Overview
CyberArk Privileged Access Management solutions provide end-to-end security for internal IT admins & 3rd party vendors enabling secure high-risk access used to migrate, scale and operate applications on-premises or in the cloud. CyberArk allows IT teams to implement role-specific least privilege, and workflows for both secure standing access and Just-in-Time access with Zero Standing Privileges.
CyberArk PAM solutions holistically secure both standing and just-in-time privileged access across the IT estate. With industry-leading capabilities for credential management, session isolation and monitoring, and detection of privileged access misuse, organizations can leverage CyberArk PAM to rapidly achieve their risk reduction, audit and compliance objectives.
Vendor PAM capabilities help organizations defend against attacks targeting external vendors, contractors and other third parties with high-risk access to critical IT and OT assets. The authentication and provisioning processes are enabled by the biometric capabilities of the users smartphone. Vendor PAM integrates with CyberArk PAM solutions to allow passwordless, Just-in-Time access to accounts managed by CyberArk, eliminating the cost and operational overhead of deploying VPNs, agents, and dedicated laptops to vendors.
For custom pricing, EULA, or a private contract, please contact AWS-Marketplace@cyberark.com , for a private offer.
Highlights
- Protect against the leading cause of breaches - compromised identities and credentials.
- Deliver digital experiences that balance security and a frictionless experience.
- A unified solution to address identity-oriented audit and compliance requirements.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
AWS_25_PRIV_STDANDARD_USER_SAAS | Standard Privilege Cloud users - 25 users | $44,712.00 |
Vendor refund policy
For refund policy, visit <www.cyberark.com/terms-service-saas/ >
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Contact CyberArk for support related questions: <www.cyberark.com/customer-support >
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Centralized access has improved privileged control and visibility yet still needs better integrations
What is our primary use case?
My main use case for Idira Privileged Access Manager is securing and controlling privileged access to critical servers and infrastructure. We use many servers, such as virtual machines for our institution to run software development. One specific use case I can share is how we manage these resources effectively.
Additionally, we have to maintain our Linux servers, which sometimes requires hiring third-party or outsourced people to access them. Idira Privileged Access Manager helped us by providing a more controlled way to handle elevated SSH access without relying on shared or permanently active privileged credentials. The session visibility and audit trail are particularly useful when multiple engineers work on the same production environment. This is another use case of our administrative activity linked to specific users and maintenance tasks.
How has it helped my organization?
The biggest change has been improved control and accountability. We have gained more visibility into who accesses servers with elevated privileges and why. Before using Idira Privileged Access Manager, we relied on system logs, which often did not tag users unless configured properly. It has reduced our dependence on shared or permanently active admin credentials while making access views and troubleshooting easier. This has helped us establish a more consistent and auditable process for managing privileged access.
I recently encountered an incident that highlights our improvements since implementing Idira Privileged Access Manager. Two weeks ago, one of our production Ubuntu servers showed unexpected changes to its Nginx configuration after a scheduled task. We used Idira Privileged Access Manager to review the privileged SSH session and identify which administrator accessed the server and the commands they executed during that session. This allowed us to correlate the activity with the configuration change, revert the incorrect settings, and restore the service. The session audit gave us much more detail than relying on standard Linux logs, which are generic.
What is most valuable?
I think the best features Idira Privileged Access Manager offers include centralized privileged access management. If I rank these features, I would give access control the best feature rating for me, as the ability to control hybrid access without relying on permanently active users or shared credentials is particularly valuable in reducing the risk of data breaches. The session visibility is also useful for troubleshooting because we can see who accessed the server and what administrative activity was performed. In my opinion, the centralized approach makes it easier for operations and security teams, allowing them to do their job without needing deep technical knowledge.
The strongest feature for us is access control in Idira Privileged Access Manager. I have noticed that giving people administrative access to our servers improves management, especially when providing temporary credentials for policy access. This makes it easier to manage privileged access among team members, and we can simply revoke the authentication license after they finish their work.
I can recall details about the features, particularly the granularity of access in Idira Privileged Access Manager, which allows us to define access based on specific servers or resources rather than providing broad pseudo access. That is quite practical, as I do not have to give my team members full administrative access to a specific server; I can grant them limited access to only what they need, so they can perform their tasks without interrupting the operations of other resources.
What needs improvement?
While the access control capabilities are useful, streamlining some configuration and policy management workflows could enhance the user experience for administrators. A simpler interface for creating access policies and quickly identifying unusual activities would make day-to-day administration more efficient.
Stronger integration with existing identity data and secret management could be a significant improvement for Idira Privileged Access Manager. Deeper integration with cloud solutions would make it easier to correlate privileged access activity with other security events. I would also appreciate more flexible reporting and dashboards so administrators can swiftly see access patterns and unusual privileged access from a single view.
For how long have I used the solution?
I have been using Idira Privileged Access Manager for approximately six to twelve months.
What do I think about the stability of the solution?
In my experience, Idira Privileged Access Manager is stable for daily Linux server access. Aside from minor issues, we have not faced significant or prolonged downtime. While we encountered operational issues during configuration or access policy changes, they were generally not noticeable and did not majorly impact our operations. The platform has been reliable and improved privileged access and administrative workflows in our environment.
What do I think about the scalability of the solution?
In terms of scalability, Idira Privileged Access Manager handles growth in users and infrastructure reasonably well. Adding new users or servers is fairly straightforward as privileged access can be managed centrally through policies instead of configuring each system individually. We have not faced major scalability issues in our current deployment, but for larger deployments, we would evaluate capacity planning and integration requirements.
How are customer service and support?
I had a generally positive experience with Idira Privileged Access Manager's customer support. I reached out a couple of times, and the support team was responsive and helpful. Our initial inquiries involved configuration and troubleshooting questions about access control, as specific answers were not found in documentation. While some complex issues required additional communication, overall, the support met our day-to-day needs effectively.
Which solution did I use previously and why did I switch?
We previously used a different solution before Idira Privileged Access Manager, but it was not enterprise-grade; we relied on native SSH access. As developers and engineers, we understood SSH well and managed tasks manually. However, we switched to Idira Privileged Access Manager because not all team members were tech-oriented. While the previous approach worked for basic administration, it offered limited centralized access and made it harder to maintain consistent audit trails.
How was the initial setup?
The initial setup required careful planning around our Oracle Linux infrastructure, privileged accounts, and access points, with licensing evaluated based on the number of users and systems needing privileged access.
What was our ROI?
We are starting to see a return on investment with Idira Privileged Access Manager. As it has been eight months since implementation, we estimate that access administration and troubleshooting take roughly fifteen to twenty percent less time. Centralized access and the audit trail make it easier to identify who performed administrative actions, allowing us to reduce headcount while saving time to allow our IT and security operational teams to focus on other tasks.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable compared to other software options we evaluated, and it is straightforward. However, overall costs depend on deployment size and licensing requirements.
Which other solutions did I evaluate?
Before choosing Idira Privileged Access Manager, I evaluated other options such as BeyondTrust and Dalina. We compared them mainly based on access control capabilities, Linux support, deployment requirements, overall cost, and licensing. Ultimately, we selected Idira Privileged Access Manager because it fits our existing environment and requirements effectively.
What other advice do I have?
My advice for others considering Idira Privileged Access Manager would be to start with clearly defined privileged access, such as controlling access to Linux production servers, and then expand from there. Before deployment, it is vital to map out existing privileged accounts, policies, and audit requirements to understand your system, which will facilitate implementation. Integrating with your identity provider and SIEM early is crucial as it can significantly impact overall deployment. I suggest piloting the access workflows with a small group of users before fully rolling them out in a production environment.
One additional thought is that Idira Privileged Access Manager has become a crucial part of our daily Linux administration and security work. The implementation of session visibility and auditing provides better accountability without introducing excessive complexity for administration. I hope to see further improvements in integrations and reporting, and while the AI implementation is good, it needs additional work. Overall, it delivers a practical foundation for managing privileged access in our operations, which aligns with our goals. I would rate this solution seven out of ten.
Versatile Across Systems, Secure, and Runs Smoothly
Secure, Flexible Access Control on Our Server
Intuitive Access Control with Responsive Support
Centralized privileged access has strengthened compliance and simplified secure admin sessions
What is our primary use case?
As an implementation engineer, I have extensive experience with CyberArk Privileged Access Manager and its implementation this year at our customer site. We have been acting as a resident engineer for one of our customers for the past six months.
CyberArk Privileged Access Manager provides a repository and management system for our administrators to have sessions on our systems. For example, we require any administration access to our firewalls to be conducted through the PAM solution first. CyberArk Privileged Access Manager allows our administrators to access the firewalls and record the sessions.
Another use case is user offboarding. If an employee like Muhammad leaves our company, we can simply delete this user from the entire organization. We also have excellent compliance capabilities to review what occurs during administration sessions because we have them already recorded.
What is most valuable?
CyberArk Privileged Access Manager is very good on stability as a PAM solution. You can consider that if you do not have a stable PAM solution and the PAM solution always has issues with many maintenance windows, your entire organization cannot access the systems. It is very critical to rely on a stable system as a PAM solution.
The most valuable features are integrations with ticketing systems, recording sessions, and running with compliance. We also have another feature from CyberArk Privileged Access Manager, especially SSH key lifecycle management, which performs excellently in this area.
CyberArk Privileged Access Manager does not interrupt the sessions or administration sessions. Our professional services team implemented it, and we deployed full PAM features and the complete CyberArk Privileged Access Manager product in just three weeks across our larger organization. I think this is a strong point for CyberArk Privileged Access Manager.
What needs improvement?
I believe account discovery and rolling support need to be improved. Account discovery is important when integrating with other systems, as other PAM solutions can perform account discovery and onboarding effectively. Because PAM projects usually fail when teams try to onboard everything manually, CyberArk Privileged Access Manager discovery workflows can reduce this issue. Therefore, I think this area needs improvement.
For how long have I used the solution?
We have recently relied on CyberArk Privileged Access Manager for only six months, so we have not tested the scalability yet.
What do I think about the stability of the solution?
We did not face any lagging or crashing during the past six months. The stability is very good, and I would rate it a ten.
What do I think about the scalability of the solution?
We have recently relied on CyberArk Privileged Access Manager for only six months, so we have not tested the scalability yet. However, I can say it appears to be good from my understanding.
How are customer service and support?
CyberArk customer support is professional. We contacted them on only one case and resolved it in time. Based on our experience, we resolved the issue in just five minutes. I can say the support team is very professional and very technical with strong technical capabilities.
What about the implementation team?
I have implemented Fortinet VM, which is Fortinet's new PAM solution, two weeks ago recently. I think Fortinet has strengths in some areas and CyberArk Privileged Access Manager succeeds in other areas. Overall, I think CyberArk Privileged Access Manager is very good and can be considered a market leader in this space.
What was our ROI?
The pricing compared to other solutions, particularly Fortinet, is favorable. Fortinet overall has excellent pricing. However, CyberArk Privileged Access Manager has good return on investment. The pricing is affordable compared to the features and the stability of the product.
What other advice do I have?
CyberArk Privileged Access Manager requires upgrading and maintenance. We have scheduled the upgrade, and we have detailed and informative documentation for upgrading. There is an integration matrix, or rather a compatibility matrix, between the newer versions of CyberArk Privileged Access Manager with other systems. Before upgrading, we study the compatibility matrix and the upgrade process is very smooth.
My overall rating for CyberArk Privileged Access Manager is ten.