No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2620077 - PeerSpot reviewer
IT Security Architect at a comms service provider with 1,001-5,000 employees
Real User
Top 5
Dec 22, 2024
Facilitates secure password rotation and out-of-band session management but the process for accessing RDP could be improved
Pros and Cons
  • "CyberArk Privileged Access Management's most valuable features are primarily its password vault functionality, specifically CyberArk's Core Privileged Manager and Privileged Session Manager."
  • "Customer support has been very helpful and responsive."
  • "The product is complex and requires extensive configuration."
  • "The current process for accessing RDP through the CyberArk or administrative portal involves downloading an RDP file. This is inconvenient for users and problematic due to security restrictions that prevent accessing servers via downloaded RDP files."

What is our primary use case?

We currently use CyberArk Privileged Access Manager for password vaulting. Our roadmap includes managing service accounts, rotating passwords, and expanding to SSH keys, AWS keys, and other login credentials. We've already implemented local administrative accounts and rotated elevated domain administrative accounts. Additionally, we've integrated Okta for multi-factor authentication, using Okta Verify, and plan to expand this to workforce identity for broader end-user security and credential management.

What is most valuable?

CyberArk Privileged Access Management's most valuable features are primarily its password vault functionality, specifically CyberArk's Core Privileged Manager and Privileged Session Manager. These components facilitate secure password rotation and out-of-band session management, addressing our organization's critical security needs.

What needs improvement?

The current process for accessing RDP through the CyberArk or administrative portal involves downloading an RDP file. This is inconvenient for users and problematic due to security restrictions that prevent accessing servers via downloaded RDP files. Ideally, the process should allow for a direct RDP connection upon providing server details, eliminating the download step and streamlining access. This issue represents a significant challenge and source of frustration for users.

The product is complex and requires extensive configuration. More tutorials and detailed use cases with troubleshooting steps would be beneficial, particularly for first-time implementers. Despite the excellent customer service, resolving issues can be time-consuming due to the product's complexity. Compared to lightweight solutions like Okta, CyberArk requires more background experience and is not as straightforward to learn and implement.

For how long have I used the solution?

I have been using CyberArk Privileged Access Manager for almost five years.

Buyer's Guide
Idira Privileged Access Manager
September 2026
Learn what your peers think about Idira Privileged Access Manager. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,076 professionals have used our research since 2012.

What do I think about the stability of the solution?

The performance of CyberArk Privileged Access Management sometimes lags or crashes, but this is not a significant concern.

What do I think about the scalability of the solution?

We have not reached platform limitations yet, as CyberArk supports up to eight hundred platforms per tenant, and documentation is clear about scalability limits.

How are customer service and support?

Customer support has been very helpful and responsive. My customer success manager facilitated many calls with technical experts, efficiently resolving critical issues.

Which solution did I use previously and why did I switch?


How was the initial setup?

CyberArk's environment setup was straightforward, but we encountered issues during the Proof of Concept stage, specifically with PAM account discovery. While the CyberArk Manager displayed discovered accounts, we couldn't download the data into a usable format like an Excel sheet. This hindered our ability to identify efficiently and inventory discovered accounts, particularly from Windows systems, for phased onboarding. Although we eventually received instructions from CyberArk support on downloading the data, the process was complex and time-consuming. Simplified data export features would greatly benefit administrators.

What about the implementation team?

I received excellent support from CyberArk's technical team and customer success manager, who arranged calls and helped resolve implementation issues.

What's my experience with pricing, setup cost, and licensing?

Although CyberArk Privileged Access Management is expensive, its protection capabilities outweigh the cost.

Which other solutions did I evaluate?

I also evaluated CyberArk, along with Okta PAM and BeyondTrust, because it encompasses all the features we require, and Gartner recognizes it as an industry leader.

What other advice do I have?

I rate CyberArk Privileged Access Management seven out of ten. 

To streamline project setup, new users should receive guidance on planning and implementation scopes. Scheduling a jump start without such direction can complicate learning.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer2695500 - PeerSpot reviewer
Senior Information Technology Security Specialist at a financial services firm with 5,001-10,000 employees
Real User
Top 20
Apr 17, 2025
Improves compliance and operational efficiency
Pros and Cons
  • "CyberArk Privileged Access Manager makes it easy for users to retrieve and manage their passwords."
  • "CyberArk Privileged Access Manager has helped our organization remain compliant in the privileged access management space."
  • "In CyberArk Privileged Access Manager, the UI has room for improvement, as does the dashboard reporting, which could be made better or easier to use."

What is our primary use case?

We're using CyberArk Privileged Access Manager to manage our service accounts, privileged service accounts, and password rotation. We also use Conjur.

How has it helped my organization?

CyberArk Privileged Access Manager has helped our organization remain compliant in the privileged access management space. It is very helpful for meeting compliance and regulatory requirements such as SOC, SWIFT, and PCI DSS.

CyberArk Privileged Access Manager has helped us become more efficient in managing these service accounts.

CyberArk Privileged Access Manager feels quite secure in ensuring data privacy.

CyberArk Privileged Access Manager has a very strong potential for preventing attacks and lateral movements, but it has not had an impact one way or the other on the number of privileged accounts in our organization. They are just managed differently.

What is most valuable?

CyberArk Privileged Access Manager makes it easy for users to retrieve and manage their passwords.

I have been using CyberArk Privileged Access Manager for a few months. I am still learning, and I appreciate all the networking and education at the CyberArk Impact in Boston, which is going to set me up for success as I take on my role.

What needs improvement?

In CyberArk Privileged Access Manager, the UI has room for improvement, as does the dashboard reporting, which could be made better or easier to use. The interface needs to be more intuitive in CyberArk Privileged Access Manager. There should be dashboards in CyberArk Privileged Access Manager with more data and reporting capability for the non-compliant scenarios.

For how long have I used the solution?

My company has been using it for a long time; I have been using it only for a few months.

How are customer service and support?

I have not had any support experience with CyberArk at this point in my journey. 

I found the CyberArk Impact event to be much more effective as an educational experience.

How would you rate customer service and support?

Positive

What was our ROI?

The time-to-value for CyberArk Privileged Access Manager was recognized pretty quickly after implementing it.

What's my experience with pricing, setup cost, and licensing?

I hope to learn how the pricing works so that I can understand it better, but I am certain it is not inexpensive.

What other advice do I have?

It is absolutely necessary to have a PAM tool like CyberArk Privileged Access Manager, even if someone is using other security tools.

Based on my experience thus far, I would recommend CyberArk Privileged Access Manager to other users.

I would rate CyberArk Privileged Access Manager as an eight out of ten. It is early in my journey with this solution.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Idira Privileged Access Manager
September 2026
Learn what your peers think about Idira Privileged Access Manager. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,076 professionals have used our research since 2012.
Infrastructure Architect, Senior Engineer at a tech vendor with 5,001-10,000 employees
Real User
Top 20
Apr 29, 2025
Helps secure our accounts and has good stability and support
Pros and Cons
  • "By implementing CyberArk Privileged Access Manager, we wanted to secure the password data and password accounts. We could see the benefits of CyberArk Privileged Access Manager immediately after we deployed it and started using it."
  • "They could improve CyberArk Privileged Access Manager by providing more reports. If I need to know the 10 most-used accounts for this week, that functionality can be made available in the reports."
  • "My company always complains about the cost of CyberArk Privileged Access Manager because it's too high."

What is our primary use case?

My use cases as of right now include configuration, implementation, and developing a PowerShell report.

What is most valuable?

By implementing CyberArk Privileged Access Manager, we wanted to secure the password data and password accounts. We could see the benefits of CyberArk Privileged Access Manager immediately after we deployed it and started using it.

What needs improvement?

They could improve CyberArk Privileged Access Manager by providing more reports. If I need to know the 10 most-used accounts for this week, that functionality can be made available in the reports.

For how long have I used the solution?

I have been using CyberArk Privileged Access Manager for seven years.

What do I think about the stability of the solution?

It is stable. The environment is stable, with no lagging, crashing, or downtime.

What do I think about the scalability of the solution?

I cannot say much about scalability because we did not have any need for it.

How are customer service and support?

I have contacted their technical support plenty of times. I would rate CyberArk's support a seven out of ten. They are always good.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have not used any alternatives to CyberArk Privileged Access Manager in my career.

How was the initial setup?

The initial deployment was easy because I went to training first. The training was set up by CyberArk. From design to implementation, it took close to six months.

In terms of maintenance, it requires OS upgrades and patches. It doesn't take a long time.

What about the implementation team?

We did not use any help from a third party, such as an integrator or consultant. The number of people required depends on the environment. I don't see how one person can manage it because there is a lot of information to collect before even doing a design.

What's my experience with pricing, setup cost, and licensing?

My company always complains about the cost of CyberArk Privileged Access Manager because it's too high.

What other advice do I have?

For a new user, I would advise them to try to configure CyberArk Privileged Access Manager a couple of times before starting to use it in a production environment.

I would rate CyberArk Privileged Access Manager a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Asheesh Sahu - PeerSpot reviewer
Team Lead at Flash.co
Real User
Top 20
Mar 13, 2025
Provides centralized management, AI capabilities, and advanced threat detection
Pros and Cons
  • "The AI capabilities, including advanced threat detection features, are very helpful for us. They reduce human effort and errors, allowing us to quickly identify and respond to threats."
  • "Overall, I would rate it a ten out of ten."
  • "Pricing is a concern for me because it is not very user-friendly for startups, new users, or very small organizations."

What is our primary use case?

We use CyberArk Privileged Access Manager to manage our privileged accounts because it protects against cyberattacks and prevents unnecessary or illegal access. 

How has it helped my organization?

It provides a centralized management system, making it easier for us to enforce policies and monitor access across our organization. Additionally, we can monitor sessions and record and detect suspicious activities that are harmful to our systems and organization.

What is most valuable?

The AI capabilities, including advanced threat detection features, are very helpful for us. They reduce human effort and errors, allowing us to quickly identify and respond to threats. This solution scales up our IT environment and resolves almost every issue that poses a threat to our organization.

What needs improvement?

Pricing is a concern for me because it is not very user-friendly for startups, new users, or very small organizations. It might be better if the price was reduced. Sometimes, the maintenance cost can also be high.

For how long have I used the solution?

I have been using CyberArk Privileged Access Manager for the last one and a half to two years.

What do I think about the stability of the solution?

Every application has downtime. However, it remains stable overall. I would rate it a nine out of ten for stability.

What do I think about the scalability of the solution?

It is scalable. I would rate it a ten out of ten for scalability.

How are customer service and support?

Sometimes, when I face issues or want to understand some features, or it is difficult to identify activities in our system, I contact the support team. They are very helpful, always available, and try to resolve our issues as soon as possible.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

This is the first PAM solution that I implemented in our organization.

How was the initial setup?

The initial setup is not very easy, nor very difficult. It is moderate to deploy.

It does not require any maintenance from our side.

What about the implementation team?

We have a team of three to five members, and they deployed it in a minimum of one week.

What's my experience with pricing, setup cost, and licensing?

Its price can be reduced.

Which other solutions did I evaluate?

I researched some solutions and found CyberArk Privileged Access Manager to be one of the good solutions. I am very happy with the product.

What other advice do I have?

I am happy with this product. If someone is looking for a PAM solution, I recommend it because it has a large developer community and good customer support. It is more stable than the others, and I am very happy with it. 

Overall, I would rate it a ten out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer2642394 - PeerSpot reviewer
CyberSecurity Analyst at a energy/utilities company with 501-1,000 employees
Real User
Top 10
Jan 24, 2025
Session recordings and timestamps make activity monitoring easy
Pros and Cons
  • "Session recordings and timestamps are valuable features. They allow me to specifically select the time a particular command was executed, so I do not have to review the entire recording. I can click on events to determine where and when they happened."
  • "I would recommend implementing CyberArk Privileged Access Manager as it is the best so far."
  • "Updates have been somewhat difficult, resulting in challenges when moving from one version to another. The current version includes automatic updates."
  • "Its implementation was very complex. It needs different servers."

What is our primary use case?

I work in the cybersecurity team. We typically provide access to other end users or IT administrators through this solution. We monitor their activity on servers, provision access, and review all logs.

By implementing this solution, we wanted identity management and access management.

How has it helped my organization?

Over these three years, there have been a lot of improvements. User management is more efficient. The interface is user-friendly, and I can create comprehensive reports.

What is most valuable?

Session recordings and timestamps are valuable features. They allow me to specifically select the time a particular command was executed, so I do not have to review the entire recording. I can click on events to determine where and when they happened. 

What needs improvement?

We are looking for improvements in user provisioning, such as access provisioning and revoking access. We still have to test these improvements in the latest version. 

Updates have been somewhat difficult, resulting in challenges when moving from one version to another. The current version includes automatic updates for minor patches, which should be easy.

For how long have I used the solution?

I have been using the solution for more than three years.

What do I think about the stability of the solution?

It has been stable so far, so I would rate it a nine out of ten.

What do I think about the scalability of the solution?

Its scalability is very good. It is in the cloud, so we can just expand it. I would rate it a nine out of ten for scalability.

How are customer service and support?

We haven't used customer support so far apart from implementation.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have not used any PAM solutions apart from this one.

How was the initial setup?

Its implementation was very complex. It needs different servers and setup parameters involving load balancers, certification, encryption keys. The implementation took more than a month.

It requires maintenance once in six months and has been hard previously.

What about the implementation team?

It was implemented by inhouse staff with oversight from vendor.

What was our ROI?

When it comes to compliance and audits the ROI on this is very good.

What's my experience with pricing, setup cost, and licensing?

Licensing is little hard as they are perpetual and can't be used from a pool of resources.

What other advice do I have?

I would recommend implementing CyberArk Privileged Access Manager as it is the best so far.

I would rate CyberArk Privileged Access Manager an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Manuel Carrillo - PeerSpot reviewer
Security Consultant at Silver Bullet IS Consulting
Real User
Top 5Leaderboard
Jul 25, 2025
Privileged access management achieves full control with comprehensive features
Pros and Cons
  • "CyberArk Privileged Access Manager has several valuable features; the basic feature is privileged access management with all the processes and procedures that are needed, and it does everything that is needed to provide a PAM project or program."
  • "When they took it to the cloud, they started cutting things out."

What is our primary use case?

For CyberArk Privileged Access Manager, use cases are providing just-in-time privileged access. The most simple use case is hosting all privileged credentials in a secure manner and managing and controlling access to those credentials. Therefore, controlling access to privileged endpoints is the usual thing that will be done with PAM.

What is most valuable?

CyberArk Privileged Access Manager has several valuable features. The basic feature is privileged access management with all the processes and procedures that are needed. It has all the relevant features required to provide a PAM project or PAM program. It does everything that is needed. A tangible benefit is that we already have full control of privileged access. We have just started and have onboarded all privileged accounts into the system.

What needs improvement?

I have noticed areas of CyberArk Privileged Access Manager that could be improved or enhanced in integration with automation tools. It's not quite the same in the cloud, the Privilege Cloud version. The on-premises version allows users to do absolutely everything. When they took it to the cloud, they started cutting things out. The other issue with CyberArk is that they are marketing their new product, SIA, which is based on Privilege Cloud. Users still need to have Privilege Cloud to achieve the same level of functionality as the on-premises version.

We are still early in the roadmap and haven't progressed far enough to identify additional needs. When organizations reach the end of their maturity roadmap, they can better identify specific tool requirements that aren't currently available.

For how long have I used the solution?

We have been deploying CyberArk Privileged Access Manager for two years now and counting.

How are customer service and support?

The evaluation of customer service and technical support for CyberArk Privileged Access Manager depends on several factors. When receiving support directly from CyberArk, they are the most knowledgeable, though they don't always have immediate solutions as they might need to create them, which can take considerable time. For instance, the Ansible integration for the cloud version has been requested for years.

When working with CyberArk partners for support, it's crucial to ensure they have actual knowledge and aren't just acting as middlemen. There have been instances where third parties are hired to provide first and second line support, but they simply forward requests to CyberArk without adding value to the process.

How would you rate customer service and support?

What about the implementation team?

We used a deployment partner recommended by CyberArk for the deployment and maintenance process. One crucial step that should be done first is creating an inventory of how privileged access is currently handled and where it is needed. Without this inventory, you might deploy CyberArk and realize it doesn't work with your existing architecture or infrastructure.

Our implementation team consisted of approximately 15 people, including architects, engineers, application owners, network specialists, Windows and Linux administrators, database administrators, and cloud specialists. While maintenance requires fewer people, input from all these stakeholders is crucial for successful implementation as they each have different requirements.

Most importantly, this needs to be a management-driven initiative with a top-down approach. Management must establish new working methods, as the biggest barrier to acceptance is typically resistance to changes in working procedures.

For ongoing operations, the staffing requirements depend on the company's operations. Typically, 24/7 coverage requires at least three people per shift in a follow-the-sun model. This accounts for first and second line support only, with additional staff needed for server maintenance, totaling around nine people.

What other advice do I have?

The primary problem addressed by implementing CyberArk Privileged Access Manager is the lack of control over privileged access - where it happens, how it occurs, and what is done with that access. When attempting to attack an enterprise, attackers target the highest-privilege credentials available. Therefore, protecting the most critical credentials within your organization is essential.

For those planning to deploy CyberArk Privileged Access Manager, it's crucial to understand that it's a multi-year program. It's not just about deploying the tool; it needs policies and governance around it. Additionally, infrastructure modifications are necessary to ensure PAM is the only way to provide privileged access to endpoints.

It's a great product that does everything required from a PAM tool. I would rate CyberArk Privileged Access Manager as a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ali Hatamleh - PeerSpot reviewer
IT operations manager at a tech services company with 11-50 employees
Real User
Top 5Leaderboard
Jul 3, 2025
Implementing robust access security and monitoring for user sessions
Pros and Cons
  • "CyberArk Privileged Access Manager has positively impacted my organization, showing significant improvement since all sessions are monitored and isolated using isolated RDP sessions, which are created temporarily and expire if not used."
  • "CyberArk Privileged Access Manager can be improved because I have experienced one issue where a user connected through RDP to a Linux server and the PAM could not fetch any commands or key store logging from the Linux server, which works fine on Windows servers."

What is our primary use case?

My main use case for CyberArk Privileged Access Manager is installing it to prevent direct access to the users. For the privileged account, we are using the PAM, and all sessions have been monitored, with all logs shared and logged on the vault.

I have more to add about my main use case for CyberArk Privileged Access Manager, specifically our Privileged Threat Analysis, which detects any suspicious event and alarms us.

What is most valuable?

The best features CyberArk Privileged Access Manager offers are PTA, Privileged Threat Analysis, and Alero, Remote Access Management, and these features are essential for enhancing security.

PTA and Alero have made a difference for my team by providing a predefined rule assigned and implemented on the PAM; for example, it sends us an email if there is any suspicious activity or threat credential loss, offering feedback related to user behavior. For Alero, Remote Access Management, it is a very wonderful Identity and Access Management with biometric MFA, mobile access, location tracking, and a small RBAC role-based matrix access that defines user roles, serving as a replacement for VPN.

CyberArk Privileged Access Manager has positively impacted my organization, showing significant improvement since all sessions are monitored and isolated using isolated RDP sessions, which are created temporarily and expire if not used.

In terms of specific metrics or outcomes, the time savings have been noticeable, and while it is not direct access, the PAM works efficiently between servers and end users, preventing users from running or installing unauthorized applications through the AppLocker application created on the PSM.

What needs improvement?

CyberArk Privileged Access Manager can be improved because I have experienced one issue where a user connected through RDP to a Linux server and the PAM could not fetch any commands or key store logging from the Linux server, which works fine on Windows servers. If they could combine both into one keylogger solution, it would be great, and increasing the number of CPM plugins for password retention while providing common web portal applications out-of-the-box would also help.

For how long have I used the solution?

I have been using CyberArk Privileged Access Manager for more than five years.

What do I think about the stability of the solution?

CyberArk Privileged Access Manager is stable in my experience, with no issues of downtime or reliability due to our disaster recovery (DR) and high availability (HA) servers in place.

What do I think about the scalability of the solution?

CyberArk Privileged Access Manager's scalability is good, as it can handle more users or workloads with our five-year roadmap indicating that the PSM server can manage around 20 sessions per hour, which is sufficient for our organization.

How are customer service and support?

I would rate customer support a nine on a scale.

How would you rate customer service and support?

Which solution did I use previously and why did I switch?

I previously used BeyondTrust and Delinea, but I did not switch because I noticed many features in CyberArk that are not available in other solutions.

Which other solutions did I evaluate?

I did not evaluate other options before choosing CyberArk Privileged Access Manager, as I had good experience with another live product.

What other advice do I have?

My advice for others looking to use CyberArk Privileged Access Manager is to pay attention to the vaulting part, which is essential for every organization, as each server has a secured vault that connects over TLS with a lot of encryption details. The product is consistently enhanced, and the latest release is 14.6. I rate this solution 9 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
CEO at CareerCraftly
Real User
Top 5
Mar 24, 2025
Privileged access management escalates efficiently with robust access control and remote connectivity
Pros and Cons
  • "The access control feature and privilege and role-based assignment are outstanding."

    What is our primary use case?

    We use CyberArk Privileged Access Manager for privileged access management (PAM) escalation, securing our website, and applications. Our cybersecurity team actively utilizes its features.

    What is most valuable?

    The PAM escalation is valued. The access control feature and privilege and role-based assignment are outstanding. Dividing the user admin for security protection is the best feature. Additionally, its remote access allows easy connection for my team, and it efficiently manages identity.

    What needs improvement?

    Initially, it was challenging to understand and use all the features incrementally. Having a better user journey with a support team to connect would improve the product and services.

    For how long have I used the solution?

    I have been using CyberArk Privileged Access Manager for about eight months in our company.

    What do I think about the stability of the solution?

    The solution is quite stable. We have not faced any issues related to stability since using CyberArk Privileged Access Manager for eight months.

    What do I think about the scalability of the solution?

    CyberArk Privileged Access Manager is scalable. As a startup, it initially handled fewer users, but it scaled well as we grew.

    How are customer service and support?

    Technical support was fast in its replies and always supportive, helping to resolve any issues efficiently.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    We used miniOrange, an Indian-based cybersecurity product for access management and PAM escalation. We also used one more product, which I don't remember the name of.

    How was the initial setup?

    The initial setup was straightforward due to well-documented resources and tutorials.

    What about the implementation team?

    Our cybersecurity team, comprising two to three people, worked on the deployment and feature implementation.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is quite well-structured with monthly and weekly plans.

    Which other solutions did I evaluate?

    I evaluated miniOrange and one other product.

    What other advice do I have?

    New users should watch the YouTube channel, read the documentation, check the resource section including CyberArk University, and see if it works well with their product. I rate the overall solution a nine. My overall product rating is 9 out of 10.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    reviewer0714174 - PeerSpot reviewer
    CyberArk Product and Vendor Contract Manager at UBS Financial
    Real User
    Oct 1, 2023
    Great session management, password management, and temporary access capabilities
    Pros and Cons
    • "The credentials management capability is key to ensuring that the credentials are kept secure and that access to them is done on a temporary and event-driven basis."
    • "The product is very vaulting-focused. I'd love to see it expanding its capabilities a bit further into areas like just-in-time elevation, and access with non-vaulted credentials."

    What is our primary use case?

    We use CyberArk to secure the last resort accounts by introducing dual control approval, ticket validation, temporary access, and regular password rotation.

    It also allows us to introduce location-aware access controls with multiple sites having access to specific location-protected content.

    Finally, the session management capabilities allowed us to introduce delegated accounts to secure access to all sorts of devices in an easy way, but without losing the individual traceability. 

    How has it helped my organization?

    It allows us to comply with the regulator requirements allowing us to operate in the different countries and to fulfil the security and compliance requirements.

    In the end, it secures all the highly privileged accounts and protects the company from internal and external threat actors.

    The solution is multifaceted and includes session management, password management, temporary access, ticketing validation, API access, single sign-on integration, load balancing, and high availability principles.

    What is most valuable?

    The credentials management capability is key to ensuring that the credentials are kept secure and that access to them is done on a temporary and event-driven basis.

    The session isolation reduces the risk of exposure of the credentials and applying simpler network controls.

    Web access allows the introduction of location-aware controlled access so that different locations can only access the data that is allowed to be retrieved from their sites allowing centralisation but fulfilling the regional requirements.

    What needs improvement?

    The product is very vaulting-focused. I'd love to see it expanding its capabilities a bit further into areas like just-in-time elevation, and access with non-vaulted credentials.

    The upgrade options are good but could be further simplified.

    The high availability options could be improved, and the load distribution as well for both the vaults and the credentials managers.

    The web interface should allow having multiple sites for location-aware access control within the same web server.

    For how long have I used the solution?

    I've used the solution for more than ten years.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    UmeshKumar4 - PeerSpot reviewer
    Security Consultant at Ernst & Young
    Real User
    May 16, 2024
    Offers password rotation and makes session recordings compulsory for data protection
    Pros and Cons
    • "Password rotation is the most valuable feature"
    • "The solution should be able to mitigate internal threats"

    What is our primary use case?

    I use the solution mainly for credential tasks. For instance, if the company I work for has recent data stored in a privileged report and needs security from cyber attackers, CyberArk Privileged Access Manager is used. The solution helps provide access only to authorized users and rotate passwords every sixty or ninety days. CyberArk Privileged Access Manager also allows the configuration of the password either manually or automatically. 

    In our organization, Privileged Session Managers (PSM) assist in recording sessions of a particular server using the solution. The product allows users to utilize different permissions, such as end-user, auditor, and administrator permissions. For CyberArk Privileged Access Manager, administrators have the major access to implement tasks like creating, changing, rotating the password and adding new users. 

    What is most valuable?

    The most valuable feature of this tool is the password rotation feature. Another vital feature of the solution is the Safe feature, which acts as a container. Only accounts included within the Safe can access a particular server. 

    The solution allows the distinguished use of PSM and PSMP for a Windows and Linux server, respectively. The tool makes all session recordings compulsory and cannot be tampered with. It also eliminates hard-coded credentials and supports demand-based applications.  

    CyberArk is very popular and provides a lot of features compared to competitors' PAM tools, which is why many customers are migrating to CyberArk's Privileged Access Manager. 

    What needs improvement?

    The solution should be able to completely mitigate internal threats. For instance, if an employee of a company saves the CyberArk passwords in a system, then another employee might be able to use it and log in, so there remains an internal threat when using the solution.  

    The feature of giving user access through a Safe should be modified. The solution should allow users access directly through an account, and the Safe concept needs to be improved. 

    For how long have I used the solution?

    I have been using CyberArk Privileged Access Manager for the past two years. 

    What do I think about the scalability of the solution?

    In my organization, about ninety to one hundred people are using CyberArk Privileged Access Manager. 

    How was the initial setup?

    It's easy to setup and install CyberArk Privileged Access Manager. Multiple components need to be installed for the solution. Often, the PVWA, PSM, and CPM need to be installed. If an organization has a Linux account, then PSMP needs to be installed for using the solution. While installing the solution, the Vaults need to be defined, if it's a standalone Vault or a cluster Vault. A cluster Vault is mostly implemented for disaster recovery to replicate data when something happens to the main Vault. 

    What's my experience with pricing, setup cost, and licensing?

    CyberArk Privileged Access Manager comes at a high cost. But the solution is worth its price. 

    What other advice do I have?

    I would recommend the solution to others depending on their goals. If the aim is to protect an organization's data and use PAM, then one should use CyberArk Privileged Access Manager. If the goals include detecting malicious activity, onboarding privileged accounts, and maintaining data accounts, then an organization should adopt the solution.   

    I have used the solution's session monitoring capabilities to monitor user activities. The solution's session monitoring feature can be useful for monitoring a user while the person logs in or performs other molecular activities.  

    CyberArk Privileged Access Manager is difficult and time-consuming to learn in comparison to other IAM tools. There are multiple components, like the vault, that need to be understood before using the solution. But basic administrator tasks like onboarding accounts and rotating passwords will be easy for a beginner user of CyberArk Privileged Access Manager. A beginner-level user of the solution may face challenges with secret rotating, management and AIM handling.  

    I would rate CyberArk Privileged Access Manager an eight out of ten. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Idira Privileged Access Manager Report and get advice and tips from experienced pros sharing their opinions.
    Updated: September 2026
    Buyer's Guide
    Download our free Idira Privileged Access Manager Report and get advice and tips from experienced pros sharing their opinions.