Idira is an enterprise privileged access management platform from Palo Alto Networks (formerly CyberArk), covering human identity security, machine secrets management, and agentic identity controls with threat detection and identity governance.
Listing updated . Checked by MSP Software .
Idira is an enterprise privileged access management platform from Palo Alto Networks, built on the legacy of CyberArk and designed to secure human, machine and agentic identities across hybrid and cloud environments. It covers human identity security with privilege controls and governance, machine identity secrets management for CI/CD workflows and automated workloads, and agentic identity governance for AI agent access and control. The platform enforces least privilege access with continuous visibility, AI-driven risk analytics, identity threat detection and response capabilities, and automated session monitoring across all identity types. Idira addresses enterprise requirements for comprehensive privileged access governance, endpoint privilege management with application execution controls, identity governance from first access through session termination, and unified secrets vault management across infrastructure and workloads. The product integrates over 300 out-of-the-box connectors and supports native CI/CD pipeline integration for DevOps and infrastructure automation workflows. Deployment runs on cloud, on-premises, or hybrid infrastructure with web console access and platform agents on Windows and Linux endpoints. Idira is designed for larger organisations with 200 or more users, particularly those with complex hybrid infrastructure, high-security compliance requirements, significant machine identity and automation workloads, or regulated industries requiring comprehensive audit trails and compliance evidence. The product suits enterprises that already manage substantial privileged access complexity and have budget for enterprise licensing and ongoing professional services. Pricing is quote-only based on deployment scope, number of identities managed, and enterprise licensing agreements; organisations should request evaluation licenses directly from Palo Alto Networks to assess specific use cases.
Idira (formerly CyberArk) is the established enterprise PAM benchmark for large organisations with complex privilege governance needs, particularly those running hybrid cloud infrastructure or requiring AI and agentic identity security. It suits enterprises needing comprehensive human, machine and agentic identity control rather than mid-market MSPs or smaller deployments. Before evaluating, confirm your use case qualifies for enterprise PAM licensing and compare against Okta, BeyondTrust, or One Identity Safeguard in the same category. Pricing is quote-only with no published tiers; request an evaluation license to assess feature coverage and integration requirements with your specific infrastructure and DevOps platforms.
| Feature | Supported | Note |
|---|---|---|
| Multi-factor authentication | unknown | Traditional MFA not explicitly documented for Idira; focus is on risk-based conditional access and device trust |
| Single sign-on | unknown | SSO not explicitly mentioned; Idira documentation emphasises identity governance and access control |
| Conditional access and device trust | yes | Risk-driven conditional access decisions with AI-driven analytics and dynamic privilege controls |
| Privileged access management | yes | Core capability; privileged access management for humans, machines and AI agents with least privilege enforcement |
| Passwordless and passkey support | unknown | Not explicitly documented; Idira emphasises machine identity secrets and dynamic access over password models |
| Directory sync | unknown | Integration with identity systems implied through 300+ connectors but not explicitly stated |
| Session and risk monitoring | yes | Identity threat detection and response with continuous discovery and AI-driven threat monitoring |
| Legacy VPN and app support | unknown | Not explicitly documented in available materials |
| Self-service password reset | unknown | Not explicitly documented; enterprise focus is on centralised privilege control rather than user self-service |
| Breach monitoring | unknown | Threat monitoring mentioned but breach-specific monitoring not explicitly stated |
| RADIUS and SAML support | unknown | Legacy protocol support not explicitly documented; Idira emphasises modern identity integration patterns |
| Admin audit log | yes | Audit trails for agent activities and session governance documented; comprehensive logging implied for compliance |
Idira is the rebranded identity security platform built on CyberArk's legacy and now powered by Palo Alto Networks. Existing CyberArk customers continue using the same platform with updated branding and logo; the underlying product architecture remains based on CyberArk's proven privileged access management foundation. Over time, Idira customers gain access to expanded capabilities across the Palo Alto Networks security ecosystem, including integration with Cortex and other Palo Alto Networks solutions.
Idira is positioned as an enterprise solution designed for larger organisations with complex infrastructure, high-security compliance requirements, and significant machine identity and automation workloads. It requires custom deployment and ongoing professional services support. Mid-market MSPs and smaller organisations typically evaluate alternatives with published per-endpoint or per-user pricing and easier self-service deployment models rather than enterprise-only, quote-based licensing.
Idira pricing is quote-only; Palo Alto Networks does not publish tiered pricing plans on their website. Pricing varies based on the number of identities managed, deployment scope (human, machine and agentic), and enterprise licensing agreements. Organisations evaluating Idira should contact Palo Alto Networks sales directly to discuss evaluation licenses, proof-of-concept terms, and custom pricing for their specific use case.
Idira manages three categories of identity: human identities with privilege controls and governance for users and administrators, machine identities including secrets management for CI/CD pipelines and cloud workloads, and agentic identities for AI agent discovery and access governance. This multi-identity approach supports modern hybrid cloud environments where both humans and automated systems require privilege access controls and comprehensive audit trails.
Idira documents over 300 out-of-the-box integrations and 200+ alliance partners. Integration coverage includes modern CI/CD platforms, cloud providers, identity systems, security tools and DevOps platforms. The platform features native integration with Palo Alto Networks Cortex and supports modern CI/CD pipeline workflows. Organisations should confirm integration availability for their specific tool stack during evaluation and proof-of-concept testing.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review