choices based off of that. I'm the onsite hands. I do a lot of the configuration on the switches, but they're doing a lot of the advising.
What was our ROI?
You're seeing less tickets and you have fewer security issues. I think the return on investment is there. It has really improved our situation in our corporate offices.
What other advice do I have?
Resilience is super important. The solution needs to be able to hold up and promise what it [intends] to deliver. In cyber security, that's super important because if you have any slight exploit, you're going to have malware attacks, ransomware attacks. That's [a] big [issue] in our company as, more and more, you hear about legacy systems being affected. These legacy systems sometimes don't go away. Sometimes you need them. You have to do your best to either patch them up or protect them either through a firewall or an access control system.
[It's about] protecting the network infrastructure from exploits and really allowing us to segment IoT devices and the corporate network. And because [on] the corporate network, once you get into it, there really isn't anything protecting against accessing critical storage systems, accessing mission-critical servers, [or] our sales numbers, it's super important that we have the ISE so that we're only allowing the things that we want into the network that we trust.
[What I would tell leaders who want to build more resilience within their organization would be] evaluate solutions, prioritize it, get manpower behind it. Also, too often they put cyber security on the back burner. They're trying to maintain operations and sometimes cyber security can get in the way of operations. But trust that system, once you build it up, will protect you and that it's worth the investment in terms of money, labor, and time.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Engineer at Kooperativa pojistovna, a.s., Vienna Insurance Group
Video Review
SGTs enable us to leverage security based on those tags and integrate with other SG firewalls
Pros and Cons
- "The most valuable thing in ISE is the adoption of EAP deep that came in [version] 2.7, so we can do authentication based on user and machine certificates in one authentication."
- "It has improved our organization very much because we're now adopting the SGTs, Security Group Tags, and we're leveraging security based on those tags on our core systems and integrating with other SG firewalls."
- "Also, the menus could have been much simpler. There are many redundant things. That's a problem with all Cisco solutions. There are too many menus and redundant things on all of them."
What is our primary use case?
We are using it mainly for .1X authentication, and we also authenticate our VPN users, and we are doing some light profiling and posture.
We're trying to solve the problem where different users have different privileges in the network. And also we're trying to block some access from our least privileged users. Those are the main use cases for us.
We have on-prem virtual appliances and a distributed model.
How has it helped my organization?
It has improved our organization very much because we're now adopting the SGTs, Security Group Tags, and we're leveraging security based on those tags on our core systems and integrating with other SG firewalls.
We have a pretty distributed network and we have only one ISE deployment and it's been really good so far for managing all of those sites.
What is most valuable?
The most valuable thing in ISE is the adoption of EAP deep that came in [version] 2.7, so we can do authentication based on user and machine certificates in one authentication.
[Regarding establishing trust for every access request] it's been pretty good so far. We've been authenticating all of our users, no matter where they're coming from. If it's from our VPNs, or if it's wireless access, we are all Cisco, so the integrations are pretty good. It's very important [that the solution considers all resources to be external]. Right now, with the challenges that the multi-cloud environment poses, you have to have a solution like this.
What needs improvement?
[When it comes to securing access to your applications we are] not [using it] so much. I'll have another session with a TAC engineer on Friday, and I will have to discuss some basic concepts of securing the application with ISE. I find it very challenging to do some micro segmentation with it. I'm staying on top of it and doing it macro, but I want to go micro, and it's something I need to discuss more with an engineer.
Also, the menus could have been much simpler. There are many redundant things. That's a problem with all Cisco solutions. There are too many menus and redundant things on all of them. This is a problem in ISE. This could be much simpler.
For how long have I used the solution?
I wasn't involved in the process of choosing this particular technology. The colleagues that made the decision made it seven or eight years ago. They were using ISE for a long time. I've been in the company for four years now so I came into an already deployed solution. But it wasn't so good, so we had to migrate from physical appliances to virtual ones because they were end-of-life and end-of-support.
What do I think about the stability of the solution?
Sometimes, they push an update that breaks the whole deployment. It happened to me with update two. It was my fault. I updated right after it came out, and I won't ever do that again. I will wait at least a month or two or three, because the update was taken down a week later.
I was lucky enough because I had updated from update one to update two. So it didn't really break the whole deployment, just parts of it. But they fixed it in a week with update three, so I was able to put it back together. Roll back is also always an option.
What do I think about the scalability of the solution?
Scalability is really good. The number of possible nodes in deployment is high. I don't know the exact number, but it's really high. Scalability is not a problem.
How are customer service and support?
I have had some problems lately with the TAC engineers being unable to investigate the logs that I gave [them]. They always ask for more, but there is not much you can do on ISE. When you give out all the debugs from the nodes, then there is nothing else to do.
It's been a bit of a ping pong with the TAC engineers. Sometimes I have four to five TAC cases open, specifically on ISE. Most of the problems I have are with the integrations of other companies' firewalls.
This year I would give them a six [out of 10]. Before, I would say eight.
How would you rate customer service and support?
Neutral
How was the initial setup?
I have had to find my own way to do the new deployment. It wasn't that there was some documentation about how to migrate. There is none of this stuff on Cisco's site. You have to search Reddit and multiple forums to assess what you can do with the deployment. I basically built it from scratch.
What was our ROI?
We are more secure thanks to ISE. That's always a return on investment.
What other advice do I have?
[When it comes to eliminating trust from our organization's network architecture] I'd say, no, ISE hasn't done that. It's been a challenge to implement this. We're trying to bridge the gap between the security guys and network guys. They're not the same teams. Sometimes the security guys also do networking, but it can be hard to cooperate on projects like this. This is a big project. ISE is a pretty big solution and security guys are sometimes lost in what's going on in the network, like equipment where you have to configure things.
It's pretty much the most resilient solution as of now.
I like this solution a lot. I would say it's a nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network engineer at Bimbo Bakeries USA
Is user-friendly, saves troubleshooting time, and is stable
Pros and Cons
- "The return on investment we have seen is related to time in terms of troubleshooting. The logs, such as the security logs, inform us of the issues that people have had. ISE has been very instrumental in helping isolate those issues. We've seen a lot of cost savings because we don't have to pay an IT person to waste time doing something that should be instantaneous."
- "My impression of Cisco ISE for helping to support an organization across a distributed network is that it's invaluable."
- "On the network services devices, when you click on filter, the filter comes up. However, when I type in a search and I want to click on something it defaults back to the main page. I keep having an issue with that, and I'm not doing anything wrong."
What is our primary use case?
We use it for our AAA authentication through Active Directory. We also use it a lot to verify command line history.
We have ISE in the data center environment with redundancy, and we use it for authentication for all our devices. We have access to our third-party vendors, and for the new projects, we all use ISE. It's an awesome enterprise product for on-premises or for cloud-based deployments.
How has it helped my organization?
The integration of ISE with Active Directory has really been a big plus for us.
What is most valuable?
I've found two features to be the most valuable. One would be AAA reporting for historical analysis, showing what's been done and by whom. The second is the log for failures on Active Directory logins.
If I were to assess Cisco ISE for establishing trust for every access request, I would give it an eight or nine on a scale from one to ten.
Cybersecurity resilience has been very important to our organization and has been a big factor. We've had issues in the past, but one of the things I like about ISE is its logging features. Security-wise or information-wise, it really has been a powerful tool.
My impression of Cisco ISE for helping to support an organization across a distributed network is that it's invaluable. It's a monster tool; we don't even touch on all the features that it offers, but the few that we do use are extremely strong and very user-friendly.
What needs improvement?
On the network services devices, when you click on filter, the filter comes up. However, when I search and want to click on something it defaults back to the main page. I keep having an issue with that, and I'm not doing anything wrong.
For how long have I used the solution?
I've been using Cisco ISE (Identity Services Engine) for about six to seven years.
What do I think about the stability of the solution?
I've had no issues with stability.
What do I think about the scalability of the solution?
We've actually scaled before and have never had an issue.
How are customer service and support?
I've used technical support only once and would give them an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used ACS.
What was our ROI?
The return on investment we have seen is related to time in terms of troubleshooting. The logs, such as the security logs, inform us of the issues that people have had. ISE has been very instrumental in helping isolate those issues. We've seen a lot of cost savings because we don't have to pay an IT person to waste time doing something that should be instantaneous.
What other advice do I have?
If you are a leader who wants to build more resilience within your organization, I would advise you to follow what they're doing at ISE.
If you're evaluating Cisco ISE, do an apples-to-apples comparison. There are a lot of features, and ISE is a monster. If you use it the right way, I think that no other product will compare to it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Client Manager at a tech vendor with 10,001+ employees
We can deep dive into each employees' usage according to our infrastructure needs
Pros and Cons
- "There are a lot of integrations available with multiple vendors. This has made the solution easier to work with."
- "We have become more reliable because we do not have any vulnerabilities coming into our network, which is important since a lot of employees are using their own endpoints to connect to our infrastructure."
- "If you have someone taking care of it, it can be quite easy to manage the solution. Otherwise, if you don't look after it and take care of it day-to-day, then it will become more complex to run."
What is our primary use case?
We have been authenticating our company's employees and certifying that they are in compliance. We have to certify our employees in regards to compliance, having all the necessary protections in our infrastructure for their endpoints, notebooks, laptops, and mobile phones.
We have implemented it across the entire company in every area and department at every single level of our organization.
So far, it has been on-premises. We are still working to expand it to integrate with multiple cloud providers, like AWS.
How has it helped my organization?
We have become more reliable because we do not have any vulnerabilities coming into our network, which is important since a lot of employees are using their own endpoints to connect to our infrastructure.
Every other time that we have a new employee, we need to make sure they have been using the latest version of the solution in order to connect to our infrastructure.
We have made our company more secure. As an IT guy, I have gained more importance to my company.
What is most valuable?
It is more about the features related to Apex. This is part of the solution where we can deep dive into each employees' usage according to our infrastructure needs.
There are a lot of integrations available with multiple vendors. This has made the solution easier to work with.
We use the management platform, which makes it easy for our IT to access and manage.
For how long have I used the solution?
We have been working with it for about 10 years.
What do I think about the stability of the solution?
If you have someone taking care of it, it can be quite easy to manage the solution. Otherwise, if you don't look after it and take care of it day-to-day, then it will become more complex to run. However, if you have someone taking care of it, maintenance is not that difficult.
What do I think about the scalability of the solution?
The scalability is good and quite easy to do. If you have the licenses, then anything is possible.
We worked with customers. The last one that we worked with had 10,000 licenses, i.e., 10,000 endpoints. We started working with the corporate office, then we replicate to the distribution centers.
How are customer service and support?
As an IT integrator, it is quite easy to work with their technical support. We have the correct people to deploy it as well as receive good support from the Cisco Technical Assistance Center. I would rate the support as 10 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have been using ISE for a while. We didn't have another solution beforehand.
How was the initial setup?
We had to do some labs beforehand, in order not to breach the environment. The deployment was not too complex.
When we work with customers, it takes four or five hours. We start with a specific environment, then we replicate to other areas.
What about the implementation team?
We are a reseller. My professional services implemented it, which includes a tech lead, engineer, senior engineer, and project manager to work with the solution.
It is an easy solution to implement with the correct partner.
What was our ROI?
It is difficult to measure security breaches, but since we have not been attacked so far, it has paid for itself over the years.
Which other solutions did I evaluate?
We worked with Fortinet to look at their solution, but ISE was more reliable and had more integration with our product vendors. Also, it had a more affordable cost.
When compared with other vendors, like Forescout, for what we need, ISE has been more usable and accessible.
What other advice do I have?
Learn about the solution, then evaluate what devices it would be implemented with. I would amalgamate the devices and their versions with a systems integrator or partner who already has experience and will try only to replicate it, not to reinvent the wheel.
Part of our journey is getting everybody connected to the infrastructure and trying to avoid any breaches. We don't want to be vulnerable.
I would rate the solution as 10 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.
ITS 1 at a government with 10,001+ employees
Keeps people who shouldn't be on our network off our network
Pros and Cons
- "We have seen ROI. It has done its job. It has protected us when we needed it to."
- "Cisco ISE works very well for establishing trust for every access request when it is deployed and running correctly."
- "I would definitely improve the deployment and maybe a little bit of the support. Our first exposure to ISE had a lot of issues."
What is our primary use case?
We use it as our complete NAC solution for both on the wire and wireless as well as guest wireless access and SGTs.
We have five hospitals. We have two service policy nodes at every hospital. We have a deployment at every hospital site.
How has it helped my organization?
We are a healthcare department. We deal with a lot of PHI so ISE is important. It is an integral part of keeping PHI safe.
The solution has helped with safety and keeping people who shouldn't be on our network off our network.
Cisco ISE works very well for establishing trust for every access request when it is deployed and running correctly. It is a great product. It does what it is supposed to do.
We know what is on our network because ISE is able to tell us.
What is most valuable?
The guest wireless works pretty smoothly. The SGTs came in very handy when we had to segregate traffic away from our network, even though it is part of our network.
The SGT function would probably be the most used. This is mainly because we have a lot of vendors on our campuses but we need to keep them from seeing the traffic and being able to touch other areas of our network. Being able to use SGTs kind of keeps them in their own little lane away from us.
When it is deployed correctly, it is very helpful. It runs smoothly. It is just integrable to what we do.
What needs improvement?
I would definitely improve the deployment and maybe a little bit of the support. Our first exposure to ISE had a lot of issues. However, I have noticed as we have been implementing patches and upgrades that it has gotten a lot better.
For how long have I used the solution?
I have been using it for about four years.
What do I think about the stability of the solution?
With patches and a little bit of babysitting, it is totally stable now.
What do I think about the scalability of the solution?
It is easily scalable.
How are customer service and support?
The technical support is phenomenal. I have called and opened up a ton of tech cases. Eventually, you get the right engineer who can solve all your problems. I would rate them as eight or nine out of 10. It has gotten a lot better. If someone asked me about support two or three years ago, I would have probably given them five out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We didn't use a solution before ISE.
What was our ROI?
We have seen ROI. It has done its job. It has protected us when we needed it to.
What other advice do I have?
Make sure you have everything ready, including all your information. Make sure you know what you will profile and what will come on your network.
Get hardware nodes versus the VMs.
You definitely want resilience. You want to keep everything protected, especially in the day and age that we live in now. Information is power. Keeping our customers' and patients' information safe is our number one priority.
I would rate it as nine out of 10 because it has gotten better. I have seen it at its worst. Now, it is running a lot better. So, I have a better opinion of it than I did.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Business Manager at Telefónica
Simple, works well, and has a lot of features
Pros and Cons
- "It's scalable."
- "We are very happy with the solution and we have no problem using Cisco ISE solutions."
- "The price here in Brazil is very expensive."
- "Sometimes we face some infrastructure where there are multiple vendors and sometimes the ISE is not the best tool to manage multiple vendor infrastructure."
What is our primary use case?
This solution provides access to the employees of the company.
What is most valuable?
It works. It is simple. It works very well. We have a good strategic setup. We are very happy with the solution and we have no problem using Cisco ISE solutions.
The solution is stable.
It's scalable.
What needs improvement?
I'm not working in the IT team. I'm working the sales team. While there are a lot of features that we could improve in our organization, I can't speak to the exact changes that should be made.
We'd like to be able to integrate the product with our solutions. Sometimes we face some infrastructure where there are multiple vendors and sometimes the ISE is not the best tool to manage multiple vendor infrastructure.
The price here in Brazil is very expensive.
Configurations can be a bit complicated.
Sometimes we have problems integrating logs into SIEM solutions. We have to deliver some logs to a SIEM secret platform, and sometimes it does not work well. It would be better if we had better integration or a better way to deliver the logging SIEM platforms.
For how long have I used the solution?
I've been using the solution for five to six years.
What do I think about the stability of the solution?
The stability is good. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
We have no problem with the management of our infrastructure when we need more accountability from the platform. Scalability was fine. There is no problem.
We have 6,000 people in Brazil using the solution.
How are customer service and support?
I consider technical support to be perfect. Anytime that I have problems with shifting solutions, they work well with me and I have no problems with working with them.
Which solution did I use previously and why did I switch?
I'm a reseller from Fortinet and Cisco solutions. I also have experience with Check Point.
How was the initial setup?
I can't speak to how the setup goes. I'm not working directly in deployment. What I've heard from my customers, for example, is that it is not difficult to set up, however, it may be to run all the features.
What I've heard is the first setup is very, very easy and to do some adjustments is very easy, however, when you want to go further in the configuration, that could be a bit easier.
What's my experience with pricing, setup cost, and licensing?
I can't speak to the exact pricing of the product.
What other advice do I have?
I work with various versions of the solution.
We're resellers.
Others should know it's a very good solution, very stable. There are a lot of features, and it is a secure solution. It's the first solution that we indicate to our customers and most of the time, the decision of the customer is to deploy a Cisco product.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer.
Network Engineer at a manufacturing company with 201-500 employees
Allows us to create different vendor and employee access groups
Pros and Cons
- "The policy sets give us more granular groups for end-user access."
- "It has also given us a lot of extra security as the backbone of authentication for our VPN and wireless network."
What is our primary use case?
It's mostly for authentication to our network for our end-users.
How has it helped my organization?
It's allowed us to create groups for different vendors and for employees in various groups in our company, without giving everyone access.
It has also given us a lot of extra security as the backbone of authentication for our VPN and wireless network.
What is most valuable?
The policy sets give us more granular groups for end-user access.
For how long have I used the solution?
I've been using Cisco ISE (Identity Services Engine) for five years.
What do I think about the stability of the solution?
The stability is really great. We haven't had any issues with it. We've had it for a long time. We ran an old version for three or four years without any issues.
What do I think about the scalability of the solution?
From what I have read, the scalability seems good. We haven't had to deal much with that. We have two nodes and about 2,000 sessions going at once.
How are customer service and support?
Technical support is very good. They've always been there to answer any questions, and if they don't know the answer they make sure to find someone who can give me the answer.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Cyber security resilience has been at the top of our list since 2020 because we had so many people working from home and that increased as time went on. That opened our eyes.
How was the initial setup?
I was involved when we upgraded at the beginning of this year. It was pretty straightforward, although we reached out for outsourced help.
What about the implementation team?
We used a CDW consultant.
What was our ROI?
For us, the return on investment is that it gives us easy ways to divide up our end-users for authentication, especially for our VPN.
What's my experience with pricing, setup cost, and licensing?
The pricing seems fair. The licensing can be confusing, but it is still pretty good.
Which other solutions did I evaluate?
I was asked a couple of years ago, when we were having issues with ISE, if there were alternatives, and I said I didn't want to switch because we're so embedded in this solution already.
What other advice do I have?
Talk to someone outside of Cisco too, if you're thinking about ISE. That way, you can get all the information.
We wanted to outsource some of our work because I only have two years of admin experience and another of our network engineers has about a year. This way, if the system goes down, we have a quick way to get it back up.
I would tell leaders who want to add cyber security resiliency to make sure they include team members who are involved and not just make decisions on their own.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager of IT at a financial services firm with 10,001+ employees
Enables us to control certificates of each device, preventing unauthenticated devices from entering our network
Pros and Cons
- "The access policies, and all of the policies in Cisco ISE, are important to us."
- "Unauthenticated devices are not allowed on our network and that has been an improvement for our company."
- "The user interface could be more user-friendly."
- "The pricing is fair."
What is our primary use case?
We use it for the identification of our devices, users, and wireless users.
How has it helped my organization?
Unauthenticated devices are not allowed on our network and that has been an improvement for our company. With Cisco ISE, we control the certificates of each device so that devices have internet access. The solution has eliminated trust from our network architecture.
What is most valuable?
The access policies, and all of the policies in Cisco ISE, are important to us.
What needs improvement?
The user interface could be more user-friendly.
For how long have I used the solution?
I have been using Cisco ISE (Identity Services Engine) for about six years.
What do I think about the stability of the solution?
The stability has been perfect. Our company has been using it for more than 10 years and it's stable. It's really good.
What do I think about the scalability of the solution?
The scalability is also good.
How are customer service and support?
The customer service has been perfect.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not have a previous solution.
What's my experience with pricing, setup cost, and licensing?
The pricing is fair. We have a base license and an OpEx license.
Which other solutions did I evaluate?
We looked at other solutions, but that was a long time ago.
What other advice do I have?
I would recommend ISE to colleagues. We are happy with it and we want to use it in the cloud, next. Our on-prem devices go end-of-support in 2023 and we will try to use it on the cloud.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Cisco Secure Firewall
Cisco Umbrella
Aruba ClearPass
Cisco Secure Email
Cisco Secure Network Analytics
Forescout Platform
ThreatLocker Zero Trust Platform
Cisco Secure Endpoint
Fortinet FortiNAC
Cisco Secure Client (including AnyConnect)
F5 BIG-IP Access Policy Manager (APM)
Cisco Secure Workload
ExtremeCloud IQ
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- ForeScout vs. Cisco ISE
- What are the main differences between Cisco ISE and Forescout Platform?
- Can Cisco ISE disallow authentication based on OS?
- Cisco ISE (Identity Services Engine) vs Fortinet FortiNAC: which solution is better and why?
- What are the requirements for integrating the Cisco Data Center and Cisco ISE?
- What is the biggest difference between Aruba ClearPass and Cisco ISE?
- Which is better - Aruba Clearpass or Cisco ISE?
- How would you compare Cisco ISE (Identity Services Engine) vs Forescout Platform?
- How does Cisco ISE compare with Fortinet FortiNAC?
- What is your experience with 802.1X when using EnGenius WAP/switch with Cisco ISE 2.1?













