Overview
CyberArk Workforce Identity is a SaaS-delivered solution designed to simplify identity and access management in enterprises. CyberArk Identity unifies Workforce and B2B Access and Identity Management solutions in a single offering. CyberArk Workforce & B2B Access solutions ensure that the right users have secure access to the right resources at the right times.
Organizations can use CyberArk Workforce solution to authenticate, authorize, and audit access to applications and IT systems, including AWS IAM and AWS SSO, with a security-first mindset. Strengthen security and reduce risk by protecting workforce and customer credentials and tightly controlling access to on-premises and cloud-based applications, services, and IT infrastructure.
CyberArk Workforce Identity solution include:
-CyberArk Single Sign-On: Enables one-click secure access to all the applications and resources including AWS IAM and AWS SSO -CyberArk Adaptive Multi-Factor Authentication: Enable a passwordless user experience with a comprehensive range of user-friendly, context and risk aware authetication methods. -CyberArk Secure Web Sessions: Protect identities beyond the login and gain visibility into every action users take within web applications. -CyberArk Workforce Password Management: Securely store, manage and share business application credentials. -CyberArk B2B Identity: Extends secure and seamless access for your business partners, vendors, and clients. -CyberArk Identity Lifecycle Management and compliance: Streamline identity lifecycle events, orchestrate identity workflows, and automate access reviews and compliance requierments.
For custom orders please contact AWS-Marketplace@cyberark.comÂ
Latest Release notes: https://docs.cyberark.com/identity/latest/en/content/releasenotes/ReleaseNotes-Latest.htmÂ
Highlights
- Identity Security Platform: CyberArk Workforce Identity includes deep integrations with CyberArk PAM, thousands of pre-integrated applications, and comprehensive support for MFA mechanisms, including the newest passwordless factors and technologies.
- Architected for the modern enterprise: Leverages scalable CyberArk Identity Cloud Directory to unify user management across the enterprise, reduce identity silos, and simplify migration to the cloud.
- With Identity Flows and Compliance eliminate manual tasks and processes by automating complex identity management workflows. Ensure all access rights are properly assigned and continually certified across the extended enterprise.
Unlock automation with AI agent solutions

Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
---|---|---|
Workforce Identity Std. | Workforce Identity users - 100 users | $12,528.00 |
Workforce Password Mgmt | Workforce Password Mgmt - 200 users | $14,400.00 |
Vendor refund policy
For refund policy, visit <www.cyberark.com/terms-service-saas/Â >
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Ensuring your CyberArk Workforce Identity is up to date and running efficiently is a priority. If you encounter a technical problem, contact CyberArk support 24x7, using our ticketing system at https://cyberark-customers.force.com - Phone and email support are also available. Further details are available at <www.cyberark.com/customer-support/#contact-supportContact >
For support related questions: <www.cyberark.com/customer-support/Â >
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
UI simplification and robust support enhance user provisioning and authentication efficiency
What is our primary use case?
We are using CyberArk Identity for user provisioning, and we have integrated multiple applications, most of them being SAML-based authentication ones.Â
We are also provisioning users to target applications and using CyberArk Identity as an authentication method for two-factor authentication.
I have worked on multiple projects where we have integrated external IdPs with CyberArk Identity. We have also implemented AD integration to get users from Active Directory to CyberArk Identity. We are using the reporting functionality and role-based access control.Â
We have created several roles for one client where I was working. It was an all-suite ISPS model that CyberArk has where CyberArk Identity, Privileged Cloud, and all those applications were present. In this case, we were using roles from CyberArk Identity to grant users access to their respective safes in the Privileged Cloud.
What is most valuable?
The UI is very simplified, and the documentation of CyberArk Identity is very crisp and clear. The support of CyberArk Identity is also really good.Â
From the support perspective, there is an excellent feature for identity verification.Â
When someone calls with identity issues, CyberArk Identity has provided one of the best features where we can use MFA verification. It sends a code to the user and validates the caller.
CyberArk Identity can be integrated with applications such as Secure Hub, Secrets Hub, Conjur, and Privileged Cloud. However, getting usage reports for specific applications is difficult. Tracking user activity across different integrated applications is challenging as the logs don't provide detailed information about which application users accessed.
What needs improvement?
The reporting functionality is somewhat complicated. While I would rate CyberArk Identity and Okta on the same level, Okta's reporting is crisper and clearer. For CyberArk Identity, you need knowledge of their scripting language to pull different sets of reports.Â
Though the out-of-the-box reports are good, they should simplify the reporting process to make it easier to pull all reports. The documentation for the reporting functionality is not very clear, which creates conflicts.Â
Additionally, CyberArk Identity needs to enhance features such as import scheduling and document clarity for new aspects such as Flows.
For how long have I used the solution?
I have been using CyberArk Identity in my career for almost four years.
What do I think about the stability of the solution?
As part of maintenance, we haven't faced any downtime with CyberArk Identity. If there are any outages, CyberArk is responsible, and they usually address them very quickly. The services were operational 24/7.Â
Previously, we faced some issues where when users were provisioned and we tried to delete them, the entry was deleted from the back end, however, a ghost entry still existed in CyberArk Identity. We did not have an option to delete that particular user, which caused issues when trying to provision the same user again from AD.
How are customer service and support?
The quality of support is really good. They respond immediately when requests are raised, and they are always available for priority one tickets. The only requirement is having access to their community portal to raise cases. The support is comparable to other SaaS products such as Okta.
How would you rate customer service and support?
How was the initial setup?
The initial deployment was straightforward. CyberArk provides the tenant, and the documentation for integrating with Active Directory is clear. You need to build the server and set up the agent. The AD integration itself takes about ten minutes, but the complete process, including server build and approvals, takes a couple of days. If all resources are ready, the actual integration is very straightforward and takes only five to ten minutes.
What about the implementation team?
We are partners providing services to other clients. I am an implementation engineer responsible for designing, architecting, and deploying solutions for clients.
What's my experience with pricing, setup cost, and licensing?
I am not certain about CyberArk Identity's exact pricing model. For comparison, Okta was around five dollars per user. CyberArk Identity offers good discounts to some clients, which influences their decision to choose the solution.
Which other solutions did I evaluate?
Okta is a more mature product compared to CyberArk Identity. Policies and customization are easier with Okta. Integration with different applications through the Okta Integration Network is straightforward, with clear guides and steps. CyberArk Identity could improve in these areas. The main difference is in the UI and some features.Â
The reporting functionality in Okta is superior. In Okta, you can control imports and manually import users from AD, applications, or CSV files. These options and the ability to schedule periodic imports are not available in CyberArk Identity.
What other advice do I have?
Comparing CyberArk Identity with products such as Ping, Okta, and RSA, CyberArk Identity still needs product development, as Okta offers additional features. Some features of CyberArk Identity are excellent, however, Okta is more user-friendly. The reporting functionality and Flows are areas for improvement. Since Flows is a new product, it needs to mature. They should conduct training, educate people, and provide clear documentation for better utilization.
In the Identity user portal, you can create secure notes, upload passwords or keys, and create bookmark applications. We have encountered some glitches when sharing applications with others, where users face issues despite having correct permissions.
I rate CyberArk Identity eight out of ten.
Gaining access and provisioning on-demand has become intuitive and efficient
What is our primary use case?
My use case for CyberArk Identity involves multiple reasons: for identity to gain access to the clients' environments, to provision on-demand access, and to provide services via the Access Manager.
What is most valuable?
I find the CyberArk Identity portal quite intuitive; it has changed a lot over the last year and a half.Â
If you think logically and understand your environment, it is easy to establish a suitable setup for yourself and all your vendors. I did see an impact on operational efficiency with CyberArk Identity.Â
If you look at all the technical requirements to set up a VPN or an access management tool, where you need to integrate four, five, or six different services with the CyberArk side, it is significantly easier. You provision a server on the inside and simply assign the services allowed from the outside by ticking a box to grant access. The person can then either scan a QR code or receive an email to log in.
CyberArk Identity has indeed helped reduce the mean time to detect; it has also aided in troubleshooting by allowing logs to be extracted and sent to a correlation engine, such as QRadar, for notifications or alerts. It also helps in preventing attacks, as someone trying multiple times to log in, and the trigger on whatever login is used aids in maintaining a quick view of what is happening.
What needs improvement?
Room for improvement for CyberArk Identity might be on the support side, as they constantly improve with new features and remove redundant ones, integrating multiple steps into a single one for easier use; however, this is not just CyberArk Identity, as many vendors start with basic troubleshooting services without recognizing that knowledgeable users often reach out after exhausting those options.
For how long have I used the solution?
I have been working with CyberArk Identity for coming on four years now.
What do I think about the stability of the solution?
The solution's stability depends on your connectivity most of the time, so if you've got a bad network, it will not be stable, but with a stable network, due to the redundant data centers across the globe, it is a lot easier to use as a SaaS solution.
What do I think about the scalability of the solution?
CyberArk Identity is definitely a scalable solution; it all depends on the money that you have, as with anything else.
How are customer service and support?
I would rate technical support from CyberArk a nine out of ten; there's always space for improvement.
How would you rate customer service and support?
How was the initial setup?
After implementing CyberArk Identity, in a big implementation, it took about four months for my organization to see time to value, while in a smaller implementation, it was a month.
What's my experience with pricing, setup cost, and licensing?
My experience with the pricing of CyberArk Identity has been good, as we've got a good relationship with the team, whether in South Africa, where I am or globally; we maintain a strong relationship and have been competitive against any other identity solutions.
What other advice do I have?
My experience of working with CyberArk solutions is quite extensive. With CyberArk tools, I have experience working with Privileged Access, Identity Access, and Secrets Manager, although with Secrets Manager not as much, but the other two quite extensively.
My relationship with CyberArk is as a partner. I purchased CyberArk Identity through both the vendor and AWS Marketplace , as it depends on what the client wants: through the vendor for purely bespoke installation or architecture and AWS for ease of use.
I would rate CyberArk Identity a nine out of ten overall.Â
I understand that different people have different requirements, which might mean they don't experience it the same way as I do.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Best Solution to increasing workflow security
What is our primary use case?
Essentially, our use case for CyberArk Identity  involves automating customer interactions and engagement, as well as onboarding new clients.
Being in retail and marketing, CyberArk Identity has made it easier to onboard new customers online, making the process much faster and efficient.
Interaction with customers has improved greatly through CyberArk Identity software through automation of most of our processes, thus freeing our time to concentrate on other key strategic activities of the company.Â
How has it helped my organization?
Cyber Identity has improved our workflow processes and seamlessly enhanced our client engagement, as well as streamlining our operations and interdepartmental collaboration. Tasks we used to perform manually are now automated, thus increasing efficiency and productivity.
Additionally, we no longer have any fear of our data being infiltrated by an unauthorised person because of the security features it comes with. Tracking processes, workflows and audit trails works perfectly well.
It has a user friendly interface and dashboard.
What is most valuable?
The best feature of CyberArk Identity is the single sign-on (SSO ) feature that offers quick and one-click access.
The second feature that I enjoy so much is the endpoint privilege security, which safeguards our sensitive information and protects against security threats.
One benefit of the software is the enhanced security. It provides strong authentication, improving our operations and access controls. Additionally, it streamlines operational processes, reducing the administrative burden on our IT experts and security teams.
The value of the software was immediate, especially for the onboarding of clients.
What needs improvement?
One area for improvement is the complexity of learning how to use the software for new users. It requires training.
For how long have I used the solution?
I have been using CyberArk Identity for two years.
What do I think about the stability of the solution?
Very stable.  Our data is safe with CyberArk Identity.
What do I think about the scalability of the solution?
Very positive and promising. I give it a nine.
How are customer service and support?
Satisfactory and knowledgeable.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have not used many other solutions to compare it to.
How was the initial setup?
Straightforward.
We spent 2-3 weeks deploying.
What about the implementation team?
Vendor.
High.
What was our ROI?
We have saved over 50% of our time to concentrate on other strategic activities since we deployed CyberArk Identity.
What's my experience with pricing, setup cost, and licensing?
The pricing for the solution is fair.
Which other solutions did I evaluate?
No
What other advice do I have?
I would highly recommend this product without hesitation due to its numerous advantages, features, and benefits, such as unified access management and high-level security.
I am a user. I am available for reference anytime.
On a scale of 1 to 10, I give CyberArk Identity 9.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Eases regulatory compliance and streamlines administrative tasks with efficient identity and password management in sensitive sectors
What is our primary use case?
CyberArk Identity is mainly used for accessing servers, partition management, and rotating passwords, especially in sensitive sectors such as banking and to protect patient data. It's crucial for complying with regulations and ensuring that administrative tasks such as encryption key management are streamlined.
What is most valuable?
CyberArk Identity provides an easy identity portal, single console, log capture for GRC compliance, and efficiently rotates passwords unknown to users, enhancing security. These features aid in reducing the attack surface by blocking unauthorized access and preventing exposure of internal solutions in sectors such as banking.
What needs improvement?
Some areas experience slowness based on the workload. There's a need to enhance network performance despite the good user experience with access management.
For how long have I used the solution?
We have been working with CyberArk Identity for more than five years. Previously, I worked with other PAM management tools. Currently, most customers are choosing it as a premier product, which is why we are focusing more on CyberArk Identity.
How are customer service and support?
They charge reasonable money for the features they provide. The price is reasonable for the product.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
While Arkon PAM is a competitor, that product is not as good nowadays. CyberArk Identity is at the top. When it comes to premium products, CyberArk Identity stands alone.
How was the initial setup?
The setup process for CyberArk Identity is singular, but it differs for all customers. Customers provide the data for implementation, based on which we receive payment. From a product perspective, it's easy, but we need to gather customer data and implement according to their requirements.
Which other solutions did I evaluate?
Other vendors include CrowdStrike and SentinelOne.
What other advice do I have?
Customers in the banking sector don't expose what solutions they have inside their systems for security reasons. My overall rating for CyberArk Identity is nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Enables efficient management of privileged access, though deployment has been complex
What is our primary use case?
If I have a core banking application platform with users or privileged users accessing that particular environment, I have to ensure that the right people are accessing what they're supposed to access. I need to have proper monitoring on them, ensuring that privileged accounts are not being shared and that generic accounts are not in use. For instance, if someone accesses the core banking application and performs changes or transactions, this solution enables me to track who did what in that session and even monitor or replay the session of that person's actions.
How has it helped my organization?
CyberArk provides identity governance. It gives you control of who, how, and what is accessing your environments. It provides simplicity for privileged users to access the environment.Â
What is most valuable?
When using IAM and PAM, CyberArk Identity is the best choice. If it is just one model, for IAM , I prefer others like One Identity. For PAM, CyberArk Identity is the best.Â
Furthermore, CyberArk Identity provides identity governance and gives me control over who and how access to environments occurs, offering significant confidentiality in what is accessed.Â
Initially, people find it challenging to adjust to these changes, however, over time, it becomes time-saving as there's no need to access each device individually. Instead, there is a single pane of glass or platform that administrators can log into to manage environments efficiently.
The partner portals are and support portals are very good.Â
CyberArk Identity's ability to safeguard financial services infrastructure is good. If you have your core banking application transformed, and have privileged users accessing the environment, you can control who and what is accessing where and generic accounts cannot be used. If some accesses core banking functionality, you will be able to track what a person is doing.
Its ability to help meet compliance requirements is good. It covers ISO standards. We easily integrate password policies. It helps us protect access within an organization.Â
It's helped us to comply with PCI DSS.
There are a lot of time savings. There's a single pane of glass to log into to access the environment. We don't have to go through individually.
We've reduced risk exposure. Instead of logging into different platforms, you just log in to one single platform. You have your resources being allocated to you. In this way, it also identifies you, with a single sign on privileges. It gives you protection in terms of not using generic accounts or administrative accounts that everybody uses. All credentials are saved in a particular system known as a vault, and only a particular port and a particular IP address can access the vault. Now, there is one way in or one way out. It doesn't create any vulnerabilities whereby people or unknown entities can enter easily.
It impacts zero trust security strategies. It prevents lateral movements in the organization. You cannot be gaining access to a privileged account.Â
The solution helps with operational efficiency as it provides a very secure mode of access.
What needs improvement?
Integration or deployment is extremely difficult for CyberArk Identity. For example, vault integration and deployments are very tedious and involve components like HSMs, requiring extensive skill sets and knowledge. This complexity is especially true when integrating into various environments, service applications, and session monitoring setups. It is very demanding.
For how long have I used the solution?
I've deployed two solutions so far. I've worked with the solution for about three years, since 2021. IÂ haven't worked with the projects this year. I've done some POCs.
What do I think about the stability of the solution?
With respect to stability, I find that stability is very good. It is very stable.
What do I think about the scalability of the solution?
The solution is very scalable.
Which solution did I use previously and why did I switch?
I'm also aware of One Identity.
How was the initial setup?
The initial setup was complex. It was very complex when it was my first time handling an implementation.
What about the implementation team?
We were the partner deploying for a customer.
What's my experience with pricing, setup cost, and licensing?
CyberArk Identity is slightly expensive compared to others. That said, it offers value for money. It comes with additional resources that I need to spin up on-premises. So, if I am not going fully cloud, there are additional resources I will need to purchase, such as spinning more VMs or acquiring an HSM device to encrypt the vault.
What other advice do I have?
I would probably give the solution a seven out of ten.Â
It offers the best PAM solution you can get compared to others, compared to One Identity.
Deployment is complex. If you are deploying CyberArk Identity, you should have the skill sets, knowledge, and resources to manage it. It is not easy to manage or deploy CyberArk Identity.Â