No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Identity Services Engine (ISE) vs Symantec Privileged Access Manager comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Network Access Control (NAC) (2nd), Cisco Security Portfolio (4th)
Symantec Privileged Access ...
Average Rating
7.8
Reviews Sentiment
7.0
Number of Reviews
53
Ranking in other categories
Privileged Access Management (PAM) (15th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and Symantec Privileged Access Manager aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 18.4%, down 24.5% compared to last year.
Symantec Privileged Access Manager, on the other hand, focuses on Privileged Access Management (PAM), holds 1.9% mindshare, up 1.5% since last year.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)18.4%
Aruba ClearPass17.5%
Fortinet FortiNAC11.9%
Other52.2%
Network Access Control (NAC)
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
Symantec Privileged Access Manager1.9%
Idira Privileged Access Manager8.6%
Safeguard by One Identity4.3%
Other85.2%
Privileged Access Management (PAM)
 

Featured Reviews

NF
IT Network Manager at a tech services company with 10,001+ employees
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
Muzi Lubisi - PeerSpot reviewer
Senior technical Consultant at CA Africa
Secure management of sensitive servers and seamless applications with direct linking
The credential injection feature is highly valued, particularly for RDP sessions. A majority of customers use it for RDP, and a couple for Linux servers. The broader capabilities, including access to multiple systems, web-based applications, and clustering, have never posed an issue. The threat analytics aspect is also a robust feature that analyzes all pertinent information.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has allowed us to pull in multiple authentication databases, then centralize them into a captive portal system."
"For guests we give them limited access to the internet when they come in so that access has been useful. Previously, we just used to give them the APN key which they would leave with. Now, we give them credentials to use that are for a limited period of time."
"For customers, it's great. It has a GUI, so the customers themselves can edit ACLs or even modify the policies. It's also an all-in-one solution with RADIUS and TACACS."
"The endpoint profiling feature is among the most valuable because it keeps me from having to manually maintain a MAC address bypass list to track endpoints. I can have ISE profile them for me and then put them in the right bucket."
"The most valuable thing in ISE is the adoption of EAP deep that came in [version] 2.7, so we can do authentication based on user and machine certificates in one authentication."
"The most valuable features are the NAC and the bundles that are available with Cisco ISE, such as Cisco ACS being integrated."
"I like the guest access feature, which has been important for us."
"Typically, the installation is pretty simple."
"The CA PAM’s ability to seamlessly integrate and provide a demarcation between users and systems is the most attractive aspect."
"This solution really makes a big difference."
"The DB clustering is a really good benefit of using CA PAM."
"The product is very scalable in terms of concurrent sessions that it can handle at a time, number of device it can support, accounts that it can manage, or number of nodes that you can deploy in a cluster."
"On the access management side, our system administrators, under privileged management, don't have to use their local tools to log on to the production servers, because they log on to a web interface that makes the access more secure and keeps the sessions strictly between the production servers and the IA PAM."
"The exposure of sensitive usernames and passwords has been limited in a massive way."
"The system is very stable."
"If I remember correctly, it was the two factor authentication, and the single most important capability was it supported PIV and CAC as one of the two factors."
 

Cons

"I would like to see them simplify the dashboard. It's very configurable, but, at the same time, it's not easy to maneuver through it. They should "Merakify" it."
"It is too complex. It should be easy to use. We are not such a big team. We only have three engineers to work with this, and we don't use all of the functionality of the product. Its range of functionality is too wide for us, and this is the reason why we are thinking of switching to a more simple product. We have shortlisted a Microsoft solution. We have a big footprint for Microsoft products, especially in security. As a global strategy, we try to leverage to the maximum what is possible around Microsoft."
"Cisco ISE can become quite complex, especially with policy sets, the entire authentication process, and everything involved."
"The interface could be more user-friendly and the ability to apply rules to MAC addresses, for example, if I wanted to allow a certain MAC address access at a particular time I cannot make this adjustment."
"In an upcoming release, the solution needs to be more agentless and more independent. Additionally, there could be improved integration with other next-generation solutions, such as Palo Alto, Fortinet, or Check Point."
"Automation and integrations are the areas it could be improved, as we get more and more away from a lot of human involvement and into machine learning and just trusting that these systems could automatically help us."
"I don't like that the licensing structure doesn't allow us to have the 3.1 operating system — it forces us to use version 2.9."
"The UI and UX could be more seamless and easier to use."
"They should include some assignments in the test environment to explore the product's features."
"I’m no fan of Java as an application front-end, as it tends to have issues depending on what browser one’s using."
"Session limitation is a very critical feature that cannot be addressed by CA PAM."
"I would like it to support more types of integration."
"Evaluations are not just about features and functions of this specific product, but it is taking that holistic view around what else we can get out of it in the next three to five years."
"We have to do a lot of manual work to automate features."
"The rule management portion and reporting is very weak on its own."
"I would like this solution to be simpler. It should have a one-click access that works together with AWS."
 

Pricing and Cost Advice

"Over the years, licensing has been confusing and complicated because there are so many different licenses for each different product and each different iteration of the product."
"It's an expensive solution when compared to other vendors."
"ISE has always been expensive compared to other products in terms of what it does on a user level."
"The pricing is good. The last time we purchased four new appliances the price was doable for any organization of our size."
"I am not aware of the current price for Cisco ISE, but considering it is a Cisco product, it is likely to be quite high."
"In terms of the licensing and the pricing structure of the Cisco Identity Services Engine, there's been a huge advantage to our clients recently with the advent of the enterprise agreement."
"I believe I have paid around $1,000 in licensing fees. The license is annual."
"Cybersecurity resilience has been very important to our organization and has been a big factor. We've had issues in the past, but one of the things I like about ISE is its logging features. Security wise or information wise, it really has been a powerful tool."
"The version we are using is affordable compared to BeyondTrust, which is maybe three to four times as expensive, but it depends on the features."
"The prices are not low, but one can ask for a discount. It’s not the cheapest PAM solution."
"Pricing is fair compared to other top vendors."
"The licensing is simple and scalable."
"I would prefer better licensing options for the 20-100 users we have at a given time."
"They offer per-device, per-user, or monthly and yearly licensing models."
"It is more expensive than other solutions on the market."
"Don’t go with an agent model. Don’t go with a model that has you buying a thousand different parts. Go with PAM that gives you everything, or you’ll just be paying costs of implementing another tool that PAM would have just given you up front."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
913,076 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
10%
Outsourcing Company
9%
Comms Service Provider
7%
Outsourcing Company
20%
Construction Company
13%
Comms Service Provider
6%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise30
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What is your experience regarding pricing and costs for Symantec Privileged Access Manager?
Due to the nature of the solution, it is hard to gauge, but compared to competitors, the pricing is very good. I would rate it as an eight and a half out of ten.
What needs improvement with Symantec Privileged Access Manager?
Recent releases need improvement in webpage management. For instance, navigating through a webpage that acts like a wizard, where I proceed to the next page and enter more information, is not handl...
What is your primary use case for Symantec Privileged Access Manager?
With the customers that I have so far, I help them broker RDP sessions to sensitive servers, particularly those that manage aspects like physical access. I have also done it for backend databases, ...
 

Also Known As

Cisco ISE
CA PAM, Xceedium Xsuite, CA Privileged Access Manager
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
NEOVERA, Telesis, eSoft
Find out what your peers are saying about Hewlett Packard Enterprise, Cisco, ThreatLocker and others in Network Access Control (NAC). Updated: August 2026.
913,076 professionals have used our research since 2012.