No more typing reviews! Try our Samantha, our new voice AI agent.

Idira Endpoint Privilege Manager vs VMware Carbon Black App Control comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Idira Endpoint Privilege Ma...
Ranking in Application Control
6th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
38
Ranking in other categories
Endpoint Compliance (4th), Privileged Access Management (PAM) (7th), Anti-Malware Tools (11th), Ransomware Protection (5th)
VMware Carbon Black App Con...
Ranking in Application Control
7th
Average Rating
9.2
Reviews Sentiment
6.8
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Application Control category, the mindshare of Idira Endpoint Privilege Manager is 9.4%, up from 5.1% compared to the previous year. The mindshare of VMware Carbon Black App Control is 10.4%, down from 17.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Control Mindshare Distribution
ProductMindshare (%)
Idira Endpoint Privilege Manager9.4%
VMware Carbon Black App Control10.4%
Other80.2%
Application Control
 

Featured Reviews

Sumit Chavan - PeerSpot reviewer
Lead Consultant at a tech vendor with 501-1,000 employees
Helps secure the infrastructure and control users with admin rights
There are many features that are currently missing. A customization option is required for certain policies. For instance, if we need to stop PowerShell scripting, we have to create a different policy for that. Being able to create a sub-level policy within a top-level policy would be good. Currently, no user-based policy option is available inside the EPM console. We can only create computer-based policies. The database is available, but there is a drawback in not being able to create local groups on the EPM console. We only have to depend on Active Directory. This limits infrastructure security as we depend on the Active Directory team to manage user groups. If they remove any users, we lose control. If we could create groups locally and block them or set specific policies, we would have more control. Local endpoint management is missing from the EPM site. Moreover, there is an issue with policies not running as expected when we make enhancements. We have to find multiple ways to whitelist applications or enhance policies.
AS
Security Administrator at EJADA
We can isolate problem machines and limit their access
We use App Control to scan the network for virtual machines that have unauthorized applications. We can isolate the problem VMs and control application access.  More than two years. I rate Carbon Black App Control 10 out of 10 for stability. I rate App Control six out of 10 for scalability.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"CyberArk Endpoint Privilege Manager enhances computer security by providing minimal access, effectively preventing ransomware attacks."
"The most valuable feature of CyberArk Endpoint Privilege Manager is its ability to reset passwords every time that it is needed or periodically."
"The tool is an endpoint management system. It monitors everything a standard user does and helps elevate privileges when necessary for advanced users. It keeps an auditable trail of all activities. Practically, it stops and blocks potentially hazardous user behavior, whether intentional or unintentional. Certain companies must use endpoint management software because of national or international rules or ISO norms."
"The biggest benefit of CyberArk EPM for our customers is control over privileged access for endpoints. Endpoints are often the starting point for attackers to enter and move within a network. CyberArk EPM bridges the gap between security and operations teams. Operations teams are happy because work isn't stopped due to admin rights issues, while security teams are satisfied that full admin rights aren't given to all users."
"Users can scale the solution."
"I like that you can remove the admin rights from the user's computer and have control over the environment. That means you can delete the local admins and grant them proper privileges with the console. So, they will get proper permissions for applications they need, but we don't have to do it. In the domain where we don't have control, the user can only do specified actions, but not all of them."
"I like that you can remove the admin rights from the user's computer and have control over the environment."
"The most valuable feature of the solution is its performance."
"We have been dealing with VMware Carbon Black App Control for one year, and during this time we have already made sure that this is the best solution to protect our user machines and servers."
"The effectiveness of application whitelisting is very good."
"The visibility, reporting, and the ability to stop or prevent malicious or undesired applications from being installed are the most valuable features."
"It offers a sense of security where anything that comes in, regardless of what it is, unless you approve it manually, it's not going to run."
"The API integration is good."
"Carbon Black offers a total lockdown solution; it shows us the attacks that are being attempted against our infrastructure and how we are being protected."
"We use App Control to scan the network for virtual machines that have unauthorized applications. We can isolate the problem VMs and control application access."
"All the functions within VMware Carbon Black App Control are valuable."
 

Cons

"CyberArk Endpoint Privilege Manager could be improved by simplifying the administration process, specifically when setting up policies and applications."
"CyberArk Endpoint Privilege Manager can be better by making its UI more consistent."
"It is hard to deal with technical support if you are not certified."
"The price of the solution should improve."
"It was complex to introduction the product to the end-users and the technical team."
"CyberArk has some performance issues. For example, servers could not handle the solution when we first took CyberArk Endpoint Privilege Manager."
"CyberArk meets clients' need very spot-on. It covers everything customers ask for. As for improvements, honestly, the feedback's been really positive. I haven't heard any specific areas that need work."
"A customization option is required for certain policies. For instance, if we need to stop PowerShell scripting, we have to create a different policy for that. Being able to create a sub-level policy within a top-level policy would be good."
"The solution should have overhead in keeping lists of applications that you want don't want to run."
"Another issue is that even sometimes if you approve, for example, Adobe as a publisher, you say any product or anything that's from Adobe has to run. It generally runs, but especially in a large environment and with a lot of users, sometimes, due to some certification validation issues or some other issue, it might stop the process from running. Genuine processes like Adobe and Chrome can get blocked. so that needs to be improved."
"Its setup is very complex, and it requires guidance from the support team, but it is well worth the effort."
"Carbon Black does not use the database for identifying the file, the fields, or malware."
"I would like to see the addition of some more features that are in other, similar solutions."
"The initial setup is somewhat complex."
"I rate App Control six out of 10 for scalability."
"The reporting is not good and needs to be improved."
 

Pricing and Cost Advice

"I rate the solution's pricing an eight out of ten since the price can be too high for smaller businesses."
"The solution's pricing is reasonable compared to other vendors' products."
"CyberArk Endpoint Privilege Manager has a very high price, so it's a one out of ten for me in terms of pricing."
"Pricing depends on how many devices you use. Right now, on-premise, it costs us a little, but it's worth it. It seems like the cloud solution is much more expensive. We got this solution one year ago, and it's like we bought the solution, and now they are not going to support it on-premise anymore. We are in the implementation phase, and we missed this, and we already paid for the licenses. This is wasted time from my perspective, and CyberArk should be more customer-friendly."
"Although I do not deal directly with the pricing, CyberArk Endpoint Privilege Manager is costly compared to other solutions. However, it offers beneficial features."
"licensing for this solution is based on the number of APV (privileged users), and the number of sessions that you want to record."
"It's not at the lower end of the market. I think the price is reasonable considering the quality it delivers. It is a top-notch solution at a fair price point."
"The tool's pricing is reasonable for customers."
"The pricing for this product is competitive and our customers who told us that often, Carbon Back is the cheaper solution."
"Its price is reasonable and what is expected for these types of products."
"We pay a fee for support, which is renewed annually."
report
Use our free recommendation engine to learn which Application Control solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
11%
Outsourcing Company
8%
Construction Company
8%
Financial Services Firm
21%
Computer Software Company
9%
Government
8%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise19
By reviewers
Company SizeCount
Small Business4
Large Enterprise4
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What is your experience regarding pricing and costs for CyberArk Endpoint Privilege Manager?
I believe it's quite a reasonably priced solution. It's not very common to use CyberArk because it's a niche solution, but customers who are willing to control administrative accounts are willing t...
What needs improvement with CyberArk Endpoint Privilege Manager?
While CyberArk Endpoint Privilege Manager is a great tool, I believe the functionality could be wider. If it could work not only with permissions but also involve pure EDR tasks or User and Entity ...
Ask a question
Earn 20 points
 

Also Known As

Viewfinity
CB Protection, Carbon Black CB Protection
 

Overview

 

Sample Customers

Information Not Available
Kaas Tailored, Core-Mark, Indeed, Hologic, Landmark Credit Union, Project Worldwide
Find out what your peers are saying about Idira Endpoint Privilege Manager vs. VMware Carbon Black App Control and other solutions. Updated: June 2026.
908,800 professionals have used our research since 2012.