No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Identity Services Engine (ISE) vs OpenIAM Identity Governance comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Network Access Control (NAC) (2nd), Cisco Security Portfolio (4th)
OpenIAM Identity Governance
Average Rating
8.0
Reviews Sentiment
7.3
Number of Reviews
1
Ranking in other categories
User Provisioning Software (13th), Identity Management (IM) (29th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and OpenIAM Identity Governance aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 18.4%, down 24.5% compared to last year.
OpenIAM Identity Governance, on the other hand, focuses on User Provisioning Software, holds 3.0% mindshare, up 1.5% since last year.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)18.4%
Aruba ClearPass17.5%
Fortinet FortiNAC11.9%
Other52.2%
Network Access Control (NAC)
User Provisioning Software Mindshare Distribution
ProductMindshare (%)
OpenIAM Identity Governance3.0%
SailPoint Identity Security Cloud18.2%
Identity Manager by One Identity9.0%
Other69.8%
User Provisioning Software
 

Featured Reviews

NF
IT Network Manager at a tech services company with 10,001+ employees
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
SM
Lead Consultant at a security firm with 51-200 employees
Manages user identities and application access in a centralized way from a single console/portal
OpenIAM provides an Identity and Access Management platform which includes identity and access management (i.e., SSO, Multi-factor Authentication, password synchronization, and RBAC). Below are the features : Lower Cost of Implementation & Total Cost of Ownership: * OpenIAM uses tools, such as Groovy script to implement business rules, Grails to create new UI functionality, Activiti for workflow, PowerShell, etc. It also support web services. So it is important to find skilled technical resources readily and at reasonable cost in comparison to the large vendors, which use proprietary tools for developing custom connector or product customization as per business requirement. * OpenIAM is also based on Open Source technologies (i.e., JBoss, Apache, MySQL, CentOS), so Total Cost of Ownership is very low in comparison to other IAM products. * Compliance with standards simplifies integration. * Subscription-based license model. Ease of Use: OpenIAM offers a single unified Admin console and a single unified self-service portal for customers to use and manage the IAM suite (i.e. Identity Management, Access Management, and Multi-Factor Authentication). Modern Architecture: * Built from the ground up, not through acquisitions and proprietary technology. * SOA architecture * Cloud-enabled Enterprise Grade Product: Even though OpenIAM is based on Open Source technologies, it is: * Built on industry standards * Simplified integration * Uses established industry frameworks

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has improved our organization very much because we're now adopting the SGTs, Security Group Tags, and we're leveraging security based on those tags on our core systems and integrating with other SG firewalls."
"I have found that all of the features are valuable."
"The most valuable feature is the flexibility of the policy sets."
"Technical support is okay."
"So far, we have had no issues with the stability."
"The first benefit is that we can implement zero trust architecture because of Cisco ISE. I can assure my CISO in my company that my network is such that nobody can just bring in their laptop, desktop, or any sort of mobile device and can directly get connected to my network. That is a benefit that I can only allow people who I trust on the network."
"Our clients like Cisco ISE because they already use various Cisco solutions. It's easy for them to use this solution because they have an engineer with Cisco certifications."
"We manage and support the Cisco ISE platform for a big car rental company, and it is very stable and adds a lot of value to the network."
"Customer support is very good and available in almost all time zones."
 

Cons

"The UI is not as intuitive as some other products, even products inside of Cisco's wheelhouse."
"The upgrades could be better. Every time we try to do an upgrade, we have problems. It's a pain."
"The tracking mechanism in Cisco ISE is relatively costly, especially its vendor-specific protocol."
"If Cisco could grant more control, the features could be more focused on network and security administration, reducing the need for integration with other components."
"The primary issue is the slowness of the application and the web interface. We have multiple admin nodes and app nodes. So when I need to get some information about a particular user, the GUI would take ten to fifteen seconds in loading when we need to know right away."
"Segmentation can be improved. They can also improve security policies for each group of users, and automation can also be better."
"A lot of people tell you the hardware requirements for ISE are pretty substantial. If you're running a virtual environment, you're going to be dedicating quite a bit of resources to an ISE VM. That is something that could be worked on."
"I can tell you, even as a Cisco person, ISE was considered very complex and difficult to deploy."
"OpenIAM should improve the product/API documentation on portal which gives more flexibility to developers for product customization and connector development."
 

Pricing and Cost Advice

"The pricing is fair for what it does."
"Cisco has actually transitioned to a lot of subscription models, fees, and licenses."
"If you consider money only, Cisco ISE is not a cheap solution."
"If you go directly with Cisco for the implementation it's very, very expensive."
"It is difficult to measure security breaches, but since we have not been attacked so far, it has paid for itself over the years."
"The solution’s pricing is okay."
"Cisco ISE is not inexpensive, but the solution is well-built and worth the expense."
"Pricing and licensing are not my expertise. As far as budgeting is concerned, we run an ELA with Cisco. It's a part of our ELA."
Information not available
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
913,924 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
10%
Outsourcing Company
9%
Comms Service Provider
7%
University
14%
Outsourcing Company
11%
Government
9%
Computer Software Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
No data available
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
Ask a question
Earn 20 points
 

Also Known As

Cisco ISE
OpenIAM, OpenIAM IGA
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Citicorp, Deutsche Bank, Morgan Stanley, Marsh and McLennan, SBC Warburg, GE Electric Insurance, Tata Communications, NettBuss, AMSCAN, Time Warner, MultiPlan, Stater Bros., County of Orange - California, TUI Hotels, NV Energy, EMCOR Group, Previred
Find out what your peers are saying about Hewlett Packard Enterprise, Cisco, ThreatLocker and others in Network Access Control (NAC). Updated: September 2026.
913,924 professionals have used our research since 2012.