Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs Cisco Secure Endpoint comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
8.4
Cisco Identity Services Engine enhances security and efficiency, providing cost savings and IT consolidation, making it vital for network management.
Sentiment score
7.4
Cisco Secure Endpoint enhances productivity and reduces costs by streamlining threat detection, integrating tools, and minimizing manual intervention.
Direct comparisons with Forescout reveal up to 30% to 40% difference in cost savings.
 

Customer Service

Sentiment score
5.9
Cisco Identity Services Engine customer service is praised for commitment, but technical support feedback varies due to delays and complexities.
Sentiment score
6.1
Cisco Secure Endpoint support is praised for responsiveness and expertise, providing quick issue resolution and valuable user guidance.
I rate the technical support as one out of ten.
Sometimes it's challenging to identify which support team is responsible for certain issues, which is a significant concern.
Cisco has good technical support, especially considering these are newer solutions compared to traditional routing and switching products.
 

Scalability Issues

Sentiment score
7.3
Cisco ISE excels in scalable environments, efficiently supporting deployments with flexibility for thousands of endpoints across various sizes.
Sentiment score
8.4
Cisco Secure Endpoint is scalable, integrates with SecureX for efficient management, and supports diverse industries without extra resources.
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
Cisco Secure Endpoint is definitely scalable.
 

Stability Issues

Sentiment score
7.7
Cisco ISE is reliable with high user satisfaction, though some report stability issues, especially during upgrades and high capacity.
Sentiment score
6.5
Cisco Secure Endpoint is highly stable, reliable, and trusted for performance, earning high ratings from users in various enterprises.
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
We have not encountered any problems.
 

Room For Improvement

Cisco ISE struggles with setup complexity, non-intuitive UI, integration challenges, upgrade issues, and demands for better features.
Cisco Secure Endpoint requires better integration, reporting, and UI enhancements, alongside improved pricing, AI capabilities, and IoT support.
The whole setup works well with Cisco access points and Cisco switches, but when you have multiple vendors in the environment, such as HP switches or access points like Aruba, you'll find they will not work well with Cisco Identity Services Engine (ISE).
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
Additionally, the product is vulnerable and has many bugs.
The forensic capabilities need enhancement, especially for deep forensic data collection.
 

Setup Cost

Cisco ISE offers strong features with complex, expensive pricing, but discounts through partnerships can help alleviate costs.
Cisco Secure Endpoint offers competitive and flexible pricing with value-rich features, despite some complexity in licensing.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
The license costs can range between $50,000 to $100,000 per year for enterprises.
The cost is about 100 million Ugandan shillings, which converts to approximately $30,000 per year.
Cisco is aggressive in pricing, making it competitive and sometimes even cheaper than other good products like CrowdStrike, Microsoft Defender, or SentinelOne.
 

Valuable Features

Cisco ISE provides comprehensive access control, seamless integration, and enhanced security with intuitive management for versatile network operations.
Cisco Secure Endpoint provides advanced security features, cross-platform support, and ease of use with strong threat intelligence and support.
There is value because it helps us secure the network and prevents certain things from happening which could cause financial loss.
This solution ensures organizations have secure environments and also supports robust policy enforcement, allowing control over who has access to various parts of the network.
Cisco Identity Services Engine (ISE) is very good at device administration.
Cisco Secure Endpoint is very good in machine learning, which allows it to secure offline contents even if not connected to the internet.
 

Categories and Ranking

Cisco Identity Services Eng...
Ranking in Cisco Security Portfolio
1st
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
143
Ranking in other categories
Network Access Control (NAC) (1st)
Cisco Secure Endpoint
Ranking in Cisco Security Portfolio
6th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
49
Ranking in other categories
Endpoint Protection Platform (EPP) (25th), Endpoint Detection and Response (EDR) (21st)
 

Mindshare comparison

As of August 2025, in the Cisco Security Portfolio category, the mindshare of Cisco Identity Services Engine (ISE) is 21.9%, up from 20.1% compared to the previous year. The mindshare of Cisco Secure Endpoint is 11.9%, up from 7.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cisco Security Portfolio
 

Featured Reviews

SunilkumarNaganuri - PeerSpot reviewer
Enhanced device administration hindered by complex deployment and security limitations
Cisco Identity Services Engine (ISE) needs to improve the profiling preauthentication. They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases. This will give them a roadmap for software-defined access (SDA) use cases and network segmentation. Threat detection capabilities are very weak. Additionally, the product is vulnerable and has many bugs.
Mark Broughton - PeerSpot reviewer
Tighter integration with Umbrella and Firepower gave us eye-opening information
We were using a third-party help desk. One of the ways that they were fixing problems was to delete the client and then add the client back if there was an issue where the client had stopped communicating. Any improvement in the client communicating back to the server would be good, particularly for machines that are offline for a couple of weeks. A lot of our guys were working on a rotation where the machine might be offline for that long. They were also terrible about rebooting their machines, so those network connections didn't necessarily get refreshed. So, anything that could improve that communication would be good. Also, an easier way to do deduplication of machines, or be alerted to the fact that there's more than one instance of a machine, would be useful. If you could say, "Okay, we've got these two machines. This one says it's not reporting and this one says it's been reporting. Obviously, somebody did a reinstall," it would help. That way you could get a more accurate device count, so you're not having an inflated number. Not that Cisco was going to come down on you and say, "Oh, you're using too many licenses," right away. But to have a much more accurate license usage count by being able to better dedupe the records would be good. I also sent over a couple of other ideas to our technical rep. A lot of that had to do with the reporting options. It would be really nice to be able to do a lot more in the reporting. You can't really drill down into the reports that are there. The reporting and the need for the documentation to be updated and current would be my two biggest areas of complaint. Also, there was one section when I was playing with the automation where it was asking for the endpoint type rather than the machine name. If I could have just put in the machine name, that would have been great. So there are some opportunities, when it comes to searching, to have more options. If I wanted to search, for example, by a Mac address because, for some reason, I thought there was a duplication and I didn't have the machine name, how could I pull it up with the Mac address? When you're getting to that level, you're really starting to get into the ticky tacky. I would definitely put the reporting and documentation way ahead of that.
report
Use our free recommendation engine to learn which Cisco Security Portfolio solutions are best for your needs.
865,164 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
10%
Government
9%
Manufacturing Company
9%
Computer Software Company
21%
Manufacturing Company
9%
Government
7%
Healthcare Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What do you like most about Cisco Secure Endpoint?
The product's initial setup phase was very simple.
What is your experience regarding pricing and costs for Cisco Secure Endpoint?
Cisco is aggressive in pricing, making it competitive and sometimes even cheaper than other good products like CrowdStrike, Microsoft Defender, or SentinelOne.
What needs improvement with Cisco Secure Endpoint?
Cisco Secure Endpoint lacks features like DLP which other vendors offer. XDR is new, so integration capabilities with third-party tools need improvement. The forensic capabilities need enhancement,...
 

Also Known As

Cisco ISE
Cisco AMP for Endpoints
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Heritage Bank, Mobile County Schools, NHL University, Thunder Bay Regional, Yokogawa Electric, Sam Houston State University, First Financial Bank
Find out what your peers are saying about Cisco Identity Services Engine (ISE) vs. Cisco Secure Endpoint and other solutions. Updated: July 2025.
865,164 professionals have used our research since 2012.