No more typing reviews! Try our Samantha, our new voice AI agent.

Active Roles by One Identity vs Idira Privileged Access Manager comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.7
Active Roles by One Identity automates user provisioning, reducing manual effort, improving compliance, and enabling efficient workload management.
Sentiment score
6.6
Idira Privileged Access Manager users benefit from time savings, enhanced security, cost savings, and increased satisfaction in access management.
One Identity Active Roles provides excellent reporting and auditing functionality, allowing administrators to track permissions, actions, and responsibilities effectively.
solution architect/ engineer at APEX.IT Sp. z o.o.
Automation has really reduced the time spent on user provisioning, access management, or access changes by around 40 to 60 percent, which has significantly improved team productivity.
Technical Specialist at VDA Infosolutions Pvt. Ltd.
User onboarding time reduced by around seventy to eighty percent, from thirty to forty-five minutes to under ten minutes.
Senior Business Development Associate at DigitalTrack Solutions ind pvt ltd
The return on investment lies in improved security infrastructure, addressing over-privileged access, and reducing the risk of credential compromise, which is a major source of data breaches.
Cyber Security Engineer at Isolutions Associates Ltd (ISOLS)
The end users have the authority to reconcile the password or verify it before using session isolation, which is one of the unique features that can be enabled through Privileged Session Manager, preventing any attacks from happening within the organization when connected with sessions through CyberArk Privileged Access Manager.
Senior Engineer at a tech vendor with 1,001-5,000 employees
CyberArk Privileged Access Manager has helped customers save on costs primarily by reducing the number of engineering and information security personnel.
Head of Sales Services Department at a comms service provider with 51-200 employees
 

Customer Service

Sentiment score
6.7
One Identity Active Roles provides effective support, though complex issues face delays; praised for expertise and reliable enterprise assistance.
Sentiment score
6.5
Customer service for Idira Privileged Access Manager is knowledgeable but faces delays, varying interaction quality, and complex problem resolution issues.
They are ready to provide support at any time.
Technical Specialist at VDA Infosolutions Pvt. Ltd.
The support team is knowledgeable about the product and AD environments.
Network Security Engineer at Digitaltrack
Support is usually responsive for critical issues and provides solid practical guidance for AD workflow problems.
Cyber Security Analyst at a tech vendor with 51-200 employees
CyberArk has been exceptional in coming back to us with immediate responses.
IT Cyber Security Lead at a mining and metals company with 1,001-5,000 employees
It could be forever until you talk to someone who knows what they are doing.
Senior PAM Consultant at iC Consult GmbH
Based on the issue resolution and support quality, I rate the support 10 out of 10.
Operation Specialists at a tech vendor with 10,001+ employees
 

Scalability Issues

Sentiment score
7.1
Active Roles by One Identity efficiently manages extensive Active Directory environments, supporting scalability and centralized control for large enterprises.
Sentiment score
7.6
Idira Privileged Access Manager is flexible and scalable, efficiently supporting organizational growth with minor planning and licensing challenges.
One Identity Active Roles works well in hybrid environments, handling both on-premises and cloud identities from a single platform.
Senior Business Development Associate at DigitalTrack Solutions ind pvt ltd
It is commonly used in medium to large organizations managing complex Microsoft Active Directory and hybrid identity environments.
Professional Services Consultant at Check Point Software
The platform can scale without needing a complete redesign.
Senior Technical Support Executive at digital track
The CPM can reportedly handle up to 50,000 accounts independently without issue.
Privileged Access Management Engineer at a hospitality company with 10,001+ employees
I would rate it a ten out of ten for scalability.
IT Cyber Security Lead at a mining and metals company with 1,001-5,000 employees
They had 40,000 passwords in this one safe, and it was saving the last ten iterations of each password object. That means they had 400,000 password objects in this safe. They exceeded the limit.
Senior PAM Consultant at iC Consult GmbH
 

Stability Issues

Sentiment score
8.3
Active Roles by One Identity is praised for stability and reliability, especially in automation and user management, with minimal downtime.
Sentiment score
7.7
Idira Privileged Access Manager is stable and reliable, with minor issues usually resolved by updates, ensuring overall high performance.
Overall, One Identity Active Roles has proven to be a stable, reliable, and well-suited solution for managing Active Directory at scale.
Senior Business Development Executive at Digitaltrack
Overall, I consider One Identity Active Roles to be a stable solution, suitable for enterprise-grade environments.
Sr.Technical Support Executive at DigitalTrack Solution Private Limited
Consistently performing for daily operations like automation and user management without major downtime reported.
Associate technical desktop support at Digitaltrack soluctions Pvt. ltd
Proper fine-tuning and expertise ensure the product performs well.
Cybersecurity Specialist at a comms service provider with 5,001-10,000 employees
Overall, the stability of the solution is high.
Senior Cybersecurity Manager at a financial services firm with 10,001+ employees
It has a large customer base and positive feedback within my network.
Senior Manager at a energy/utilities company with 1,001-5,000 employees
 

Room For Improvement

Active Roles needs a modern UI, simplified setup, better cloud integration, streamlined workflows, and detailed documentation.
Idira Privileged Access Manager needs improved UI, integrations, pricing, installation, support, reporting, and API for better accessibility and efficiency.
The current REST API feels like an afterthought, and my developers want the ability to operate through CI/CD pipelines instead of logging into the GUI.
Identity and Access Management Specialist at a university with 10,001+ employees
Improving documentation and providing more guided implementation resources would help organizations accelerate deployment and reduce dependency on external support.
Sr.Technical Support Executive at DigitalTrack Solution Private Limited
Stronger, more seamless integration with cloud and hybrid environments like Azure AD, along with enhanced real-time reporting dashboards and easier troubleshooting tools, would help in faster issue resolution and a better overall administration experience.
Senior System Administrator at 3i Infotech
They want everything to be on the cloud, but even in the SaaS version of CyberArk Privileged Access Manager, they need to deploy some servers on-premises.
Presales Engineer at a computer software company with 201-500 employees
We cannot generate a plug-in for web-based applications.
Contractor at a pharma/biotech company with 5,001-10,000 employees
If they want clients to move to the cloud, they need to support them in real-time.
Senior Manager at a consultancy with 11-50 employees
 

Setup Cost

Active Roles by One Identity offers scalable enterprise solutions with high costs, justified by automation, security, and efficiency benefits.
Idira Privileged Access Manager is seen as high-cost but justified for large enterprises due to advanced features and support.
It is quite expensive, costing more than 50 euros per identity.
solution architect/ engineer at APEX.IT Sp. z o.o.
I think our total was in the seven-figure range for a couple of years of service.
Director, Identity & M365 Engineering at a healthcare company with 10,001+ employees
The initial investment includes licensing, infrastructure setup, and implementation effort, with licensing typically based on the number of managed users or accounts, which can increase costs in large environments.
Sr.Technical Support Executive at DigitalTrack Solution Private Limited
CyberArk is expensive compared to other products I know.
Cybersecurity Specialist at a comms service provider with 5,001-10,000 employees
CyberArk is comparatively expensive compared to other PAM solutions, such as Delinea, especially during renewal.
Presales Engineer at a computer software company with 201-500 employees
CyberArk's SaaS solution is particularly expensive.
Senior Manager at a energy/utilities company with 1,001-5,000 employees
 

Valuable Features

Active Roles by One Identity enhances security and efficiency through automation, role-based access control, and centralized management for IT teams.
Idira Privileged Access Manager enhances security with session monitoring, password management, integration flexibility, compliance support, and a user-friendly interface.
It's improved our security posture. It has limited access to our crown jewels, where all our identities lie within Active Directory.
IAM Specialist
It helps in removing custom Active Directory delegation, which enhances security by eliminating unnecessary privileges, addressing identity-based breaches by reducing the number of Active Directory delegations.
Head of Global Digital Identity Services at a hospitality company with 10,001+ employees
Dynamic groups are also one of the best features, eliminating the need to add or manage members manually.
Technical Specialist at LSEG
CyberArk Privileged Access Manager helps ensure data privacy because we now know who is using which credentials and at what time.
Senior Cybersecurity Manager at a financial services firm with 10,001+ employees
It keeps a record of activities, allowing me to easily fetch screen recordings to detect any misuse and see who did what and what happened.
Senior Manager at a consultancy with 11-50 employees
It can integrate with Splunk, SNMP, and other solutions and technologies.
Technical Support Analyst at Capgemini
 

Categories and Ranking

Active Roles by One Identity
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
92
Ranking in other categories
User Provisioning Software (3rd), Active Directory Management (1st), Non-Human Identity Management (NHIM) (1st)
Idira Privileged Access Man...
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
231
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (2nd), Privileged Access Management (PAM) (1st), Mainframe Security (1st), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Active Roles by One Identity is designed for Active Directory Management and holds a mindshare of 11.8%, up 10.1% compared to last year.
Idira Privileged Access Manager, on the other hand, focuses on Privileged Access Management (PAM), holds 8.6% mindshare, down 16.0% since last year.
Active Directory Management Mindshare Distribution
ProductMindshare (%)
Active Roles by One Identity11.8%
Netwrix Auditor10.2%
ManageEngine ADManager Plus8.6%
Other69.4%
Active Directory Management
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
Idira Privileged Access Manager8.6%
Safeguard by One Identity4.4%
Teleport3.6%
Other83.4%
Privileged Access Management (PAM)
 

Featured Reviews

Puru Solanki ( ITIL. CISM , CCSP ) - PeerSpot reviewer
IT Head at Citadel Global
Automation has streamlined onboarding and governance and delivers faster, more secure access
Overall, we are very satisfied with Active Roles by One Identity, but there are a few areas that could be improved. The user interface could be more modern and intuitive, especially for new administrators. Some advanced configuration and policy settings have a steep learning curve and could be simplified. We would also like to see more built-in integrations with cloud platforms and SaaS applications, along with additional out-of-the-box reporting templates. These improvements would make the product even easier and more flexible for organizations managing hybrid environments. One thing that would make our daily work even smoother is having more ready-to-use templates for common administrative tasks and reports. This would reduce the need for customization and help teams get up and running more quickly. Additionally, faster and simpler synchronization for hybrid and cloud environments would be beneficial, especially for organizations managing both on-premises and cloud identities. More detailed documentation and guided setup for advanced features would help new administrators learn the platform faster and more easily. One additional improvement I would like to see for Active Roles by One Identity is a better built-in dashboard with more real-time insights into identity and access activities. It would be helpful if upgrades and migrations were simpler and required less planning. Finally, expanding native integrations with more cloud services and third-party applications would make the platform even more versatile and reliable. These enhancements would improve the overall user experience while keeping the product's strong security and automation capabilities.
Singaravelu C - PeerSpot reviewer
CyberArk Engineer at Tata Consultancy
Provides full visibility into user activity and ensures secure end-to-end access across critical systems
In CyberArk Privileged Access Manager, I see room for improvement as I am working in the on-premises networks, and now we are also having the cloud-based PAM. So there, everything is maintained by the CyberArk Privileged Access Manager team, and we are only maintaining the PSM servers. So it is already upgraded from the on-premises network to the cloud network. If you ask me what we can implement beyond that, I just need a few minutes to think about what new things, because it is already an end-to-end security on-premises itself. Now, when it comes to PCloud, Privileged Cloud, it is more secure than the on-premises networks because most of the things are handled using the cloud itself. So it is an already upgraded version; we do not need to implement something new. But if you think in that way, we can have a chance to implement our things. If anything could be improved in CyberArk Privileged Access Manager, I think we could build a small agent AI in my team, we could give access to these logs—the Vault logs, PSM logs, and CPM logs. Whenever the system is going down, the AI will automatically check. If we actually implement agent AI in CyberArk Privileged Access Manager, it will check the logs, and if any errors are coming, it automatically triggers alerts and gives the solution. That is the best improvement I can think of because these days, most things are done by agent AI. So if we also implement this agent AI in CyberArk Privileged Access Manager, we can add more features.
report
Use our free recommendation engine to learn which Active Directory Management solutions are best for your needs.
915,287 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
28%
Healthcare Company
9%
Financial Services Firm
8%
Computer Software Company
6%
Outsourcing Company
13%
Financial Services Firm
11%
Manufacturing Company
10%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business101
Midsize Enterprise16
Large Enterprise45
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise43
Large Enterprise175
 

Questions from the Community

What is your experience regarding pricing and costs for One Identity Active Roles?
Our experience with the pricing, setup cost, and licensing of Active Roles by One Identity has been very positive. Although Active Roles by One Identity is not the lowest-priced solution, we believ...
What needs improvement with One Identity Active Roles?
Overall, we are very satisfied with Active Roles by One Identity, but there are a few areas that could be improved. The user interface could be more modern and intuitive, especially for new adminis...
What is your primary use case for One Identity Active Roles?
Active Roles by One Identity is our main solution for simplifying and automating user account management in our Active Directory environment. We use it for tasks like user provisioning, deprovision...
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What needs improvement with CyberArk Privileged Access Manager?
I believe account discovery and rolling support need to be improved. Account discovery is important when integrating with other systems, as other PAM solutions can perform account discovery and onb...
 

Also Known As

Quest Active Roles
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Rockwell Automation
Find out what your peers are saying about One Identity, Netwrix, Microsoft and others in Active Directory Management. Updated: August 2026.
915,287 professionals have used our research since 2012.