No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Identity Services Engine (ISE) vs One Identity Active Roles comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.1
Cisco Identity Services Engine enhances security, simplifies operations, and reduces costs while boosting productivity and ensuring regulatory compliance.
Sentiment score
6.7
One Identity Active Roles automates tasks, significantly reducing manual efforts, improving efficiency, and achieving rapid ROI for organizations.
Direct comparisons with Forescout reveal up to 30% to 40% difference in cost savings.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
One Identity Active Roles provides excellent reporting and auditing functionality, allowing administrators to track permissions, actions, and responsibilities effectively.
solution architect/ engineer at APEX.IT Sp. z o.o.
Automation has really reduced the time spent on user provisioning, access management, or access changes by around 40 to 60 percent, which has significantly improved team productivity.
Technical Specialist at VDA Infosolutions Pvt. Ltd.
User onboarding time reduced by around seventy to eighty percent, from thirty to forty-five minutes to under ten minutes.
Senior Business Development Executive at DigitalTrack Solutions Ind Pvt Ltd
 

Customer Service

Sentiment score
6.7
Cisco ISE support is highly rated for knowledge and responsiveness but struggles with response times and communication challenges.
Sentiment score
6.9
Users rate One Identity Active Roles support highly for expertise and guidance, with some delays for complex issues.
I rate the technical support as one out of ten.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Cisco support has pretty good teams for support and every time we had good answers and we could somehow solve the issues we had.
Network and Technology Information Manager at Akkodis
Sometimes it's challenging to identify which support team is responsible for certain issues, which is a significant concern.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
They are ready to provide support at any time.
Technical Specialist at VDA Infosolutions Pvt. Ltd.
The support team is knowledgeable about the product and AD environments.
Network Security Engineer at DigitalTrack Solutions Private Limited
Support is usually responsive for critical issues and provides solid practical guidance for AD workflow problems.
Cyber Security Analyst at a tech vendor with 51-200 employees
 

Scalability Issues

Sentiment score
7.3
Cisco ISE supports smooth scalability for diverse enterprises, but virtualization and hardware challenges may require strategic solutions.
Sentiment score
7.0
One Identity Active Roles supports enterprise identity management with scalability, centralized control, automation, and role-based delegation for multi-domain environments.
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
However, you can have some latency issues depending on where your devices are.
Network and Technology Information Manager at Akkodis
One Identity Active Roles works well in hybrid environments, handling both on-premises and cloud identities from a single platform.
Senior Business Development Executive at DigitalTrack Solutions Ind Pvt Ltd
It is commonly used in medium to large organizations managing complex Microsoft Active Directory and hybrid identity environments.
Professional Services Consultant at Check Point Software
The platform can scale without needing a complete redesign.
Senior Technical Support Executive at digital track
 

Stability Issues

Sentiment score
7.7
Cisco ISE is stable and reliable, but large deployments may face challenges, requiring proper configuration and effective support.
Sentiment score
8.2
One Identity Active Roles is stable, reliable, and efficient for user management and AD automation, ideal for enterprise use.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Sometimes when we have upgrades or failovers with Cisco Identity Services Engine (ISE), we had some minor issues.
Network and Technology Information Manager at Akkodis
Overall, One Identity Active Roles has proven to be a stable, reliable, and well-suited solution for managing Active Directory at scale.
Bdm at Digitaltrack
Overall, I consider One Identity Active Roles to be a stable solution, suitable for enterprise-grade environments.
Technical Support Engineer at Digitaltrack
Consistently performing for daily operations like automation and user management without major downtime reported.
Associate technical desktop support at Digitaltrack soluctions Pvt. ltd
 

Room For Improvement

Cisco ISE is hindered by complexity, compatibility issues, costly licensing, and needs improvements in usability, support, and performance.
Enhancing user interface, setup, cloud integration, performance, and pricing can improve usability and accessibility of One Identity Active Roles.
The whole setup works well with Cisco access points and Cisco switches, but when you have multiple vendors in the environment, such as HP switches or access points like Aruba, you'll find they will not work well with Cisco Identity Services Engine (ISE).
Technical Services Lead at Telenet Solutions
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
The current REST API feels like an afterthought, and my developers want the ability to operate through CI/CD pipelines instead of logging into the GUI.
Identity and Access Management Specialist at a university with 10,001+ employees
Improving documentation and providing more guided implementation resources would help organizations accelerate deployment and reduce dependency on external support.
Technical Support Engineer at Digitaltrack
Stronger, more seamless integration with cloud and hybrid environments like Azure AD, along with enhanced real-time reporting dashboards and easier troubleshooting tools, would help in faster issue resolution and a better overall administration experience.
Senior System Administrator at 3i Infotech
 

Setup Cost

Cisco ISE pricing is complex and costly, with strong vendor partnerships needed for discounts, favoring large enterprises over smaller businesses.
One Identity Active Roles is costly but offers high ROI through automation, efficiency, governance, and security for enterprises.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
The license costs can range between $50,000 to $100,000 per year for enterprises.
Technical Services Lead at Telenet Solutions
Cloud solutions are expensive, while on-prem setups with shared environments are cheaper but not effective.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
It is quite expensive, costing more than 50 euros per identity.
solution architect/ engineer at APEX.IT Sp. z o.o.
I think our total was in the seven-figure range for a couple of years of service.
Director, Identity & M365 Engineering at a healthcare company with 10,001+ employees
The initial investment includes licensing, infrastructure setup, and implementation effort, with licensing typically based on the number of managed users or accounts, which can increase costs in large environments.
Technical Support Engineer at Digitaltrack
 

Valuable Features

Cisco ISE excels in security, network access control, and integration, offering adaptability, scalability, and centralized management for organizations.
One Identity Active Roles automates Active Directory tasks, enhancing security, efficiency, and compliance through centralized management and integration.
Cisco Identity Services Engine (ISE) offers authentication using RADIUS, enhancing network security by separating and segregating networks.
Technical Services Lead at Telenet Solutions
There is value because it helps us secure the network and prevents certain things from happening which could cause financial loss.
Ag Systems & Networks Head at UNBS
The adaptability of Cisco Identity Services Engine (ISE) policy enforcement can fit to the site we have depending on which kind of devices we have on site and then the needs for authentication, granting access and then assigning each device into its correct network for segmentation.
Network and Technology Information Manager at Akkodis
It's improved our security posture. It has limited access to our crown jewels, where all our identities lie within Active Directory.
IAM Specialist
It helps in removing custom Active Directory delegation, which enhances security by eliminating unnecessary privileges, addressing identity-based breaches by reducing the number of Active Directory delegations.
Head of Global Digital Identity Services at a hospitality company with 10,001+ employees
Dynamic groups are also one of the best features, eliminating the need to add or manage members manually.
Technical Specialist at LSEG
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Network Access Control (NAC) (2nd), Cisco Security Portfolio (4th)
One Identity Active Roles
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
80
Ranking in other categories
User Provisioning Software (3rd), Active Directory Management (1st), Non-Human Identity Management (NHIM) (2nd)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and One Identity Active Roles aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 19.4%, down 25.8% compared to last year.
One Identity Active Roles, on the other hand, focuses on Active Directory Management, holds 11.9% mindshare, up 6.8% since last year.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)19.4%
Aruba ClearPass18.5%
Fortinet FortiNAC14.5%
Other47.6%
Network Access Control (NAC)
Active Directory Management Mindshare Distribution
ProductMindshare (%)
One Identity Active Roles11.9%
Netwrix Auditor10.6%
ManageEngine ADManager Plus10.1%
Other67.4%
Active Directory Management
 

Featured Reviews

NF
Network and Technology Information Manager at Akkodis
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
Varun Mehra - PeerSpot reviewer
Collaboration Support Engineer at a retailer with 11-50 employees
Automation has transformed onboarding and access control and now streamlines daily governance
While One Identity Active Roles is a strong identity and access management solution overall, there are a few areas where it could improve. One challenge we experienced was the initial setup and configuration complexity. Deploying workflows, policies, and delegation models require careful planning and a good understanding of the Active Directory environment. For organizations without experienced administrators, the learning curve can feel quite steep in the beginning. The user interface could also be more modern and intuitive. Some administrative tasks require navigating through multiple menus and the overall experience could be simplified for faster day-to-day management. Another area for improvement is reporting and customization. While the auditing features are good, creating highly customized reports sometimes requires additional efforts or scripting knowledge. More built-in reporting templates and easier dashboard customization would be helpful. We have also noticed that troubleshooting workflows or synchronization issues can occasionally take time because the logs can be very detailed and technical. Better diagnostic tools and simpler error explanations would improve the operational experience. That said, once the platform is properly configured and maintained, it performs reliably and delivers strong automation, delegation, and governance capabilities. One additional area where One Identity Active Roles could improve is cloud integration and hybrid environment management. While it works well with Active Directory and the Microsoft environment, organizations moving heavily towards cloud-first infrastructure may want even deeper and more seamless integration with modern SaaS platforms and identity providers. Performance optimization in large environments could be improved. In very large enterprise deployments with complex workflows and multiple managed domains, some administrative actions and synchronization tasks can occasionally feel slower than expected. Another point is documentation and onboarding resources. The product is feature-rich, but some advanced configurations require going through extensive documentation. More practical examples, guided setup wizards, and easier to follow best practice guides would help new administrators adopt the platform faster. Overall, the core functionality is solid, and most of the pain points are related more to usability, complexity, and modernization rather than the reliability. One additional improvement I would mention is around integration flexibility with third-party ITSM and DevOps tools. While the platform integrates well within Microsoft-centric environments, broader out-of-the-box integration and simpler API workflows for non-Microsoft ecosystems would make deployment and automation easier for organizations using diverse infrastructure. Another area is upgrade and migration simplicity. In enterprise environments, version upgrades and environment migration sometimes require careful planning and testing. Streamlining that process with more automated compatibility checks and migration assistance would reduce operational overhead.
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
896,202 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
10%
Government
7%
Computer Software Company
7%
Outsourcing Company
20%
Computer Software Company
8%
Financial Services Firm
8%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
By reviewers
Company SizeCount
Small Business83
Midsize Enterprise14
Large Enterprise40
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What is your experience regarding pricing and costs for One Identity Active Roles?
My experience with pricing and licensing for One Identity Active Roles has been reasonable for an enterprise solution, but it does require proper planning. The initial setup can involve some cost i...
What needs improvement with One Identity Active Roles?
One Identity Active Roles is very useful, though there are a few areas where it could be improved, such as the user interface, policy creation, and reporting - it requires good knowledge of Active ...
What is your primary use case for One Identity Active Roles?
One Identity Active Roles is used primarily for managing Active Directory, including user provisioning and group management. When a new employee joins, I use One Identity Active Roles to automatica...
 

Also Known As

Cisco ISE
Quest Active Roles
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Find out what your peers are saying about Hewlett Packard Enterprise, Cisco, Fortinet and others in Network Access Control (NAC). Updated: May 2026.
896,202 professionals have used our research since 2012.