

Find out in this report how the two Non-Human Identity Management (NHIM) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
One Identity Active Roles provides excellent reporting and auditing functionality, allowing administrators to track permissions, actions, and responsibilities effectively.
Automation has really reduced the time spent on user provisioning, access management, or access changes by around 40 to 60 percent, which has significantly improved team productivity.
User onboarding time reduced by around seventy to eighty percent, from thirty to forty-five minutes to under ten minutes.
It has also reduced the time spent on password management, saving our team time in managing privileged accounts, and is helping with automation that reduces manual efforts.
Instead of manually reconstructing activity, everything is already logged and searchable, which has improved response time during internal reviews.
It has reduced inside and external threats, which is essential for preventing privileged user damage, and decreased privileged account incidents by 40%.
They are ready to provide support at any time.
The support team is knowledgeable about the product and AD environments.
Everything is good, and I can give One Identity technical support a rating of ten.
Documentation and knowledge base resources are also useful for resolving common issues and understanding product features, making customer support reliable and meeting enterprise expectations.
The customer team is knowledgeable and technically strong, especially when dealing with configuration issues, session monitoring, or password-related queries.
I sometimes need escalations to reach expertise.
One Identity Active Roles works well in hybrid environments, handling both on-premises and cloud identities from a single platform.
It is commonly used in medium to large organizations managing complex Microsoft Active Directory and hybrid identity environments.
The platform can scale without needing a complete redesign.
The scalability of One Identity Safeguard is perfect, scoring ten out of ten.
The system can distribute tasks across nodes, improving performance as demand grows.
The platform is designed to support horizontal scaling, so adding capacity is relatively straightforward without redesigning the entire architecture.
Overall, One Identity Active Roles has proven to be a stable, reliable, and well-suited solution for managing Active Directory at scale.
Overall, I consider One Identity Active Roles to be a stable solution, suitable for enterprise-grade environments.
Consistently performing for daily operations like automation and user management without major downtime reported.
With proper sizing and high availability configuration, the system handles multiple concurrent sessions efficiently, making it a dependable and stable platform suitable for enterprise environments.
It appears designed as a dependable enterprise-grade solution, reflecting well in its production performance.
I would rate it a nine out of ten for stability.
I also want One Identity Active Roles to improve in their policy configuration area, which requires advanced expertise, and in the area of reporting, I want the reporting to be more basic, visible, and have the ability to export and customize options.
The current REST API feels like an afterthought, and my developers want the ability to operate through CI/CD pipelines instead of logging into the GUI.
Improving documentation and providing more guided implementation resources would help organizations accelerate deployment and reduce dependency on external support.
For some configurations on the SPS side, if I need to make changes, such as for DNS servers, I must redeploy the machine.
There are many steps. We are still in the onboarding phase, and it seems very manual.
Another area for improvement could be the threat detection capabilities, like those seen in other PAM vendors.
It is quite expensive, costing more than 50 euros per identity.
I think our total was in the seven-figure range for a couple of years of service.
The initial investment includes licensing, infrastructure setup, and implementation effort, with licensing typically based on the number of managed users or accounts, which can increase costs in large environments.
It is one of those where the more you buy, the cheaper it is.
It is cheaper than CyberArk.
Regarding pricing, it may appear slightly on the higher side initially compared to some alternatives, but when we evaluate it against the security benefits, compliance support, and risk reduction, it proves to be cost-effective in the long run.
It's improved our security posture. It has limited access to our crown jewels, where all our identities lie within Active Directory.
It helps in removing custom Active Directory delegation, which enhances security by eliminating unnecessary privileges, addressing identity-based breaches by reducing the number of Active Directory delegations.
Dynamic groups are also one of the best features, eliminating the need to add or manage members manually.
The auditing and approval mechanisms are features we did not have before and are greatly appreciated.
Automatic credential rotation helps our team by removing the need for manual changes to privileged passwords, reducing the risk of stale or shared credentials and ensuring that every access is controlled and compliant.
The password vault has been a game changer because it provides a secure and controlled way to store, manage, and rotate sensitive credentials without exposing them to users.
| Product | Mindshare (%) |
|---|---|
| One Identity Safeguard | 6.8% |
| One Identity Active Roles | 5.5% |
| Other | 87.7% |


| Company Size | Count |
|---|---|
| Small Business | 50 |
| Midsize Enterprise | 12 |
| Large Enterprise | 29 |
| Company Size | Count |
|---|---|
| Small Business | 63 |
| Midsize Enterprise | 25 |
| Large Enterprise | 30 |
One Identity Active Roles enhances Active Directory management by automating essential tasks and improving security through efficient delegation and role-based access control.
One Identity Active Roles offers advanced features for managing Active Directory environments, aiding in automating user provisioning, group management, and de-provisioning. It integrates seamlessly with Microsoft environments and provides centralized management for both on-premises and cloud identities. By improving operational efficiency and reducing manual errors, it enforces robust governance across organizations. Active Roles includes auditing and reporting tools that strengthen compliance and security monitoring. Companies find the setup could be simplified with better documentation, more customization options in reporting, and expanded cloud integration, particularly with Azure. Improved workflows and deeper native connectors are needed for seamless automation. Price adjustments and user-friendly analytics with intuitive dashboards are recommended for better usability.
What are the key features of One Identity Active Roles?Many industries deploy One Identity Active Roles for automating user lifecycle management, especially in Active Directory environments. It significantly eases operations by automating onboarding for new hires, managing role changes, and modifying access. The platform efficiently handles tasks like password resets and compliance audits while empowering teams to securely manage user access without requiring full administrative rights.
One Identity Safeguard manages and monitors privileged access, enhancing security with features like automatic session recording, real-time monitoring, and credential rotation. It integrates seamlessly, supports compliance with audit trails, and improves operational efficiency across organizations. This robust platform significantly bolsters security protocols while controlling sensitive operations.
We monitor all Non-Human Identity Management (NHIM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.