

Active Roles and One Identity Safeguard compete in the identity and security management space. Active Roles gains an edge with its automation of Active Directory tasks, while Safeguard excels in robust security through password vaulting and session monitoring.
Features: Active Roles provides automation of Active Directory tasks, role-based access control, and enhanced security management, significantly reducing manual efforts. One Identity Safeguard offers privileged access management with password vaulting, session monitoring, and detailed auditing, emphasizing strong security measures.
Room for Improvement: Active Roles could improve its user interface, simplify reporting customizations, and enhance cloud integration capabilities. One Identity Safeguard may benefit from a more intuitive interface, better documentation for complex configurations, and improved integration with modern cloud platforms and third-party applications.
Ease of Deployment and Customer Service: Active Roles typically involves on-premises setups, requiring careful planning but delivering automation benefits. Customer support is knowledgeable, though response times can vary for technical issues. One Identity Safeguard is commonly deployed in a hybrid model, leveraging both on-premises and cloud capabilities, with strong support and deployment assistance ensuring minimal disruption.
Pricing and ROI: Active Roles is priced at an enterprise level, justified by operational efficiency and automation savings, despite high initial costs. Users report reduced administrative workload and faster provisioning times. One Identity Safeguard, similarly enterprise-priced, delivers significant risk reduction and compliance benefits, making it a valuable investment for high-security environments.
One Identity Active Roles provides excellent reporting and auditing functionality, allowing administrators to track permissions, actions, and responsibilities effectively.
Automation has really reduced the time spent on user provisioning, access management, or access changes by around 40 to 60 percent, which has significantly improved team productivity.
User onboarding time reduced by around seventy to eighty percent, from thirty to forty-five minutes to under ten minutes.
It has also reduced the time spent on password management, saving our team time in managing privileged accounts, and is helping with automation that reduces manual efforts.
Instead of manually reconstructing activity, everything is already logged and searchable, which has improved response time during internal reviews.
After implementing One Identity Safeguard, we saw a significant drop in manual tasks including password handling, privileged access approvals, and incident troubleshooting.
They are ready to provide support at any time.
The support team is knowledgeable about the product and AD environments.
Support is usually responsive for critical issues and provides solid practical guidance for AD workflow problems.
Documentation and knowledge base resources are also useful for resolving common issues and understanding product features, making customer support reliable and meeting enterprise expectations.
The customer team is knowledgeable and technically strong, especially when dealing with configuration issues, session monitoring, or password-related queries.
I rate support from 1 to 10 overall as 9 because compared to other customer PAM solutions that we have like iRage PAM and Commvault PAM, this is superior and offers a more advanced procedure.
One Identity Active Roles works well in hybrid environments, handling both on-premises and cloud identities from a single platform.
It is commonly used in medium to large organizations managing complex Microsoft Active Directory and hybrid identity environments.
The platform can scale without needing a complete redesign.
The scalability of One Identity Safeguard is perfect, scoring ten out of ten.
The system can distribute tasks across nodes, improving performance as demand grows.
The platform is designed to support horizontal scaling, so adding capacity is relatively straightforward without redesigning the entire architecture.
Overall, One Identity Active Roles has proven to be a stable, reliable, and well-suited solution for managing Active Directory at scale.
Overall, I consider One Identity Active Roles to be a stable solution, suitable for enterprise-grade environments.
Consistently performing for daily operations like automation and user management without major downtime reported.
With proper sizing and high availability configuration, the system handles multiple concurrent sessions efficiently, making it a dependable and stable platform suitable for enterprise environments.
I would rate it a nine out of ten for stability.
In terms of stability, I rate One Identity Safeguard nine to ten out of ten.
The current REST API feels like an afterthought, and my developers want the ability to operate through CI/CD pipelines instead of logging into the GUI.
Improving documentation and providing more guided implementation resources would help organizations accelerate deployment and reduce dependency on external support.
Stronger, more seamless integration with cloud and hybrid environments like Azure AD, along with enhanced real-time reporting dashboards and easier troubleshooting tools, would help in faster issue resolution and a better overall administration experience.
Better real-time monitoring, clearer authentication error reporting, and simpler troubleshooting tools in One Identity Safeguard would be helpful, especially when working in large and complex environments.
From a governance and security perspective, One Identity Safeguard is very strong; it helps enforce privileged access control, secure credential management, session monitoring, and detailed auditing, which are all important for reducing security risks.
More proactive insights around privileged access, users, and security trends would help security teams identify potential risks faster and improve overall visibility across the environment.
It is quite expensive, costing more than 50 euros per identity.
I think our total was in the seven-figure range for a couple of years of service.
The initial investment includes licensing, infrastructure setup, and implementation effort, with licensing typically based on the number of managed users or accounts, which can increase costs in large environments.
It is one of those where the more you buy, the cheaper it is.
It is cheaper than CyberArk.
Regarding pricing, it may appear slightly on the higher side initially compared to some alternatives, but when we evaluate it against the security benefits, compliance support, and risk reduction, it proves to be cost-effective in the long run.
It's improved our security posture. It has limited access to our crown jewels, where all our identities lie within Active Directory.
It helps in removing custom Active Directory delegation, which enhances security by eliminating unnecessary privileges, addressing identity-based breaches by reducing the number of Active Directory delegations.
Dynamic groups are also one of the best features, eliminating the need to add or manage members manually.
The auditing and approval mechanisms are features we did not have before and are greatly appreciated.
Automatic credential rotation helps our team by removing the need for manual changes to privileged passwords, reducing the risk of stale or shared credentials and ensuring that every access is controlled and compliant.
The password vault has been a game changer because it provides a secure and controlled way to store, manage, and rotate sensitive credentials without exposing them to users.
| Product | Mindshare (%) |
|---|---|
| One Identity Active Roles | 6.5% |
| One Identity Safeguard | 7.0% |
| Other | 86.5% |


| Company Size | Count |
|---|---|
| Small Business | 96 |
| Midsize Enterprise | 14 |
| Large Enterprise | 44 |
| Company Size | Count |
|---|---|
| Small Business | 90 |
| Midsize Enterprise | 25 |
| Large Enterprise | 37 |
One Identity Active Roles enhances Active Directory management by automating essential tasks and improving security through efficient delegation and role-based access control.
One Identity Active Roles offers advanced features for managing Active Directory environments, aiding in automating user provisioning, group management, and de-provisioning. It integrates seamlessly with Microsoft environments and provides centralized management for both on-premises and cloud identities. By improving operational efficiency and reducing manual errors, it enforces robust governance across organizations. Active Roles includes auditing and reporting tools that strengthen compliance and security monitoring. Companies find the setup could be simplified with better documentation, more customization options in reporting, and expanded cloud integration, particularly with Azure. Improved workflows and deeper native connectors are needed for seamless automation. Price adjustments and user-friendly analytics with intuitive dashboards are recommended for better usability.
What are the key features of One Identity Active Roles?
What benefits and ROI should users evaluate?
Many industries deploy One Identity Active Roles for automating user lifecycle management, especially in Active Directory environments. It significantly eases operations by automating onboarding for new hires, managing role changes, and modifying access. The platform efficiently handles tasks like password resets and compliance audits while empowering teams to securely manage user access without requiring full administrative rights.
One Identity Safeguard manages and monitors privileged access, enhancing security with features like automatic session recording, real-time monitoring, and credential rotation. It integrates seamlessly, supports compliance with audit trails, and improves operational efficiency across organizations. This robust platform significantly bolsters security protocols while controlling sensitive operations.
We monitor all Non-Human Identity Management (NHIM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.