No more typing reviews! Try our Samantha, our new voice AI agent.

IBM Security Secret Server vs Idira Privileged Access Manager comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Security Secret Server
Ranking in Privileged Access Management (PAM)
20th
Average Rating
8.2
Reviews Sentiment
5.7
Number of Reviews
8
Ranking in other categories
No ranking in other categories
Idira Privileged Access Man...
Ranking in Privileged Access Management (PAM)
1st
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (2nd), Mainframe Security (1st), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

As of September 2026, in the Privileged Access Management (PAM) category, the mindshare of IBM Security Secret Server is 1.4%, up from 1.0% compared to the previous year. The mindshare of Idira Privileged Access Manager is 8.6%, down from 16.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
Idira Privileged Access Manager8.6%
IBM Security Secret Server1.4%
Other90.0%
Privileged Access Management (PAM)
 

Featured Reviews

AsifIqbal - PeerSpot reviewer
Chief Information Security Officer at a insurance company with 501-1,000 employees
Privileged access monitoring has strengthened identity control and improved security posture
I find the monitoring and recording parts of IBM Security Secret Server to be the most valuable features. Password vaulting is somewhat typical, but I rate monitoring and recording as very good features, along with ease of deployment. The reporting tools in IBM Security Secret Server have helped me identify vulnerabilities. From the monitoring part, you can somewhat cover the identity vulnerability aspect. However, for identity vulnerability, I think the best approach is to use IAM rather than PAM. It is easy to integrate IBM Security Secret Server with cybersecurity frameworks, which is a very important aspect. When we are improving our attack surface, identity is the most important thing that we need to cover, and PAM will play a very crucial role in improving our cybersecurity framework and architecture. The main benefits that IBM Security Secret Server provides for me include complete control over the privileged identities, which are the main sources that can have the privilege to make numerous changes on the system. If we protect these identities through PAM and provide elevation on their accounts when required, then we can improve our security posture and infrastructure security.
Singaravelu C - PeerSpot reviewer
CyberArk Engineer at Tata Consultancy
Provides full visibility into user activity and ensures secure end-to-end access across critical systems
In CyberArk Privileged Access Manager, I see room for improvement as I am working in the on-premises networks, and now we are also having the cloud-based PAM. So there, everything is maintained by the CyberArk Privileged Access Manager team, and we are only maintaining the PSM servers. So it is already upgraded from the on-premises network to the cloud network. If you ask me what we can implement beyond that, I just need a few minutes to think about what new things, because it is already an end-to-end security on-premises itself. Now, when it comes to PCloud, Privileged Cloud, it is more secure than the on-premises networks because most of the things are handled using the cloud itself. So it is an already upgraded version; we do not need to implement something new. But if you think in that way, we can have a chance to implement our things. If anything could be improved in CyberArk Privileged Access Manager, I think we could build a small agent AI in my team, we could give access to these logs—the Vault logs, PSM logs, and CPM logs. Whenever the system is going down, the AI will automatically check. If we actually implement agent AI in CyberArk Privileged Access Manager, it will check the logs, and if any errors are coming, it automatically triggers alerts and gives the solution. That is the best improvement I can think of because these days, most things are done by agent AI. So if we also implement this agent AI in CyberArk Privileged Access Manager, we can add more features.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The main benefits that IBM Security Secret Server provides for me include complete control over the privileged identities, which are the main sources that can have the privilege to make numerous changes on the system, and if we protect these identities through PAM and provide elevation on their accounts when required, then we can improve our security posture and infrastructure security."
"Stability-wise, I think it is a very good solution."
"Access to privileged, shared credentials is simplified by optimizing the whole workflow and approval processes."
"What I like best about IBM Security Secret Server is its single-access console. It's also easy to manage and fulfills the requirements with the least resistance."
"This product has been able to cover most of the requests from our customers."
"It is one of the most well-known names in this field."
"Centralized Password Management: Our client has more than 400 geographical locations and approximately ten employees work at each location."
"The live recording is a very useful feature."
"The combination of CPM and PSM resolves a lot of use cases."
"It is a central repository. Therefore, if someone needs to access a server, then they go through CyberArk PAM. It provides a secure way to do this and CyberArk PAM records everything. For example, if you are connecting to a Linux server, then once you get into the Linux server and if it is integrated with CyberArk, it will automatically start recording everything that is being done. In most banks, seeing the recordings is very useful. If there are any gaps or something has happened which shouldn't have happened, then we can check the logs and videos. So, it gives security, in a robust manner, to the organization."
"The value is probably the best of all of the other products which are offering the same services."
"The password rotation and cyber gateway have been quite useful."
"I see the Auto IT integration as the most valuable feature."
"The features that are most effective, like every PAM solution, include monitoring and password rotations."
"The auditing and recording functionality along with stringent password-change policies and one-time password use has made compliance with customer requirements a much clearer and easily managed process."
"If properly set up, CyberArk Enterprise Password Vault has good stability, and is a very solid tool. It can run by itself. Its most valuable features are auto password recycling and PSM."
 

Cons

"I mention that password vaulting and password rotation in IBM Security Secret Server are basically the same thing, and it becomes somewhat complex when integrating a different system with them because it requires API development."
"Secret Server should have the ability to discover privileged accounts in the servers, like the administrator or users, from SQL and Oracle without having to import a script."
"If you have a hosted PIM in your local environment and you plan to migrate it to some cloud-based environment, then migration will become a painful task."
"Although much has improved in last two years, the GUI for IBM products can be improved."
"The newer interface is more difficult to use than the previous one, and consequently, new users might need more training."
"The newer interface is maybe confusing old customer that using previous one from their point of views, I think they will need little pass of time to be familiar with."
"Unfortunately, the technical support is not very responsive because we purchased it from IBM; however, the actual support comes from Thycotic."
"It would be preferable if the full proxy was included in the IBM Security Secret Server."
"There are upwards of six components you need to set it up. And you might need anywhere from two to five servers. It takes some work to set that up, especially in a larger environment."
"One area for improvement is the plug-in development challenge. Although CyberArk provides a plug-in generator utility, it does not fully meet our needs, particularly for web-based applications. The plug-in generator currently works only for Telnet and SSH connections. We cannot generate a plug-in for web-based applications."
"Areas of CyberArk Privileged Access Manager that can be improved include offering clearer configuration options."
"The major pain point that we have is the capacity of CyberArk due to the sheer volume of NPAs that we are managing."
"CyberArk could enhance its usability by simplifying its architecture and design."
"Authentication to the PVWA utilises integration to IIS. Therefore, it is not as strong as desired."
"I sometimes require learning resources when there is a new solution for CyberArk."
"For users to access a system via CyberArk Privileged Session Manager, a universal connector needs to be coded in a language called AutoIT and its support for web browsers is so-so. Other products like Centrify have browser plugins that can help automate the process when using their products."
 

Pricing and Cost Advice

"I believe that we paid 35,000 or 40,000 US dollars for it."
"My rating for the IBM Security Secret Server pricing is seven out of ten. It could be cheaper."
"The price could be better. I think it's a good price for the on-premises environment and the high availability for enterprises the solution provides."
"The price of this solution is quite reasonable."
"I do not have any opinions to add about the pricing of the product."
"I would rate the tool’s pricing a six out of ten."
"I would rate CyberArk's pricing a nine out of ten, with one being cheap and ten being expensive. It's one of the most expensive solutions in the market, but it's worth it."
"CyberArk is very expensive and there are additional fees for add-ons."
"They have two types of licensing: purchase and subscription. You have to pay for each admin user, such as Microsoft admin, mail admin, database admin, etc."
"Compared to other solutions, it is costly."
"Although CyberArk Privileged Access Management is expensive, its protection capabilities outweigh the cost."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
913,076 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Insurance Company
19%
Outsourcing Company
13%
Construction Company
12%
Performing Arts
7%
Outsourcing Company
12%
Financial Services Firm
12%
Manufacturing Company
9%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise2
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise175
 

Questions from the Community

What needs improvement with IBM Security Secret Server?
I believe there is not much that can be improved for IBM Security Secret Server. Providing local support and local vendor availability would be beneficial so we are not dependent on international s...
What is your primary use case for IBM Security Secret Server?
IBM Security Secret Server serves multiple use cases for us, including the monitoring of privileged users, as well as the recording and password vaulting of their accounts, passwords, and need-base...
What advice do you have for others considering IBM Security Secret Server?
I mention that password vaulting and password rotation in IBM Security Secret Server are basically the same thing, and it becomes somewhat complex when integrating a different system with them beca...
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What needs improvement with CyberArk Privileged Access Manager?
I believe account discovery and rolling support need to be improved. Account discovery is important when integrating with other systems, as other PAM solutions can perform account discovery and onb...
 

Also Known As

IBM Secret Server, Secret Server, IBM Security Privileged Identity Manager
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

Information Not Available
Rockwell Automation
Find out what your peers are saying about IBM Security Secret Server vs. Idira Privileged Access Manager and other solutions. Updated: September 2026.
913,076 professionals have used our research since 2012.