No more typing reviews! Try our Samantha, our new voice AI agent.

Active Roles by One Identity vs IBM Tivoli Access Manager [EOL] comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 20, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Active Roles by One Identity
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
90
Ranking in other categories
User Provisioning Software (3rd), Active Directory Management (1st), Non-Human Identity Management (NHIM) (1st)
IBM Tivoli Access Manager [...
Average Rating
8.0
Reviews Sentiment
3.8
Number of Reviews
29
Ranking in other categories
No ranking in other categories
 

Featured Reviews

Varun Mehra - PeerSpot reviewer
collaboration support engineer at a retailer with 11-50 employees
Automation has transformed onboarding and access control and now streamlines daily governance
While One Identity Active Roles is a strong identity and access management solution overall, there are a few areas where it could improve. One challenge we experienced was the initial setup and configuration complexity. Deploying workflows, policies, and delegation models require careful planning and a good understanding of the Active Directory environment. For organizations without experienced administrators, the learning curve can feel quite steep in the beginning. The user interface could also be more modern and intuitive. Some administrative tasks require navigating through multiple menus and the overall experience could be simplified for faster day-to-day management. Another area for improvement is reporting and customization. While the auditing features are good, creating highly customized reports sometimes requires additional efforts or scripting knowledge. More built-in reporting templates and easier dashboard customization would be helpful. We have also noticed that troubleshooting workflows or synchronization issues can occasionally take time because the logs can be very detailed and technical. Better diagnostic tools and simpler error explanations would improve the operational experience. That said, once the platform is properly configured and maintained, it performs reliably and delivers strong automation, delegation, and governance capabilities. One additional area where One Identity Active Roles could improve is cloud integration and hybrid environment management. While it works well with Active Directory and the Microsoft environment, organizations moving heavily towards cloud-first infrastructure may want even deeper and more seamless integration with modern SaaS platforms and identity providers. Performance optimization in large environments could be improved. In very large enterprise deployments with complex workflows and multiple managed domains, some administrative actions and synchronization tasks can occasionally feel slower than expected. Another point is documentation and onboarding resources. The product is feature-rich, but some advanced configurations require going through extensive documentation. More practical examples, guided setup wizards, and easier to follow best practice guides would help new administrators adopt the platform faster. Overall, the core functionality is solid, and most of the pain points are related more to usability, complexity, and modernization rather than the reliability. One additional improvement I would mention is around integration flexibility with third-party ITSM and DevOps tools. While the platform integrates well within Microsoft-centric environments, broader out-of-the-box integration and simpler API workflows for non-Microsoft ecosystems would make deployment and automation easier for organizations using diverse infrastructure. Another area is upgrade and migration simplicity. In enterprise environments, version upgrades and environment migration sometimes require careful planning and testing. Streamlining that process with more automated compatibility checks and migration assistance would reduce operational overhead.
it_user711612 - PeerSpot reviewer
Senior Consultant at a insurance company with 1,001-5,000 employees
Reverse proxy provides central control over authentication and authorization.
It is a single product that caters for all the business needs throughout the organization. It provides a seamless integration that in turn encourages most of the applications to use the SSO features Reverse proxy is the most valuable feature as it provides central control over authentication and…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Previously, I was handling a 100 percent workload, but after using One Identity Active Roles, 70 percent of my load has been resolved."
"The provisioning and deprovisioning saves a lot of time and skips a lot of errors."
"I saw a strong ROI with One Identity Active Roles through around a forty to fifty percent reduction in service desk workload, faster user provisioning from hours to minutes, fewer manual errors, and improved compliance and audit efficiency, which saves significant administrative time and operational efforts."
"Since we have implemented One Identity Active Roles, we have seen significant improvements, with faster user management, better control over Active Directory, reduced errors, and improved security."
"One Identity Active Roles has significantly reduced both the complexity and workload of administrative tasks related to Active Directory; many repetitive tasks are automated, so admins spend much less time on routine activities."
"One Identity Active Roles has had a very positive impact on our organization, mainly by improving efficiency and security at the same time."
"With the use of the sync service we were able to import information from multiple external systems and populate them within our space and leverage them for downstream systems."
"One Identity Active Roles has significantly reduced the complexity and workload of administrative tasks related to Active Directory, as routine tasks like user creation, password resets, and access changes are automated or delegated, saving time and reducing manual efforts while making management more structured and consistent, making overall administration easier and more efficient."
"I like the primary function of this product allowing the administration of user/network accounts with a fair amount of ease."
"Centralized policy management and reverse proxy-based architecture make it very flexible in terms of deployment, adoption, and implementation."
"It is a totally secure way of accessing clients through various application portals for more than ten EU countries, just by using single sign-on."
"It is one of the best products in the present market in the area of access management."
"The SSO, URL-based access control, OAuth 2 and OIDC are the most valuable features."
"Some of the valuable features are: Reverse proxy Protected object space Ease of integration Multiple and robust AuthN and AuthZ mechanisms built-in No single point of failure (SPOF)"
"Tivoli Access Manager's proxy product (WebSEAL) is extremely fast."
"It provides good scalability and reliability, not to mention the overall availability of the service."
 

Cons

"A few improvements I would like to see in One Identity Active Roles are mainly around usability, reporting, and modern integration."
"One Identity Active Roles is a mature and reliable product, but there are definitely areas where it could be improved."
"One area for improvement would be the initial setup, which feels a little bit complex and could be simplified."
"One area is the user interface and administrative experience. While the platform is feature-rich, some workflows and configuration screens can feel complex for new administrators, especially in large enterprise environments with extensive policy configurations."
"When doing a workflow, we would like a bit better feedback on the screen, as we're trying to get it to work."
"The initial setup of One Identity Active Roles can be more simplified."
"Most of the time it just works."
"I think its governance and security are very good. If they use a third party as an AI, the security may be compromised. However, if they are using their inbuilt assistance, it gives a very good result."
"What I don’t particularly like is the flow duration."
"The whole product could be made into one suite instead of multiple components which are essentially a part of the same infrastructure."
"We have had stability issues lately with the hardware and SAN that the product runs on."
"The product has not been updated with emerging technologies over the years specifically around AJAX, REST and Mobile app integration."
"The self-service portal needs improvement."
"Older TAM versions are not compatible for connecting to a DB."
"Complex to install and run."
"Administration of the product can be improved a lot."
 

Pricing and Cost Advice

"It's fairly priced."
"The pricing is high. I have not been involved with the renewal or cost aspect, but I know it is not cheap by any means. However, it is very useful for our environment."
"It's expensive."
"The licensing model is a simple user-based model, not that much complicated."
"The pricing for Active Roles is expensive but not as expensive as other solutions like Okta."
"The pricing is on the higher end."
"The price is reasonable. It costs us about 1 million Danish kroner annually, and we also spend about half as much on consultants."
"The IBM prices are, as ever, extortionate, even with a business partnership, and high levels of discounts."
report
Use our free recommendation engine to learn which User Provisioning Software solutions are best for your needs.
906,829 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
24%
Financial Services Firm
8%
Computer Software Company
8%
Manufacturing Company
6%
Construction Company
15%
Financial Services Firm
14%
Outsourcing Company
11%
Marketing Services Firm
11%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business97
Midsize Enterprise14
Large Enterprise45
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise18
 

Questions from the Community

What is your experience regarding pricing and costs for One Identity Active Roles?
I wasn't directly involved in the pricing or licensing decisions, so I cannot comment on the exact cost. For our operations, I believe the investment was considered worthwhile because the product r...
What needs improvement with One Identity Active Roles?
I think One Identity Active Roles is a mature and reliable solution, but there are a few areas where it could be improved. The biggest one is the management interface, which feels dated compared to...
What is your primary use case for One Identity Active Roles?
Our main use case for One Identity Active Roles is to simplify and standardize Active Directory administration across multiple business units while reducing the amount of manual work handled by our...
Ask a question
Earn 20 points
 

Also Known As

Quest Active Roles
Tivoli Access Manager, IBM Security Access Manager
 

Overview

 

Sample Customers

City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Essex Technology Group Inc.
Find out what your peers are saying about One Identity, SailPoint, Omada and others in User Provisioning Software. Updated: July 2026.
906,829 professionals have used our research since 2012.