No more typing reviews! Try our Samantha, our new voice AI agent.

Active Roles by One Identity vs Entro Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 20, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Active Roles by One Identity
Ranking in Non-Human Identity Management (NHIM)
1st
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
90
Ranking in other categories
User Provisioning Software (3rd), Active Directory Management (1st)
Entro Security
Ranking in Non-Human Identity Management (NHIM)
4th
Average Rating
9.6
Reviews Sentiment
8.4
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2026, in the Non-Human Identity Management (NHIM) category, the mindshare of Active Roles by One Identity is 6.5%, up from 2.7% compared to the previous year. The mindshare of Entro Security is 8.1%, up from 7.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Non-Human Identity Management (NHIM) Mindshare Distribution
ProductMindshare (%)
One Identity Active Roles6.5%
Entro Security8.1%
Other85.4%
Non-Human Identity Management (NHIM)
 

Featured Reviews

Varun Mehra - PeerSpot reviewer
collaboration support engineer at a retailer with 11-50 employees
Automation has transformed onboarding and access control and now streamlines daily governance
While One Identity Active Roles is a strong identity and access management solution overall, there are a few areas where it could improve. One challenge we experienced was the initial setup and configuration complexity. Deploying workflows, policies, and delegation models require careful planning and a good understanding of the Active Directory environment. For organizations without experienced administrators, the learning curve can feel quite steep in the beginning. The user interface could also be more modern and intuitive. Some administrative tasks require navigating through multiple menus and the overall experience could be simplified for faster day-to-day management. Another area for improvement is reporting and customization. While the auditing features are good, creating highly customized reports sometimes requires additional efforts or scripting knowledge. More built-in reporting templates and easier dashboard customization would be helpful. We have also noticed that troubleshooting workflows or synchronization issues can occasionally take time because the logs can be very detailed and technical. Better diagnostic tools and simpler error explanations would improve the operational experience. That said, once the platform is properly configured and maintained, it performs reliably and delivers strong automation, delegation, and governance capabilities. One additional area where One Identity Active Roles could improve is cloud integration and hybrid environment management. While it works well with Active Directory and the Microsoft environment, organizations moving heavily towards cloud-first infrastructure may want even deeper and more seamless integration with modern SaaS platforms and identity providers. Performance optimization in large environments could be improved. In very large enterprise deployments with complex workflows and multiple managed domains, some administrative actions and synchronization tasks can occasionally feel slower than expected. Another point is documentation and onboarding resources. The product is feature-rich, but some advanced configurations require going through extensive documentation. More practical examples, guided setup wizards, and easier to follow best practice guides would help new administrators adopt the platform faster. Overall, the core functionality is solid, and most of the pain points are related more to usability, complexity, and modernization rather than the reliability. One additional improvement I would mention is around integration flexibility with third-party ITSM and DevOps tools. While the platform integrates well within Microsoft-centric environments, broader out-of-the-box integration and simpler API workflows for non-Microsoft ecosystems would make deployment and automation easier for organizations using diverse infrastructure. Another area is upgrade and migration simplicity. In enterprise environments, version upgrades and environment migration sometimes require careful planning and testing. Streamlining that process with more automated compatibility checks and migration assistance would reduce operational overhead.
YL
Cybersecurity Analyst at a hospitality company with 1,001-5,000 employees
We get improved visibility and excellent support but require better detection of custom data
Reduction in the attack surface is the main benefit. We have not worked with it much yet, but so far, it has been good. It can be improved a bit more in the future, but so far, we have just scratched the surface with Entro Security. Entro Security has helped develop a better culture among developers. They are willing and starting to use something called Vault to store credentials, and they even do it without us telling them. In the past, they used to post everything like in ClearText, whereas now, they are voluntarily migrating the information to Vault. I am pretty sure it is because Entro Security is also annoying them. Every time there is a finding, we ping them via Slack. The ping comes from Entro itself. They do not want to be bothered by messages. They do not want to be seen as a bad employee, so they are using it on their own. It is not hard for us to establish behavioral baselines for non-human identities (NHI) in Entro Security. It is important that Entro Security’s detection and mitigation of NHI threats is done in real-time. It is becoming a worldwide issue, not only in our company. So many companies are trying to solve this issue where developers are posting credentials in plain text. It is of very high priority. It is not critical, but it is highly important. Entro Security has improved visibility, revealing the extent of our credential issues, where strong credentials like admin accounts were found in plaintext in numerous projects. We have more visibility and control. We got to know that the issue was much bigger than we thought. We thought that only one out of ten projects would have some kind of password, but we found more than five to seven projects having plain text credentials. The credentials stored were of strong accounts. They had put admin account information in plain text. We did not think it would be this severe. We thought that, at worst, they would be some maintainer credentials, but they were using full admin credentials in their code and had put them just in plain text. Entro Security has helped improve our organization’s security posture. Entro Security has decreased our exposure to risk. It reduces exposure from the inside, not from the outside.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Having a tool to manage all changes to AD from a single pane of glass is awesome."
"We have definitely seen a strong return on investment after implementing One Identity Active Roles, mainly in terms of time saving, reduced workload, and improved efficiency, where user provisioning and access requests that earlier took hours are now completed in a few minutes through automation, and we observe around a 40 to 50% reduction in service desk tickets related to Active Directory tasks, which allows the team to focus on more critical activities instead of repetitive work, while delegation reduces dependency on senior administrators, indirectly saving manpower effort, and overall, the reduction in errors, faster onboarding, and improved compliance also contribute to cost savings and operational efficiency, making it a valuable investment for the organization."
"One Identity Active Roles has impacted my organization positively by reducing manual work, improving security, saving administrative time, and reducing human errors."
"One positive impact we noticed from One Identity Active Roles was improved operational efficiency; earlier, many user management tasks were handled manually, which took more time and sometimes created inconsistencies, but using intelligent role-based workflows and automation made onboarding and access modification faster and more standardized, and we also saw better control over privileged access since permissions were delegated properly, reducing high-level administrative rights, which improved accountability and balanced security with operational speed."
"In comparison to native Active Directory tools, using Active Roles for delegation is so much better. It uses an access template and that makes it easy to see who can access what. In fact, you can do that for many objects as well."
"We have two staff members and so per staff member, Active Roles saves us 0.2 FTE."
"One Identity Active Roles has had a very positive impact on our organization, especially in terms of productivity, security, and compliance."
"One Identity Active Roles brings a positive impact to organizations in that they will start realizing the ROI in a much faster manner because the implementation time is very short and it is easy to use."
"They are very helpful and responsive. They acknowledge issues, take feedback seriously, and implement features based on user requests."
"The top features of Entro Security that stand out are its ease of onboarding and discovery."
"Entro Security's free evaluation managed to find thousands of secrets, which was a game-changer for us."
"Entro Security has helped develop a better culture among developers."
 

Cons

"The solution needs an attestation process that includes certification and recertification attestation."
"One area where One Identity Active Roles can be improved is in the user interface. It can feel outdated and not very intuitive for new users."
"We don't get a lot of communication from the One Identity side. I don't know who our account representative is, and that is kind of not good since we have had some turnover there."
"Another issue we have with the product is that we run a lot of custom tasks. You have to program them to run on one particular host and there's no automatic failover to a second host. If that host is down when a task is supposed to run, it has to wait until the next time it runs when that host is up."
"The user interface needs to be more modern and scalable. There are certain screen resolutions where the product is unusable."
"When doing a workflow, we would like a bit better feedback on the screen, as we're trying to get it to work."
"One area where One Identity Active Roles could be improved is troubleshooting and visibility."
"When doing a workflow, we would like a bit better feedback on the screen, as we're trying to get it to work. For example, there is a "Find" function that you need set up in a workflow to do some of the automation. It is not the easiest to get a result from those finds when you're trying to do that. In the MMC, they have a couple different types of workflows. In this particular case, we use their workflow functionality to find all of X within the environment, then if you find it, do X, Y, and Z. You can have multiple steps. When you do that search function within that workflow, it's really hard to find out, "Is my search working?" It would be nice if there was some feedback on the screen so you could see if your search is working properly within the workflow."
"Entro Security could benefit from improvements in IAM control to allow segregation of duties among developers."
"The detection of generic content or custom data specific to our company needs improvement. It has trouble detecting unique patterns of secrets."
 

Pricing and Cost Advice

"The pricing is on the higher end."
"The pricing for Active Roles is expensive but not as expensive as other solutions like Okta."
"It's fairly priced."
"It's expensive."
"The licensing model is a simple user-based model, not that much complicated."
"The price is reasonable. It costs us about 1 million Danish kroner annually, and we also spend about half as much on consultants."
"The pricing is high. I have not been involved with the renewal or cost aspect, but I know it is not cheap by any means. However, it is very useful for our environment."
Information not available
report
Use our free recommendation engine to learn which Non-Human Identity Management (NHIM) solutions are best for your needs.
905,526 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
24%
Financial Services Firm
8%
Computer Software Company
7%
Manufacturing Company
6%
Wholesaler/Distributor
17%
Computer Software Company
13%
Hospitality Company
10%
Healthcare Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business96
Midsize Enterprise14
Large Enterprise44
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for One Identity Active Roles?
I wasn't directly involved in the pricing or licensing decisions, so I cannot comment on the exact cost. For our operations, I believe the investment was considered worthwhile because the product r...
What needs improvement with One Identity Active Roles?
I think One Identity Active Roles is a mature and reliable solution, but there are a few areas where it could be improved. The biggest one is the management interface, which feels dated compared to...
What is your primary use case for One Identity Active Roles?
Our main use case for One Identity Active Roles is to simplify and standardize Active Directory administration across multiple business units while reducing the amount of manual work handled by our...
What is your experience regarding pricing and costs for Entro Security?
Entro Security is not the cheapest solution. However, I am willing to pay for quality cybersecurity products. We received a good discount this year, which significantly reduced the price. Next year...
What needs improvement with Entro Security?
Entro Security could benefit from improvements in IAM control to allow segregation of duties among developers. Providing a more modular alerting system to have proactive measures without extensive ...
What is your primary use case for Entro Security?
I am a Security Engineer at a company called Regatta. We started using Entro Security to address a request from one of the head developers to gain control over secrets and identities. We initially ...
 

Also Known As

Quest Active Roles
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Paramount, Agoda, Dropbox, Kayak, Elastic, Fubo, SafeBreach, Sprinklr, Aqua, Mastech Digital, Solarwinds, Crum&Forster, Regatta Group, ISO New England, Nasuni, Maccabi Healthcare Services
Find out what your peers are saying about Active Roles by One Identity vs. Entro Security and other solutions. Updated: June 2026.
905,526 professionals have used our research since 2012.