No more typing reviews! Try our Samantha, our new voice AI agent.

Idira Endpoint Privilege Manager vs Symantec Privileged Access Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Idira Endpoint Privilege Ma...
Ranking in Privileged Access Management (PAM)
6th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
38
Ranking in other categories
Endpoint Compliance (4th), Anti-Malware Tools (10th), Application Control (5th), Ransomware Protection (6th)
Symantec Privileged Access ...
Ranking in Privileged Access Management (PAM)
16th
Average Rating
7.8
Reviews Sentiment
7.0
Number of Reviews
53
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2026, in the Privileged Access Management (PAM) category, the mindshare of Idira Endpoint Privilege Manager is 2.4%, down from 3.3% compared to the previous year. The mindshare of Symantec Privileged Access Manager is 1.8%, up from 1.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
Idira Endpoint Privilege Manager2.4%
Symantec Privileged Access Manager1.8%
Other95.8%
Privileged Access Management (PAM)
 

Featured Reviews

Sumit Chavan - PeerSpot reviewer
Lead Consultant at a tech vendor with 501-1,000 employees
Helps secure the infrastructure and control users with admin rights
There are many features that are currently missing. A customization option is required for certain policies. For instance, if we need to stop PowerShell scripting, we have to create a different policy for that. Being able to create a sub-level policy within a top-level policy would be good. Currently, no user-based policy option is available inside the EPM console. We can only create computer-based policies. The database is available, but there is a drawback in not being able to create local groups on the EPM console. We only have to depend on Active Directory. This limits infrastructure security as we depend on the Active Directory team to manage user groups. If they remove any users, we lose control. If we could create groups locally and block them or set specific policies, we would have more control. Local endpoint management is missing from the EPM site. Moreover, there is an issue with policies not running as expected when we make enhancements. We have to find multiple ways to whitelist applications or enhance policies.
Muzi Lubisi - PeerSpot reviewer
Senior technical Consultant at CA Africa
Secure management of sensitive servers and seamless applications with direct linking
The credential injection feature is highly valued, particularly for RDP sessions. A majority of customers use it for RDP, and a couple for Linux servers. The broader capabilities, including access to multiple systems, web-based applications, and clustering, have never posed an issue. The threat analytics aspect is also a robust feature that analyzes all pertinent information.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of CyberArk Endpoint Privilege Manager is its high performance, it's the best identity security platform. The security is good. It's easy to showcase the feature and capabilities and compare it with other competitors. It competes well with other solutions. Additionally, it is a complete solution."
"I am impressed with the product's seamless integration. The PAM wallet and enterprise password wallet are good also good."
"It identifies the original source, and all instances of malicious applications in the environment."
"The solution's technical support is good."
"CyberArk Endpoint Privilege Manager helped us reduce the time for regulatory processes to approximately two to four months, completing the solution and training."
"CyberArk Endpoint Privilege Manager (EPM) 's most valuable feature is its ability to manage user application privileges and protect against ransomware attacks by controlling access to specific files and applications."
"CyberArk Endpoint Privilege Manager is entirely cloud-based, so no further upkeep is required."
"You can use it to strip users of their local admin rights and, at the same time, elevate applications for them."
"According to the users who have actually used CyberArk and CA PAM, they have said that CA PAM is ten times easier to use and manage."
"Some of the valuable features are safe access to company resources, quick, comprehensible, and intuitive management interface, and good integration capabilities."
"It is the best product for monitoring the recorded session of your IT admins and external consultants."
"CA PAM is the least expensive option than most and is easy to deploy."
"I like the fact that passwords are checked-in automatically."
"We can enforce complicated password policies and very important frequent password changes."
"One of the key things for us about the product is around its simplicity. Being able to put in the technology that allows the business to remove complexity and also allow the security improvements."
"On the access management side, our system administrators, under privileged management, don't have to use their local tools to log on to the production servers, because they log on to a web interface that makes the access more secure and keeps the sessions strictly between the production servers and the IA PAM."
 

Cons

"The installation process is pretty difficult."
"The turnaround time of the support team is an area of concern where improvements are required."
"The price of the product is an area of concern where improvements are required. The product's price should be made more flexible."
"For an experienced system implementer it will take approximately one day. However, for somebody who is inexperienced it may take up to five days."
"CyberArk Endpoint Privilege Manager is not suitable for the current situation because when you compare it to OTP, OTP is the strongest password solution. You can use it as a one-time password, but you have to log into the password manager itself and if you don't change your password, it will be the weakest link in the security. In OTP, you don't have that weakest link."
"There are many features that are currently missing. A customization option is required for certain policies."
"The tool should be more user-friendly."
"Technical support is slow to respond when we run into issues."
"I wouldn't recommend this solution because the support isn't good, and the response time isn't good."
"A better discovery interface of accounts. It does do discovery of accounts for Windows servers, and you could do UNIX servers as well, but it's kind of clunky how it does it."
"Reporting is very limited."
"We experience stability issues after every patch upgrade. This is a place where CA needs to improve drastically."
"What I hope happens with the new product CA PAM is to keep all the useful features that exist in PA, but what I’ve noticed with many new products is the UI gets polished but systems lags stability and performance or it adds additional complexity instead of simplifying the user experience."
"They need to improve how it scales."
"I wish it could create local accounts on desktops."
"Instead of just giving passwords to the user based on job function, from auditing perspective, turn that cycle around. That would really help from an auditing standpoint."
 

Pricing and Cost Advice

"I think that it was in the range of $200,000 that had to get approved."
"It's not at the lower end of the market. I think the price is reasonable considering the quality it delivers. It is a top-notch solution at a fair price point."
"The price of CyberArk Endpoint Privilege Manager is expensive."
"The professional services for one eight-hour day would be $1,800."
"I rate the solution's pricing an eight out of ten since the price can be too high for smaller businesses."
"licensing for this solution is based on the number of APV (privileged users), and the number of sessions that you want to record."
"The tool is a bit pricey compared to its competitors. My company does work with competitors, but I don't have hands-on experience with other software. I've just done some comparisons."
"The price of CyberArk Endpoint Privilege Manager is expensive. The solution is priced based on the number of accounts onboarded and the number of concurrent sessions. Everyone else is included in the price, such as support."
"Don’t go with an agent model. Don’t go with a model that has you buying a thousand different parts. Go with PAM that gives you everything, or you’ll just be paying costs of implementing another tool that PAM would have just given you up front."
"I would prefer better licensing options for the 20-100 users we have at a given time."
"It is more expensive than other solutions on the market."
"They offer per-device, per-user, or monthly and yearly licensing models."
"Pricing is fair compared to other top vendors."
"The prices are not low, but one can ask for a discount. It’s not the cheapest PAM solution."
"Cost-wise, CA was better compared to others in the market. ​"
"Appliances are relatively cheap, don’t skimp. Make sure you have redundancy, high availability, and enough appliances to manage the concurrent workload."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
906,852 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Manufacturing Company
11%
Outsourcing Company
7%
Government
7%
Outsourcing Company
14%
Construction Company
13%
Financial Services Firm
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise19
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise30
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What is your experience regarding pricing and costs for CyberArk Endpoint Privilege Manager?
I believe it's quite a reasonably priced solution. It's not very common to use CyberArk because it's a niche solution, but customers who are willing to control administrative accounts are willing t...
What needs improvement with CyberArk Endpoint Privilege Manager?
While CyberArk Endpoint Privilege Manager is a great tool, I believe the functionality could be wider. If it could work not only with permissions but also involve pure EDR tasks or User and Entity ...
What is your experience regarding pricing and costs for Symantec Privileged Access Manager?
Due to the nature of the solution, it is hard to gauge, but compared to competitors, the pricing is very good. I would rate it as an eight and a half out of ten.
What needs improvement with Symantec Privileged Access Manager?
Recent releases need improvement in webpage management. For instance, navigating through a webpage that acts like a wizard, where I proceed to the next page and enter more information, is not handl...
What is your primary use case for Symantec Privileged Access Manager?
With the customers that I have so far, I help them broker RDP sessions to sensitive servers, particularly those that manage aspects like physical access. I have also done it for backend databases, ...
 

Also Known As

Viewfinity
CA PAM, Xceedium Xsuite, CA Privileged Access Manager
 

Overview

 

Sample Customers

Information Not Available
NEOVERA, Telesis, eSoft
Find out what your peers are saying about Idira Endpoint Privilege Manager vs. Symantec Privileged Access Manager and other solutions. Updated: June 2026.
906,852 professionals have used our research since 2012.