Try our new research platform with insights from 80,000+ expert users

One Identity Safeguard vs Symantec Privileged Access Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

One Identity Safeguard
Ranking in Privileged Access Management (PAM)
2nd
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
53
Ranking in other categories
User Entity Behavior Analytics (UEBA) (5th), Non-Human Identity Management (NHIM) (1st)
Symantec Privileged Access ...
Ranking in Privileged Access Management (PAM)
18th
Average Rating
7.8
Reviews Sentiment
7.0
Number of Reviews
53
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Privileged Access Management (PAM) category, the mindshare of One Identity Safeguard is 4.4%, up from 4.2% compared to the previous year. The mindshare of Symantec Privileged Access Manager is 1.6%, up from 1.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
One Identity Safeguard4.4%
Symantec Privileged Access Manager1.6%
Other94.0%
Privileged Access Management (PAM)
 

Featured Reviews

ST
Senior Information Technology Consultant at Helse Nord IKT
Centralized privileged access has improved control and now supports secure vendor billing oversight
The transparent mode is a seamless approach when using it. We have some issues with it, but we are working on it to make it work for us. Managing remote access for privileged users with the secure remote access feature is both easy and hard depending on the scenario we face. We have some systems that are easy and take not even a minute to set up, while others take a bit longer. We are in the middle of integrating One Identity Safeguard with the IGA solution, Identity Manager. We have some A2A setups, but it is not optimal. We are using RPA for developers, not actually RPA accounts, but that is something we are working on. We are also using the service account password rotation on the asset to some degree, and we are exploring options there. For integrating One Identity Safeguard, figuring out how password rotation works is a bit difficult because we have to make custom integrations. After that, it was no problem really. For the A2A use, it is not as easy as using something like HashiCorp's password management tools. It is mostly for certain features in One Identity Safeguard that I would like some improvements. Some of the things you can do in entitlements, there is a lot you can do there, but not everything is optimal. You have to have duplicates of a lot of things to make it work the way you want.
Muzi Lubisi - PeerSpot reviewer
Senior technical Consultant at CA Africa
Secure management of sensitive servers and seamless applications with direct linking
The credential injection feature is highly valued, particularly for RDP sessions. A majority of customers use it for RDP, and a couple for Linux servers. The broader capabilities, including access to multiple systems, web-based applications, and clustering, have never posed an issue. The threat analytics aspect is also a robust feature that analyzes all pertinent information.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The system is easy to manage, as it is not a system that you will change everything all of a sudden. It evolves most of the time with customer requests."
"Flexible modes are easily integrated into the customer infrastructure."
"The initial setup is very easy."
"Implementing this solution, we have reduced privileged account-related incidents by thirty percent, and we have also cut manual password management time by nearly fifty to sixty percent, while just-in-time access has sped up admin task completion and improved our overall compliance reporting, allowing audits to be completed nearly half the time compared to earlier."
"There is ease of implementation."
"We use the solution’s “transparent mode” feature for privileged sessions. It is very easy because it is only a simple configuration for our users. We don't have to modify our network. We install it, configure it, and it works. So, it is super easy. The rollout for our users is seamless."
"It offers high availability and enables end users to deploy the solution with 99.999 percent uptime, which is crucial in an enterprise environment with a large number of endpoints."
"The transparent mode for privileged sessions is one of the best things for customers, because they don't see the system in-between."
"The exposure of sensitive usernames and passwords has been limited in a massive way."
"The password manager is a valuable feature."
"We know we can scale up with what we have, and we probably will not need to buy any further appliances down the road."
"Stability is solid as a rock."
"The tool helps us manage local, domain, and service accounts, and it helps us meet compliance standards."
"It reduces the viral attacks on my website. It also allows certain users access to see what happens daily."
"The product is very scalable in terms of concurrent sessions that it can handle at a time, number of device it can support, accounts that it can manage, or number of nodes that you can deploy in a cluster."
"The access control component is solid, adding another layer of security beyond the basic OS security of Linux and Windows while keeping administration costs the same across different operating systems."
 

Cons

"From a management point of view, it would be beneficial if One Identity Safeguard Privilege Password and One Identity Safeguard Privilege Session had a more similar interface."
"We should be able to create customized connectors in a better way. For ad hoc or special use cases, I sometimes find we have limitations. Improving the way we develop new connectors for non-typical systems would be beneficial."
"The multilanguage functionality does not support the Arabic language, even though this solution is deployed in an Arabic region."
"We would like to have the option of importing assets by using the CSV file. It was available in the earlier versions, but it is not available now."
"I have encountered scalability issues. The system needs to be properly analysed before putting it into production."
"When we compare One Identity Safeguard with Cyberark, we know CyberArk has other tools or other features that are more complex and more useful for the customers. For example, I have one customer that wants to elevate the permission that is available in CyberArk."
"The deployment affects our privileged users because it takes a long time for them to request privileges, which impacts the SLA."
"The multilanguage functionality does not support the Arabic language, even though this solution is deployed in an Arabic region."
"Evaluations are not just about features and functions of this specific product, but it is taking that holistic view around what else we can get out of it in the next three to five years."
"I wish it could create local accounts on desktops."
"I believe continued expansion of integration to multiple systems including SSO and SAML technologies will provide a more-expansive, enterprise view of access orchestration, which will in turn strengthen the security of the environment."
"Session limitation is a very critical feature that cannot be addressed by CA PAM."
"The accessibility and other issues were big blockers for our customer: The local accounts with AD integration multi-tenant deployment Java installation on the local machines; those three elements were the biggest blockers for our project when we used it, and we were always putting out fires to do that."
"I think the management console could be improved."
"They need to do a little bit more on the mainframe side.​"
"We experience stability issues after every patch upgrade. This is a place where CA needs to improve drastically."
 

Pricing and Cost Advice

"As compared to other products, it is reasonable, but the training sessions are too expensive."
"Its subscription cost is too much, and sometimes, it is very difficult to pitch the solution to the management for cost approval. If the cost is reduced a little bit, it would be easier. If its cost was less, many other organizations that currently cannot afford it would be able to use this technology. I'm sure many organizations around the globe are having issues with identity management, and it is a very difficult task for IT to manage privileged accounts."
"The license is very expensive for us, partly due to inflation and partly because of the exchange rate between the Dollar and the Iranian Rial. We purchased a perpetual license that we've been using up until now, but I believe that we are not going to update it in the future. Instead, we plan to find another third-party to support us with the license, in the sense that we would have access to their license as a shared agreement."
"The pricing depends on our perspective, our budget, and, of course, the competitors we are taking into account."
"We bought their other products, so it was not that expensive. It is one of those where the more you buy, the cheaper it is."
"It is a bit on the pricey side, but you get what you pay for. You don't want to get anything too cheap because then you get cheap stuff and cheap support. That really never helps anybody."
"It was definitely cheaper than the other two products that we evaluated."
"The pricing is about $80,000 per 100 servers. There are few elective costs."
"Pricing is fair compared to other top vendors."
"The prices are not low, but one can ask for a discount. It’s not the cheapest PAM solution."
"The licensing is simple and scalable."
"Cost-wise, CA was better compared to others in the market. ​"
"They offer per-device, per-user, or monthly and yearly licensing models."
"It is more expensive than other solutions on the market."
"The version we are using is affordable compared to BeyondTrust, which is maybe three to four times as expensive, but it depends on the features."
"It is reasonably priced."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
884,976 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
University
12%
Computer Software Company
8%
Financial Services Firm
7%
Comms Service Provider
7%
Marketing Services Firm
10%
Comms Service Provider
10%
Computer Software Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business33
Midsize Enterprise22
Large Enterprise20
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise30
 

Questions from the Community

What is your experience regarding pricing and costs for One Identity Safeguard?
We have a separate department that studies setup costs for each product, but as far as my information goes, the pricing and setup costs are very good.
What needs improvement with One Identity Safeguard?
The most common improvement needed is for upgrades. One Identity Safeguard's desktop client should have a faster and easier upgrade process that ensures compatibility.
What is your primary use case for One Identity Safeguard?
One Identity Safeguard serves as our Privileged Access Management solution to enforce session management for administrators and allow them to access our systems in recorded sessions, which secures ...
What is your experience regarding pricing and costs for Symantec Privileged Access Manager?
Due to the nature of the solution, it is hard to gauge, but compared to competitors, the pricing is very good. I would rate it as an eight and a half out of ten.
What needs improvement with Symantec Privileged Access Manager?
Recent releases need improvement in webpage management. For instance, navigating through a webpage that acts like a wizard, where I proceed to the next page and enter more information, is not handl...
What is your primary use case for Symantec Privileged Access Manager?
With the customers that I have so far, I help them broker RDP sessions to sensitive servers, particularly those that manage aspects like physical access. I have also done it for backend databases, ...
 

Also Known As

No data available
CA PAM, Xceedium Xsuite, CA Privileged Access Manager
 

Overview

 

Sample Customers

Cavium
NEOVERA, Telesis, eSoft
Find out what your peers are saying about One Identity Safeguard vs. Symantec Privileged Access Manager and other solutions. Updated: March 2026.
884,976 professionals have used our research since 2012.