Skip to content

CyberArk Identity

Palo Alto Networks, Inc. · Palo Alto Networks (CyberArk acquisition closed 11 February 2026; $45.00 cash plus 2.2005 PANW shares per CyberArk share). Earlier: CyberArk acquired Idaptive in May 2020 for $70M.

Last verified 2026-09-18 · Reviewed by guptadeepak

enterpriseb2b-saascloud-saasenterprise-quote

Editorial verdict

This product no longer exists. Palo Alto Networks completed its acquisition of CyberArk on 11 February 2026, and the customer identity line was retired rather than carried forward. The old product URL, cyberark.com/products/customer-identity, now returns a 301 to paloaltonetworks.com/idira, and Idira is a workforce, machine, and agentic identity platform with no CIAM offering. Do not shortlist it, quote it, or compare it as a live option. Existing deployments should be planning a replacement now; the profile below is kept as a dated record of what the product was and where the capability went.

Last verified by @guptadeepak on 2026-09-18.

At a glance

Best for
Nobody. This profile exists so existing deployments can find migration context.
Pricing
enterprise-quote
Free tier
None
Deployment
cloud-saas
SOC 2 Type II
Yes
Passkeys
Native
Self-host
No
Open source
No

Funding & business

Funding model
Platform division
Total raised
None
Latest round
Acquired · $21.1B · 2026
Years in business
8 yrs
Round led by
Palo Alto Networks
Profitable
Not disclosed

CyberArk (formerly NASDAQ: CYBR) was acquired by Palo Alto Networks, closing 11 February 2026 for $45.00 cash plus 2.2005 PANW shares per CyberArk share, roughly $2.3B cash and 112M shares in aggregate. The privileged access and machine identity lines were folded into Palo Alto's Idira platform; the customer identity product was not carried over.

Funding data from primary source. See also the CIAM investor landscape.

Strengths

  • Historical only. The CIAM-plus-PAM consolidation was uncommon while the product was sold.
  • Historical only. FedRAMP Moderate authorization plus a broad enterprise compliance footprint.
  • Historical only. Adaptive MFA and risk decisioning inherited from Idaptive's security-first design.

Limitations

  • The product no longer exists. Palo Alto Networks completed its CyberArk acquisition on 11 February 2026 and retired the customer identity line.
  • cyberark.com/products/customer-identity now returns a 301 to paloaltonetworks.com/idira, which covers workforce, machine, and agentic identity and has no CIAM offering.
  • Public product documentation for the CIAM line is no longer published.
  • Not quotable, not renewable as a net-new purchase, and not a migration destination.

Capability matrix

Every vendor scored on the same axes. See the methodology for criteria.

Authentication
Password authentication Yes
Social login Yes
Magic links Yes
SMS OTP Yes
Email OTP Yes
TOTP (authenticator app) Yes
Push MFA Yes
WebAuthn / passkeys Yes
Biometric Yes
Hardware security keys Yes
SAML SSO Yes
OIDC SSO Yes
OAuth 2.0 SSO Yes
Enterprise federation Yes
Passwordless-only flows Yes
Adaptive MFA Yes
Step-up auth Yes
Swipe table horizontally →
Authorization
RBAC Yes
ABAC Yes
ReBAC No
FGA engine No
API authorization Yes
Fine-grained permissions Yes
Swipe table horizontally →
User management
Self-service registration Yes
Progressive profiling Partial
Self-service account Yes
Bulk user import Yes
Admin user search Yes
Custom user metadata Yes
Organizations / tenants Yes
Multi-tenancy Yes
SCIM provisioning Yes
Swipe table horizontally →
Developer experience
REST API Yes
GraphQL API No
SDKsjs, node, java, python, dotnet
CLI Yes
Terraform provider Yes
Local emulator No
Extension modelWorkflows + custom rules
Swipe table horizontally →
Security
Bot detection Yes
Breached password detection Yes
Brute-force protection Yes
Anomaly detection Yes
Log streams Yes
Audit logs Yes
GDPR data export Yes
PII minimization Yes
Post-quantum roadmap No
Swipe table horizontally →
Agentic identity
MCP support No
OAuth 2.1 Yes
Dynamic client registration Yes
Agent vs human token separation No
Web Bot Auth No
Swipe table horizontally →
Compliance
SOC 2 Type II Yes
ISO 27001 Yes
ISO 27018 Yes
HIPAA Yes
PCI DSS No
GDPR Yes
CCPA Yes
FedRAMPModerate
EU data residency Yes
Swipe table horizontally →
Consent & privacy
Consent management Partial
Preference center Partial
Purpose-specific consent No
Integrates with CMPsn/a
Swipe table horizontally →
Scalability & regions
Multi-region deployment Yes
Data residency control Yes
Proven at high scale (1M+ MAU) Yes
Swipe table horizontally →
Enterprise operations
Password-hash import Yes
Lazy / just-in-time migration Yes
Account linking & dedup Yes
Custom domains per brand Yes
Per-brand theming of all flows Yes
Per-brand consent partitioning Partial
Deletion webhooks / cascade Yes
Event streaming / webhooks Yes
Documented rate limits Yes
Swipe table horizontally →

Developer experience & lock-in

Editorial 1–5 scores and migration effort, scored on the same axes for every vendor. See the methodology for how these are graded.

Developer experience

DX overall3/5
Docs quality4/5
Passkey orchestration4/5
Community
Medium

Migration & lock-in

High lock-in
Migrating inInvolved

Effort to adopt this platform

Migrating outInvolved

Effort to leave later (your exit cost)

Higher exit effort means more switching cost. Ask about bulk user export (including password hashes) before you commit. This product is winding down; treat it as a migration source, not a destination.

Enterprise readiness

Enterprise-ready · 100/100

A computed read of how ready this vendor is to sell into the enterprise, derived from the capability matrix. See the enterprise-ready pillars.

  • Enterprise SSO

    SAML SSO · OIDC SSO · Enterprise federation

    100
  • Directory sync (SCIM)

    SCIM provisioning · Organizations

    100
  • Organizations & tenancy

    Organizations · Multi-tenancy

    100
  • RBAC & custom roles

    RBAC · ABAC / ReBAC / FGA · Fine-grained permissions

    100
  • Audit logs & streaming

    Audit logs · Log streaming

    100
  • Compliance certifications

    SOC 2 Type II · ISO 27001 · HIPAA / FedRAMP

    100
  • Security posture

    Anomaly detection · Brute-force protection · Breached-password checks · Adaptive / step-up auth

    100

Scored from our capability review; confirm the exact plan tier and SCIM scope with the vendor before you commit.

Pricing

Estimated monthly cost (USD)
10,000 MAUQuote required
100,000 MAUQuote required
500,000 MAUQuote required
1,000,000 MAUQuote required
Swipe table horizontally →
  • Not available for purchase. Existing contracts run through Palo Alto Networks account teams.
  • Budget the migration instead: a replatform off this product is the real cost line.

Estimates use the standard assumptions in our methodology. Always confirm with the vendor.

Best for

  • Nobody. This profile exists so existing deployments can find migration context.

Not for

  • Any net-new CIAM selection
  • Any renewal or expansion plan
  • Any shortlist, RFP, or vendor comparison as a live option

Solves for

Enterprise pain points this vendor covers on the mapped capabilities. See all pain points.

FAQ

Can I still buy CyberArk Customer Identity?
No. Palo Alto Networks completed its acquisition of CyberArk on 11 February 2026, and the customer identity product was retired. The product page at cyberark.com/products/customer-identity returns a 301 redirect to paloaltonetworks.com/idira, which sells workforce, machine, and agentic identity and has no CIAM product. There is no successor CIAM SKU.
What is Idira, and does it replace the CIAM product?
Idira is Palo Alto Networks' identity security platform, built largely on the CyberArk privileged access, secrets, and machine identity portfolio. It covers human workforce identities, machine identities, and agentic identities. It does not cover customer identity, so it is not a replacement for a CIAM deployment. The privileged access capability survived the acquisition; the customer identity capability did not.
Where should existing CyberArk Customer Identity deployments migrate?
Treat this as a standard heritage-CIAM replatform. Enterprise buyers typically evaluate Auth0, Microsoft Entra External ID, SAP Customer Data Cloud, or Ping Identity; teams wanting lower cost or a self-hosted path look at Keycloak or Ory. Start with a password hash export and an account linking plan, since those two items set the timeline. Budget 12 to 18 months from decision to completed cutover at enterprise scale.
What was Idaptive?
Idaptive was a workforce-and-customer identity platform founded in 2018, originally spun out from Centrify. CyberArk acquired Idaptive in May 2020 for $70M and folded it into its Identity Security Platform, where it became the Customer Identity product. That lineage ended with the Palo Alto Networks acquisition in February 2026.

Sources

Where to next


This product has been withdrawn

CyberArk Customer Identity, later branded CyberArk Identity, is no longer a product you can buy. Palo Alto Networks completed its acquisition of CyberArk on 11 February 2026, paying $45.00 in cash plus 2.2005 Palo Alto shares per CyberArk share, and identity security became a core pillar of the Palo Alto platform. Palo Alto had announced the deal in July 2025 at about $25 billion in equity value; the final consideration is stated in the closing release and the FY2026 10-Q, which defers the purchase-price allocation, so no single headline total is quoted here. The privileged access, secrets, and machine identity portfolio was carried forward into Idira. The customer identity line was not.

The evidence is in the URLs. cyberark.com/products/customer-identity/ returns a 301 to paloaltonetworks.com/idira, as does cyberark.com/products/ generally. The Idira page describes human workforce identities, machine identities, and agentic identities. It says nothing about consumer registration, social login, progressive profiling, consent, or any other CIAM surface, because Palo Alto Networks does not sell one.

This page is kept, with its original capability matrix intact, so that anyone arriving from an old link, an old shortlist, or an old RFP gets the correct answer rather than a 404.

What the product was

It originated as Idaptive, founded in 2018 as a Centrify spinout, which CyberArk acquired in May 2020 for $70M and folded into its Identity Security Platform. The pitch was consolidation: one vendor covering both customer identity and privileged access, so an enterprise could apply the same risk decisioning, policy, and audit across customer-facing and privileged-employee identities. That pairing was uncommon, and it was the main reason to pick the product. It carried FedRAMP Moderate, strong adaptive MFA, and a broad enterprise compliance footprint. Pricing was enterprise quote-based with no public list, and developer experience trailed the developer-first tier substantially.

The capability matrix below is preserved as it stood at the last verification while the product was still sold. Read it as history, not as a buying signal.

What existing deployments should do

Treat this as a heritage-CIAM replatform with a known end date rather than an open-ended one. The two items that set the timeline are the password hash export and the account linking plan, so raise both with the Palo Alto Networks account team early and get the export format in writing before anything else. Enterprise buyers replacing this product typically evaluate Auth0, Microsoft Entra External ID, SAP Customer Data Cloud, and Ping Identity; teams that want lower cost or a self-hosted path look at Keycloak or Ory. The CIAM migration framework covers the sequencing.

If privileged access rather than customer identity is what you actually bought this for, that capability survived the acquisition and now lives in Idira. It is outside the scope of this index, which covers customer identity only.

Archived comparisons

Three comparison pages on this site pair this product against a live vendor: Auth0, Ping Identity, and Beyond Identity. All three are now archived records of a head-to-head that no longer has two sides. In each case the live vendor is the only remaining option.

Editorial changelog (3 entries)
  1. Status changed to 'deprecated'. Palo Alto Networks closed its CyberArk acquisition on 11 Feb 2026 and retired the CIAM line; product URL now 301s to Idira, which has no CIAM. Verdict, pricing, and FAQs rewritten as a migration record.

  2. Profile reviewed: capabilities, pricing, and verdict checked against current public sources.

  3. Renamed from 'CyberArk Customer Identity' to 'CyberArk Identity' to reflect the current brand. Lineage clarified in legal_name: Centrify → Idaptive → CyberArk Identity.

Last verified by @guptadeepak on 2026-09-18.