We use Omada Identity for managing 99% of our employees and non-employee identities. We also use it for provisioning to Active Directory and across 12 different SAP systems and two other application integrations.
Omada provides us with a clear roadmap for getting additional features deployed. Our company, in particular, has been a key player in getting new features developed through the years. A lot of the features that are in their product today started as a custom enhancement implemented just for us, which they eventually rolled into the core product. We have been a customer for ten years, and their product has grown significantly in terms of feature set and so forth over the last ten years. A lot of that functionality started with us. Not all of it, of course.
We were able to realize its benefits immediately. Prior to Omada Identity, we did not have an identity access management platform in place. Everything was done manually. We did not even have a homegrown solution or anything. Identity management, account creation, and other similar things were done manually, so there were immediate benefits as one would expect. Of course, not everything was implemented all at once. We primarily started with Active Directory, so we started with primary identity management and so forth and then rolled in other things through the years, which was well before my time in the space.
Their identity analytics helped us make informed decisions, but we are running a much older version of their product. They have made a lot of progress over the last few years. We have not been able to take advantage of a lot of new functionality that has been implemented particularly around analytics.
Omada's solution is set up to remove an employee's access as soon as that employee leaves our organization. It has significantly impacted our security. Omada does its part very fast, and then we have to wait for replication across the main controllers and things like that, which could take up to an hour. We desire to do it immediately. We would like people to lose access immediately, and Omada does its part, but the rest of our infrastructure is not always immediate due to replication and so forth. That is huge from a security perspective because we have use cases all the time with regard to employees or non-employees leaving abruptly and in a manner where you need to cut off access immediately. Prior to Omada, it required a lot of phone calls and manual steps to make it happen and usually not at convenient times.
We have used Omada's certification surveys to recertify roles or to determine if roles are relevant. That is one of my primary roles. I am on the governance side, so I am well-versed in their recertification capabilities. We have a variety of different ones that we run at different intervals. Most of them are semiannual, but, of course, we deal with the same challenges as every other organization. That has nothing to do with the tool itself. It is with regards to people rubber-stamping access and so forth.
We use Omada for role-based access control in a very limited way. The capability is there. We would like to do more, but anybody who knows anything about role-based access control knows that the tool is the easiest part. The business processes are the hardest part. It is hard to get people to define their access model so that you can use a tool to implement that access model. We are very limited when it comes to role-based access control. It is mostly for high-level birthright type of access and so forth.
It has very much helped us save time when provisioning access for identities, but it is difficult for me to provide any metrics because we have been doing it for so long. We do not have people, either employees or as part of managed services, who are in roles to do this on a regular basis.
Omada Identity has helped us consolidate disparate systems for access management.
Omada Identity has also helped us to automate reviews of access requests and reroute them to the appropriate people. It is hard to compare how it affects our help-desk workload involving access requests because we have been doing it for so long, but it certainly avoids a significant number of calls to the help desk. If this was done manually, there would be calls to our help desk. It will either be done by the help desk or escalated to an applicable tier-two support team.
They have gotten better in terms of the comprehensiveness of the out-of-the-box connectors. They do not have as extensive a connector portfolio as SailPoint does, but they have enough to meet our needs. They have the basics, and we do not need a lot of connectors to various applications because we have an access model that is highly dependent on Active Directory groups for access management. Omada Identity Suite does very well in managing AD resources.
Technically, the product does everything one would expect from an identity and access management platform. The product offers robust handling of Active Directory resources.
The ease of working with Omada itself is commendable. They have been a great partner of ours for ten years, and it is clear they fully understand the identity space.
The biggest issue, which is the reason why we are transitioning from their product to SailPoint, is the overall user experience. From a technical perspective, it is a very good product, but from an end-user experience perspective, it significantly lacks. Although they have made some improvements over the last few years, it is still not on par with many of their competitors, particularly SailPoint. We have gotten so much negative feedback through the years on users not being able to effectively use the system. It was not always intuitive, so our leadership wanted a change.
We have used the solution for about ten years.
We do not contact their technical support directly because we have a service agreement already in place with them with some dedicated and some non-dedicated resources. We work through them if they need to escalate anything to the development or the level 3 support team. We never have to do that directly.
We are in the process of migrating from Omada Identity Suite to SailPoint IdentityIQ due to the need for a better user experience.
We did an evaluation and looked at some of the other key players in the space but quickly settled on SailPoint.
From an implementation perspective, we had Omada resources who did the implementation. They do our support and all of our upgrade work. Omada does not have a lot of partners out there.
In terms of upgrades, the tool itself is not easy or hard. It is probably comparable to other identity solutions. For us, it is extremely difficult because of the detailed and thorough regression testing that we do for any upgrades, but that would be the case for any solution.
Early on, we did a lot of customization of the product that we had to go in and regression test everything, which made it extremely difficult. That is not Omada's fault. That is on us.
Being an on-prem solution, it does require maintenance. I would have loved to have gone to the Omada cloud product, but being an on-prem solution, there is regular support maintenance. We use Omada as a managed service provider for us, and they do a very good job with that.
They are positioned at a good price point. They are lower than some of their competitors.
I would rate Omada Identity an eight out of ten. The reason why I would not give it a nine or a ten has to do with the user experience.