No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Identity Services Engine (ISE) vs One Identity Active Roles comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.1
Cisco Identity Services Engine enhances security, simplifies operations, and reduces costs while boosting productivity and ensuring regulatory compliance.
Sentiment score
5.8
One Identity Active Roles boosts efficiency and security, reduces costs, and enhances compliance and productivity through task automation.
Direct comparisons with Forescout reveal up to 30% to 40% difference in cost savings.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
One Identity Active Roles provides excellent reporting and auditing functionality, allowing administrators to track permissions, actions, and responsibilities effectively.
solution architect/ engineer at APEX.IT Sp. z o.o.
Automation has really reduced the time spent on user provisioning, access management, or access changes by around 40 to 60 percent, which has significantly improved team productivity.
Technical Specialist at VDA Infosolutions Pvt Ltd
User onboarding time reduced by around seventy to eighty percent, from thirty to forty-five minutes to under ten minutes.
Senior Business Development Associate at a integrator with 501-1,000 employees
 

Customer Service

Sentiment score
6.7
Cisco ISE support is highly rated for knowledge and responsiveness but struggles with response times and communication challenges.
Sentiment score
6.7
One Identity Active Roles support is praised for expertise and responsiveness but seeks improvement in escalation processes for complex issues.
I rate the technical support as one out of ten.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Cisco support has pretty good teams for support and every time we had good answers and we could somehow solve the issues we had.
Network and Technology Information Manager at Akkodis
Sometimes it's challenging to identify which support team is responsible for certain issues, which is a significant concern.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
They are ready to provide support at any time.
Technical Specialist at VDA Infosolutions Pvt Ltd
Everything is good, and I can give One Identity technical support a rating of ten.
Assistant Manager- Pre-sales ( IT-Enterprise Vertical ) at a tech vendor with 201-500 employees
They are knowledgeable, and the response time is low.
IT Infrastructure & Cloud Manager at Softcell Technologies Limited
 

Scalability Issues

Sentiment score
7.3
Cisco ISE supports smooth scalability for diverse enterprises, but virtualization and hardware challenges may require strategic solutions.
Sentiment score
6.2
One Identity Active Roles is scalable, supports various sizes, and adapts to technologies despite concerns about database performance and policies.
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
However, you can have some latency issues depending on where your devices are.
Network and Technology Information Manager at Akkodis
One Identity Active Roles works well in hybrid environments, handling both on-premises and cloud identities from a single platform.
Senior Business Development Associate at a integrator with 501-1,000 employees
It is commonly used in medium to large organizations managing complex Microsoft Active Directory and hybrid identity environments.
Professional services consultant at checkpoint software
It is very beneficial for large and complex environments.
Team Lead, Technical & Enterprise Directory Services Vita Program at AIS Network
 

Stability Issues

Sentiment score
7.7
Cisco ISE is stable and reliable, but large deployments may face challenges, requiring proper configuration and effective support.
Sentiment score
7.7
One Identity Active Roles is mostly stable and reliable, with users noting few bugs and straightforward maintenance.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Sometimes when we have upgrades or failovers with Cisco Identity Services Engine (ISE), we had some minor issues.
Network and Technology Information Manager at Akkodis
Overall, One Identity Active Roles has proven to be a stable, reliable, and well-suited solution for managing Active Directory at scale.
BDM at Digitaltrack
Overall, I consider One Identity Active Roles to be a stable solution, suitable for enterprise-grade environments.
Sr.technical Support Executive at Digitaltrack Solution Private Limited
There were no major problems with One Identity Active Roles.
solution architect/ engineer at APEX.IT Sp. z o.o.
 

Room For Improvement

Cisco ISE is hindered by complexity, compatibility issues, costly licensing, and needs improvements in usability, support, and performance.
One Identity Active Roles improvements include UI modernization, enhanced cloud integration, setup simplification, performance optimization, and reevaluated pricing.
The whole setup works well with Cisco access points and Cisco switches, but when you have multiple vendors in the environment, such as HP switches or access points like Aruba, you'll find they will not work well with Cisco Identity Services Engine (ISE).
Technical Services Lead at Telenet Solutions
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
I also want One Identity Active Roles to improve in their policy configuration area, which requires advanced expertise, and in the area of reporting, I want the reporting to be more basic, visible, and have the ability to export and customize options.
Cybersecurity Consultant at CyberBackbone
The current REST API feels like an afterthought, and my developers want the ability to operate through CI/CD pipelines instead of logging into the GUI.
Identity and Access Management Specialist at a university with 10,001+ employees
Improving documentation and providing more guided implementation resources would help organizations accelerate deployment and reduce dependency on external support.
Sr.technical Support Executive at Digitaltrack Solution Private Limited
 

Setup Cost

Cisco ISE pricing is complex and costly, with strong vendor partnerships needed for discounts, favoring large enterprises over smaller businesses.
One Identity Active Roles is costly but offers justified ROI with competitive pricing and supportive vendor services.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
The license costs can range between $50,000 to $100,000 per year for enterprises.
Technical Services Lead at Telenet Solutions
Cloud solutions are expensive, while on-prem setups with shared environments are cheaper but not effective.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
It is quite expensive, costing more than 50 euros per identity.
solution architect/ engineer at APEX.IT Sp. z o.o.
I think our total was in the seven-figure range for a couple of years of service.
Director, Identity & M365 Engineering at a healthcare company with 10,001+ employees
The initial investment includes licensing, infrastructure setup, and implementation effort, with licensing typically based on the number of managed users or accounts, which can increase costs in large environments.
Sr.technical Support Executive at Digitaltrack Solution Private Limited
 

Valuable Features

Cisco ISE excels in security, network access control, and integration, offering adaptability, scalability, and centralized management for organizations.
One Identity Active Roles enhances AD management with automation, robust access control, integration, and improved security across domains.
Cisco Identity Services Engine (ISE) offers authentication using RADIUS, enhancing network security by separating and segregating networks.
Technical Services Lead at Telenet Solutions
There is value because it helps us secure the network and prevents certain things from happening which could cause financial loss.
Ag Systems & Networks Head at UNBS
The adaptability of Cisco Identity Services Engine (ISE) policy enforcement can fit to the site we have depending on which kind of devices we have on site and then the needs for authentication, granting access and then assigning each device into its correct network for segmentation.
Network and Technology Information Manager at Akkodis
It's improved our security posture. It has limited access to our crown jewels, where all our identities lie within Active Directory.
IAM Specialist
It helps in removing custom Active Directory delegation, which enhances security by eliminating unnecessary privileges, addressing identity-based breaches by reducing the number of Active Directory delegations.
Head of Global Digital Identity Services at a hospitality company with 10,001+ employees
Dynamic groups are also one of the best features, eliminating the need to add or manage members manually.
Technical Specialist at LSEG
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Network Access Control (NAC) (2nd), Cisco Security Portfolio (4th)
One Identity Active Roles
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
49
Ranking in other categories
User Provisioning Software (3rd), Active Directory Management (1st), Non-Human Identity Management (NHIM) (3rd)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and One Identity Active Roles aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 20.5%, down 26.3% compared to last year.
One Identity Active Roles, on the other hand, focuses on Active Directory Management, holds 12.0% mindshare, up 6.2% since last year.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)20.5%
Aruba ClearPass19.5%
Fortinet FortiNAC14.6%
Other45.4%
Network Access Control (NAC)
Active Directory Management Mindshare Distribution
ProductMindshare (%)
One Identity Active Roles12.0%
ManageEngine ADManager Plus10.9%
Netwrix Auditor10.0%
Other67.1%
Active Directory Management
 

Featured Reviews

NF
Network and Technology Information Manager at Akkodis
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
Mahesh Malve - PeerSpot reviewer
Senior Business Development Associate at a integrator with 501-1,000 employees
Automation has transformed user lifecycle tasks and now enforces consistent secure access
While One Identity Active Roles is a strong platform, a few improvements would make it even better. Many users feel the user interface is not very modern or intuitive, and it can take time to get used to navigating the console and workflows. Another improvement area is the learning curve and setup complexity. One Identity Active Roles is very powerful, but initial configuration, especially for policies, workflows, and delegation, can be complex and require experienced resources. From an integration perspective, although it supports multiple systems, organizations would benefit from more out-of-the-box connectors and smoother cloud integrations such as Azure Active Directory and software-as-a-service applications, as some setups currently require customization. In terms of reporting, while auditing is strong, generating business-friendly reports can be challenging. Users have mentioned the need for better dashboards and easier report generation. There are also some performance considerations, especially in large environments, such as slower PowerShell execution or delays in dynamic group processing in certain cases. Overall, improvements in user interface, ease of use, integration, reporting, and performance optimization would significantly enhance the product experience.
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
886,932 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
10%
Government
8%
Computer Software Company
7%
Computer Software Company
9%
Financial Services Firm
9%
Manufacturing Company
8%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise10
Large Enterprise24
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What is your experience regarding pricing and costs for One Identity Active Roles?
I am aware of the pricing; it is on the expensive side, though pricing is not my department.
What needs improvement with One Identity Active Roles?
I do not see anything that needs to be changed as of now concerning the organization's needs because it is working very well and it is providing great features with great processes. The initial set...
What is your primary use case for One Identity Active Roles?
When a new user is created, predefined rules automatically apply naming standards and assigned groups. This reduces manual tasks while ensuring consistency across all operations. It prevents and av...
 

Also Known As

Cisco ISE
Quest Active Roles
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Find out what your peers are saying about Hewlett Packard Enterprise, Cisco, Fortinet and others in Network Access Control (NAC). Updated: March 2026.
886,932 professionals have used our research since 2012.