Okta's marketing is everywhere, but their actual hybrid story is weak. ForgeRock's documentation is a nightmare, but their on-prem components are more mature.
If your "hybrid" means mostly cloud with a few legacy apps on-prem, Okta will push you toward their Advanced Server Access agent. It's another piece of complexity you have to host and manage. Their on-prem LDAP interface is a connector, not a real directory.
ForgeRock's Identity Platform is built from the ground up to be deployed anywhere. You can run the full stack in your data center. The trade-off:
* The learning curve is vertical.
* You'll need a dedicated team to wrangle it.
* The cost model can get opaque.
For a true 50/50 split with complex legacy auth requirements (Kerberos, SAML2, custom LDAP schemas), ForgeRock might be the less painful long-term choice. For a cloud-first company with a few on-prem holdouts, Okta's managed service might win, despite the agent sprawl.
Simple question: are you prepared to become an identity platform vendor to your own company? If not, lean Okta. If yes, maybe ForgeRock. Both will be painful; just in different ways.
Simplicity is the ultimate sophistication
I'm the identity and access management lead at a 3,500-person healthcare company with a genuine 50/50 hybrid footprint. We run ForgeRock Identity Platform 7.2 on-prem for our core employee and partner directory, integrated with legacy EHRs, while using Okta for our SaaS application portfolio.
1. **Fit / Target Audience:** Okta targets organizations where >80% of the IT estate is cloud SaaS. ForgeRock's sweet spot is regulated enterprises (finance, healthcare) with >30% legacy on-prem systems requiring custom authentication flows.
2. **Real Pricing:** Okta's per-user monthly fee is straightforward, scaling from roughly $4/user/mo to over $15/user/mo for the highest tier with MFA and lifecycle. ForgeRock's perpetual license plus annual support model started for us at a six-figure capex, with 22% yearly support. The hidden cost is staffing: you need at least 2-3 full-time engineers to manage a ForgeRock deployment, where Okta might need one part-time admin.
3. **Deployment / Integration Effort:** Standup time differs by orders of magnitude. We had a pilot Okta org configured for SSO to major SaaS apps in under two weeks. Our initial ForgeRock deployment took nine months to go live, as we configured AM, IDM, and DS nodes across two data centers. Integrating a legacy app using SAML or OIDC is faster in Okta. Integrating something requiring a custom JDBC connector or a modified LDAP schema is only possible in ForgeRock.
4. **Where It Breaks:** Okta's Advanced Server Access agent introduces a new failure domain; we've had issues with agent heartbeats failing during network segmentation changes. ForgeRock's operational complexity is the limitation; a misconfigured policy tree can silently fail authentication, and debugging requires deep knowledge of the audit logs. Its performance on a cold cache, in our environment, was 3-4x slower for user profile lookups until the JVM warmed up.
Given your description of a true 50/50 split with complex legacy auth, I'd recommend you evaluate ForgeRock, but only if you have executive buy-in for the dedicated team and extended timeline. For a cleaner recommendation, tell us your team's size dedicated to IAM and your tolerance for a multi-month versus multi-week implementation.