No more typing reviews! Try our Samantha, our new voice AI agent.

Idira Privileged Access Manager vs SAP Access Control comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Idira Privileged Access Man...
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (2nd), Privileged Access Management (PAM) (1st), Mainframe Security (1st), Operational Technology (OT) Security (3rd)
SAP Access Control
Average Rating
7.6
Reviews Sentiment
3.5
Number of Reviews
2
Ranking in other categories
Access Management (21st)
 

Featured Reviews

Singaravelu C - PeerSpot reviewer
CyberArk Engineer at Tata Consultancy
Provides full visibility into user activity and ensures secure end-to-end access across critical systems
In CyberArk Privileged Access Manager, I see room for improvement as I am working in the on-premises networks, and now we are also having the cloud-based PAM. So there, everything is maintained by the CyberArk Privileged Access Manager team, and we are only maintaining the PSM servers. So it is already upgraded from the on-premises network to the cloud network. If you ask me what we can implement beyond that, I just need a few minutes to think about what new things, because it is already an end-to-end security on-premises itself. Now, when it comes to PCloud, Privileged Cloud, it is more secure than the on-premises networks because most of the things are handled using the cloud itself. So it is an already upgraded version; we do not need to implement something new. But if you think in that way, we can have a chance to implement our things. If anything could be improved in CyberArk Privileged Access Manager, I think we could build a small agent AI in my team, we could give access to these logs—the Vault logs, PSM logs, and CPM logs. Whenever the system is going down, the AI will automatically check. If we actually implement agent AI in CyberArk Privileged Access Manager, it will check the logs, and if any errors are coming, it automatically triggers alerts and gives the solution. That is the best improvement I can think of because these days, most things are done by agent AI. So if we also implement this agent AI in CyberArk Privileged Access Manager, we can add more features.
reviewer2129061 - PeerSpot reviewer
Sap Its Workstream Manager at a energy/utilities company with 10,001+ employees
Centralized access control has improved risk detection and streamlined multi-system user provisioning
Having one tool to populate many systems for one user is one of the most beneficial aspects of the product, along with the audit part. When using Firefighter, we could have information about what a user modified or did in production because we sometimes have to use an SU01 transaction, so in that case, we use Firefighter. The main benefit for me is that it is a global system to manage the user in many systems, and also the assessment of risk with GRC. We are using Access Request to onboard people. I see some potential improvements for stability because sometimes we do not know why the approval workflow of GRC stops in the middle. When we have a look in GRC, we see that the validation is finished, but that is not the case. Sometimes, we have to check and relaunch GRC. It helps in risk detection. The benefits of SAP Access Control's user permissions management are measured through the reports in GRC. Time savings are obvious. In one request, we are able to create a user in a different system, so it is a time saving. It is a money saving as well because the access manager spends less time creating a user in a different system.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's a highly flexible solution that can adapt to each customer's needs."
"From my experience, the kind of work I have done with this solution, it's absolutely amazing."
"The most valuable feature is that it always provides flexibility, password quality and one-time user check-in and check-out."
"The AI capabilities, including advanced threat detection features, are very helpful for us. They reduce human effort and errors, allowing us to quickly identify and respond to threats."
"The most valuable feature of this product is the Central Policy Manager, as from the operation and security point of view a robot that can connect to destination machines, change passwords at fixed times, and put them in the vault, like a person, is the best that you can ask for because it combines more functionality in a single product and solves a lot of problems, from security to compliance."
"We have been able to really transform how all of our sysadmins manage all our infrastructure."
"Cost-wise, it is not a cheap product, but it does a ton of things, and it does them well."
"If your business/organization has crown-jewel data, this is the tool to use."
"Having one tool to populate many systems for one user is one of the most beneficial aspects of the product, along with the audit part."
"It is an SAP product, so it integrates very well with other SAP products."
 

Cons

"We found a lot of errors during the initial setup. They should work to improve the implementation experience and to remove errors from the process."
"A greater number of out-of-the-box integrations with other vendors: They are working on it, but more is better!"
"I would like to see a simplification of the product."
"The product is very vaulting-focused. I'd love to see it expanding its capabilities a bit further into areas like just-in-time elevation, and access with non-vaulted credentials."
"They are sometimes not flexible with things. For instance, from one day to another, there might be something that had been done years ago by CyberArk, then they say, "We do not support that." You then have to initiate a complaint and start working with them. Things might become complicated and months pass while you are working with them. Usually, they are good and fast, but sometimes they seem to be blocked with problems, e.g., you will suddenly be working with another team instead of the team that you were working with the day before."
"It is web-based, but other competitors have apps. We need to get there. It is just smoother to have an app. You don't have all the bugs from having a browser, and people like them better, since you can get to them via mobile."
"The initial setup of CyberArk is a challenge if you do not have prior experience with it."
"I don't know if "failed authentication" is a glitch or if that was an update... However, since we are the CyberArk support within our organization, we need to know that the password is suspended and we won't know that unless we have the ITA log up. So when a user calls and says, "Hey, I'm locked out of CyberArk, I can't get into CyberArk," we have to go through all of these other troubleshooting steps because the first thing we don't think of right now is, "The account is suspended." It doesn't say that anymore."
"It would be better if we could also manage other systems with it. Currently, you have to purchase plugins for it to work with other non-SAP systems. It would be good if there is an easy way to integrate SAP Access Control with other non-SAP systems."
"Because it took time to get advice on a tricky issue, the support from SAP could be better."
 

Pricing and Cost Advice

"It's per-company, license-based."
"It is in line with its competitors, but all such solutions cost too much money."
"The solution is cost-effective for the features."
"It's not a cheap application. It's very expensive."
"I'm a technician so I don't handle the licensing for CyberArk Privileged Access Manager, but I know that the price for the core license is about €140 per year. There's another type of license, the external vendor license, and that's about €600 and you can manage twenty devices. From what I know, the price for one device in a subscription is about €65 per year. You can buy the CyberArk Endpoint Privilege Manager too, or you can buy some other application or application license with CyberArk Privileged Access Manager, but all other features, such as the Analytics Server is included in the basic CyberArk license. With WALLIX, you need to buy separate licenses for the features."
"I have heard from my leaders that CyberArk is costlier in terms of licensing. The support and maintenance are also costly. We use their premium support, but for the price we pay, we do not get the value."
"The pricing is slightly higher compared to other solutions, but it is reasonable because there are better security features."
"Compared to other solutions, it is costly."
"It is a part of our package with SAP. There is no extra cost in addition to the license."
report
Use our free recommendation engine to learn which Access Management solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
13%
Financial Services Firm
11%
Manufacturing Company
9%
Construction Company
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise175
No data available
 

Questions from the Community

How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What needs improvement with CyberArk Privileged Access Manager?
I believe account discovery and rolling support need to be improved. Account discovery is important when integrating with other systems, as other PAM solutions can perform account discovery and onb...
What needs improvement with SAP Access Control?
SAP Access Control is quite complex. The complexity arises because we need a GRC specialist to set up the connection between GRC and the other system. We also spend time doing some specific configu...
What is your primary use case for SAP Access Control?
The major use case for SAP Access Control is to create an end-user account, and the second purpose is to check the Separation of Duties risk and the risk on our roles and authorizations. Having one...
What advice do you have for others considering SAP Access Control?
We do work with some other SAP products. We are using SAP Access Control with the GRC Access Control product. We are also using the module for Separation of Duties and the Firefighter module. It is...
 

Also Known As

CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
No data available
 

Overview

 

Sample Customers

Rockwell Automation
Information Not Available
Find out what your peers are saying about Idira Privileged Access Manager vs. SAP Access Control and other solutions. Updated: September 2026.
913,683 professionals have used our research since 2012.