Try our new research platform with insights from 80,000+ expert users

One Identity Active Roles vs OpenText Identity Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 28, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

One Identity Active Roles
Ranking in User Provisioning Software
5th
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
29
Ranking in other categories
Active Directory Management (1st), Non-Human Identity Management (NHIM) (4th)
OpenText Identity Manager
Ranking in User Provisioning Software
9th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
18
Ranking in other categories
Identity Management (IM) (17th)
 

Mindshare comparison

As of January 2026, in the User Provisioning Software category, the mindshare of One Identity Active Roles is 5.6%, up from 4.5% compared to the previous year. The mindshare of OpenText Identity Manager is 3.2%, down from 3.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Provisioning Software Market Share Distribution
ProductMarket Share (%)
One Identity Active Roles5.6%
OpenText Identity Manager3.2%
Other91.2%
User Provisioning Software
 

Featured Reviews

reviewer2789802 - PeerSpot reviewer
Director, Identity & M365 Engineering at a healthcare company with 10,001+ employees
Granular delegated access has strengthened least privilege control across complex directories
One of the things I would like to see more robust is the change history. One Identity Active Roles can only monitor changes that happen in the console, and the logs don't go back longer than thirty days, maybe sixty days. The change history, when we've seen accounts get modified, we leverage a container domain that funnels accounts into our Active Directory console. I would like to see from an initial user provisioning perspective, for them to isolate the workflow and say that this came in on X date and account was created. If anyone were to modify that account from an external resource, I would like to be able to read that as well. One Identity Active Roles is strictly limited to the console. If someone makes a change, the history of those changes is not as long as I would prefer.
reviewer2401464 - PeerSpot reviewer
Architect at a consultancy with 51-200 employees
Updates systems quickly and does not have a limit on the number of users
NetIQ does not have a limit on the number of users. The tool is secure by nature. It can have more than one billion users. Event-based systems know what has to be changed. SQL-based systems can only change using time and date. Event-based systems provide immediate results, while SQL-based systems need time to sync. It is totally different from a security perspective. Event-based systems can update all the systems in seconds or minutes. Other systems do it within 24 hours. The basic event-based system is AI-driven. It has some kind of robotics and programming. Other tools need programming. I like systems that have prebuilt ideas of security. NetIQ has been in the market for a long period. It has all the systems and connectors. There is not much coding. We just need to configure the products. We need not do any programming. I haven't seen any other product that needs only configuration to do the job. Most products in the market are SQL-based. They need programming. Some service providers who sell other products to customers do not sell NetIQ because they can make more money by selling solutions that need more consultancy and programming. More hours lead to more money.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Another good feature is the change history. It's centralized in a single place and allows us to manage people's Active Directory domains from a central location. We can also drill down into individual objects in a troubleshooting or even an auditing situation. We can show evidence to auditors by drilling down into the individual history. It gives you all the history of what happened around an individual object. That is something that would be almost impossible to do in Active Directory, or extremely complicated."
"The solution is stable."
"Because of Active Roles, we're able to synchronize on an even more regular basis. It enables us to provide even more information to the Active Directory, which helped us to group our users in a more consistent manner."
"The provisioning and deprovisioning saves a lot of time and skips a lot of errors."
"One Identity Active Roles absolutely helps reduce identity-based breaches, making it very seamless for our user base to ensure that folks in specific positions have the least privileged access possible across our for-profit healthcare conglomerate with thirty states and over fifty community hospitals under a single Active Directory domain."
"One Identity Active Roles has helped my organization reduce the number of incorrect privileged accounts through the management unit feature and enables comprehensive group membership management with features not available in Active Directory, such as adding multiple secondary owners and dynamic groups."
"With the use of the sync service we were able to import information from multiple external systems and populate them within our space and leverage them for downstream systems."
"The access templates help set up granular permissions and the web portal to manage Active Directory."
"It's a very flexible tool, so you can synchronize multiple sources of data and you have multiple connections to various kinds of systems."
"I like the eDirectory feature."
"The main value lies in the simplicity of implementation, as well as its customized look and feel."
"The product is easy to use."
"The most valuable features of NetIQ Identity Manager are the synchronization of different directories, such as Active Directory. We have many Active Directory systems, not only one."
"The most valuable feature of NetIQ Identity Manager for identity synchronization is the ability to provide users with all necessary access on day one through automated provisioning, facilitated by approval workflows."
"The most valuable feature of this solution has been the ability for us to integrate a lot of external systems, and the automatic transfer of a lot of identity information. Additionally, the customization is very good."
"The access request management has improved significantly in terms of its user interface. What sets it apart from competitors like SailPoint is that it's an event-based solution rather than schedule-based. That's a key differentiator."
 

Cons

"For the AAD management feature, it needs to improve the objects that we can manage and the security."
"There is always room to improve the user interface for increased clarity. I believe enhancements to the console are also necessary because it is more confusing than the web interface."
"There are some features that we think should be included in their next release. We think these things would take them to the next level: the ability to completely force or limit any dynamic group processing to specific servers, change-tracking reporting of virtual attributes, and the ability to use files as inputs to automation workloads. These things have also been talked about. Knowing them, they're probably working on them."
"The initial setup was quite easy, but it was time-consuming. It took about three months."
"The solution needs an attestation process that includes certification and recertification attestation."
"The possibility to request group membership, similar to the past, was disabled and moved to Identity Manager."
"If One Identity Active Roles has to be positioned for all customers, not just the entities which are being regulated, then the pricing has to be normalized."
"Additional documentation about the Angular web interface is needed."
"Areas for improvement are further enhancing the access granting process to reduce time and improve accuracy."
"There's no huge thing missing, because it's already comprehensive. Now and then, however, there might be a minor issue."
"The interface is old and outdated, and the design software seems archaic."
"The solution architecture is somewhat complex. For some components, the necessary resilience is not inherent."
"The integrations must be made easier."
"It needs some modern features. They should improve and modernize their management interface. It has been created over years and by different persons. You can see different applications, different management consoles for different things. There should be an integrated interface."
"If it could be operated in such a way that anybody could use it, with just the user interface, and there's no need for programming, then that would be a great improvement."
"NetIQ Identity Manager could improve by updating the user portal, it is out of date."
 

Pricing and Cost Advice

"The pricing for Active Roles is expensive but not as expensive as other solutions like Okta."
"The pricing is on the higher end."
"The licensing model is a simple user-based model, not that much complicated."
"The price is reasonable. It costs us about 1 million Danish kroner annually, and we also spend about half as much on consultants."
"It's fairly priced."
"The pricing is high. I have not been involved with the renewal or cost aspect, but I know it is not cheap by any means. However, it is very useful for our environment."
"It's expensive."
"It would easily help them in getting more market and more customers if more consultants knew about their software. If they could keep it free for schools for teaching purposes, it would be good. I had to pay myself to get it and use it for training. Their competitors are giving it for free. I had to pay for it myself. They are losing market to their competitors."
"The solution is quite affordable."
"You just need to be aware that the more systems you connect, the more license fees you have to pay."
"I would rate the pricing a two out of ten, with one being low price and ten being high price. It is significantly more cost-effective than the major players in the market."
"Micro Focus is flexible when it comes to price. The cost varies from customer to customer. There are no additional costs, though. Everything is included."
"The price of the solution is a bit high and could be reduced."
report
Use our free recommendation engine to learn which User Provisioning Software solutions are best for your needs.
879,768 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Healthcare Company
9%
Financial Services Firm
9%
Manufacturing Company
8%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise4
Large Enterprise19
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise4
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for One Identity Active Roles?
The product is expensive, but if you want to save money, the delegation set-up process is quite easy. After setting up Active Roles once, defining the delegation model, it is very efficient, almost...
What needs improvement with One Identity Active Roles?
The interface appears outdated. Once logged in, everything inside remains unchanged from years ago. Additionally, when they release new features, they should provide training or webinars at least o...
What is your primary use case for One Identity Active Roles?
I use One Identity Active Roles primarily for identity management. We use it for managing multiple domains from a single interface, and the domains do not have trust between them. It has been used ...
What do you like most about NetIQ Identity Manager?
The most valuable feature of NetIQ Identity Manager for identity synchronization is the ability to provide users with all necessary access on day one through automated provisioning, facilitated by ...
What is your experience regarding pricing and costs for NetIQ Identity Manager?
The pricing depends on whether we buy the solution as a service or a license. The license is expensive. If we buy it as a service for a large number of users, it is the cheapest tool we can get. Th...
What needs improvement with NetIQ Identity Manager?
The tool is used mostly in big systems to understand what is happening. There are not many technicians who know how to use the product. The vendor must provide an easier console for configuring thi...
 

Also Known As

Quest Active Roles
Novell Identity Manager
 

Overview

 

Sample Customers

City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Sheetz
Find out what your peers are saying about One Identity Active Roles vs. OpenText Identity Manager and other solutions. Updated: December 2025.
879,768 professionals have used our research since 2012.