TrustRadius: an HG Insights company

CyberArk Privileged Access Management

Score9.2 out of 10

65 Reviews and Ratings

What is CyberArk Privileged Access Management?

CyberArk is a privileged account and access security suite issued by the company of the same name in Massachusetts . The Core Privileged Access Security Solution unifies Enterprise Password Vault, Privileged Session Manager and Privileged Threat Analytics to protect an organization’s most critical assets.

Categories & Use Cases

Media

Screenshot of ISPSS
Screenshot of Privilege Cloud
Screenshot of Identity Security Intelligence
Screenshot of Identity Security Intelligence

1 / 4

Screenshot of ISPSS

A comfortable way to manage privileged and service accounts

Pros

  • Managing Service Accounts. We like using CyberArk for using it when we need to remote into certain systems and the password is stored on CyberArk.
  • Managing Privileged Accounts. It allows our IT personal to use their privileged accounts without having to remember their passwords. It also keeps our staff compliant with complexities with passwords.
  • Using CyberArk as a jump host has saved us on licensing issues. It's also easy to use when needing to remote in and automatically signing you in.

Cons

  • I'm not sure what could be done differently. There are some things that were once an issue that are no longer an issue. For instance, creating a short cut on the desktop for RDP through CyberArk. Since the upgrade and updates, we are now able to save shortcuts to our desktop.

Return on Investment

  • A positive impact is passing SOX audits when it comes to privileged account management. Making sure we are compliant with password expiration policies and complexities.

Other Software Used

Netwrix Auditor, FireEye Network Security, FireMon

A reliable solution to store credentials

Use Cases and Deployment Scope

CyberArk Privileged Account Security provides robust and resilient for enterprise level deployments and it is one of the nice PAM solutions out there. It works well with both Windows and Linux systems.

Pros

  • Product capabilities
  • Integration & deployment
  • Services and support

Cons

  • Upgrades are not easy
  • Deployment wouldn't be easy for complex environment

Most Important Features

  • Customer focus
  • Services expertise
  • Compliance & risk management

Return on Investment

  • Improved compliance & risk management

Alternatives Considered

The Okta Identity Cloud, Broadcom Unified Infrastructure Management and formerly from CA

Other Software Used

The Okta Identity Cloud, Snowflake, Talend Cloud Integration, Cloudera Data Platform

Make your privileged data safe using CyberArk

Pros

  • Identify and reduce the number of privileged accounts
  • Eliminate shared/service accounts having non-expiring passwords
  • Automatically changing privileged account passwords
  • Automate password verification and reconciliation
  • Frequently identify, change and verify hardcoded passwords
  • Connect Target Systems directly without displaying passwords to users

Cons

  • The initial product cost is a little on the higher side, which might turn off small & medium enterprises.
  • As it talks about security, it has a lot of hardware/software requirements for the initial setup, which might make the rollout timeline a little lengthy.
  • Product should be easy to customize based on different industry's needs.

Return on Investment

  • Decreased the probability of an external cyber attack to privileged accounts..
  • Management can control privileged account life cycle management more effectively
  • Recording privileged sessions allows our organization to play back exactly the point of a breach or malicious behavior
  • Automated system to manage and verify passwords, as privileged accounts are constantly created and deleted
  • Automatic PWD change functionality will substantially decrease probability of PWD theft or misuse.

Alternatives Considered

Centrify Endpoint Services

Other Software Used

Imprivata OneSign, Oracle Service Cloud

Making passwords more secure than Password123

Pros

  • The user interface is intuitive and easy to use.
  • The local server/workstation account management is great with the ability to remove local admin accounts but still leverage admin privileges.
  • Prevents unauthorized access and meets security requirements and allowing for robust and detailed reporting and audit logs.

Cons

  • The copy button in a web-browser requires an add-on to the browser. The feature should be included without the add-on.
  • Forced purchase of re-branded dell servers as account vaults is terrible.
  • Reports are ok but requires some expertise to export data into a better reporting DB.

Return on Investment

  • The costs to operate are high.
  • Has been very easy to share passwords through a secure means. Valuable when compared to compromised credentials and the risks associated with PR or data breach.
  • There are solutions out there that are more cost effective, but the additional features don't match that of CyberArk.

Alternatives Considered

manage engine and pleasant solutions

CyberArk PAS - Great Product to add security

Pros

  • Password segregation via RBAC
  • Rotation of passwords
  • View/reconcile/Verify passwords
  • Options to store passwords

Cons

  • GUI - right now everything is on one page/dashboard. Some level of folder/Safe type view would be great
  • More options when storing passwords - especially for network based passwords
  • Better integrations with vendors like Cisco so that admins dont need to really get the password from the vault (think Last Pass type add on)

Return on Investment

  • It provided extra security for passwords in use and rotation of admin-level passwords.
  • Complexity of passwords guranteed.
  • Some basic integrations.

Other Software Used

Okta Customer Identity, SolarWinds Network Performance Monitor (NPM), SolarWinds Network Configuration Manager (NCM), Cisco Defense Orchestrator, Cisco Umbrella, Cisco Firepower Management Center (FMC series appliances), Cisco Firepower NGFW (formerly Sourcefire), Rackspace Cloud Hosting, Cisco Identity Services Engine (ISE)