No more typing reviews! Try our Samantha, our new voice AI agent.

IBM Resource Access Control Facility vs Idira Privileged Access Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Resource Access Control...
Ranking in Mainframe Security
5th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
3
Ranking in other categories
No ranking in other categories
Idira Privileged Access Man...
Ranking in Mainframe Security
1st
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (3rd), Privileged Access Management (PAM) (1st), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

As of June 2026, in the Mainframe Security category, the mindshare of IBM Resource Access Control Facility is 11.5%, down from 15.5% compared to the previous year. The mindshare of Idira Privileged Access Manager is 5.3%, up from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Mainframe Security Mindshare Distribution
ProductMindshare (%)
CyberArk Privileged Access Manager5.3%
IBM Resource Access Control Facility11.5%
Other83.2%
Mainframe Security
 

Featured Reviews

KC
Senior systems engineer at Unum
We're able to do role-based security so when new people join the company we're able to quickly add them to the proper security through role-based security groups.
It's completely secure. That's the best answer I can give you. We're able to do role-based security so when new people join the company we're able to quickly add them to the proper security through role-based security groups. Our resources are secured with this product I would welcome something…
Atul-Gujar - PeerSpot reviewer
CyberArk manager at a comms service provider with 10,001+ employees
Secures critical infrastructures with essential user session audit records
A potential area for improvement is enhancing support for cluster environments and distributed Vaults. Clients in multiple countries that need central access have different challenges that require better solutions from CyberArk. For financial services, CyberArk can improve incident response by ensuring fast support for critical priority tickets to meet compliance requirements. Providing more documentation on CyberArk is recommended for new team members to enhance their troubleshooting capabilities. I understand it's up to the client, but 99% fail to change the demo key, so it's crucial for CyberArk to emphasize changing the key and documenting it as part of the installation process.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Technical support is exceptional."
"It's completely secure."
"Perfectly integrated with the z/OS operating system and all the other products in the IBM z/OS family."
"CyberArk PAM can be easily automated."
"This solution is quite efficient."
"Its' quite stable."
"There are no issues with scalability, and our clients are very happy to use the product."
"The benefit is knowing where your accesses are, who has access to what, and it provides improved security around having your credentials locked down and rotated regularly."
"It has improved our organization by being able to consolidate several privileged access technologies into a unified tool, while session recording, auditing capability, and approval workflows allow a high degree of control over the organisation’s privileged access requirements for compliance purposes."
"The most valuable feature is that it always provides flexibility, password quality and one-time user check-in and check-out."
"It supports lots of requirements in the privileged access management area."
 

Cons

"I would welcome something that is more easily integrated with distributor platforms."
"The way to pull security logs could be better."
"I would like the generation of RACF on-screen listings and reports to be more flexible."
"The documentation is rather basic and it is missing many use cases."
"We would like to expand the usage of the auto discovery accounts feed, then on our end, tie in the REST API for automation."
"The scalability, sometimes, is lacking. It works really well for more static environments... But for an environment where you're constantly spinning up new infrastructure or new endpoints, sometimes it has a hard time keeping up."
"I think they can improve account onboarding. For instance, you have to use the Password Vault utility, whereas in Thycotic I think there is a feature in the user interface that allows you to upload your account with an Excel file. So I'd like to have a similar thing in CyberArk."
"It's not a cheap application. It's very expensive."
"There is a bit of a learning curve, but it's a pretty complex solution."
"It needs more plugin connectors for all devices."
"Three-year support (unlimited case and call support) is free with license purchase but I would say sometimes it's not sufficient to resolve the issues with this model."
 

Pricing and Cost Advice

Information not available
"It can be an expensive product."
"The main problem for the tool is its licensing. I work for a really big company. When you try to develop this as a service, usually you work with leverage teams who are formed with dozens of members. You might dedicate one FTE, or less, for something, e.g., an antivirus administrator. You might have half an FTE's effort dedicated to administering the antivirus, but then you have a team of about 30 users who might access that ticket. The problem is that CyberArk eliminated the possibility of concurrent users years ago. This is a big problem for companies who work with leverage teams. You need to pay for everyone. 40 licenses are used by 20 or 30 people. This is a big problem because licenses are not precisely cheap."
"The pricing for CyberArk is on the higher side compared to other Privileged Access Management products. Something should be done regarding enterprise licensing for long-standing customers."
"The price of the solution is reasonable."
"My company always complains about the cost of CyberArk Privileged Access Manager because it's too high."
"From a client perspective, CyberArk's pricing is fair but there is a significant increase each year. They should limit the price increase because this could potentially drive customers to other partners. Price changes should be at defined intervals. There should not be sudden jumps."
"Before we bought it, they were licensing each function individually, which got complicated and very expensive. When we decided to buy it, it was much more straightforward and still quite expensive, but it brings a lot of value and risk reduction to the organization."
"The product's licensing is yearly. I would rate the solution's pricing a six out of ten."
report
Use our free recommendation engine to learn which Mainframe Security solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
26%
Manufacturing Company
11%
Government
9%
Healthcare Company
8%
Financial Services Firm
13%
Manufacturing Company
11%
Construction Company
6%
Computer Software Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise175
 

Questions from the Community

Ask a question
Earn 20 points
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What needs improvement with CyberArk Privileged Access Manager?
I believe account discovery and rolling support need to be improved. Account discovery is important when integrating with other systems, as other PAM solutions can perform account discovery and onb...
 

Also Known As

IBM RACF
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

Information Not Available
Rockwell Automation
Find out what your peers are saying about IBM Resource Access Control Facility vs. Idira Privileged Access Manager and other solutions. Updated: June 2026.
900,644 professionals have used our research since 2012.