No more typing reviews! Try our Samantha, our new voice AI agent.

One Identity Active Roles vs OpenText Identity Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

One Identity Active Roles
Ranking in User Provisioning Software
3rd
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
38
Ranking in other categories
Active Directory Management (1st), Non-Human Identity Management (NHIM) (4th)
OpenText Identity Manager
Ranking in User Provisioning Software
8th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
18
Ranking in other categories
Identity Management (IM) (15th), Identity Governance Administration (IGA) (7th)
 

Mindshare comparison

As of April 2026, in the User Provisioning Software category, the mindshare of One Identity Active Roles is 6.4%, up from 6.2% compared to the previous year. The mindshare of OpenText Identity Manager is 3.8%, down from 4.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Provisioning Software Mindshare Distribution
ProductMindshare (%)
One Identity Active Roles6.4%
OpenText Identity Manager3.8%
Other89.8%
User Provisioning Software
 

Featured Reviews

SN
Identity and Access Management Specialist at a university with 10,001+ employees
Governed access has transformed user management and now reduces internal attack surface
The crown jewels of One Identity Active Roles that make my life as an architect easier are Access Templates, Virtual Attributes, Workflow and Approval Engine, and Managed Units, which allowed us to structure our directory into a policy-driven asset rather than constantly firefighting manual errors. Access Templates and Managed Units are the real secret sauce of One Identity Active Roles for us. Access Templates standardize permission settings, reducing security drift and allowing for the creation of modular permission bundles such as those I created for the Tier 1 help desk. Managed Units help me stay organized without rewriting the physical structure of the directory, saving me hours of cleanup. A critical feature that I found essential for a clean environment is Dynamic Group management, which prevents permission creep by using rule-defined group memberships rather than manual additions. One Identity Active Roles automatically manages group membership based on rules tied to the HR records. One Identity Active Roles has had a transformative impact on my organization, moving from controlled chaos to governed operations. The biggest win has been a reduction in the internal attack surface, achieving over a 40% reduction in unauthorized or accidental access attempts.
reviewer2401464 - PeerSpot reviewer
Architect at a consultancy with 51-200 employees
Updates systems quickly and does not have a limit on the number of users
NetIQ does not have a limit on the number of users. The tool is secure by nature. It can have more than one billion users. Event-based systems know what has to be changed. SQL-based systems can only change using time and date. Event-based systems provide immediate results, while SQL-based systems need time to sync. It is totally different from a security perspective. Event-based systems can update all the systems in seconds or minutes. Other systems do it within 24 hours. The basic event-based system is AI-driven. It has some kind of robotics and programming. Other tools need programming. I like systems that have prebuilt ideas of security. NetIQ has been in the market for a long period. It has all the systems and connectors. There is not much coding. We just need to configure the products. We need not do any programming. I haven't seen any other product that needs only configuration to do the job. Most products in the market are SQL-based. They need programming. Some service providers who sell other products to customers do not sell NetIQ because they can make more money by selling solutions that need more consultancy and programming. More hours lead to more money.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Because of Active Roles, we're able to synchronize on an even more regular basis. It enables us to provide even more information to the Active Directory, which helped us to group our users in a more consistent manner."
"It is an easier way for me to manage Active Directory with more advanced features."
"The AD and AAD management features of this solution are really good... They offer added value by showing more fields such as password age and the statuses of some things that we normally wouldn't see."
"Active Roles is easy to configure. It isn't a plug-and-play solution, and you need expertise to set it up. However, once you have your templates, it's easy to deploy in a highly decentralized environment. The custom configuration for our customers is fantastic, especially the web interface."
"Instead of deleting accounts, we like the deprovision option so that we can reverse any accidental deletions. It also gives a higher level of quality control in terms of enforcing any number of variables, such as making sure that an account has a description entered before the account can be created. We can backtrack and know the history of it that way."
"It gives us attribute-level control and the AD management features work very well."
"We have eased the burden on the support desk and reduced the risk of them doing something they shouldn't."
"Another good feature is the change history. It's centralized in a single place and allows us to manage people's Active Directory domains from a central location. We can also drill down into individual objects in a troubleshooting or even an auditing situation. We can show evidence to auditors by drilling down into the individual history. It gives you all the history of what happened around an individual object. That is something that would be almost impossible to do in Active Directory, or extremely complicated."
"Identity and access management processes have developed to become automatic and fast."
"I would recommend this product, its quite flexible and quick to start with."
"The Identity Engine is event-based and provides real-time synchronization and password synchronization to more than 40 different applications and services."
"The main value lies in the simplicity of implementation, as well as its customized look and feel."
"NetIQ Identity Manager is by far the most flexible product available, and the pricing is incredibly good, even if you're not situated in the BeNeLux."
"I like the eDirectory feature."
"To my knowledge it is the only event based IDM system."
"The most valuable feature of NetIQ Identity Manager for identity synchronization is the ability to provide users with all necessary access on day one through automated provisioning, facilitated by approval workflows."
 

Cons

"The third area for improvement, which is the weakest portion of ARS, is the workflow engine, which was introduced a few years ago. It's slow and not very intuitive to use, so I would like to see improvement there."
"The possibility to request group membership, similar to the past, was disabled and moved to Identity Manager."
"In terms of improvement, it could be made even more user-friendly for administrators when they need to create new workflows and rulesets."
"Active Roles could add more options for web customization. Our requirements are exceedingly specific. We'd like to get the web interface down to just five buttons, but in some cases, we can only get to six. The web interface in the current version is less customizable than in the previous one."
"The user and group management in Azure AD could be better. Our focus these days is dynamic sharing with several on-prem Microsoft applications like SharePoint."
"Integration capabilities are somewhere in the middle; it is not easy to integrate, but it is not the hardest thing out there."
"For the AAD management feature, it needs to improve the objects that we can manage and the security."
"The third area for improvement, which is the weakest portion of ARS, is the workflow engine, which was introduced a few years ago. It's slow and not very intuitive to use, so I would like to see improvement there."
"Areas for improvement are further enhancing the access granting process to reduce time and improve accuracy."
"There are some limitations in the custom workflows, mainly in the GUI presentation, but the latest release improved."
"NetIQ Identity Manager can improve the bulk account uploads, it's very slow. We work in the education sector, and every year we have approximately 20,000 accounts to create in a very short period, the NetIQ Identity Manager has a problem with this, we need to use a batch job."
"The vendor must provide an easier console for configuring things for smaller customers."
"The user facing interfaces are not too friendly and they are also fairly hard to configure."
"Technical support is average. When it's come to complex issues, it takes longer than expected to solve."
"It needs some modern features. They should improve and modernize their management interface."
"If it could be operated in such a way that anybody could use it, with just the user interface, and there's no need for programming, then that would be a great improvement."
 

Pricing and Cost Advice

"The pricing is on the higher end."
"The licensing model is a simple user-based model, not that much complicated."
"It's fairly priced."
"The price is reasonable. It costs us about 1 million Danish kroner annually, and we also spend about half as much on consultants."
"The pricing for Active Roles is expensive but not as expensive as other solutions like Okta."
"The pricing is high. I have not been involved with the renewal or cost aspect, but I know it is not cheap by any means. However, it is very useful for our environment."
"It's expensive."
"It would easily help them in getting more market and more customers if more consultants knew about their software. If they could keep it free for schools for teaching purposes, it would be good. I had to pay myself to get it and use it for training. Their competitors are giving it for free. I had to pay for it myself. They are losing market to their competitors."
"The price of the solution is a bit high and could be reduced."
"Micro Focus is flexible when it comes to price. The cost varies from customer to customer. There are no additional costs, though. Everything is included."
"The solution is quite affordable."
"You just need to be aware that the more systems you connect, the more license fees you have to pay."
"I would rate the pricing a two out of ten, with one being low price and ten being high price. It is significantly more cost-effective than the major players in the market."
report
Use our free recommendation engine to learn which User Provisioning Software solutions are best for your needs.
885,728 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
9%
Manufacturing Company
8%
Financial Services Firm
8%
University
7%
Manufacturing Company
9%
Computer Software Company
7%
Financial Services Firm
7%
Marketing Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business23
Midsize Enterprise7
Large Enterprise21
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise4
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for One Identity Active Roles?
I am aware of the pricing; it is on the expensive side, though pricing is not my department.
What needs improvement with One Identity Active Roles?
One Identity Active Roles can be improved by simplifying the setup process since a small team in a small business requires implementation without extensive IT support. Additionally, the pricing cou...
What is your primary use case for One Identity Active Roles?
One Identity Active Roles is used primarily to simplify and automate Active Directory user and permission management. The solution automates routine tasks such as account creation, password reset, ...
What do you like most about NetIQ Identity Manager?
The most valuable feature of NetIQ Identity Manager for identity synchronization is the ability to provide users with all necessary access on day one through automated provisioning, facilitated by ...
What is your experience regarding pricing and costs for NetIQ Identity Manager?
The pricing depends on whether we buy the solution as a service or a license. The license is expensive. If we buy it as a service for a large number of users, it is the cheapest tool we can get. Th...
What needs improvement with NetIQ Identity Manager?
The tool is used mostly in big systems to understand what is happening. There are not many technicians who know how to use the product. The vendor must provide an easier console for configuring thi...
 

Also Known As

Quest Active Roles
Novell Identity Manager
 

Overview

 

Sample Customers

City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Sheetz
Find out what your peers are saying about One Identity Active Roles vs. OpenText Identity Manager and other solutions. Updated: March 2026.
885,728 professionals have used our research since 2012.