No more typing reviews! Try our Samantha, our new voice AI agent.

ForgeRock vs One Identity Active Roles comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.2
ForgeRock enhanced market efficiency, security, and customer trust, reducing staffing needs and improving time to market without exact ROI figures.
Sentiment score
6.8
One Identity Active Roles automates tasks, reducing time by up to 60%, increasing efficiency, and enhancing compliance without extra hiring.
On a B2B level, it opened up the market for TomTom to sell its services in a more efficient way to car companies.
Principal Consultant at Road2Value
We can use a Linux image from ForgeRock with different systems, applications, websites, and mobile apps to create various types of access for users.
Assistant Architect at a energy/utilities company with 501-1,000 employees
I can definitely see that fewer employees are needed compared to using different SaaS applications.
Identity and Access Management Specialist at a university with 10,001+ employees
One Identity Active Roles provides excellent reporting and auditing functionality, allowing administrators to track permissions, actions, and responsibilities effectively.
solution architect/ engineer at APEX.IT Sp. z o.o.
Automation has really reduced the time spent on user provisioning, access management, or access changes by around 40 to 60 percent, which has significantly improved team productivity.
Technical Specialist at VDA Infosolutions Pvt. Ltd.
User onboarding time reduced by around seventy to eighty percent, from thirty to forty-five minutes to under ten minutes.
Senior Business Development Executive at DigitalTrack Solutions Ind Pvt Ltd
 

Customer Service

Sentiment score
5.8
ForgeRock customer service is flexible and responsive, but improvements are needed for professional services and ticket resolution speed.
Sentiment score
7.0
One Identity Active Roles is praised for knowledgeable service and reliability, though complex issues may need escalated support.
The support portals offer comprehensive documentation, troubleshooting guides, and community forums that have been helpful for resolving common issues independently.
Software Engineer at a financial services firm with 10,001+ employees
For standard support tickets, response times were very decent, and the support team was helpful in identifying configuration issues, especially with authentication trees, token settings, and directory replications.
Identity and Access Management Specialist at a university with 10,001+ employees
The team is very responsive and takes a sense of ownership and accountability.
Principal Consultant at Road2Value
They are ready to provide support at any time.
Technical Specialist at VDA Infosolutions Pvt. Ltd.
The support team is knowledgeable about the product and AD environments.
Network Security Engineer at a outsourcing company with 501-1,000 employees
Support is usually responsive for critical issues and provides solid practical guidance for AD workflow problems.
Cyber Security Analyst at a tech vendor with 51-200 employees
 

Scalability Issues

Sentiment score
7.3
ForgeRock offers scalable solutions for diverse enterprises, supporting seamless expansion, efficient administration, and integration across multiple environments.
Sentiment score
7.0
One Identity Active Roles efficiently scales for large enterprises, managing users across domains with automation and role-based delegation.
The access management layer is stateless, so I can scale horizontally by adding more nodes behind a load balancer as traffic increases.
Identity and Access Management Specialist at a university with 10,001+ employees
The platform provides flexible authentication trees, enabling us to design custom MFA flows tailored for different user groups and risk profiles.
Software Engineer at a financial services firm with 10,001+ employees
We scaled up with ForgeRock. My team received an award for implementing it for a 60 million customer base, which was the largest implementation at that time.
Principal Consultant at Road2Value
One Identity Active Roles works well in hybrid environments, handling both on-premises and cloud identities from a single platform.
Senior Business Development Executive at DigitalTrack Solutions Ind Pvt Ltd
It is commonly used in medium to large organizations managing complex Microsoft Active Directory and hybrid identity environments.
Professional Services Consultant at Check Point Software
The platform can scale without needing a complete redesign.
Senior Technical Support Executive at digital track
 

Stability Issues

Sentiment score
7.3
ForgeRock is stable and reliable, though customization affects stability, with users rating it seven to nine out of ten.
Sentiment score
8.2
One Identity Active Roles is stable, reliable, supports AD operations efficiently, and is well-rated by enterprise users for performance.
ForgeRock supports integration with legacy systems in our organization by offering a wide range of connectors and APIs.
Software Engineer at a financial services firm with 10,001+ employees
ForgeRock is very stable because it manages access, authentication, and authorization effectively.
Assistant Architect at a energy/utilities company with 501-1,000 employees
Overall, One Identity Active Roles has proven to be a stable, reliable, and well-suited solution for managing Active Directory at scale.
Senior Business Development Executive at Digitaltrack Solutions Pvt Ltd
Overall, I consider One Identity Active Roles to be a stable solution, suitable for enterprise-grade environments.
Technical Support Engineer at Digitaltrack
Consistently performing for daily operations like automation and user management without major downtime reported.
Associate technical desktop support at Digitaltrack soluctions Pvt. ltd
 

Room For Improvement

ForgeRock users suggest improving documentation, UI, DevOps support, onboarding, and training for better customization and admin experience.
One Identity Active Roles requires user interface modernization, easier setup, enhanced reporting, seamless integration, better documentation, and performance optimization.
ForgeRock needs to focus on low-code, no-code solutions that allow for drag-and-drop functionality with good orchestration.
CIAM Engineer at a tech vendor with 10,001+ employees
It would be better if they were available for support whenever the customer needs it, especially during migration or go-live time periods.
IAM Solution Architect at a tech services company with 1-10 employees
The main area is complexity. ForgeRock is extremely flexible, but the learning curve can be steep.
Identity and Access Management Specialist at a university with 10,001+ employees
The current REST API feels like an afterthought, and my developers want the ability to operate through CI/CD pipelines instead of logging into the GUI.
Identity and Access Management Specialist at a university with 10,001+ employees
Improving documentation and providing more guided implementation resources would help organizations accelerate deployment and reduce dependency on external support.
Technical Support Engineer at Digitaltrack
Stronger, more seamless integration with cloud and hybrid environments like Azure AD, along with enhanced real-time reporting dashboards and easier troubleshooting tools, would help in faster issue resolution and a better overall administration experience.
Senior System Administrator at 3i Infotech
 

Setup Cost

ForgeRock offers flexible pricing with community and enterprise options, seen as fair, supporting various features and open-source choices.
One Identity Active Roles has high upfront costs but offers long-term efficiency, security, and positive ROI for enterprises.
One has to spend considerable time trying to understand the different modules and different needs for those modules on the licensing front.
Principal Consultant at Road2Value
It is quite expensive, costing more than 50 euros per identity.
solution architect/ engineer at APEX.IT Sp. z o.o.
I think our total was in the seven-figure range for a couple of years of service.
Director, Identity & M365 Engineering at a healthcare company with 10,001+ employees
The initial investment includes licensing, infrastructure setup, and implementation effort, with licensing typically based on the number of managed users or accounts, which can increase costs in large environments.
Technical Support Engineer at Digitaltrack
 

Valuable Features

ForgeRock offers flexible authentication, scalability, and DevOps support with strong API integration, enhancing security and operational efficiency.
One Identity Active Roles improves efficiency and security by automating Active Directory management, reducing errors and enhancing access control.
Centralized management makes the biggest difference because it allows us to define, update, and enforce security and compliance rules from a single location.
Software Engineer at a financial services firm with 10,001+ employees
ForgeRock positively impacts our organization as we manage a large number of users with ease, providing a standard IAM solution that simplifies our processes.
CIAM Engineer at a tech vendor with 10,001+ employees
ForgeRock has positively impacted my organization by allowing us to migrate from the older system to the newer ForgeRock component, enabling us to go live with many products across geographies, enhancing security as it is all cloud-based, and with the company taking care of availability, it has reduced costs for the company.
IAM CONSULTANT at a tech services company with 10,001+ employees
It's improved our security posture. It has limited access to our crown jewels, where all our identities lie within Active Directory.
IAM Specialist
It helps in removing custom Active Directory delegation, which enhances security by eliminating unnecessary privileges, addressing identity-based breaches by reducing the number of Active Directory delegations.
Head of Global Digital Identity Services at a hospitality company with 10,001+ employees
Dynamic groups are also one of the best features, eliminating the need to add or manage members manually.
Technical Specialist at LSEG
 

Categories and Ranking

ForgeRock
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
37
Ranking in other categories
Identity Management (IM) (9th), Access Management (8th), Customer Identity and Access Management (CIAM) (4th)
One Identity Active Roles
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
71
Ranking in other categories
User Provisioning Software (3rd), Active Directory Management (1st), Non-Human Identity Management (NHIM) (2nd)
 

Mindshare comparison

While both are Identity and Access Management solutions, they serve different purposes. ForgeRock is designed for Access Management and holds a mindshare of 4.5%, down 6.6% compared to last year.
One Identity Active Roles, on the other hand, focuses on Active Directory Management, holds 11.9% mindshare, up 6.8% since last year.
Access Management Mindshare Distribution
ProductMindshare (%)
ForgeRock4.5%
Microsoft Entra ID12.9%
Okta Platform11.4%
Other71.2%
Access Management
Active Directory Management Mindshare Distribution
ProductMindshare (%)
One Identity Active Roles11.9%
Netwrix Auditor10.6%
ManageEngine ADManager Plus10.1%
Other67.4%
Active Directory Management
 

Featured Reviews

SR
Software Engineer at a financial services firm with 10,001+ employees
Centralized access control has improved secure onboarding and supports strict compliance
I wish we had used ForgeRock's adaptive risk-based authentication, which allows dynamic adjustment of authentication requirements based on user behavior. This could have helped us further strengthen our security. Another hidden gem is the built-in support for custom authentication modules and scripting, which gives a great deal of flexibility to tailor authentication flows. The self-service capabilities for password resets and account recovery have been very helpful in reducing support overhead and improving user experience. Discovering and utilizing these features would have definitely made our integration even smoother and would have provided additional value for both our users and our security team. One area of improvement would be the user interface for policy and workflow configuration, which can become complex and sometimes unintuitive, especially for new administrators. A more streamlined and user-friendly UI would help reduce the learning curve. Enhanced out-of-the-box analytics and reporting would also be valuable, as our current options often require custom development or integration with external tools. While extensibility is a strength, documentation for advanced customizations and integrations could be more comprehensive and easier to follow. Improved support for seamless upgrades and backward compatibility would also help minimize downtime. In terms of performance, optimizing the platform for high concurrency environments would be beneficial, especially for organizations with large user bases or peak usage periods. Enhanced scalability features such as more granular or horizontal scaling options would provide better support for distributed deployments. For integrations, having more pre-built connectors and easy integration with modern cloud-native services would accelerate adoption. Improved monitoring and real-time health dashboards would help proactively identify and resolve performance bottlenecks.
Mahesh Malve - PeerSpot reviewer
Senior Business Development Executive at DigitalTrack Solutions Ind Pvt Ltd
Automation has transformed user lifecycle tasks and now enforces consistent secure access
While One Identity Active Roles is a strong platform, a few improvements would make it even better. Many users feel the user interface is not very modern or intuitive, and it can take time to get used to navigating the console and workflows. Another improvement area is the learning curve and setup complexity. One Identity Active Roles is very powerful, but initial configuration, especially for policies, workflows, and delegation, can be complex and require experienced resources. From an integration perspective, although it supports multiple systems, organizations would benefit from more out-of-the-box connectors and smoother cloud integrations such as Azure Active Directory and software-as-a-service applications, as some setups currently require customization. In terms of reporting, while auditing is strong, generating business-friendly reports can be challenging. Users have mentioned the need for better dashboards and easier report generation. There are also some performance considerations, especially in large environments, such as slower PowerShell execution or delays in dynamic group processing in certain cases. Overall, improvements in user interface, ease of use, integration, reporting, and performance optimization would significantly enhance the product experience.
report
Use our free recommendation engine to learn which Access Management solutions are best for your needs.
895,151 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Computer Software Company
6%
Manufacturing Company
6%
Insurance Company
6%
Outsourcing Company
19%
Financial Services Firm
8%
Computer Software Company
8%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise5
Large Enterprise18
By reviewers
Company SizeCount
Small Business71
Midsize Enterprise14
Large Enterprise38
 

Questions from the Community

What is your experience regarding pricing and costs for ForgeRock?
The pricing, setup cost, and licensing are very straightforward, which is a good success. I appreciate that it is very straightforward and helpful.
What needs improvement with ForgeRock?
There are some areas I want ForgeRock to improve. These areas include policy configuration, documentation clarity, UI complexity, and debugging token flow. I want ForgeRock to improve in documentat...
What is your primary use case for ForgeRock?
I am using ForgeRock for standard support, policy configurations, and documentation clarity. The pricing, setup cost, and licensing are very straightforward, which is a good success. I appreciate t...
What is your experience regarding pricing and costs for One Identity Active Roles?
My experience with pricing and licensing for One Identity Active Roles has been reasonable for an enterprise solution, but it does require proper planning. The initial setup can involve some cost i...
What needs improvement with One Identity Active Roles?
One Identity Active Roles is very useful, though there are a few areas where it could be improved, such as the user interface, policy creation, and reporting - it requires good knowledge of Active ...
What is your primary use case for One Identity Active Roles?
One Identity Active Roles is used primarily for managing Active Directory, including user provisioning and group management. When a new employee joins, I use One Identity Active Roles to automatica...
 

Also Known As

ForgeRock Identity Platform, ForgeRock OpenIDM
Quest Active Roles
 

Overview

 

Sample Customers

Geico, Thomson Reuters, Salesforce, McKesson, Trinet, SKY, BNP Paribas, Deloitte, Capgemini, North Western University
City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Find out what your peers are saying about ForgeRock vs. One Identity Active Roles and other solutions. Updated: March 2020.
895,151 professionals have used our research since 2012.