CyberArk Identity
Palo Alto Networks, Inc. · Palo Alto Networks (CyberArk acquisition closed 11 February 2026; $45.00 cash plus 2.2005 PANW shares per CyberArk share). Earlier: CyberArk acquired Idaptive in May 2020 for $70M.
Last verified 2026-09-18 · Reviewed by guptadeepak
Editorial verdict
This product no longer exists. Palo Alto Networks completed its acquisition of CyberArk on 11 February 2026, and the customer identity line was retired rather than carried forward. The old product URL, cyberark.com/products/customer-identity, now returns a 301 to paloaltonetworks.com/idira, and Idira is a workforce, machine, and agentic identity platform with no CIAM offering. Do not shortlist it, quote it, or compare it as a live option. Existing deployments should be planning a replacement now; the profile below is kept as a dated record of what the product was and where the capability went.
Last verified by @guptadeepak on 2026-09-18.
At a glance
- Best for
- Nobody. This profile exists so existing deployments can find migration context.
- Pricing
- enterprise-quote
- Free tier
- None
- Deployment
- cloud-saas
- SOC 2 Type II
- Yes
- Passkeys
- Native
- Self-host
- No
- Open source
- No
Funding & business
- Funding model
- Platform division
- Total raised
- None
- Latest round
- Acquired · $21.1B · 2026
- Years in business
- 8 yrs
- Round led by
- Palo Alto Networks
- Profitable
- Not disclosed
CyberArk (formerly NASDAQ: CYBR) was acquired by Palo Alto Networks, closing 11 February 2026 for $45.00 cash plus 2.2005 PANW shares per CyberArk share, roughly $2.3B cash and 112M shares in aggregate. The privileged access and machine identity lines were folded into Palo Alto's Idira platform; the customer identity product was not carried over.
Funding data from primary source. See also the CIAM investor landscape.
Strengths
- Historical only. The CIAM-plus-PAM consolidation was uncommon while the product was sold.
- Historical only. FedRAMP Moderate authorization plus a broad enterprise compliance footprint.
- Historical only. Adaptive MFA and risk decisioning inherited from Idaptive's security-first design.
Limitations
- The product no longer exists. Palo Alto Networks completed its CyberArk acquisition on 11 February 2026 and retired the customer identity line.
- cyberark.com/products/customer-identity now returns a 301 to paloaltonetworks.com/idira, which covers workforce, machine, and agentic identity and has no CIAM offering.
- Public product documentation for the CIAM line is no longer published.
- Not quotable, not renewable as a net-new purchase, and not a migration destination.
Capability matrix
Every vendor scored on the same axes. See the methodology for criteria.
| Password authentication | Yes |
|---|---|
| Social login | Yes |
| Magic links | Yes |
| SMS OTP | Yes |
| Email OTP | Yes |
| TOTP (authenticator app) | Yes |
| Push MFA | Yes |
| WebAuthn / passkeys | Yes |
| Biometric | Yes |
| Hardware security keys | Yes |
| SAML SSO | Yes |
| OIDC SSO | Yes |
| OAuth 2.0 SSO | Yes |
| Enterprise federation | Yes |
| Passwordless-only flows | Yes |
| Adaptive MFA | Yes |
| Step-up auth | Yes |
| RBAC | Yes |
|---|---|
| ABAC | Yes |
| ReBAC | No |
| FGA engine | No |
| API authorization | Yes |
| Fine-grained permissions | Yes |
| Self-service registration | Yes |
|---|---|
| Progressive profiling | Partial |
| Self-service account | Yes |
| Bulk user import | Yes |
| Admin user search | Yes |
| Custom user metadata | Yes |
| Organizations / tenants | Yes |
| Multi-tenancy | Yes |
| SCIM provisioning | Yes |
| REST API | Yes |
|---|---|
| GraphQL API | No |
| SDKs | js, node, java, python, dotnet |
| CLI | Yes |
| Terraform provider | Yes |
| Local emulator | No |
| Extension model | Workflows + custom rules |
| Bot detection | Yes |
|---|---|
| Breached password detection | Yes |
| Brute-force protection | Yes |
| Anomaly detection | Yes |
| Log streams | Yes |
| Audit logs | Yes |
| GDPR data export | Yes |
| PII minimization | Yes |
| Post-quantum roadmap | No |
| MCP support | No |
|---|---|
| OAuth 2.1 | Yes |
| Dynamic client registration | Yes |
| Agent vs human token separation | No |
| Web Bot Auth | No |
| SOC 2 Type II | Yes |
|---|---|
| ISO 27001 | Yes |
| ISO 27018 | Yes |
| HIPAA | Yes |
| PCI DSS | No |
| GDPR | Yes |
| CCPA | Yes |
| FedRAMP | Moderate |
| EU data residency | Yes |
| Consent management | Partial |
|---|---|
| Preference center | Partial |
| Purpose-specific consent | No |
| Integrates with CMPs | n/a |
| Multi-region deployment | Yes |
|---|---|
| Data residency control | Yes |
| Proven at high scale (1M+ MAU) | Yes |
| Password-hash import | Yes |
|---|---|
| Lazy / just-in-time migration | Yes |
| Account linking & dedup | Yes |
| Custom domains per brand | Yes |
| Per-brand theming of all flows | Yes |
| Per-brand consent partitioning | Partial |
| Deletion webhooks / cascade | Yes |
| Event streaming / webhooks | Yes |
| Documented rate limits | Yes |
Developer experience & lock-in
Editorial 1–5 scores and migration effort, scored on the same axes for every vendor. See the methodology for how these are graded.
Developer experience
- Community
- Medium
Migration & lock-in
High lock-inEffort to adopt this platform
Effort to leave later (your exit cost)
Higher exit effort means more switching cost. Ask about bulk user export (including password hashes) before you commit. This product is winding down; treat it as a migration source, not a destination.
Enterprise readiness
Enterprise-ready · 100/100A computed read of how ready this vendor is to sell into the enterprise, derived from the capability matrix. See the enterprise-ready pillars.
- 100
Enterprise SSO
SAML SSO · OIDC SSO · Enterprise federation
- 100
Directory sync (SCIM)
SCIM provisioning · Organizations
- 100
Organizations & tenancy
Organizations · Multi-tenancy
- 100
RBAC & custom roles
RBAC · ABAC / ReBAC / FGA · Fine-grained permissions
- 100
Audit logs & streaming
Audit logs · Log streaming
- 100
Compliance certifications
SOC 2 Type II · ISO 27001 · HIPAA / FedRAMP
- 100
Security posture
Anomaly detection · Brute-force protection · Breached-password checks · Adaptive / step-up auth
Scored from our capability review; confirm the exact plan tier and SCIM scope with the vendor before you commit.
Pricing
| 10,000 MAU | Quote required |
|---|---|
| 100,000 MAU | Quote required |
| 500,000 MAU | Quote required |
| 1,000,000 MAU | Quote required |
- Not available for purchase. Existing contracts run through Palo Alto Networks account teams.
- Budget the migration instead: a replatform off this product is the real cost line.
Estimates use the standard assumptions in our methodology. Always confirm with the vendor.
Best for
- Nobody. This profile exists so existing deployments can find migration context.
Not for
- Any net-new CIAM selection
- Any renewal or expansion plan
- Any shortlist, RFP, or vendor comparison as a live option
Solves for
Enterprise pain points this vendor covers on the mapped capabilities. See all pain points.
- B2B multi-tenancy: the edge cases bolted-on models miss
- Identity unification and deduplication as a program
- Integration sprawl and the single customer view that wasn't scoped
- Lifecycle management: dormancy, deletion, and the cascade
- Migrating millions of users without losing them
- Multi-brand rollout: the scenario that breaks architectures
- Pricing opacity: the SSO tax and the MAU trap
- Scaling the user directory itself
- The build-vs-buy trap: identity is bigger than it looks
- The friction-versus-security dial that never stops moving
FAQ
- Can I still buy CyberArk Customer Identity?
- No. Palo Alto Networks completed its acquisition of CyberArk on 11 February 2026, and the customer identity product was retired. The product page at cyberark.com/products/customer-identity returns a 301 redirect to paloaltonetworks.com/idira, which sells workforce, machine, and agentic identity and has no CIAM product. There is no successor CIAM SKU.
- What is Idira, and does it replace the CIAM product?
- Idira is Palo Alto Networks' identity security platform, built largely on the CyberArk privileged access, secrets, and machine identity portfolio. It covers human workforce identities, machine identities, and agentic identities. It does not cover customer identity, so it is not a replacement for a CIAM deployment. The privileged access capability survived the acquisition; the customer identity capability did not.
- Where should existing CyberArk Customer Identity deployments migrate?
- Treat this as a standard heritage-CIAM replatform. Enterprise buyers typically evaluate Auth0, Microsoft Entra External ID, SAP Customer Data Cloud, or Ping Identity; teams wanting lower cost or a self-hosted path look at Keycloak or Ory. Start with a password hash export and an account linking plan, since those two items set the timeline. Budget 12 to 18 months from decision to completed cutover at enterprise scale.
- What was Idaptive?
- Idaptive was a workforce-and-customer identity platform founded in 2018, originally spun out from Centrify. CyberArk acquired Idaptive in May 2020 for $70M and folded it into its Identity Security Platform, where it became the Customer Identity product. That lineage ended with the Palo Alto Networks acquisition in February 2026.
Sources
- Palo Alto Networks Completes Acquisition of CyberArk to Secure the AI Eraaccessed 2026-09-18
- Palo Alto Networks Idira, the platform the CyberArk product pages now redirect toaccessed 2026-09-18
- CyberArk Customer Identity product page, now a 301 redirect to Idiraaccessed 2026-09-18
Where to next
This product has been withdrawn
CyberArk Customer Identity, later branded CyberArk Identity, is no longer a product you can buy. Palo Alto Networks completed its acquisition of CyberArk on 11 February 2026, paying $45.00 in cash plus 2.2005 Palo Alto shares per CyberArk share, and identity security became a core pillar of the Palo Alto platform. Palo Alto had announced the deal in July 2025 at about $25 billion in equity value; the final consideration is stated in the closing release and the FY2026 10-Q, which defers the purchase-price allocation, so no single headline total is quoted here. The privileged access, secrets, and machine identity portfolio was carried forward into Idira. The customer identity line was not.
The evidence is in the URLs. cyberark.com/products/customer-identity/ returns a 301 to paloaltonetworks.com/idira, as does cyberark.com/products/ generally. The Idira page describes human workforce identities, machine identities, and agentic identities. It says nothing about consumer registration, social login, progressive profiling, consent, or any other CIAM surface, because Palo Alto Networks does not sell one.
This page is kept, with its original capability matrix intact, so that anyone arriving from an old link, an old shortlist, or an old RFP gets the correct answer rather than a 404.
What the product was
It originated as Idaptive, founded in 2018 as a Centrify spinout, which CyberArk acquired in May 2020 for $70M and folded into its Identity Security Platform. The pitch was consolidation: one vendor covering both customer identity and privileged access, so an enterprise could apply the same risk decisioning, policy, and audit across customer-facing and privileged-employee identities. That pairing was uncommon, and it was the main reason to pick the product. It carried FedRAMP Moderate, strong adaptive MFA, and a broad enterprise compliance footprint. Pricing was enterprise quote-based with no public list, and developer experience trailed the developer-first tier substantially.
The capability matrix below is preserved as it stood at the last verification while the product was still sold. Read it as history, not as a buying signal.
What existing deployments should do
Treat this as a heritage-CIAM replatform with a known end date rather than an open-ended one. The two items that set the timeline are the password hash export and the account linking plan, so raise both with the Palo Alto Networks account team early and get the export format in writing before anything else. Enterprise buyers replacing this product typically evaluate Auth0, Microsoft Entra External ID, SAP Customer Data Cloud, and Ping Identity; teams that want lower cost or a self-hosted path look at Keycloak or Ory. The CIAM migration framework covers the sequencing.
If privileged access rather than customer identity is what you actually bought this for, that capability survived the acquisition and now lives in Idira. It is outside the scope of this index, which covers customer identity only.
Archived comparisons
Three comparison pages on this site pair this product against a live vendor: Auth0, Ping Identity, and Beyond Identity. All three are now archived records of a head-to-head that no longer has two sides. In each case the live vendor is the only remaining option.
Editorial changelog (3 entries)
Status changed to 'deprecated'. Palo Alto Networks closed its CyberArk acquisition on 11 Feb 2026 and retired the CIAM line; product URL now 301s to Idira, which has no CIAM. Verdict, pricing, and FAQs rewritten as a migration record.
Profile reviewed: capabilities, pricing, and verdict checked against current public sources.
Renamed from 'CyberArk Customer Identity' to 'CyberArk Identity' to reflect the current brand. Lineage clarified in legal_name: Centrify → Idaptive → CyberArk Identity.
