Cybersecurity Technology Lead at a tech vendor with 10,001+ employees
MSP
Top 20
Aug 24, 2026
An example of how I used Idira IGA was when I implemented it in the form of CyberArk with privileged access management, or PAM. I mentioned the SOX compliance at the bank as the primary regulatory driver behind the CyberArk program. The SOX Act requires financial institutions to maintain strict control over access to financial systems, knowing who has access, what they did, and whether the access is properly managed and audited. The ISO/IEC 27001 compliance requires organizations to implement and maintain an information security management system with documented controls across access management, logging, monitoring, and incident response. Several of these controls were mapped directly to what the CyberArk program delivered. I would rate Idira IGA a six out of ten overall. I chose this rating because of the areas where I see improvements could be made. My observations about operational friction points and the challenges slowing down adoption during implementation have led to this rating. Regarding Idira IGA's AI capabilities, I believe there could be improvements in prioritizing features that reduce implementation friction and increase adoption. The AI-driven anomaly detection and improvements represent a long-term opportunity for Idira IGA. This is where the platform needs to head to stay ahead of the threat landscape. Simpler legacy application onboarding, smarter rotation readiness checks, and native dependency discovery will make a significant difference for organizations. Idira IGA is deployed in the cloud across the two organizations I have experience with. Improvements needed for Idira IGA that I have not mentioned yet include alignment with banking regulations and compliance as well as enhancements according to the national NIST framework. At Truist Bank, it took us about six months to deploy our previous IGA solution, primarily because we had to conduct compliance checks with various teams. Deploying CyberArk Modern IGA took three months. Compared to past solutions, the CyberArk deployment was pretty fast due to strong support from account managers and the many out-of-the-box configurations CyberArk offered. My team spends less time on access reviews and evidence collection compared to before, taking about two to three hours of work with two technical people, depending on the subject matter experts available. Automation has made access reviews faster and more accurate. My advice for others looking into using Idira IGA would be to prioritize improvements that reduce implementation friction and increase adoption. The gap between what CyberArk can do and what an organization achieves is not due to platform capability, but rather the difficulty of achieving effective implementation. Simpler legacy application onboarding, smarter rotation readiness checks, and native dependency discovery will differentiate organizations that achieve full privileged access coverage from those that stall at 60 percent and stop. My insights come from leading delivery and identifying operational friction points rather than from a product engineering perspective. Idira IGA is a very good solution for privileged access management and stands out against the rest. I hope it continues to improve. My overall rating for this review is six out of ten.
Technical Services Lead, Cybersecurity Engineer at a financial services firm with 10,001+ employees
Real User
Top 20
Jul 16, 2026
On a daily basis, we rotate passwords automatically. Whenever the user retrieves the password, after settings such as twelve hours or eight hours, the password expires. This means that the user cannot use the same password again. This is very secure. The organization, as I work in the banking sector, finds this very helpful for us and our clients to maintain all applications securely. I would suggest to them that whenever an issue occurs, with the help of logs, we need to go to Idira IGA community portal and validate that.
Infrastructure Lead at a tech vendor with 10,001+ employees
Real User
Top 5
Jun 25, 2026
I would definitely recommend customers use Idira IGA as a single platform for all governance around PAM, application, and user provisioning. It is definitely recommended for large organization deployments. I provided this review with a rating of nine.
I have seen measurable improvements in reviews and provisioning. Specifically, in provisioning, it provides just-in-time access and a role-based architecture that helps in configuring access restrictions based on user roles, such as preventing registered nurses from accessing systems meant for doctors. I would rate CyberArk IGA Powered by Zilla at seven point five overall.
I would advise others considering CyberArk IGA Powered by Zilla that it is best for large enterprises with many accounts and a focus on compliance; if compliance is a significant concern for your organization, then it is definitely worth choosing. I provided this review with a rating of 9.
CyberArk IGA Powered by Zilla is expensive when compared to One Identity IGA and BeyondTrust. My overall review rating for this product is an eight out of ten.
Associate Director at a legal firm with 10,001+ employees
Real User
Top 20
Jan 11, 2026
Customization involves making changes to fit customer requirements. Maintenance usually involves sometimes having issues with different connectors, mostly the Active Directory and LDAP connectors. Periodic aggregation of accounts and applications sometimes go through issues with firewalls. Sometimes they do not work, and you need to make sure your connectors are all in sync, especially your LDAP and AD connectors. Sometimes there could be some issues occurring between these two connectors, so there will be maintenance on that side, making sure they are working on a regular basis based on your monitoring plan. Taking backups regularly and periodic backups are essential. Both the support rating and the overall product rating for CyberArk IGA Powered by Zilla is eight out of ten. Eight means they have complete processes in place to help support, they have resources available, and there is a method to contact them and get response quickly. In that regard, eight is appropriate because they reuse some of their main PAM components which is very good, and compared to other products which I ranked around nine, they should be at eight.
I would advise knowing the source of truth that you are going to use upfront. If you need to change, that can be more complicated. Educating end users is always the biggest challenge with any process, but spending time to learn it is worth it. I would rate Zilla Security a nine out of ten. It has been very easy to use. I have liked working with their team on different things, and they are very responsive.
CyberArk IGA Powered by Zilla is designed to streamline identity governance and administration by automating access controls and compliance processes, enhancing security and efficiency.
Known for its robust capabilities, CyberArk IGA Powered by Zilla offers comprehensive identity governance that simplifies policy enforcement and compliance management. It enables organizations to efficiently manage user access, reducing risks and ensuring secure operations. By leveraging automation, it...
An example of how I used Idira IGA was when I implemented it in the form of CyberArk with privileged access management, or PAM. I mentioned the SOX compliance at the bank as the primary regulatory driver behind the CyberArk program. The SOX Act requires financial institutions to maintain strict control over access to financial systems, knowing who has access, what they did, and whether the access is properly managed and audited. The ISO/IEC 27001 compliance requires organizations to implement and maintain an information security management system with documented controls across access management, logging, monitoring, and incident response. Several of these controls were mapped directly to what the CyberArk program delivered. I would rate Idira IGA a six out of ten overall. I chose this rating because of the areas where I see improvements could be made. My observations about operational friction points and the challenges slowing down adoption during implementation have led to this rating. Regarding Idira IGA's AI capabilities, I believe there could be improvements in prioritizing features that reduce implementation friction and increase adoption. The AI-driven anomaly detection and improvements represent a long-term opportunity for Idira IGA. This is where the platform needs to head to stay ahead of the threat landscape. Simpler legacy application onboarding, smarter rotation readiness checks, and native dependency discovery will make a significant difference for organizations. Idira IGA is deployed in the cloud across the two organizations I have experience with. Improvements needed for Idira IGA that I have not mentioned yet include alignment with banking regulations and compliance as well as enhancements according to the national NIST framework. At Truist Bank, it took us about six months to deploy our previous IGA solution, primarily because we had to conduct compliance checks with various teams. Deploying CyberArk Modern IGA took three months. Compared to past solutions, the CyberArk deployment was pretty fast due to strong support from account managers and the many out-of-the-box configurations CyberArk offered. My team spends less time on access reviews and evidence collection compared to before, taking about two to three hours of work with two technical people, depending on the subject matter experts available. Automation has made access reviews faster and more accurate. My advice for others looking into using Idira IGA would be to prioritize improvements that reduce implementation friction and increase adoption. The gap between what CyberArk can do and what an organization achieves is not due to platform capability, but rather the difficulty of achieving effective implementation. Simpler legacy application onboarding, smarter rotation readiness checks, and native dependency discovery will differentiate organizations that achieve full privileged access coverage from those that stall at 60 percent and stop. My insights come from leading delivery and identifying operational friction points rather than from a product engineering perspective. Idira IGA is a very good solution for privileged access management and stands out against the rest. I hope it continues to improve. My overall rating for this review is six out of ten.
On a daily basis, we rotate passwords automatically. Whenever the user retrieves the password, after settings such as twelve hours or eight hours, the password expires. This means that the user cannot use the same password again. This is very secure. The organization, as I work in the banking sector, finds this very helpful for us and our clients to maintain all applications securely. I would suggest to them that whenever an issue occurs, with the help of logs, we need to go to Idira IGA community portal and validate that.
I would definitely recommend customers use Idira IGA as a single platform for all governance around PAM, application, and user provisioning. It is definitely recommended for large organization deployments. I provided this review with a rating of nine.
I have seen measurable improvements in reviews and provisioning. Specifically, in provisioning, it provides just-in-time access and a role-based architecture that helps in configuring access restrictions based on user roles, such as preventing registered nurses from accessing systems meant for doctors. I would rate CyberArk IGA Powered by Zilla at seven point five overall.
I would advise others considering CyberArk IGA Powered by Zilla that it is best for large enterprises with many accounts and a focus on compliance; if compliance is a significant concern for your organization, then it is definitely worth choosing. I provided this review with a rating of 9.
CyberArk IGA Powered by Zilla is expensive when compared to One Identity IGA and BeyondTrust. My overall review rating for this product is an eight out of ten.
Customization involves making changes to fit customer requirements. Maintenance usually involves sometimes having issues with different connectors, mostly the Active Directory and LDAP connectors. Periodic aggregation of accounts and applications sometimes go through issues with firewalls. Sometimes they do not work, and you need to make sure your connectors are all in sync, especially your LDAP and AD connectors. Sometimes there could be some issues occurring between these two connectors, so there will be maintenance on that side, making sure they are working on a regular basis based on your monitoring plan. Taking backups regularly and periodic backups are essential. Both the support rating and the overall product rating for CyberArk IGA Powered by Zilla is eight out of ten. Eight means they have complete processes in place to help support, they have resources available, and there is a method to contact them and get response quickly. In that regard, eight is appropriate because they reuse some of their main PAM components which is very good, and compared to other products which I ranked around nine, they should be at eight.
I would advise knowing the source of truth that you are going to use upfront. If you need to change, that can be more complicated. Educating end users is always the biggest challenge with any process, but spending time to learn it is worth it. I would rate Zilla Security a nine out of ten. It has been very easy to use. I have liked working with their team on different things, and they are very responsive.