CyberArk is a privileged account and access security suite issued by the company of the same name in Massachusetts . The Core Privileged Access Security Solution unifies Enterprise Password Vault, Privileged Session Manager and Privileged Threat Analytics to protect an organization’s most critical assets.
N/A
Microsoft Intune
Score 8.4 out of 10
N/A
Microsoft Intune (formerly Microsoft Endpoint Manager), combining the capabilities of the former Microsoft System Center Configuration Manager, SCCM or ConfigMgr, is presented as a unified endpoint management option. Microsoft Intune is an endpoint management solution for mobile devices, an MDM solution that allows the user to securely manage iOS, Android, Windows, and macOS devices with a single endpoint management solution. The component Endpoint Configuration Manager (the…
$5
per user/per month
Pricing
CyberArk Privileged Access Management
Microsoft Intune
Editions & Modules
No answers on this topic
Microsoft 365 Business Basic
$5
per user/per month
Microsoft 365 For Individuals
$6.99
per month
Microsoft 365 Apps
$8.25
per user/per month
Microsoft 365 For Families
$9.99
per month
Microsoft 365 Business Standard
$12.50
per user/per month
Microsoft 365 Business Premium
$15
per user/per month
Offerings
Pricing Offerings
CyberArk Privileged Access Management
Microsoft Intune
Free Trial
Yes
No
Free/Freemium Version
No
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
No setup fee
No setup fee
Additional Details
CyberArk offers a variety of Identity Security packages for different user types within an organization.
I always recommend CyberArk based on my experiences at several different jobs and industries. It does a great job of helping you create all kinds of use cases and approval flows for accessing and using privileged accounts. It also does a great job securing local admin passwords on servers. End-users of the system are able to quickly and easily start utilizing the more secure method of obtaining credentials in minimal time with minimal overhead/tax on their work time.
Windows Autopilot makes provisioning user Windows PC laptops a breeze. A user only needs to turn on the laptop, join it to their local WiFi, login with their O365 account then sit back and let Windows Autopilot handle the app installations required for work, configure the laptop settings to meet my organization requirements. I have seen this all completed in less than 30 minutes depending on how fast the internet connection is. Where Microsoft Intune needs to improve I think is the part where it can push out software updates to 3rd party apps. Right now I have to use Automox to fill in this gap.
[Microsoft Endpoint Manager (Microsoft Intune + SCCM)] helps to speed up the deployment of patches/software throughout our environment. I can easily build a package and then deploy across all endpoints.
The ability to supercede software is also quite handy. This automates the removal of old versions and replacing them with newer versions.
The Intune Autopilot option is very useful if you want to deploy software to devices straight out of the box. You can configure them to download software when a user opens a new PC and turns it on for the first time.
The initial product cost is a little on the higher side, which might turn off small & medium enterprises.
As it talks about security, it has a lot of hardware/software requirements for the initial setup, which might make the rollout timeline a little lengthy.
Product should be easy to customize based on different industry's needs.
Installation is very laborious and complicated. The number of things to manually configure during the installation is incredible.
OS deployment is hard to configure and troubleshoot. The Microsoft article on deploying Windows 10 via System Center Configuration Manager in a test environment takes 44 minutes to read (Microsoft's estimate, not mine -- check here: https://docs.microsoft.com/en-us/windows/deployment/windows-10-poc-sc-config-mgr). If something goes wrong, there are multiple log locations to check on both the server and client, making troubleshooting difficult.
The management console looks old, and its performance isn't great. It is often hard to find settings in the console, and it refreshes slowly. The old name for System Center Configuration Manager, SMS, comes to mind often. "Slowly Moving Software."
Mascom Wireless is a Microsoft shop and SCCM has proved to be helpful in keeping our Microsoft products up to date every month without fail. We also have a Microsoft Enterprise Agreement which we renewed for three years ending 2022. The remote access utility works wonders for the organisation and have saved travel bills including subsistance allowance. We have been able to fulfill security audits both internal and external. We have been able to keep a robust inventory of our computer assets and nothing falls of the cracks
Overall, Microsoft Intune is very usable. While help documentation can be lacking, once setup and configured, Intune does all the work that used to be manual. There is a lot of automation and advanced features and manufacturer integrations you don't get anywhere else. These are absolutely game changers when managing IT workloads.
It's a 'heavy' system, which demands a lot of resources form the datacenter perspective. So, make sure you followed the requirements to avoid frustration in the future. From the 'client' perspective, it's fine. I've never had any issue with that.
I've been an engineer and architect in the Identity space for many years and CyberArk is the #1 tool I've found to help me secure accounts and credentials. I've architected CyberArk and built the implementation from the ground up twice in previous roles and found it here upon my arrival at my current job. I wouldn't want to have to live without it as it helps me sleep at night
Being a Microsoft product, support was good. Out interaction was limited to our in-house IT team which was installing the Intune app in our mobile device. The installation was smooth and we haven't faced any difficulties with the app while using it. Provides a smooth and secure access to all Office 365 apps in mobile while separating the personal and professional data.
Work with a "test group" of users who you have a good relationship with so that when things don't work properly they understand! Work with your partner nicely without forcing things especially timelines as you are bound to make mistakes and create oversights in the project Management can also interfere with the implementation (which can cause delays) if you make too many mistakes which takes me back to having a "test group" where you have good relations
Manage Engine's Password Management solution can accomplish the same features however, their system is cumbersome and not as user friendly to operate. It is however great for small teams. Pleasant Solutions Password Manager Pro can accomplish some of the same things, but the web browser interface is not user friendly at all
Microsoft Intune is more robust as far as fine-tuning security controls. It also allows for software installs, folder access controls, updating PCs, and other features simply not found in previous products we have used. Because it is rolled into MS 365 it's very cost effective. It's also a single pane of glass for managing user PCs and personal devices
A positive impact is passing SOX audits when it comes to privileged account management. Making sure we are compliant with password expiration policies and complexities.
The positive impact it's had was it has been really beneficial in having an all-in-one Systems Management solution to be able to manage all endpoints across the organization. This has saved both time and costs from having to search/setup/manage other System Management applications and also have saved money from having to purchase a license for other commercial products.
Another positive impact it has had was in being able to easily remote into computers/endpoints, and also being able to provide remote assistance to end-users.
The negative impact has been it is not being fully utilized by most of the IT staff, as it is a more complicated platform to learn/master. This would require funding for IT staff to take training in learning the product, or require time to consult the documentation in the use of the product. As a result, this may hurt productivity in being able to have to work on other things.