No more typing reviews! Try our Samantha, our new voice AI agent.

Idira Endpoint Privilege Manager vs McAfee Application Control comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Idira Endpoint Privilege Ma...
Ranking in Application Control
6th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
38
Ranking in other categories
Endpoint Compliance (4th), Privileged Access Management (PAM) (7th), Anti-Malware Tools (11th), Ransomware Protection (5th)
McAfee Application Control
Ranking in Application Control
8th
Average Rating
7.6
Reviews Sentiment
6.5
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Application Control category, the mindshare of Idira Endpoint Privilege Manager is 9.4%, up from 5.1% compared to the previous year. The mindshare of McAfee Application Control is 5.7%, down from 7.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Control Mindshare Distribution
ProductMindshare (%)
Idira Endpoint Privilege Manager9.4%
McAfee Application Control5.7%
Other84.9%
Application Control
 

Featured Reviews

Sumit Chavan - PeerSpot reviewer
Lead Consultant at a tech vendor with 501-1,000 employees
Helps secure the infrastructure and control users with admin rights
There are many features that are currently missing. A customization option is required for certain policies. For instance, if we need to stop PowerShell scripting, we have to create a different policy for that. Being able to create a sub-level policy within a top-level policy would be good. Currently, no user-based policy option is available inside the EPM console. We can only create computer-based policies. The database is available, but there is a drawback in not being able to create local groups on the EPM console. We only have to depend on Active Directory. This limits infrastructure security as we depend on the Active Directory team to manage user groups. If they remove any users, we lose control. If we could create groups locally and block them or set specific policies, we would have more control. Local endpoint management is missing from the EPM site. Moreover, there is an issue with policies not running as expected when we make enhancements. We have to find multiple ways to whitelist applications or enhance policies.
reviewer1437648 - PeerSpot reviewer
IT Security Specialist at a tech services company with 201-500 employees
Easy to configure, reliable, secure, and has good support
With some specific versions, we are experiencing some issues where the policy configuration has some problems with the parent and child processes. There have been problems with the relationship between the parent and child process, from time to time. I would like to see better reporting and alerting features in the future.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of CyberArk Endpoint Privilege Manager is its ability to reset passwords every time that it is needed or periodically."
"It identifies the original source, and all instances of malicious applications in the environment."
"I like that we have the power to blacklist, whitelist, and greylist applications."
"The password rotation and the session recording are the most valuable features."
"The feature called PTA, which stands for Privileged Threat Analytics keeps track of what admins are doing and works with Centimeters. If something fishy is going on with a user's credentials, it alerts the security team so they can act fast. Plus, it automates stuff like resetting credentials or blocking users. So, if there's a potential hack, CyberArk can change passwords and lock out users in a snap. It also gives you a heads-up if anything unusual is going on with server activities, like someone creating new users with uncontrolled credentials."
"I like that you can remove the admin rights from the user's computer and have control over the environment. That means you can delete the local admins and grant them proper privileges with the console. So, they will get proper permissions for applications they need, but we don't have to do it. In the domain where we don't have control, the user can only do specified actions, but not all of them."
"It has drastically reduced the attack surface for local administrative rights and the chance of escalation of privilege. We've removed, at this point, close to 98 percent of the local administrative accounts on workstations. If there were an incident, it would stop at that point and we'd be able to know."
"The product is very flexible"
"This is a basic solution; the policy screen is okay, and it's easy to configure."
"We also like the Change Control. We can control how things get executed. It has signatures for different kinds of protocols."
"The most valuable feature is the whitelisting; I can test the applications and we can also predefine rules for Windows, rules for the application and control."
"It does its job well, and it's not causing a lot of trouble."
 

Cons

"What I would really like to see improved is the AIM (Application Identity Manager). I think that it could be simpler to use, and much more straight forward."
"CyberArk Endpoint Privilege Manager can be better by making its UI more consistent."
"The solution is very expensive."
"The price of the solution should improve."
"It is hard to deal with technical support if you are not certified."
"For an experienced system implementer it will take approximately one day. However, for somebody who is inexperienced it may take up to five days."
"My recommendation for improvement is to add functionality for when users request access to an application. There's a pop-up UI, but it's not very customizable. I suggest creating a UI where we can write scripts or use SDKs to enhance it. This could automatically create tickets in a system like ServiceNow when users request an application. If a manager approves, we could automatically push policies to those users."
"CyberArk Endpoint Privilege Manager is not suitable for the current situation because when you compare it to OTP, OTP is the strongest password solution. You can use it as a one-time password, but you have to log into the password manager itself and if you don't change your password, it will be the weakest link in the security. In OTP, you don't have that weakest link."
"I would like to see better reporting and alerting features in the future."
"The initial setup is not straightforward, it was complex. The manuals don't have all the information you need to deploy it."
"The intrusion detection features should also be improved. It is a very good feature but it should be maximized."
"With some specific versions, we are experiencing some issues where the policy configuration has some problems with the parent and child processes."
 

Pricing and Cost Advice

"CyberArk Endpoint Privilege Manager is slightly expensive, but costs can be negotiated to become more competitive."
"The tool's pricing is reasonable for customers."
"It is an expensive solution."
"The cost for CyberArk is very high."
"The tool is priced high. I would rate its pricing an eight out of ten."
"Pricing depends on how many devices you use. Right now, on-premise, it costs us a little, but it's worth it. It seems like the cloud solution is much more expensive. We got this solution one year ago, and it's like we bought the solution, and now they are not going to support it on-premise anymore. We are in the implementation phase, and we missed this, and we already paid for the licenses. This is wasted time from my perspective, and CyberArk should be more customer-friendly."
"I think that it was in the range of $200,000 that had to get approved."
"I believe it's quite a reasonably priced solution. It's not very common to use CyberArk because it's a niche solution, but customers who are willing to control administrative accounts are willing to pay this money."
Information not available
report
Use our free recommendation engine to learn which Application Control solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
11%
Outsourcing Company
8%
Construction Company
8%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise19
No data available
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What is your experience regarding pricing and costs for CyberArk Endpoint Privilege Manager?
I believe it's quite a reasonably priced solution. It's not very common to use CyberArk because it's a niche solution, but customers who are willing to control administrative accounts are willing t...
What needs improvement with CyberArk Endpoint Privilege Manager?
While CyberArk Endpoint Privilege Manager is a great tool, I believe the functionality could be wider. If it could work not only with permissions but also involve pure EDR tasks or User and Entity ...
Ask a question
Earn 20 points
 

Also Known As

Viewfinity
McAfee Application, Change Control
 

Overview

 

Sample Customers

Information Not Available
Contec
Find out what your peers are saying about Idira Endpoint Privilege Manager vs. McAfee Application Control and other solutions. Updated: June 2026.
908,800 professionals have used our research since 2012.