No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer1248516 - PeerSpot reviewer
Senior Manager, Cyber Security at a tech vendor with 1,001-5,000 employees
MSP
Top 10
Feb 11, 2024
Comes with automatic password rotation feature but UI and pricing needs improvement
Pros and Cons
  • "Previously, we used to share passwords for service and normal admin accounts among team members. However, since we started managing it through the product, we've transitioned to individual admin accounts or implemented dual control for shared accounts. With dual control, exclusive checking and checkout options are available, and passwords are not stored in clear text anywhere in the credentials."
  • "The tool's UI has bugs and lags. It needs to be improved. The deployment process can be complex due to multiple components for various functionalities, each requiring separate infrastructure management. To simplify this process, consolidating all these components into a single platform could be beneficial. The product's pricing could be cheaper."

What is most valuable?

Previously, we used to share passwords for service and normal admin accounts among team members. However, since we started managing it through the product, we've transitioned to individual admin accounts or implemented dual control for shared accounts. With dual control, exclusive checking and checkout options are available, and passwords are not stored in clear text anywhere in the credentials.

The solution's most valuable features are automatic password rotation, privilege manager, and secret manager. Previously, IT personnel had admin rights on their regular accounts, allowing them to log in to domain controllers. However, this posed a security risk as compromised accounts could grant unauthorized access to domain controllers. To mitigate this risk, we implemented separate DA accounts for IT staff. These DA accounts were restricted from logging in to domain controllers and did not have associated email addresses. They were dedicated AD accounts solely for accessing domain controllers, and the solution handled their management.

Previously, manually rotating admin credentials was a time-consuming task. However, implementing the tool's automatic password management feature has made this process easier. We've configured defined policies within the solution to dictate when these credentials should be changed.

What needs improvement?

The tool's UI has bugs and lags. It needs to be improved. The deployment process can be complex due to multiple components for various functionalities, each requiring separate infrastructure management. To simplify this process, consolidating all these components into a single platform could be beneficial. The product's pricing could be cheaper. 

For how long have I used the solution?

I have been using the product for eight to nine years. 

What do I think about the stability of the solution?

I rate the product's stability a seven out of ten. 

Buyer's Guide
Idira Privileged Access Manager
September 2026
Learn what your peers think about Idira Privileged Access Manager. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,076 professionals have used our research since 2012.

What do I think about the scalability of the solution?

I rate the tool's scalability a seven out of ten. 

How are customer service and support?

The tool's support gets worse each year. Support is outsourced to smaller companies, which doesn't work fine. Its support was good eight to nine years back. Over the years, it hasn't improved but degraded. 

Which solution did I use previously and why did I switch?

I work with BeyondTrust. BeyondTrust's UI and support are good and never lag. BeyondTrust is also cheaper. 

How was the initial setup?

CyberArk Enterprise Password Vault's implementation timeline largely depends on the size and complexity of the infrastructure. A smaller infrastructure with around a thousand servers can typically be implemented within a week or two. However, the implementation process may extend to four or five months for more extensive infrastructures with tens or hundreds of thousands of workstations and accounts. The tool's transition into a security-focused product necessitates strong integration with security orchestration platforms. Prebuilt packages with ready-made integrations are required instead of developing everything from scratch. It lags in automation. 

What was our ROI?

We have seen 40-50 percent improvements after using the solution. 

What other advice do I have?

I rate the product a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1398690 - PeerSpot reviewer
Information Security Consultant at a tech vendor with 10,001+ employees
Real User
Dec 13, 2023
Reduces organizational risk with password vaulting, password rotation, session management, and secret management
Pros and Cons
  • "We use the solution for password vaulting, password rotation, session management, and secret management."
  • "CyberArk Enterprise Password Vault must incorporate connectors for password and session managers in the marketplace."

What is our primary use case?

We use the solution for password vaulting, password rotation, session management, and secret management. 

What needs improvement?

CyberArk Enterprise Password Vault must incorporate connectors for password and session managers in the marketplace.

For how long have I used the solution?

I have been working with the product for seven years. 

What do I think about the stability of the solution?

The product is highly stable. 

What do I think about the scalability of the solution?

CyberArk Enterprise Password Vault is highly scalable. My company has over 3000 users. We use it regularly. 

How are customer service and support?

CyberArk Enterprise Password Vault's support quality is good, but there are delays. 

How would you rate customer service and support?

Neutral

How was the initial setup?

I rate the tool's deployment an eight out of ten. Experienced engineers can complete the deployment in a few days. We need three to four resources to complete the deployment. 

What was our ROI?

CyberArk Enterprise Password Vault reduces risks. 

What's my experience with pricing, setup cost, and licensing?

I rate the tool's pricing an eight out of ten. 

What other advice do I have?

I rate CyberArk Enterprise Password Vault a nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Idira Privileged Access Manager
September 2026
Learn what your peers think about Idira Privileged Access Manager. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,076 professionals have used our research since 2012.
Lead Automation Developer at COUNTRY Financial
Real User
Oct 12, 2023
CyberArk's Password Vault is a must have for Privileged Account & Identity management
Pros and Cons
  • "AIM has been a great help in automating password retrieval which removes the need for hard-coded credentials."

    What is our primary use case?

    To securely manage privileged accounts within the enterprise and automate password compliance where possible. Bringing multiple account types all into a single central repository with an intuitive user interface has greatly improved our security standing. Instead of managing each account in its disparate location like Database, Active Directory, LDAP, and Mainframe, we can now do it from a single solution. This has enabled great strides in standardizations across account types for password and access management.

    How has it helped my organization?

    CyberArk has enabled my organization to monitor and manage privileged accounts in a secure manner while also giving the ability to adhere to password compliance automatically. CyberArk has helped us to remove hard-coded credentials in applications and scripts. Traditional password policies often fall short of providing adequate protection, but CyberArk's PAM has allowed my organization to set robust password policies that require a combination of uppercase and lowercase letters, numbers, and special characters.

    What is most valuable?

    AIM has been a great help in automating password retrieval which removes the need for hard-coded credentials. Hard-coded credentials are a risk to organizations as they are easy for attackers to target. Therefore less hard-coded credentials increase the security stance of the enterprise. We have greatly utilized the out-of-the-box usage automation like Windows Scheduled tasks and password config files. The reconcile feature is another must-have to give users the ability to not only change their password but to unlock it as well where needed. 

    What needs improvement?

    CyberArk's Privileged Access Management (PAM) stands out as an industry leader, and it is often considered at the top of its class. This comprehensive solution has consistently delivered robust features and innovative security measures that make it an essential component of any organization's cybersecurity strategy. While no system is without room for advancement, CyberArk has continuously demonstrated its commitment to innovation and improvement, and many of the potential areas of improvement are already being actively addressed.

    For how long have I used the solution?

    I have been using this solution for 13 years.

    What do I think about the stability of the solution?

    This solution is very stable with the ability of satellite vaults and HA.

    What do I think about the scalability of the solution?

    CyberArk is incredibly scalable. Make sure to check out the unlimited option.

    How are customer service and support?

    Excellent service and quick responses with engineers who understand the product.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We started out with CyberArk. When we started to look into using a PAM solution they were the leader in the space (and still are).

    What was our ROI?

    For the time saved and security added, the benefit far outweighs the cost.

    What's my experience with pricing, setup cost, and licensing?

    Check out the unlimited model as it can save money and make for a more scalable solution depending on the size and needs of your organization.

    Which other solutions did I evaluate?

    My company evaluated other options, but I was not with the company when this occurred.

    What other advice do I have?

    Contact the professional help for a demo, and you will not be disappointed. Even if you do not choose CyberArk, they can help identify current security gaps.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Cyber Security Senior Consultant at Ernst & Young
    Real User
    Aug 23, 2023
    Provides a comprehensive access control list and auditing and offers robust reporting
    Pros and Cons
    • "The product is an important security measure against credential theft. It ensures session isolation and password rotation including pushing passwords to the endpoints."
    • "The documentation is rather basic and it is missing many use cases."

    What is our primary use case?

    It's a privileged access management tool so it helps in making sure that all privileged accounts are compliant.

    How has it helped my organization?

    The product is an important security measure against credential theft. It ensures session isolation and password rotation including pushing passwords to the endpoints. 

    It's also possible to pull the password from the CyberArk to ensure that there are no hardcoded credentials in scrips or DevOps tools. 

    It provides a comprehensive access control list and auditing. Reporting capabilities are extensive.

    What is most valuable?

    New features are being added in every release, and there are few releases a year.

    Enhancement requests can be submitted by the community and are taken into consideration by the company.

    What needs improvement?

    As configuration options are very extensive, it is sometimes hard to find the correct and complete way of customization or specific configuration. 

    The documentation is rather basic and it is missing many use cases. 

    It's also hard to test solutions without a development environment as CyberArk doesn't provide the possibility to run the environment for personal purposes.

    For how long have I used the solution?

    I've used the solution for six years.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    BRUNO REYNAUD - PeerSpot reviewer
    Information Security Engineer - Pre-sales at a tech services company with 11-50 employees
    Real User
    May 13, 2023
    Beneficial privileged threat analytics, high availability, and priced well
    Pros and Cons
    • "The most valuable feature of CyberArk Privileged Access Manager is privileged threat analytics."
    • "The issue of technical support is crucial, as there are not many specialized partners available in Brazil to provide this service. While English language support is of good quality, there is a significant shortage of partners capable of meeting the demand locally."

    What is our primary use case?

    We currently employ CyberArk Privileged Access Management, which involves extremely complex processes for ensuring the secure management, verification, and guarantee of credentials. Implementing the professional installation tool represents another challenging aspect of this task.

    What is most valuable?

    The most valuable feature of CyberArk Privileged Access Manager is privileged threat analytics.

    What needs improvement?

    The support could improve for CyberArk Privileged Access Manager.

    For how long have I used the solution?

    I have been using CyberArk Privileged Access Manager for approximately three years.

    What do I think about the stability of the solution?

    The solution has high availability.

    What do I think about the scalability of the solution?

    CyberArk Privileged Access Manager is highly scalable. When compared to other solutions it scales well.

    I plan to use the solution more in the future.

    How are customer service and support?

    The issue of technical support is crucial, as there are not many specialized partners available in Brazil to provide this service. While English language support is of good quality, there is a significant shortage of partners capable of meeting the demand locally.

    How was the initial setup?

    The initial setup of CyberArk Privileged Access Manager is easy.

    What was our ROI?

    We have received a high ROI using CyberArk Privileged Access Manager.

    What's my experience with pricing, setup cost, and licensing?

    The price of the solution is reasonable.

    I rate the price CyberArk Privileged Access Manager a seven out of ten.

    What other advice do I have?

    Individuals who wish to utilize CyberArk should be cautious when selecting a partner to implement the solution, as proper architecture design is essential to ensure a streamlined and effective implementation.

    I rate CyberArk Privileged Access Manager a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2169219 - PeerSpot reviewer
    Node.js Backend Developer at a tech services company with 1,001-5,000 employees
    Real User
    May 5, 2023
    It has features to deal with a large company that has a complex structure and many partners
    Pros and Cons
    • "CyberArk makes our environment more secure and prevents possible attacks by compromised accounts."
    • "The price is high compared to Azure Key Vault. It's the most expensive solution."

    What is our primary use case?

    CyberArk vouches for access to domain controllers in Unix and Windows Server

    How has it helped my organization?

    CyberArk makes our environment more secure and prevents possible attacks by compromised accounts.

    What needs improvement?

    The price is high compared to Azure Key Vault. It's the most expensive solution. 

    For how long have I used the solution?

    I have used CyberArk for about three months.

    What do I think about the stability of the solution?

    We have 98 percent uptime. 

    What do I think about the scalability of the solution?

    CyberArk is scalable. We have around 4,000 users. 

    Which solution did I use previously and why did I switch?

    We previously used Telos. We switched to CyberArk because it has features to deal with a large company that has a complex structure and many partners. 

    How was the initial setup?

    Deploying CyberArk was moderately difficult. It isn't too hard, but it isn't easy. One person is enough to install it. It took about one month to select the product and deploy it.

    What's my experience with pricing, setup cost, and licensing?

    CyberArk is more expensive than other solutions, but it's necessary when the company has contacts with other branches and partners. 

    What other advice do I have?

    I rate CyberArk Enterprise Password Vault eight out of 10. It's more expensive than Azure Key Vault, but Key Vault doesn't have CyberArk's analytics and user tracking. I recommend CyberArk if you need those features. However, it's costly in the Brazilian market because of the conversion fro reals to dollars. 

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    ProbalThakurta - PeerSpot reviewer
    Senior Partner at a tech consulting company with 51-200 employees
    Real User
    Mar 26, 2023
    Integrates well, flexible, but custom connectors
    Pros and Cons
    • "The integrations are the most valuable aspect of CyberArk Privileged Access Manager. The software offers pre-built integrations, and our team can also create custom connectors. This flexibility allows us to integrate with systems that we previously didn't consider integrating with, making it a significant advantage for us."
    • "There is room for improvement in the availability of custom connectors on the marketplace for this solution. Additionally, their services for the CICD pipeline and ease of integration could be improved."

    What is our primary use case?

    CyberArk Privileged Access Manager is used for identity and privilege access management.

    What is most valuable?

    The integrations are the most valuable aspect of CyberArk Privileged Access Manager. The software offers pre-built integrations, and our team can also create custom connectors. This flexibility allows us to integrate with systems that we previously didn't consider integrating with, making it a significant advantage for us.

    What needs improvement?

    There is room for improvement in the availability of custom connectors on the marketplace for this solution. Additionally, their services for the CICD pipeline and ease of integration could be improved.

    For how long have I used the solution?

    I have been using CyberArk Privileged Access Manager for approximately three years.

    What do I think about the stability of the solution?

    Once the implementation is completed and the solution is hardened, I consider it to be stable. 

    What do I think about the scalability of the solution?

    CyberArk Privileged Access Manager is scalable on-premise but not on the cloud.

    I rate the scalability of CyberArk Privileged Access Manager a seven out of ten.

    How was the initial setup?

    The time it took for the deployment was approximately two years. It was not a simple process for the vendor. It should have been completed in one year, it took too long.

    Our process steps for deployment involve specific stages, starting with onboarding Windows and Linux devices, and concluding with the onboarding of application service accounts and related components.

    I rate the initial setup of CyberArk Privileged Access Manager an eight out of ten. 

    What about the implementation team?

    The solution's deployment was completed by the vendor. 

    A team of two to three people was required for the deployment of our solution. One of them had a high level of expertise in architecture and a thorough understanding of the solution. The remaining team members were junior-level personnel in charge of activities including connection development, data collection, and deployment. The vendor was also used by the team to help with data collection, planning, and execution.

    What's my experience with pricing, setup cost, and licensing?

    The license CyberArk Privileged Access Manager is on an annual basis.

    What other advice do I have?

    A team of five to six people would be sufficient to maintain 24/7 operations.

    I would recommend reducing the fee for cancellations, but when it comes to cloud services, there are superior options available in the market.

    I rate CyberArk Privileged Access Manager a seven out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    reviewer1786770 - PeerSpot reviewer
    Principal Information Security Engineer/Lead Active Directory Architect at a healthcare company with 10,001+ employees
    Real User
    Dec 16, 2022
    Helps our organization in supporting privileged identities but requires more connectors to other third-party systems
    Pros and Cons
    • "The password management feature is valuable."
    • "The initial setup was a bit complex."

    What is our primary use case?

    Our primary use case for the solution is to support privileged identities.

    What is most valuable?

    The password management feature is valuable.

    What needs improvement?

    The solution can be improved by including more connectors to other third-party systems for integration.

    For how long have I used the solution?

    We have been using the solution for approximately five years.

    What do I think about the stability of the solution?

    The solution is stable.

    What do I think about the scalability of the solution?

    The solution is scalable. Approximately 150,000 people are using the solution.

    Which solution did I use previously and why did I switch?

    We previously used One Identity.

    How was the initial setup?

    The initial setup was a bit complex.

    What about the implementation team?

    We deployed the solution in-house.

    What was our ROI?

    We have seen a return on investment. The solution makes our procedures better, making the environment more secure and changing the mindset of people. 

    What other advice do I have?

    I rate the solution a seven out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    IkedeEbhole - PeerSpot reviewer
    Pre sales Engineer (West Africa) at StarLink - Trusted Security Advisor
    Real User
    Oct 20, 2022
    A useful solution for privileged identity and application identity management
    Pros and Cons
    • "Regardless it's a good solution, it works, and the bank is happy with it."
    • "The architecture needs to be improved."

    What is our primary use case?

    Our primary use case for his solution is privileged identity and application identity management, and we deploy the solution on-premises.

    What is most valuable?

    We have found the core features of the product most valuable, such as password management, session recording and vaulting.

    What needs improvement?

    The architecture needs to be improved. For example, the whole solution can come within a single software bundle instead of the distributed components we have for the on-premise deployments. I think there's room for improvements in that area because the competitors within that space have appliances and software that are just a single software. You don't have to split functionality across several servers like the current deployment.

    For how long have I used the solution?

    We have been using this solution for approximately five years.

    What do I think about the scalability of the solution?

    The solution is scalable. At the point of implementation, 300 users in our organization were using it, but that number may have increased.

    How was the initial setup?

    The initial setup is not very complex because of my experience and skills. Still, the end users are only in charge of the administrative aspects, but I think the set up is a bit complex for those who are not very savvy with the solution. Implementation took approximately two weeks.

    What other advice do I have?

    I rate the solution nine out of ten. The solution is good, but the main feature to be improved is having the product in a consolidated software bundle. So the moment we have PSM, it's a dedicated server. We can also have a PVWA in another server, so having a singular bundle is just like the cloud offering. The infrastructure is abstracted from the end user. So if we can have something like that for on-premises, that would simplify implementation. Regardless it's a good solution, it works, and the bank is happy with it. My recommendation to people considering implementing this product is to get the scoping appropriately done. It comes down to scoping the initial deployment, so it doesn't take forever. Still, if you're not scoping correctly, you could have a situation where people keep adding new accounts continuously, and your project never ends. Hence, scoping is kind of important.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Mammad BNB - PeerSpot reviewer
    Director Of Technical Operations at BNB Security Alliance
    Reseller
    Oct 12, 2022
    Beneficial integration, helpful support, and scales well
    Pros and Cons
    • "The most valuable feature of CyberArk Privileged Access Manager is the vault. I am satisfied with the interface and the documentation."
    • "CyberArk Privileged Access Manager could improve the integration with other solutions and ease of use. Additionally, there should be a feature to have remote connections without a VPN."

    What is most valuable?

    The most valuable feature of CyberArk Privileged Access Manager is the vault. I am satisfied with the interface and the documentation.

    What needs improvement?

    CyberArk Privileged Access Manager could improve the integration with other third-party secret managers, and vault solutions.

    For how long have I used the solution?

    I have been working with CyberArk Privileged Access Manager for approximately three years. Our clients are typically financial institutions.

    What do I think about the stability of the solution?

    CyberArk Privileged Access Manager is stable.

    What do I think about the scalability of the solution?

    The scalability of CyberArk Privileged Access Manager is good.

    Most of our clients are enterprise-sized companies.

    How are customer service and support?

    I am satisfied with the vendor's support.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have used Balabit and One Identity prior to using CyberArk Privileged Access Manager. I found that CyberArk has more integration out of the box with other solutions and it solves a lot of problems for customers if they have different solutions.

    How was the initial setup?

    The initial setup CyberArk Privileged Access Manager is easy.

    What's my experience with pricing, setup cost, and licensing?

    The price of CyberArk Privileged Access Manager could be less expensive.

    What other advice do I have?

    My advice to others is this solution can solve a lot of problems.

    I rate CyberArk Privileged Access Manager a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. B&B Security Alliance has been established in 2019 and only deals with cyber security. B&B Security Alliance provides cyber security solutions to customers wanting to be resilient against new and existing threats. We offer professional services, advisory and through our vendor network we will help you select a suite of best in class products that enhances your reputation and company value.
    PeerSpot user
    Buyer's Guide
    Download our free Idira Privileged Access Manager Report and get advice and tips from experienced pros sharing their opinions.
    Updated: September 2026
    Buyer's Guide
    Download our free Idira Privileged Access Manager Report and get advice and tips from experienced pros sharing their opinions.