Cisco Duo vs. Zscaler Private Access

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Cisco Duo
Score 9.5 out of 10
N/A
Cisco Duo is a two-factor authentication system (2FA), acquired by Cisco in October 2018. It provides single sign-on (SSO) and endpoint visibility, as well as access controls and policy controlled adaptive authentication.
$3
per month per user
Zscaler Private Access
Score 7.9 out of 10
N/A
Zscaler Private Access™ (ZPA) gives users secure access to private apps and OT devices while enabling zero trust connectivity for workloads.N/A
Pricing
Cisco DuoZscaler Private Access
Editions & Modules
Duo Essentials
$3
per month per user
Duo Advantage
$6
per month per user
Duo Premier
$9
per month per user
No answers on this topic
Offerings
Pricing Offerings
Cisco DuoZscaler Private Access
Free Trial
YesNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Cisco DuoZscaler Private Access
Considered Both Products
Cisco Duo
Chose Cisco Duo
None, we are happy with offering Cisco Duo
Chose Cisco Duo
Cisco Identity Services Engine (ISE)
Chose Cisco Duo
Cisco Duo supplements the above products in providing MFA
Chose Cisco Duo
Cisco Duo provides a much richer user experience, the UI is way more modern, and the product itself is easier to use.
Chose Cisco Duo
I would fully expect a competitor like Okta or any other multifactor mechanic to function pretty similarly, and I hesitate to say duos the best. I think the idea is that it's a simple concept, but it does it well. So I haven't evaluated any myself outside of duo, but I'm also …
Chose Cisco Duo
Cisco Duo was much better suited to integrate with our Citrix solution.
Chose Cisco Duo
We didn't evaluate any other MFA solutions to compare outside of using Keeper as a password vault but that works in conjunction with Cisco Duo.
Chose Cisco Duo
The organization chose Cisco Duo prior to the acquisition with its strong brand and reputation from the security community.
Chose Cisco Duo
Cisco is one of our trusted solution vendors and Cisco Duo can be good integrated to our security landscape.
Chose Cisco Duo
It's more easy and user-friendly.
Chose Cisco Duo
Similar but priced quite well as part of a product suite.
Chose Cisco Duo
Cisco Duo had an integrated method for handling MFA on Endpoints and Servers. This was a huge bonus. Administration and implementation seemed more efficient as well.
Chose Cisco Duo
Cisco Secure Access by Duo is the best and most familiar. Users have no issues using it and it is a breeze to administer as well.
Chose Cisco Duo
There are Okta has that Duo does not have, however since my environment has CISCO solutions implemented and the service that we receive from the vendor and integrator is top quality, DUO was the right choice.
Chose Cisco Duo
We selected Cisco Secure Access by Duo due to its ability to interoperate with almost any on premise, cloud, or hybrid application or system. Duo also integrates nicely with our other security systems, including XDR. As well, Duo is a market leader and always pushing the sector …
Chose Cisco Duo
Cisco Secure Access by Duo's ability to integrate with a wide variety of SSO applications and systems, as well as its focus on usability, make it an attractive option.
Zscaler Private Access
Chose Zscaler Private Access
Ivanti had its moment. However moving to Zscaler Private Access was the best decision for us. Zscaler Private Access is faster, smoother UI and has heaps of feature that, in my opinion, makes it tower over Ivanti. The authenticate early option, ensures we don't loose connection …
Chose Zscaler Private Access
Cisco Secure Access, Cisco AnyConnect and Ivanti Secure Unified Client
Chose Zscaler Private Access
Zscaler Private Access is a better fit for overall Zero Trust ecosystem.
Chose Zscaler Private Access
All of these tools are for different needs. Zscaler Private Access being for internal seems very simple as it really only allows filtering up to L4 whereas ZIA allows for filtering up to L7. ZDX often tries to give insight into the environment but since it only works with …
Chose Zscaler Private Access
Zscaler Private Access was chosen as trusted VPN system versus Cisco, due to better licensing model, more flexible configuration of the security protocols, verification scenarios. Also it
Chose Zscaler Private Access
We had a nightmare experience with Prisma Access. The tool was not the most intuitive, and their peripherals to make it more secure were not efficient. Their integration with other tools to provide MFA was mediocre at best. That is the main reason we decided to explore …
Chose Zscaler Private Access
Well ZPA is a good solution, however everyone has their own advantage and disadvantages, with ZPA you can deploy ZTNA model, which will help you better control on access, however Palo Alto, Fortinet they are also market leading firewall solution, and you can not deny if they …
Chose Zscaler Private Access
We originally used Cisco AnyConnect but when the pandemic hit and everyone started working remotely the Cisco VPN just couldn't handle the massive increase in users. The connection was unreliable both inability to connect and stay connected. It also seemed to include a lot more …
Chose Zscaler Private Access
Both are good but sometimes relationship and cost is the factor to decide the final vendor.
Features
Cisco DuoZscaler Private Access
Threat Intelligence
Comparison of Threat Intelligence features of Product A and Product B
Cisco Duo
-
Ratings
Zscaler Private Access
10.0
Ratings
13% above category average
Network Analytics00 Ratings10.00 Ratings
Automated Alerts and Reporting00 Ratings10.00 Ratings
Zero Trust Security
Comparison of Zero Trust Security features of Product A and Product B
Cisco Duo
-
Ratings
Zscaler Private Access
10.0
Ratings
7% above category average
Continuous Verification00 Ratings10.00 Ratings
Secure Web Gateways00 Ratings10.00 Ratings
Network Flow Control00 Ratings10.00 Ratings
Network Data Encryption00 Ratings10.00 Ratings
Network Topology Mapping00 Ratings10.00 Ratings
Best Alternatives
Cisco DuoZscaler Private Access
Small Businesses
WatchGuard AuthPoint
WatchGuard AuthPoint
Score 9.1 out of 10
ThreatLocker
ThreatLocker
Score 9.5 out of 10
Medium-sized Companies
WatchGuard AuthPoint
WatchGuard AuthPoint
Score 9.1 out of 10
Palo Alto Networks Prisma Access
Palo Alto Networks Prisma Access
Score 8.9 out of 10
Enterprises
Microsoft Entra ID
Microsoft Entra ID
Score 8.7 out of 10
Palo Alto Networks Prisma Access
Palo Alto Networks Prisma Access
Score 8.9 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Cisco DuoZscaler Private Access
Likelihood to Recommend
9.4
(0 ratings)
8.0
(0 ratings)
Likelihood to Renew
9.8
(0 ratings)
-
(0 ratings)
Usability
9.9
(0 ratings)
-
(0 ratings)
Availability
9.8
(0 ratings)
-
(0 ratings)
Performance
8.7
(0 ratings)
-
(0 ratings)
Support Rating
9.9
(0 ratings)
-
(0 ratings)
Online Training
10.0
(0 ratings)
-
(0 ratings)
Implementation Rating
9.8
(0 ratings)
-
(0 ratings)
Configurability
10.0
(0 ratings)
-
(0 ratings)
Ease of integration
9.9
(0 ratings)
-
(0 ratings)
Product Scalability
9.3
(0 ratings)
-
(0 ratings)
Vendor post-sale
9.3
(0 ratings)
-
(0 ratings)
Vendor pre-sale
9.3
(0 ratings)
-
(0 ratings)
User Testimonials
Cisco DuoZscaler Private Access
Likelihood to Recommend
Cisco Duois is well suited in all kinds of scenarios where you need to ensure proper security measurements, I think. We can't just rely on our passwords only, as they can be easily stolen through phishing or data breaches thus keeping multi factor authentication is quite essential. I always prefer MFA or at least 2FA for any critical system.
Read full review
The tool is, for the most part, very intuitive. Most of our issues so far (working through them with our Resident Engineer) are the one-off applications. We are working on some exemptions to make them functional. Besides that, the team loves the tool and how it can provide better security than our previous tool.
Read full review
Pros
  • Speed - it's fast with almost no delay between triggering the MFA request and receiving the notification on an iPhone
  • Security - in addition to the added MFA layer, a simple, 4-digit passcode can be added to the authentication request
  • Ease of use - it doesn't scare users. It's simple to install, configure, and use.
Read full review
  • Allows strong cyber security corporate policies
  • Very reliable VPN application that operates at 100% efficiency
  • Very easy to be configured with friendly user interface
Read full review
Cons
  • Documentation is oftentimes missing key information for proper implementation. This is circumvented by reading third-party guides or contacting support for additional details.
  • They do not push Fail-Closed as much as I think they should. Fail-Open is fairly trivial to bypass and it should be made known to the customer during setup how much this will affect overall security.
  • More vendor integration is something that is always craved by administrators. There are so many third-parties to integrate with.
Read full review
  • Granularity and Complexity of Policy Enforcement
  • Application Segmentation and Listener Configuration - The way applications are defined and listened for is fundamental to ZPA, but can be a source of frustration, especially when dealing with legacy or non-HTTP protocols
  • The ZCC is the user's primary gateway, but its control over local system network behavior can sometimes clash with enterprise requirements.
Read full review
Likelihood to Renew
There are a lot of competing solutions on the market; however, Duo "just works", and there is little to no learning curve for the new members to be acclimated to it. As long as that continues I see it as the preferred option moving forward
Read full review
No answers on this topic
Usability
La interfaz es intuitiva y fácil de navegar, lo que permite a los usuarios administrar sus dispositivos y acceder a las políticas sin problemas. La integración con las aplicaciones SSO y SaaS facilita aún más el proceso de acceso, mejorando la experiencia del usuario.
Read full review
Few things stand out. The ease of access: It very convenient - one click to open add details and done. Packet capture: Can't talk enough about this feature. Troubleshooting private access is always problematic,but this feature helped a lot. One thing that can be improved is early warning about expiring authentication
Read full review
Reliability and Availability
In the last 5+ years we've been using Duo, there may have been 1 outage that impacted us. We do receive periodic notifications of issues but, for the most part, they impact carriers or functionality that we either don't use, or do not care about.
Read full review
No answers on this topic
Performance
We do not see any degradation of performance of the protected applications. There are occasional lags in receiving the push but no show stooppers.
Read full review
No answers on this topic
Support Rating
Since it’s a reputable company, I have received technical support when needed and I trust that if anything else happens I can contact them with any issues. I haven’t experienced bad customer service and I totally feel supported while using this authentication method. No complains so far and the high rating!
Read full review
No answers on this topic
In-Person Training
There was no in person training but checking the box was the only way I could complete all of the questions.
Read full review
No answers on this topic
Online Training
This was not organized training but the videos that Duo provides to teach you how to install a particular integration are top notch.
Read full review
No answers on this topic
Implementation Rating
Implementation was straight forward and you can isolate different scenarios in order to test new application setup or add to an existing setup. Gui interface is pretty easy to understand and follow. I had no experience with Duo and still manage to easily set up new policies and rules.
Read full review
No answers on this topic
Alternatives Considered
Ultimately we ended up going with Cisco Duo because we are a Cisco shop. All of our networking infrastructure, our phones, our wireless environment is Cisco based. It made logical sense to stay with a product that we already have a line of support with. With a smaller support / tech group we depend on outside Cisco support. That support is already here for us, so we stayed with a Cisco product.
Read full review
All of these tools are for different needs. Zscaler Private Access being for internal seems very simple as it really only allows filtering up to L4 whereas ZIA allows for filtering up to L7. ZDX often tries to give insight into the environment but since it only works with preconfigured items, that then means when a new problem shows up - ZDX isn't helpful troubleshooting postmortem. For the internal side of the house - Zscaler Private Access' strength is its simplicity to configure.
Read full review
Scalability
So far, the only limits we've encountered were tied to our imagination. Duo's strong list of supported integrations is amazing.
Read full review
No answers on this topic
Return on Investment
  • It's one of those things that only costs money in the sense of you have to convince a leadership team to spend money to save money, right? Like a compromise is far more expensive than duo paying for duo. So specifically it's really just about trying to prevent problems. And so while it costs money and we don't have a direct return on investment that we can point out immediately, I would still always advocate for it just because it keeps security. Paying for security is cheaper than getting compromised essentially.
Read full review
  • Positive: We have now charged users internally for the service
  • Negative: Dealing with users who also have the Zscaler Client Connector for their company, can cause confusions
  • Negative: Enabling the Zscaler Internet Access entitlement has been a major headache for us because Zscaler Private Access users can't autheniticate through ZIA on a non corporate device.
Read full review
ScreenShots

Zscaler Private Access Screenshots

Screenshot of how ZPA provides access for all users while minimizing the attack surface, eliminating lateral movement, and stopping zero day threats. A cloud native service, ZPA can be deployed in just hours to replace legacy remote access tools like VPNs and VDIs.