Aswin  K.
AK
Full-Stack Developer Intern
Computer Software
Small-Business (50 or fewer emp.)
"Unified Machine Identity Security That Eliminates Certificate Expiry Outages"
5/5
What do you like best about Idira Identity Security Platform?

Managing machine identities at scale is one of those problems that sneaks up on you, certificates expiring unexpectedly, SSH keys sprawling across environments with no visibility, secrets hardcoded in places they shouldn't be. CyberArk Machine Identity Security tackles all of that from a single platform, and that consolidation alone is worth a lot.

Certificate lifecycle management is where it immediately earns its place. The automated discovery, renewal, and revocation workflows mean we're no longer scrambling when a cert is about to expire or worse, finding out it already did. The visibility across our entire certificate inventory, including ones we didn't even know existed, was genuinely eye-opening in the first few weeks of deployment. Outages caused by expired certificates have effectively dropped to zero since we rolled this out.

Secrets management is equally strong. Having a centralised, auditable vault for credentials, API keys, and tokens, with fine-grained access controls and rotation policies, replaced a genuinely chaotic mix of environment variables and scattered config files. Development teams initially pushed back on the workflow change, but once it was integrated into the CI/CD pipeline it became invisible and non-disruptive.

SSH key management cleaned up years of key sprawl across our Linux estate. Knowing exactly which keys exist, who they belong to, what they can access, and being able to revoke them instantly is a security posture improvement that's hard to overstate, especially for compliance purposes.

Workload and cloud identity support has kept pace with our hybrid infrastructure reasonably well. Dynamic secrets for cloud workloads, Kubernetes integration, and support for major cloud providers means the platform stretches across on-prem and cloud without requiring entirely separate tooling for each environment. Review collected by and hosted on G2.com.

What do you dislike about Idira Identity Security Platform?

The implementation complexity is real and should not be underestimated. Initial deployment, especially across a heterogeneous environment, requires significant planning, professional services involvement, and internal expertise. This is not a product you spin up in an afternoon, budget time and resources accordingly or the rollout will drag.

The admin interface, while functional, feels dated compared to more modern security tooling. Navigating between certificate management, secrets, and SSH key workflows involves more context-switching between different console areas than feels necessary, and the UX hasn't kept up with the product's expanding capabilities.

Pricing is enterprise-tier and reflects that positioning, smaller organisations or teams without a dedicated secrets management budget will feel the cost acutely. Licensing can also get complex depending on which modules you're combining.

Reporting and analytics could be deeper. For audit and compliance purposes the basics are covered, but building custom reports or getting granular operational insights requires more manual effort than it should. Review collected by and hosted on G2.com.

See what 244 reviewers think of Idira Identity Security Platform

4.5 out of 5 · Verified reviews from real users

Read all reviews