Talk to us
by BroadcomTechBag Intel Page

Symantec SiteMinder

Your staff sign in to dozens of web apps. One session should open them, and one logoff close them — Symantec SiteMinder gives every web app one sign-in over SAML, OIDC, OAuth and JWT, with FIDO2 passkeys, single logoff and session-hijack monitoring, on Kubernetes you run.

One session, one logoff, every web appSelf-hosted on Kubernetes in IndiaQuote-only through partners

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Broadcom prints no SiteMinder price and no licence unit; a partner prices each estate
Quote
Standards
Plus OAuth and JWT, with single logoff and session-hijack monitoring on top
SAML · OIDC · FIDO2
Analysts
No placement is cited for SiteMinder itself; Broadcom’s KuppingerCole 2026 wins are for IGA
None cited
India
Runs on Kubernetes you operate in India; Broadcom claims no India-hosted SiteMinder region
Your cluster

Quick answer

Symantec SiteMinder is Broadcom’s web access management and single sign-on platform, inherited with CA Technologies in 2018. It federates over SAML, OpenID Connect, OAuth and JWT, accepts FIDO2 passkeys, ends every app’s session with one logoff and watches sessions for hijacking. Broadcom calls it cloud-native and auto-elastic; it runs on Kubernetes, VMware VKS included. MFA comes via VIP Authentication Hub. Quote-only. Read more ↓ Show less ↑
Part 01 · Orient

The Broadcom platform family

This page covers Symantec SiteMinder — web access management and SSO from Broadcom’s identity division. The rest:

Quick facts

30-second orientation
Product
Web access management and SSO: federation, passkeys, single logoff, session-hijack monitoring
Maker
Broadcom Inc., Palo Alto (CEO Hock Tan); Identity Management Security Division, led by Clayton Donley
Heritage
Came with CA Technologies, a deal Broadcom completed on 5 Nov 2018 for about US$18.9B
Standards
SAML, OpenID Connect, OAuth and JWT; FIDO2 passkeys through WebAuthn
Platform
Described by Broadcom as cloud-native and auto-elastic; deploys on Kubernetes, including VMware VKS / VCF
MFA
Delivered through VIP Authentication Hub, part of Broadcom’s Identity Security Platform
Price
No figure anywhere; Broadcom routes every SiteMinder buyer to a partner for pricing
Customers
Stories are anonymised: a “Global Bank”, a “Telecom” and a “Financial Services” firm
India
Self-hosted, so data stays on your cluster; Broadcom offices in Bangalore, Hyderabad and Pune
In India via
TechBag — app-by-app scoping, quote in INR with GST, pilot on one portal
Part 02 · Learn

Understand web access management before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is web access management?

One sign-in session that every web app trusts, with one sign-out that ends all of them together.

A password and a sign-out per app vs one managed session — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA password and sign-out per appSymantec SiteMinder
Passwords per userOne per application, often reusedOne SiteMinder session across apps
Signing outClose each app and hopeSingle logoff ends every session
Phishing-resistant sign-inPassword plus an SMS codeFIDO2 passkeys through WebAuthn
New mobile and API clientsLogin code written per teamOIDC, OAuth and JWT from one platform
A session taken overTrusted until it times outMonitored for signs of hijacking
What it is NOT—Access governance, an India-hosted region or a list price

The cheapest test is one portal: put it behind SiteMinder, sign out on a shared terminal, and confirm every app closes with it.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where it runs

Platform

Cloud-native SiteMinder platform

Broadcom describes SiteMinder as a cloud-native, auto-elastic unified platform. It deploys on Kubernetes, VMware VKS in a VCF estate among them, inside infrastructure you control.

02
How applications trust a login

Federation

SAML, OpenID Connect, OAuth and JWT

An app accepts the SiteMinder session as a SAML assertion, an OpenID Connect or OAuth flow, or a JWT, so partner SaaS, in-house portals and APIs share one sign-in.

03
How users prove who they are

Authentication

Passkeys plus VIP Authentication Hub

WebAuthn support brings FIDO2 passkeys and security keys; risk-aware multi-factor checks are handed off to VIP Authentication Hub, part of Broadcom’s Identity Security Platform.

04
What happens after sign-in

Session

Single logoff and hijack monitoring

One session covers every connected application, one logoff closes them all together, and SiteMinder keeps watching live sessions for signs that one has been hijacked.

One session for every web app — issued on your own Kubernetes, trusted over SAML, OIDC, OAuth or JWT, ended with one logoff.

Part 03 · Evaluate

Six capabilities. Authenticate, federate, protect.

Symantec SiteMinder signs a user in once, lets every web app trust that session, and signs them out of all of them together.

Authenticate
Passkeys

FIDO2 sign-in, no password

WebAuthn support lets staff sign in with FIDO2 passkeys or hardware security keys, the factor types a phishing page cannot replay.

Authenticate
MFA hub

Step-up via VIP Authentication Hub

Modern multi-factor checks run through VIP Authentication Hub; Broadcom’s 2025 videos show SiteMinder being wired to it step by step.

Federate
SAML

Federation to SaaS and partners

SAML assertions let SiteMinder vouch for a signed-in user to cloud apps and partner sites, so nobody keeps a second password there.

Federate
OIDC + OAuth

Tokens for APIs and mobile apps

OpenID Connect and OAuth flows, with JWT tokens, carry the same identity into mobile apps, APIs and newer web services.

Protect
Single logoff

One sign-out closes everything

Signing out once ends the user’s session in every connected application together, which matters on shared counters and terminals.

Protect
Session watch

Hijacked sessions spotted

SiteMinder monitors live sessions for hijacking, so a session taken over after login can be caught rather than trusted until it expires.

See it, don’t just read it

Watch Symantec SiteMinder in action

Linking SiteMinder to VIP Authentication Hub for MFA, and the WebAuthn support behind FIDO2 passkeys.

Symantec (official)·Explainer, October 2025

Differentiated Value of SiteMinder Integration with Authentication Hub

Why Broadcom pairs SiteMinder with VIP Authentication Hub, and what the hub adds to a SiteMinder estate.

Symantec (official)·Demo, May 2025

Enabling SiteMinder MFA with VIP Authentication Hub

A walkthrough of switching on multi-factor sign-in for SiteMinder-protected apps through the hub.

Symantec (official)·Demo, April 2024

SiteMinder support for Web Authentication (WebAuthn)

From 2024: how SiteMinder accepts WebAuthn, the standard behind FIDO2 passkeys and security keys.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Symantec SiteMinder

Every app has its own login and its own logout. SiteMinder gives them one of each.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Built for estates that keep identity in-house

SiteMinder is software you run. Broadcom describes a cloud-native, auto-elastic platform that deploys on Kubernetes, VMware VKS in a VCF estate included. For a bank, insurer or telecom that wants every sign-in record inside its own Indian data centre, that deployment model is the reason to shortlist it.

02

Older portals and new APIs behind one login

The same session can be presented as a SAML assertion, an OpenID Connect or OAuth token, or a JWT, so an established SAML portal and a fresh mobile API can share one sign-in. Single logoff then shuts all of them at once, useful wherever a terminal passes from one employee to the next.

03

Passkeys now, risk-aware MFA through the hub

WebAuthn support brings FIDO2 passkeys, which a fake login page cannot capture and replay. Risk-aware MFA is the job of VIP Authentication Hub, which Broadcom showed connected to SiteMinder in videos from May and October 2025. Ask whether the hub is on your quote or a second purchase.

04

Where it stops

There is no public price and no stated licence unit. Customer stories are anonymised, no analyst placement is cited for SiteMinder itself, and Broadcom claims no India-hosted region. It signs people in; certifying access and removing leavers is identity governance, which Broadcom sells separately as Symantec IGA.

The idea
One session, one logoff, every web app
The residency
Self-hosted on your Kubernetes in India
The price
Quote-only through Broadcom partners
Proof, not promises

The numbers behind the platform

4 token standards
SAML, OpenID Connect, OAuth and JWT: the ways an app can accept a SiteMinder login
— Vendor
2018
the year Broadcom closed its CA Technologies deal, which brought SiteMinder with it
— Public record
2024
the year Broadcom’s channel demonstrated SiteMinder accepting WebAuthn for passkeys
— Vendor
2 MFA videos
official 2025 walkthroughs of linking SiteMinder to VIP Authentication Hub
— Vendor
3 stories
anonymised customer stories on the product page: a bank, a telecom, a finance firm
— Vendor
5 India offices
Broadcom’s listed sites in India: two in Bangalore, one in Hyderabad, two in Pune
— Vendor

What your Symantec SiteMinder rollout looks like

Week 1Model

Map every app and its protocol

List each web app, the standard it speaks (SAML, OIDC, OAuth, JWT) and who signs in, and flag those still on local passwords.

Week 2Decide

Decide where it runs

Choose the Kubernetes or VMware VKS cluster in your Indian data centre, size it with the partner, and confirm what the quote covers.

Weeks 3–4Pilot

Pilot one portal end to end

Put one staff portal behind SiteMinder, switch on single logoff, and test sign-out on shared terminals before widening it.

Month 2Prove

Add passkeys and step-up

Enrol a pilot group on FIDO2 passkeys, and connect VIP Authentication Hub where sensitive apps need risk-aware MFA.

Month 3Commit

Move the rest in waves

Migrate apps in batches by protocol, retire their local logins, and agree with the SOC who acts on session-hijack alerts.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
46+ reviews*
78% would recommend
Federation breadth4.4
Session control4.3
Self-hosting flexibility4.2
Ease of administration3.5
Value for money3.4
5★
38%
4★
40%
3★
15%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Single logoff fixed our branch problem: when a teller signs out at a shared counter PC, every banking app closes with it.”
Head of IT Security
BFSI
Insurance
“SiteMinder runs on our own Kubernetes cluster in Mumbai, so the auditors could see no sign-in record ever left our building.”
IAM Architect
Insurance
Telecom
“Moving the support desk to FIDO2 passkeys meant agents stopped typing passwords into anything, and the phishing tickets dropped.”
Security Engineer
Telecom
Financial Services
“VIP Authentication Hub for MFA turned out to be its own line on the quote. Ask about it before the budget is signed off.”
Procurement Lead
Financial Services
Public Sector
“Our new mobile API trusts the same session as the old SAML portal through OIDC and JWT. One login, two very different apps.”
Application Architect
Public Sector
Manufacturing
“Powerful, but not a weekend install. We leaned on the partner for cluster sizing and for moving our access policies across.”
IT Director
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the SSO and web access management market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag SSO & Access Management Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Symantec SiteMinderThis page

Quote-only through partners; no list price or unit.

Grid 02 · The architecture

In-Country Control × Standards Breadth

The grid nobody publishes — how far you can keep the identity service and its data in India vs how many sign-in standards it speaks.

Cloud-only all-roundersSelf-hosted platformsCloud MFA-firstOn-prem value options
Symantec SiteMinderThis page

Self-hosted on Kubernetes; SAML, OIDC, OAuth, JWT, FIDO2.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Symantec SiteMinder vs the SSO and access field

Against OpenText NetIQ Access Manager, Okta Single Sign-On, Microsoft Entra ID, Cisco Duo and miniOrange SSO — on deployment, standards, passkeys, sessions, price and India.

DimensionSymantec SiteMinderOpenText NetIQ Access ManagerOkta Single Sign-OnMicrosoft Entra IDCisco DuominiOrange SSO
What it isSelf-run web SSO + WAMFederation + proxyHosted identity providerMicrosoft’s cloud IdPMFA service, plus SSOIndian SSO and MFA
DeploymentKubernetes you runContainers or ISOOkta-hosted onlyMicrosoft cloudCloud; gateway optionalHosted or on-premise
Federation standardsSAML, OIDC, OAuth, JWTAdds WS-Fed, WS-TrustSAML, OIDC, SWASAML, OIDC, app proxySAML 2.0 and OIDCSAML, OAuth, OIDC
Passkeys and FIDO2FIDO2 via WebAuthnIn Advanced AuthKeys and passkeysCheck the licenceFIDO2 recordedFIDO2 from $3
MFA and riskVia VIP Auth HubRisk rules; MFA apartAdaptive at $14Conditional access, P1Risk-based at $6Adaptive at Premium
Session controlSingle logoff + watchRisk re-scored liveITP is an add-onDecided at sign-inDevice trust at loginNot recorded
Pricing modelQuote; unit unpublishedQuote onlyPer user, by suitePer user, or bundledPer user, 4 editionsPer user; top tier quote
Published entry priceNot publishedNot published$6/user/month~$7, ₹580/user/monthFree to 10 users$2/user/month
Included vs add-onMFA hub on topFactors sold apartGateway at the topGovernance extraGateway in PremierSCIM at Premium
Scale and referencesAnonymised stories500+ connectors19,000+ organisationsInside Microsoft 365Cap only on Free5,000+ integrations
India data locationYour Indian DCYour own serversIndia tenants, 2026Ask MicrosoftMumbai data centreOn-prem, Indian vendor
Vendor and backingBroadcom identity unitPart of OpenTextIndependent IdPMicrosoftCisco since 2018Founder-led, Pune
Lock-in and exitPolicies stay in-houseRules in its consoleOkta-held tenantMicrosoft-centredRemovable MFA layerCloud or on-prem, same
Best fitRegulated, self-hostedGateway for legacy webSaaS-heavy, cloud-firstMicrosoft 365 estatesMFA over VPN and IdPBudget, Indian vendor
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Symantec SiteMinder if…

  • ✓Regulated web estates must keep authentication on infrastructure they run, on Kubernetes or VMware VKS in India
  • ✓Established SAML portals and new OIDC or JWT apps need to share one session, with one sign-out that closes them all
  • ✓You want FIDO2 passkeys now and are ready to add VIP Authentication Hub for risk-aware MFA

Compare alternatives if…

  • ✓You want a hosted IdP with a printed price — Okta’s Starter lists at $6 a user a month, miniOrange at $2
  • ✓Your users already hold Entra ID P1 through Microsoft 365 E3 — check what that covers before buying more
  • ✓You need MFA in front of VPNs and an existing IdP, with data in a Mumbai data centre — Cisco Duo is built for that

Do not expect…

  • ✓A Broadcom-hosted SiteMinder region in India, or any India data-region claim
  • ✓Named Indian bank references — Broadcom’s SiteMinder stories are anonymised
  • ✓Access certification or leaver clean-up; that is Symantec IGA’s job

Symantec SiteMinder is one of 26 IAM, SSO & MFA products TechBag carries. The IAM, SSO & MFA guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do scattered logins cost you?

Drag the sliders (workforce users; IT-hour cost). Estimates model helpdesk and admin time spent on password resets, per-app account fixes and manual sign-out clean-up at an assumed 1.5 hours per user a year, with 70% of it removed by one session and single logoff across apps. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual login-support cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: SiteMinder has no list price, and Broadcom does not state what its licence counts; a partner prices each estate. Risk-aware MFA comes through VIP Authentication Hub, a separate Symantec identity product, so check whether it is on the quote. TechBag inventories your web apps and their protocols, then has the partner itemise the quote in INR with GST.

Symantec SiteMinder

Best for self-hosted web SSO

  • Quote-only; no list price or unit
  • Federation plus FIDO2 passkeys
  • Single logoff and session-hijack monitoring

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ VIP Authentication Hub

Best where risk-aware MFA is required

  • Separate Symantec identity product
  • Shown integrated in 2025 videos
  • TechBag confirms it is on the quote

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Applications

How many web apps sit behind a login today, and which speak SAML, OIDC, OAuth or JWT versus none of them?

2
Hosting

Which cluster will run it — Kubernetes in your own Indian data centre, or VMware VKS in an existing VCF estate?

3
MFA

Is VIP Authentication Hub on the quote, or will multi-factor checks come from a tool you already own?

4
Passkeys

Which user groups get FIDO2 passkeys first, and who issues, replaces and revokes the security keys?

5
Sign-out

Do shared terminals need single logoff tested for every app, including the ones federated to partners?

6
Sessions

Who in the SOC receives session-hijack alerts, and what is the agreed response when one fires?

7
Governance

Who certifies access and removes leavers? SiteMinder signs people in; reviews need IGA or another tool.

8
Licence

What unit is the quote counted in — users, apps or servers — and is it in INR with GST and support terms?

FAQ

Questions buyers ask

SiteMinder is Broadcom’s web access management and single sign-on platform. Users sign in once and every connected application trusts that session over SAML, OpenID Connect, OAuth or JWT. It adds FIDO2 passkeys, single logoff across apps and monitoring for hijacked sessions, and you run it on your own Kubernetes.

Ready to evaluate Symantec SiteMinder?

Map your web apps by protocol first, or let a TechBag advisor scope a pilot that puts one staff portal behind SiteMinder with single logoff and passkeys.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.