TrustRadius: an HG Insights company

F5 BIG-IP Access Policy Manager (APM) Reviews & Insights

Score8.9 out of 10

23 Reviews and Ratings

Top industries

Based on 219 HG Insights installations.

Powered by

Community Insights for F5 BIG-IP Access Policy Manager (APM)

Synthesised from 8 verified reviews.


Synthesised from 8 reviews | Last Published May 27, 2026


F5 BIG-IP Access Policy Manager (APM) is deployed by organizations primarily to secure access to applications, particularly those exposed to the internet, and to enable secure remote work environments, including virtual desktop infrastructure. In TrustRadius reviews, it is frequently highlighted for its robust policy management, often facilitated by its Visual Policy Editor, and its strong support for diverse authentication methods, including MFA, SAML, and OIDC, allowing integration with various identity providers for seamless access.

Reviewers consistently report that APM serves as an effective central solution for Multi-Factor Authentication and Single Sign-On, contributing positively to security posture and user experience. However, some reviewers note challenges with the user interface and configuration management, particularly for replicating settings and reusing policy objects. Advanced configurations for OAuth and API protection are also cited as areas needing refinement. Despite these points, the overall sentiment indicates APM is a powerful and manageable solution for access control.


  • Robust policy management via Visual Policy Editor (VPE)
  • Strong support for diverse authentication methods (MFA, PKI, RSA, LDAP, SAML, OIDC, OAuth)
  • Seamless integration with various identity providers
  • High degree of customization and granular access control
  • Effective central solution for Multi-Factor Authentication (MFA) and Single Sign-On (SSO)
  • Challenges with user interface and configuration management
  • Difficulties in replicating configurations and reusing policy objects
  • Advanced configuration for OAuth and API protection could be more robust
  • Specific security feature concerns, such as JWT token processing
  • Lack of integrated zero-trust VPN for outbound connection scrutiny
What positive or negative impact (i.e. Return on Investment or ROI) has F5 BIG-IP Access Policy Manager (APM) had on your overall business objectives?

From 8 reviews | Last Published May 27, 2026

F5 BIG-IP Access Policy Manager (APM) demonstrates a positive impact on business objectives, primarily by serving as a central and effective solution for Multi-Factor Authentication (MFA) and Single Sign-On (SSO). This capability was highlighted by four of eight reviewers, who noted its significant role in enhancing security and streamlining access management. The system's robust support for MFA has positioned it as a trusted "landing spot" for authentication in several environments, contributing to a stronger security posture. Furthermore, its SSO functionality is valued for improving user experience for various stakeholders, including students and staff, by simplifying login processes. The ability of APM to integrate diverse identity provider components further reinforces its utility, suggesting a positive return on investment through consolidated security infrastructure, reduced administrative complexity, and increased user productivity. These features collectively contribute to operational efficiency and bolster trust in the overall access management framework.

MFA and SSO support

Positive is that due to how much F5 BIG-IP Access Policy Manager can do, the F5 is the landing spot in our environment for MFA authentication.

Besides F5 BIG-IP Access Policy Manager (APM), what other software do you regularly use? How likely would you be to recommend it to a friend or colleague?

From 8 reviews | Last Published May 27, 2026

Reviewers frequently integrate other software solutions alongside F5 BIG-IP Access Policy Manager (APM) within their operational environments. A notable finding is that 4 of 8 reviewers explicitly mention using F5 BIG-IP Local Traffic Manager (LTM) in conjunction with APM, suggesting a common and complementary pairing within the F5 ecosystem. This indicates that LTM is often considered an essential component for managing local traffic when APM is deployed. Additionally, 4 of 8 reviewers also cited a diverse array of other third-party software, spanning various functional areas. These external tools include solutions for network performance monitoring, software development, contract management, and cloud infrastructure, illustrating the broad technological landscape in which F5 BIG-IP APM operates. The integration of these varied systems underscores the need for robust interoperability and highlights the complex IT environments managed by these users.

F5 BIG-IP LTM

F5 BIG-IP Local Traffic Manager (LTM)

Other Software Usage

NetBrain Technologies, ScienceLogic SL1, Splunk Enterprise

Describe how you use F5 BIG-IP Access Policy Manager (APM) in your organization. What are the business problems the product addresses and what is the scope of your use case?

From 8 reviews | Last Published May 27, 2026

F5 BIG-IP Access Policy Manager (APM) is primarily utilized by organizations to establish secure access to applications and to implement robust authentication mechanisms. A significant portion of reviewers, 50% (4 of 8), highlighted its role in protecting applications, particularly when exposed to the internet or for enabling remote work scenarios. The platform facilitated secure transitions to work-from-home environments for IT workforces and provided secure access to internal virtual desktop infrastructure. Beyond secure connectivity, 38% of reviewers (3 of 8) emphasized APM's capabilities in authentication, including meeting multi-factor authentication (MFA) requirements and integrating with various identity providers. This includes support for PKI certificates, RSA, LDAP, and single sign-on (SSO) solutions like SAML and OIDC, addressing the challenge of seamless access across numerous internal and third-party applications for large user bases.

Secure Application Access

Protecting applications before exposing them to the Internet.

Authentication and MFA

We utilize this mainly to meet MFA requirements. Displaying DoD Access Warning banners, utilize the F5 BIG-IP Access Policy Manager ability to work with PKI certs, RSA, and authenticate with LDAP to authenticate the user prior to load balancing them.

Please provide some detailed examples of areas where F5 BIG-IP Access Policy Manager (APM) has room for improvement.

From 8 reviews | Last Published May 27, 2026

Reviewers identified several areas where F5 BIG-IP Access Policy Manager (APM) could be enhanced, primarily focusing on user experience, advanced configurations, and specific security functionalities. Half of the reviewers (4 of 8) pointed to challenges with the user interface and configuration management processes. This includes the UI being cumbersome and difficulties in replicating configurations and reusing policy objects. Beyond general usability, three reviewers noted that advanced configuration options, particularly for OAuth and API protection, could be more robust and user-friendly. Specific concerns included the need for better API protection and improved training materials. Additionally, two reviewers raised issues with certain security features, such as JWT token processing, and suggested the integration of a zero-trust VPN to enhance outbound connection scrutiny. These observations collectively suggest opportunities for F5 BIG-IP APM to refine its interface, streamline complex setups, and bolster specific security mechanisms.

UI and Configuration Management

UI is cumbersome.

Advanced Configuration Options

There's some more advanced configurations within OAuth that I think could be fleshed out and easier to approach.

Security Features

JWT tokens process DIES.

Please provide some detailed examples of things that F5 BIG-IP Access Policy Manager (APM) does particularly well.

From 8 reviews | Last Published May 27, 2026

F5 BIG-IP Access Policy Manager (APM) is primarily recognized by reviewers for its robust capabilities in policy management and authentication. A majority of reviewers, 5 out of 8, highlighted the ease and clarity of its policy editor and configuration processes. This is often attributed to the Visual Policy Editor (VPE), which streamlines the approach to building and modifying policies. Beyond policy creation, the platform's strong support for various authentication methods and federation features also received significant positive attention, with half of the reviewers (4 out of 8) specifically noting its utility in integrating diverse authentication systems, including modern standards like OAuth and SAML. Furthermore, 3 out of 8 reviewers appreciated the product's high degree of customization and flexibility, allowing for granular control over access policies. These aspects collectively suggest that APM excels in providing a powerful yet manageable solution for access control.

Policy Editor and Configuration

VPE editor makes for a clean thought out approach to building the policy.

Authentication and Federation

Using OAuth with a COTS app that does not support it.

Customization and Flexibility

Insanely customizable

Loading Reviews List....