Try our new research platform with insights from 80,000+ expert users

CyberArk Privileged Access Manager vs Microsoft Enterprise Mobility + Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CyberArk Privileged Access ...
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
229
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (3rd), Privileged Access Management (PAM) (1st), Mainframe Security (2nd), Operational Technology (OT) Security (3rd)
Microsoft Enterprise Mobili...
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
13
Ranking in other categories
Enterprise Mobility Management (EMM) (15th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. CyberArk Privileged Access Manager is designed for Privileged Access Management (PAM) and holds a mindshare of 11.6%, down 20.0% compared to last year.
Microsoft Enterprise Mobility + Security, on the other hand, focuses on Enterprise Mobility Management (EMM), holds 1.2% mindshare, up 0.8% since last year.
Privileged Access Management (PAM) Market Share Distribution
ProductMarket Share (%)
CyberArk Privileged Access Manager11.6%
WALLIX Bastion5.1%
Delinea Secret Server5.0%
Other78.3%
Privileged Access Management (PAM)
Enterprise Mobility Management (EMM) Market Share Distribution
ProductMarket Share (%)
Microsoft Enterprise Mobility + Security1.2%
Microsoft Intune28.7%
Workspace ONE UEM11.5%
Other58.6%
Enterprise Mobility Management (EMM)
 

Featured Reviews

SI
Senior PAM Consultant at iC Consult GmbH
Makes privileged access management easy with automation and granular control
Many people underestimate the value of these tools because they treat them as simple automated password management. Once you realize the volume of passwords in your organization and factor in nonhuman passwords, you realize its value. Last year, CyberArk Impact cited 45 nonhuman passwords for every human password. If you have 10,000 employees, you can imagine the number of passwords. There are also many other operations. For example, you have a Qualys scanner that needs to reach out and touch all your endpoints and scan them for vulnerabilities. They use an API call to CyberArk to pull out a Privileged credential that allows them to log in to that target. This is an automated machine call. It is tapping into CyberArk to get that credential. There can be hundreds of thousands of those operations a day. You do not want to manage those passwords by hand. Some people marginalize the significance of such a solution by saying that it is just a fancy password changer. It goes well beyond that, especially with API calls and automation. Its importance extends beyond merely changing passwords; it involves automation, API calls, and process integration, crucial in agile environments for standing up new Amazon servers or other processes needing privileged credentials. CyberArk can automate these tasks into their build processes. Another critical feature is the proxy service via Privileged Session Manager (PSM), providing not only a proxy between your user and the target servers, protecting against malware but also offering session recording. Many companies I have worked with implemented a PAM product as a knee-jerk reaction to SOX audit requirements. They discovered they needed session recording and retention for regulatory compliance. This has become a major factor for clients instituting CyberArk, so PSM is a big deal in addition to regular password rotation.
AD
Manager IT at Konverge.AI
User experience improves efficiency while awaiting improved application performance
The solution is meeting my requirements. I don't have any direct inputs here, except that stability of the application can be improved. Sometimes it gets hung or restarts multiple times in the background, which consumes battery life. If stability can be improved, it will generally help everyone. These solutions are usually a little expensive. If costs can come down, that will generally help the masses. A reduction of around 30-35% would make it more prompting for people to take that extra jump. Due to budget constraints, I have seen people not going for Microsoft Enterprise Mobility + Security because even if the commercials get discounted for the first year, subsequent years see significant price increases.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"What I appreciate about CyberArk Privileged Access Manager is that it is not only for password security; we can also manage their applications and platforms, and whenever a user logs in, end-to-end protection is handled, including monitoring user activity through PSM servers and reacting to threats with Privileged Threat Analysis."
"The best thing about CyberArk Privileged Access Manager is that they keep on upgrading it. They continually conduct research and development from their end, and we get immediate support from CyberArk whenever OEM support is required for any task."
"The session recording and monitoring capabilities are valuable. We have real-time session management ability to record, audit, and monitor any privileged user activities. That is a big deal."
"It is scalable."
"The established sessions on the target systems are fully isolated and the privileged account credentials are never exposed to the end-users or their client applications and devices."
"It takes people out of the machine work of ensuring credentials remain up-to-date, and handles connection brokering such that human usage and credential management remain independent."
"It is useful for protecting passwords. If you need to do access security management, you can first use the CyberArk console, and after that, you can connect the firewall interface or firewall command line. Similarly, if you need to do an RDP session, you need to first log in to CyberArk before connecting to the Windows RDP session. This way, the admin doesn't know the password, and that password is changed immediately. To change the password, you first discover the old password in the network, and after that, you can change the password."
"It enables companies to automate password management on target systems gaining a more secure access management approach."
"A good feature that is present is MAM or Mobile Application Management. We can deploy this feature on the device, which is not managed by the organization. If I apply some security configuration on a personal device, the user would be really disappointed. What we do instead is that we give all access to the applications related to corporate and ask the users to use the application. We secure the application by putting the security features on the applications and not on the users' devices. This way, the users are happy, and we also meet our company's compliance standards. Then, everyone is happy."
"Microsoft Mobility and EMS include Intune for Mobility, which provides mobile device management and mobile application management. With mobile device management, you can control the entire device in an organization."
"I am very happy with it currently."
"The solution is very good at securing files. For example, if I forward a secure document, it's blocked from others, as I can send it with restrictions in relation to who can open it."
"You can scale the solution up or down by department."
"The best advantage of the product is that it provides an all-in-one solution."
"It is a stable solution...It is a scalable solution."
"The solution is scalable."
 

Cons

"One area for improvement is the plug-in development challenge. Although CyberArk provides a plug-in generator utility, it does not fully meet our needs, particularly for web-based applications."
"There should be more models and licensing plans for this software."
"The initial setup of CyberArk is a challenge if you do not have prior experience with it."
"It is very complex and difficult to set up the solution."
"The solution should be able to mitigate internal threats"
"Currently, in Secure Connect, an end user is required to enter account information manually, and cannot save any of this information for future use."
"I think they can improve account onboarding. For instance, you have to use the Password Vault utility, whereas in Thycotic I think there is a feature in the user interface that allows you to upload your account with an Excel file. So I'd like to have a similar thing in CyberArk."
"The initial setup could be simpler but it may not be as effective."
"Technical support could be improved. Sometimes they use a third party that's not so knowledgeable in the product and that can slow down things a bit."
"Microsoft Enterprise Mobility + Security is expensive."
"Microsoft's feature management is based on licenses. Microsoft follows ethical licensing and hence do not restrict the use of it."
"The MDM part of the engine could be better."
"The licensing is quite expensive."
"The licensing can be messy at times."
"The technical support from Microsoft could be better."
"Its performance needs enhancement."
 

Pricing and Cost Advice

"CyberArk Enterprise Password Vault's pricing is reasonable."
"Its price can be reduced."
"Generally, I don't get involved in the licensing or the purchasing side of it, but I do know that the licenses are expensive."
"CyberArk Enterprise Password Vault is a very expensive product."
"I have heard from my leaders that CyberArk is costlier in terms of licensing. The support and maintenance are also costly. We use their premium support, but for the price we pay, we do not get the value."
"I do not have any opinions to add about the pricing of the product."
"My company always complains about the cost of CyberArk Privileged Access Manager because it's too high."
"The product’s pricing is feasible for enterprise customers. The pricing is expensive for smaller businesses. You need to pay additional costs for service implementation and local support."
"I would rate pricing at eight out of ten. It is a bit higher because of the security features that Microsoft provides."
"The solution is cost-effective."
"We have to pay 10 dollars per user. I would rate the tool's pricing a six out of ten."
"The increase in the prices of the product might not be the actual problem, but things become complex with some new plans that were introduced by Microsoft recently."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Manufacturing Company
10%
Computer Software Company
9%
Government
6%
Pharma/Biotech Company
12%
Computer Software Company
12%
Manufacturing Company
12%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise40
Large Enterprise173
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise1
Large Enterprise5
 

Questions from the Community

How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What is your experience regarding pricing and costs for Microsoft Enterprise Mobility + Security?
The increase in the prices of the product might not be the actual problem, but things become complex with some new plans that were introduced by Microsoft recently. Initially, my company used to ha...
What needs improvement with Microsoft Enterprise Mobility + Security?
The technical support from Microsoft could be better. Because there are many changes in Microsoft, and most support centers or representatives moved to India, I can share that my experience with su...
 

Also Known As

CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
Enterprise Mobility + Security E3, Enterprise Mobility + Security E5, MS Enterprise Mobility + Security
 

Overview

 

Sample Customers

Rockwell Automation
Mars, Whole Foods, Land O'Lakes, Dow
Find out what your peers are saying about CyberArk, One Identity, Delinea and others in Privileged Access Management (PAM). Updated: January 2026.
881,082 professionals have used our research since 2012.