Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs One Identity Active Roles comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.1
Cisco Identity Services Engine enhances security, simplifies operations, and reduces costs while boosting productivity and ensuring regulatory compliance.
Sentiment score
5.4
One Identity Active Roles enhances security and efficiency, automating tasks and reducing IT workload, achieving up to 30% ROI.
Direct comparisons with Forescout reveal up to 30% to 40% difference in cost savings.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
We also save money because we increased security, stopped incidents, and reduced breaches and security breaches.
Cybersecurity Team Leader at EMAK For Integrated Solutions
One Identity Active Roles provides excellent reporting and auditing functionality, allowing administrators to track permissions, actions, and responsibilities effectively.
solution architect/ engineer at APEX.IT Sp. z o.o.
It has saved 90% of the time compared to before.
IAM Specialist
One Identity has a theme that they want the right people to have the right set of access, and this is what they are able to provide with their tool.
Assistant Manager- Pre-sales ( IT-Enterprise Vertical ) at a tech vendor with 201-500 employees
 

Customer Service

Sentiment score
6.7
Cisco ISE support is highly rated for knowledge and responsiveness but struggles with response times and communication challenges.
Sentiment score
6.9
One Identity Active Roles support is praised for efficiency and expertise, though some face delays and need professional services.
I rate the technical support as one out of ten.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Cisco support has pretty good teams for support and every time we had good answers and we could somehow solve the issues we had.
Network and Technology Information Manager at Akkodis
TAC support from Cisco is a notable feature; it provides very professional support.
Cybersecurity Team Leader at EMAK For Integrated Solutions
Everything is good, and I can give One Identity technical support a rating of ten.
Assistant Manager- Pre-sales ( IT-Enterprise Vertical ) at a tech vendor with 201-500 employees
One Identity's support is great.
Team Lead, Technical & Enterprise Directory Services Vita Program at AIS Network
I rate customer service and support as a seven because, although they are helpful when needed, there can be delays in responding to tickets and finding necessary fixes.
IAM Product owner at a hospitality company with 10,001+ employees
 

Scalability Issues

Sentiment score
7.3
Cisco ISE supports smooth scalability for diverse enterprises, but virtualization and hardware challenges may require strategic solutions.
Sentiment score
7.3
One Identity Active Roles offers scalability and flexibility, supporting up to 150,000 users and accommodating complex enterprise environments.
You can run an all-in-one deployment and switch to distributed mode as your company grows, relying on Cisco Identity Services Engine (ISE) to support your scalability needs.
Cybersecurity Team Leader at EMAK For Integrated Solutions
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
However, you can have some latency issues depending on where your devices are.
Network and Technology Information Manager at Akkodis
It is very beneficial for large and complex environments.
Team Lead, Technical & Enterprise Directory Services Vita Program at AIS Network
If you are a major enterprise customer, it is a matter of scaling out on resources with more memory, disk, and CPU power.
IAM Specialist
The solution is highly scalable, with a scalability rating of nine.
IAM Product owner at a hospitality company with 10,001+ employees
 

Stability Issues

Sentiment score
7.7
Cisco ISE is stable and reliable, but large deployments may face challenges, requiring proper configuration and effective support.
Sentiment score
7.1
One Identity Active Roles is a stable, reliable tool with minor bugs, high ratings, and occasional performance issues.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
Sometimes when we have upgrades or failovers with Cisco Identity Services Engine (ISE), we had some minor issues.
Network and Technology Information Manager at Akkodis
There were no major problems with One Identity Active Roles.
solution architect/ engineer at APEX.IT Sp. z o.o.
Regarding stability, One Identity Active Roles is mostly stable.
Director, Identity & M365 Engineering at a healthcare company with 10,001+ employees
We haven't had any glitches.
IAM Specialist
 

Room For Improvement

Cisco ISE is hindered by complexity, compatibility issues, costly licensing, and needs improvements in usability, support, and performance.
One Identity Active Roles needs enhancements in its interface, customization, integration, multilingual support, and pricing to stay competitive.
The whole setup works well with Cisco access points and Cisco switches, but when you have multiple vendors in the environment, such as HP switches or access points like Aruba, you'll find they will not work well with Cisco Identity Services Engine (ISE).
Technical Services Lead at Telenet Solutions
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
A way to connect to various directories and integrate with cloud directories would be beneficial.
Team Lead, Technical & Enterprise Directory Services Vita Program at AIS Network
Enhancements to the console are also necessary because it is more confusing than the web interface.
System Administrator at a healthcare company with 501-1,000 employees
The user interface needs to be more modern and scalable.
IAM Specialist
 

Setup Cost

Cisco ISE pricing is complex and costly, with strong vendor partnerships needed for discounts, favoring large enterprises over smaller businesses.
One Identity Active Roles is costly but valued for its functionality, ease of use, and flexible user-based licensing model.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
Solution Architect, Presales Engineer at a computer software company with 51-200 employees
The license costs can range between $50,000 to $100,000 per year for enterprises.
Technical Services Lead at Telenet Solutions
Cloud solutions are expensive, while on-prem setups with shared environments are cheaper but not effective.
Service Line Manager (Service Operations Expert) - Network Access Control at a pharma/biotech company with 10,001+ employees
It is quite expensive, costing more than 50 euros per identity.
solution architect/ engineer at APEX.IT Sp. z o.o.
I think our total was in the seven-figure range for a couple of years of service.
Director, Identity & M365 Engineering at a healthcare company with 10,001+ employees
The pricing is high.
Team Lead, Technical & Enterprise Directory Services Vita Program at AIS Network
 

Valuable Features

Cisco ISE excels in security, network access control, and integration, offering adaptability, scalability, and centralized management for organizations.
One Identity Active Roles enhances AD management with automation, security, and efficiency while offering a user-friendly interface and powerful features.
Cisco Identity Services Engine (ISE) offers authentication using RADIUS, enhancing network security by separating and segregating networks.
Technical Services Lead at Telenet Solutions
There is value because it helps us secure the network and prevents certain things from happening which could cause financial loss.
Ag Systems & Networks Head at UNBS
The adaptability of Cisco Identity Services Engine (ISE) policy enforcement can fit to the site we have depending on which kind of devices we have on site and then the needs for authentication, granting access and then assigning each device into its correct network for segmentation.
Network and Technology Information Manager at Akkodis
It's improved our security posture. It has limited access to our crown jewels, where all our identities lie within Active Directory.
IAM Specialist
It helps in removing custom Active Directory delegation, which enhances security by eliminating unnecessary privileges, addressing identity-based breaches by reducing the number of Active Directory delegations.
Head of Global Digital Identity Services at a hospitality company with 10,001+ employees
Dynamic groups are also one of the best features, eliminating the need to add or manage members manually.
Technical Specialist at LSEG
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
145
Ranking in other categories
Network Access Control (NAC) (2nd), Cisco Security Portfolio (4th)
One Identity Active Roles
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
29
Ranking in other categories
User Provisioning Software (5th), Active Directory Management (1st), Non-Human Identity Management (NHIM) (4th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and One Identity Active Roles aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 22.4%, down 28.3% compared to last year.
One Identity Active Roles, on the other hand, focuses on Active Directory Management, holds 10.8% mindshare, up 6.5% since last year.
Network Access Control (NAC) Market Share Distribution
ProductMarket Share (%)
Cisco Identity Services Engine (ISE)22.4%
Aruba ClearPass21.6%
Fortinet FortiNAC16.1%
Other39.9%
Network Access Control (NAC)
Active Directory Management Market Share Distribution
ProductMarket Share (%)
One Identity Active Roles10.8%
ManageEngine ADManager Plus12.6%
Netwrix Auditor9.4%
Other67.2%
Active Directory Management
 

Featured Reviews

NF
Network and Technology Information Manager at Akkodis
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
reviewer2789802 - PeerSpot reviewer
Director, Identity & M365 Engineering at a healthcare company with 10,001+ employees
Granular delegated access has strengthened least privilege control across complex directories
One of the things I would like to see more robust is the change history. One Identity Active Roles can only monitor changes that happen in the console, and the logs don't go back longer than thirty days, maybe sixty days. The change history, when we've seen accounts get modified, we leverage a container domain that funnels accounts into our Active Directory console. I would like to see from an initial user provisioning perspective, for them to isolate the workflow and say that this came in on X date and account was created. If anyone were to modify that account from an external resource, I would like to be able to read that as well. One Identity Active Roles is strictly limited to the console. If someone makes a change, the history of those changes is not as long as I would prefer.
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
879,455 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Manufacturing Company
11%
Financial Services Firm
9%
Government
9%
Computer Software Company
13%
Healthcare Company
9%
Manufacturing Company
9%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise32
Large Enterprise91
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise4
Large Enterprise19
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What is your experience regarding pricing and costs for One Identity Active Roles?
The product is expensive, but if you want to save money, the delegation set-up process is quite easy. After setting up Active Roles once, defining the delegation model, it is very efficient, almost...
What needs improvement with One Identity Active Roles?
The interface appears outdated. Once logged in, everything inside remains unchanged from years ago. Additionally, when they release new features, they should provide training or webinars at least o...
What is your primary use case for One Identity Active Roles?
I use One Identity Active Roles primarily for identity management. We use it for managing multiple domains from a single interface, and the domains do not have trust between them. It has been used ...
 

Also Known As

Cisco ISE
Quest Active Roles
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Find out what your peers are saying about Hewlett Packard Enterprise, Cisco, Fortinet and others in Network Access Control (NAC). Updated: December 2025.
879,455 professionals have used our research since 2012.