Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs One Identity Active Roles comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Number of Reviews
139
Ranking in other categories
Network Access Control (NAC) (1st), Cisco Security Portfolio (1st)
One Identity Active Roles
Average Rating
8.6
Number of Reviews
17
Ranking in other categories
User Provisioning Software (5th), Active Directory Management (5th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and One Identity Active Roles aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 29.9%, down 31.4% compared to last year.
One Identity Active Roles, on the other hand, focuses on User Provisioning Software, holds 6.6% mindshare, up 5.9% since last year.
Network Access Control (NAC)
User Provisioning Software
 

Featured Reviews

TO
May 3, 2024
Helped improve our security and is reliable
The solution is being used for authentication purposes and for sharing assessments.  Cisco ISE has helped improve our security.  It helps ensure that you are working in accordance with the organizational policy before you join the network. Also, the solution is very reliable.  I would like to…
FJ
Dec 2, 2022
It centralizes and distributes IT functions to our sub-IT administrators, making everything more efficient
Active Roles improved the management of users, groups, and AD objects in the organization. It reduces the time we spend on password resets by 50 percent and speeds up other administrative tasks by providing a faster channel to do these things. We can use it everywhere in the organization. It centralizes and distributes IT functions to our sub-IT administrators, making everything more efficient. It makes us more productive because users don't need to submit a ticket to our service desk. The solution makes AD management simpler and more secure. Security is a priority here because we are using lots of GDPR data. It's more specific because users can see what things mean. We can manage all our users in a more granular way than before.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Assisting a larger number of users in gaining access and guiding them through the process of getting on Cisco ISE has been seamless."
"Using this solution gives us the ability to allow proper access to the network."
"There is good integration with third-party systems like antivirus patch management, MDM."
"It's easy to change and add policies."
"For guests we give them limited access to the internet when they come in so that access has been useful. Previously, we just used to give them the APN key which they would leave with. Now, we give them credentials to use that are for a limited period of time."
"Cisco ISE provides authentication for various applications. It can integrate with other applications to manage access, including Privileged Access Management for those applications. For a comprehensive environment, Cisco ISE should be able to integrate and provide asset management for an IT organization or any organization."
"I like the automation of the collection of information."
"The most valuable feature is the provisioning of the device so as to ensure that they are compliant with the security policy that we need to have."
"It's valuable to us in that it resembles the native tools that most people have grown accustomed to... Active Roles resembles traditional tools, such as from Microsoft. That is really good because it eases the way people interact with the tool."
"The biggest thing for us is Active Roles saves a lot of man-hours in keeping groups up-to-date manually or trying to write some sort of script that you have to run, so we don't have to reinvent the wheel. Instead of when every time somebody joins a department, then somebody has to remember to put in a request to add "meet user Joe" to this group, the solution does it automatically for us. Therefore, it saves our business and IT staff time because they do not have to process requests since Active Role can do it for them."
"Secure access is the most valuable feature."
"It gives us attribute-level control and the AD management features work very well."
"Active Roles improved the management of users, groups, and AD objects in the organization."
"Because of Active Roles, we're able to synchronize on an even more regular basis. It enables us to provide even more information to the Active Directory, which helped us to group our users in a more consistent manner."
"The provisioning and deprovisioning saves a lot of time and skips a lot of errors."
"The AD and AAD management features of this solution are really good... They offer added value by showing more fields such as password age and the statuses of some things that we normally wouldn't see."
 

Cons

"ISE is a little clunky. The front-end feels like it is from the 1980s."
"Sometimes, there are instances when Cisco ISE simply fails to function without any apparent reason, and regardless of the investigation we undertake, the logs indicate that everything is functioning properly, making it somewhat inexplicable."
"Cisco ISE's real-time data analytics for database logging could be improved."
"In an upcoming release, it would be nice to have NAC already standard in the solution."
"A main issue is that the upgrade process, over time, is extraordinarily fragile. Repeatedly, over the past several years, when we've tried to upgrade our Cisco ISE implementation, the upgrade has broken it. Ultimately, we have then had to rebuild it because we need it."
"Since we have started, we struggled a lot to implement this solution into our network, and we opened a case a couple of times. Up until this point, nothing else needs to be improved with this product."
"The initial setup was a little bit complex. It's not that simple because it requires a lot of prerequisites for the solution to get a hold on."
"Cisco could improve the GUIs on their hardware."
"For the AAD management feature, it needs to improve the objects that we can manage and the security."
"There are some features that we think should be included in their next release. We think these things would take them to the next level: the ability to completely force or limit any dynamic group processing to specific servers, change-tracking reporting of virtual attributes, and the ability to use files as inputs to automation workloads. These things have also been talked about. Knowing them, they're probably working on them."
"Another issue we have with the product is that we run a lot of custom tasks. You have to program them to run on one particular host and there's no automatic failover to a second host. If that host is down when a task is supposed to run, it has to wait until the next time it runs when that host is up."
"In terms of improvement, it could be made even more user-friendly for administrators when they need to create new workflows and rule sets."
"The way you can search groups could be better."
"It also has workflows and those are really powerful, but there are no built-in workflows. When it comes to them, it's empty. I would personally love for it to come with ten, 15, or 20 workflows where each achieves a certain task... I could just look at how each is done, clone them, copy them, modify them the way I want them, and be good to go. Right now we have to invent things from scratch."
"The ability to send logs to a SIEM would be very beneficial."
"The third area for improvement, which is the weakest portion of ARS, is the workflow engine, which was introduced a few years ago. It's slow and not very intuitive to use, so I would like to see improvement there."
 

Pricing and Cost Advice

"I have complaints. I don't enjoy the licensing model. Once we moved from 2.7 to 3.1, switching from Base, Plus, and Apex to Essential and Advantage in Premier, we went from a perpetual, with our base licenses, to now a subscription-base. So, we will have to renew those licenses every year, and I'm not a fan of that for our base licenses. Apex/Premier, we already expected, which is fine, but for basic connectivity, I am not a fan of that."
"The pricing is complicated."
"Being fully honest, the Cisco licensing model right now is really confusing. We don't know what licenses we have where. We have Smart licensing, but the different levels are way confusing."
"The price of the solution is price fair for the features you receive."
"According to my sales and account team, the prices we're getting are pretty good."
"Standard licensing gives backup access and very few features, and then there's VM licensing - each VM we use needs to be licensed."
"That's where things got a bit more complicated. Previously, it was a one-time purchase and we just had to renew support. These days, there's a subscription model, which is supposed to be easier and cheaper as well, but it's more pricey"
"ISE has always been expensive compared to other products in terms of what it does on a user level."
"The licensing model is a simple user-based model, not that much complicated."
"It's fairly priced."
"It's expensive."
"The pricing is on the higher end."
"The price is reasonable. It costs us about 1 million Danish kroner annually, and we also spend about half as much on consultants."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
801,634 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
16%
Government
8%
Financial Services Firm
7%
Computer Software Company
16%
Financial Services Firm
11%
Healthcare Company
9%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What is your experience regarding pricing and costs for One Identity Active Roles?
The solution is fairly priced. That said, I have nothing to compare it to.
What needs improvement with One Identity Active Roles?
The solution has not enabled us to reduce password reset times. It has not automated provisioning. The group attestation could be improved. It was a feature that was available in version 5. You can...
 

Also Known As

Cisco ISE
Quest Active Roles
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Find out what your peers are saying about Cisco, HPE Aruba Networking, Fortinet and others in Network Access Control (NAC). Updated: September 2024.
801,634 professionals have used our research since 2012.