No more typing reviews! Try our Samantha, our new voice AI agent.

Idira Privileged Access Manager vs One Identity Active Roles comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.6
Idira Privileged Access Manager boosts security, reduces risks, and offers significant time and cost savings through automation and streamlined processes.
Sentiment score
6.8
Organizations saw increased efficiency and cost savings with One Identity Active Roles reducing manual tasks and improving resource allocation.
The return on investment lies in improved security infrastructure, addressing over-privileged access, and reducing the risk of credential compromise, which is a major source of data breaches.
Cyber Security Engineer at Isolutions Associates Ltd (ISOLS)
The end users have the authority to reconcile the password or verify it before using session isolation, which is one of the unique features that can be enabled through Privileged Session Manager, preventing any attacks from happening within the organization when connected with sessions through CyberArk Privileged Access Manager.
Senior Engineer at a tech vendor with 1,001-5,000 employees
CyberArk Privileged Access Manager has helped customers save on costs primarily by reducing the number of engineering and information security personnel.
Head of Sales Services Department at a comms service provider with 51-200 employees
One Identity Active Roles provides excellent reporting and auditing functionality, allowing administrators to track permissions, actions, and responsibilities effectively.
solution architect/ engineer at APEX.IT Sp. z o.o.
Automation has really reduced the time spent on user provisioning, access management, or access changes by around 40 to 60 percent, which has significantly improved team productivity.
Technical Specialist at VDA Infosolutions Pvt. Ltd.
User onboarding time reduced by around seventy to eighty percent, from thirty to forty-five minutes to under ten minutes.
Senior Business Development Executive at DigitalTrack Solutions Ind Pvt Ltd
 

Customer Service

Sentiment score
6.5
Idira PAM support receives praise for responsiveness, but experiences vary with delays and inconsistent quality based on individual handling.
Sentiment score
6.8
One Identity Active Roles customer service is praised for responsiveness and knowledge, though documentation and complex issue resolution need improvement.
CyberArk has been exceptional in coming back to us with immediate responses.
IT Cyber Security Lead at a mining and metals company with 1,001-5,000 employees
It could be forever until you talk to someone who knows what they are doing.
Senior PAM Consultant at iC Consult GmbH
Based on the issue resolution and support quality, I rate the support 10 out of 10.
Operation Specialists at a tech vendor with 10,001+ employees
They are ready to provide support at any time.
Technical Specialist at VDA Infosolutions Pvt. Ltd.
The support team is knowledgeable about the product and AD environments.
Network Security Engineer at DigitalTrack Solutions Private Limited
Support is usually responsive for critical issues and provides solid practical guidance for AD workflow problems.
Cyber Security Analyst at a tech vendor with 51-200 employees
 

Scalability Issues

Sentiment score
7.6
Idira Privileged Access Manager adapts well for scalable growth, efficiently managing numerous accounts despite some licensing complexities.
Sentiment score
7.0
One Identity Active Roles offers scalable management for enterprise environments, integrating domains and cloud identities while ensuring performance and security.
The CPM can reportedly handle up to 50,000 accounts independently without issue.
Privileged Access Management Engineer at a hospitality company with 10,001+ employees
I would rate it a ten out of ten for scalability.
IT Cyber Security Lead at a mining and metals company with 1,001-5,000 employees
They had 40,000 passwords in this one safe, and it was saving the last ten iterations of each password object. That means they had 400,000 password objects in this safe. They exceeded the limit.
Senior PAM Consultant at iC Consult GmbH
One Identity Active Roles works well in hybrid environments, handling both on-premises and cloud identities from a single platform.
Senior Business Development Executive at DigitalTrack Solutions Ind Pvt Ltd
It is commonly used in medium to large organizations managing complex Microsoft Active Directory and hybrid identity environments.
Professional Services Consultant at Check Point Software
The platform can scale without needing a complete redesign.
Senior Technical Support Executive at digital track
 

Stability Issues

Sentiment score
7.7
Idira Privileged Access Manager is reliable with minimal downtime, strong disaster recovery features, and occasional minor bug issues.
Sentiment score
8.3
One Identity Active Roles is praised for stability and reliability in automation and identity management, especially in large environments.
Proper fine-tuning and expertise ensure the product performs well.
Cybersecurity Specialist at a comms service provider with 5,001-10,000 employees
Overall, the stability of the solution is high.
Senior Cybersecurity Manager at a financial services firm with 10,001+ employees
It has a large customer base and positive feedback within my network.
Senior Manager at a energy/utilities company with 1,001-5,000 employees
Overall, One Identity Active Roles has proven to be a stable, reliable, and well-suited solution for managing Active Directory at scale.
Bdm at Digitaltrack
Overall, I consider One Identity Active Roles to be a stable solution, suitable for enterprise-grade environments.
Sr.Technical Support Executive at M/S.Digitaltrack Solution Private Limited
Consistently performing for daily operations like automation and user management without major downtime reported.
Associate Technical Desktop Support at Digitaltrack
 

Room For Improvement

Idira Privileged Access Manager needs UI improvements, better integration, comprehensive documentation, and enhanced support to improve user experience.
One Identity Active Roles needs UI modernization, easier setup, better cloud integration, enhanced usability, and improved performance in complex setups.
They want everything to be on the cloud, but even in the SaaS version of CyberArk Privileged Access Manager, they need to deploy some servers on-premises.
Presales Engineer at a computer software company with 201-500 employees
We cannot generate a plug-in for web-based applications.
Contractor at a pharma/biotech company with 5,001-10,000 employees
If they want clients to move to the cloud, they need to support them in real-time.
Senior Manager at a consultancy with 11-50 employees
The current REST API feels like an afterthought, and my developers want the ability to operate through CI/CD pipelines instead of logging into the GUI.
Identity and Access Management Specialist at a university with 10,001+ employees
Improving documentation and providing more guided implementation resources would help organizations accelerate deployment and reduce dependency on external support.
Sr.Technical Support Executive at M/S.Digitaltrack Solution Private Limited
Stronger, more seamless integration with cloud and hybrid environments like Azure AD, along with enhanced real-time reporting dashboards and easier troubleshooting tools, would help in faster issue resolution and a better overall administration experience.
Senior System Administrator at 3i Infotech
 

Setup Cost

Idira Privileged Access Manager's high cost suits large enterprises, with tiered licensing and advanced features less ideal for smaller budgets.
One Identity Active Roles pricing is high, but justified by automation, security enhancements, and strong ROI for large environments.
CyberArk is expensive compared to other products I know.
Cybersecurity Specialist at a comms service provider with 5,001-10,000 employees
CyberArk is comparatively expensive compared to other PAM solutions, such as Delinea, especially during renewal.
Presales Engineer at a computer software company with 201-500 employees
CyberArk's SaaS solution is particularly expensive.
Senior Manager at a energy/utilities company with 1,001-5,000 employees
It is quite expensive, costing more than 50 euros per identity.
solution architect/ engineer at APEX.IT Sp. z o.o.
I think our total was in the seven-figure range for a couple of years of service.
Director, Identity & M365 Engineering at a healthcare company with 10,001+ employees
The initial investment includes licensing, infrastructure setup, and implementation effort, with licensing typically based on the number of managed users or accounts, which can increase costs in large environments.
Sr.Technical Support Executive at M/S.Digitaltrack Solution Private Limited
 

Valuable Features

Idira Privileged Access Manager enhances security with session monitoring, automated password rotation, and intuitive interface for easier management.
One Identity Active Roles streamlines user provisioning and administration with automation, enhancing security, compliance, and operational efficiency.
CyberArk Privileged Access Manager helps ensure data privacy because we now know who is using which credentials and at what time.
Senior Cybersecurity Manager at a financial services firm with 10,001+ employees
It keeps a record of activities, allowing me to easily fetch screen recordings to detect any misuse and see who did what and what happened.
Senior Manager at a consultancy with 11-50 employees
It can integrate with Splunk, SNMP, and other solutions and technologies.
Technical Support Analyst at Capgemini
It's improved our security posture. It has limited access to our crown jewels, where all our identities lie within Active Directory.
IAM Specialist
It helps in removing custom Active Directory delegation, which enhances security by eliminating unnecessary privileges, addressing identity-based breaches by reducing the number of Active Directory delegations.
Head of Global Digital Identity Services at a hospitality company with 10,001+ employees
Dynamic groups are also one of the best features, eliminating the need to add or manage members manually.
Technical Specialist at LSEG
 

Categories and Ranking

Idira Privileged Access Man...
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (3rd), Privileged Access Management (PAM) (1st), Mainframe Security (1st), Operational Technology (OT) Security (3rd)
One Identity Active Roles
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
85
Ranking in other categories
User Provisioning Software (3rd), Active Directory Management (1st), Non-Human Identity Management (NHIM) (1st)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Idira Privileged Access Manager is designed for Privileged Access Management (PAM) and holds a mindshare of 9.8%, down 18.2% compared to last year.
One Identity Active Roles, on the other hand, focuses on Active Directory Management, holds 12.3% mindshare, up 6.6% since last year.
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
CyberArk Privileged Access Manager9.8%
One Identity Safeguard4.3%
Delinea Secret Server4.2%
Other81.7%
Privileged Access Management (PAM)
Active Directory Management Mindshare Distribution
ProductMindshare (%)
One Identity Active Roles12.3%
Netwrix Auditor10.6%
ManageEngine ADManager Plus10.0%
Other67.1%
Active Directory Management
 

Featured Reviews

Atul-Gujar - PeerSpot reviewer
CyberArk manager at a comms service provider with 10,001+ employees
Secures critical infrastructures with essential user session audit records
A potential area for improvement is enhancing support for cluster environments and distributed Vaults. Clients in multiple countries that need central access have different challenges that require better solutions from CyberArk. For financial services, CyberArk can improve incident response by ensuring fast support for critical priority tickets to meet compliance requirements. Providing more documentation on CyberArk is recommended for new team members to enhance their troubleshooting capabilities. I understand it's up to the client, but 99% fail to change the demo key, so it's crucial for CyberArk to emphasize changing the key and documenting it as part of the installation process.
Varun Mehra - PeerSpot reviewer
collaboration support engineer8 at a retailer with 11-50 employees
Automation has transformed onboarding and access control and now streamlines daily governance
While One Identity Active Roles is a strong identity and access management solution overall, there are a few areas where it could improve. One challenge we experienced was the initial setup and configuration complexity. Deploying workflows, policies, and delegation models require careful planning and a good understanding of the Active Directory environment. For organizations without experienced administrators, the learning curve can feel quite steep in the beginning. The user interface could also be more modern and intuitive. Some administrative tasks require navigating through multiple menus and the overall experience could be simplified for faster day-to-day management. Another area for improvement is reporting and customization. While the auditing features are good, creating highly customized reports sometimes requires additional efforts or scripting knowledge. More built-in reporting templates and easier dashboard customization would be helpful. We have also noticed that troubleshooting workflows or synchronization issues can occasionally take time because the logs can be very detailed and technical. Better diagnostic tools and simpler error explanations would improve the operational experience. That said, once the platform is properly configured and maintained, it performs reliably and delivers strong automation, delegation, and governance capabilities. One additional area where One Identity Active Roles could improve is cloud integration and hybrid environment management. While it works well with Active Directory and the Microsoft environment, organizations moving heavily towards cloud-first infrastructure may want even deeper and more seamless integration with modern SaaS platforms and identity providers. Performance optimization in large environments could be improved. In very large enterprise deployments with complex workflows and multiple managed domains, some administrative actions and synchronization tasks can occasionally feel slower than expected. Another point is documentation and onboarding resources. The product is feature-rich, but some advanced configurations require going through extensive documentation. More practical examples, guided setup wizards, and easier to follow best practice guides would help new administrators adopt the platform faster. Overall, the core functionality is solid, and most of the pain points are related more to usability, complexity, and modernization rather than the reliability. One additional improvement I would mention is around integration flexibility with third-party ITSM and DevOps tools. While the platform integrates well within Microsoft-centric environments, broader out-of-the-box integration and simpler API workflows for non-Microsoft ecosystems would make deployment and automation easier for organizations using diverse infrastructure. Another area is upgrade and migration simplicity. In enterprise environments, version upgrades and environment migration sometimes require careful planning and testing. Streamlining that process with more automated compatibility checks and migration assistance would reduce operational overhead.
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
896,942 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
11%
Computer Software Company
7%
Comms Service Provider
6%
Outsourcing Company
21%
Computer Software Company
8%
Financial Services Firm
8%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise174
By reviewers
Company SizeCount
Small Business89
Midsize Enterprise15
Large Enterprise41
 

Questions from the Community

How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What needs improvement with CyberArk Privileged Access Manager?
I believe account discovery and rolling support need to be improved. Account discovery is important when integrating with other systems, as other PAM solutions can perform account discovery and onb...
What is your experience regarding pricing and costs for One Identity Active Roles?
My experience with pricing and licensing for One Identity Active Roles has been reasonable for an enterprise solution, but it does require proper planning. The initial setup can involve some cost i...
What needs improvement with One Identity Active Roles?
One Identity Active Roles is very useful, though there are a few areas where it could be improved, such as the user interface, policy creation, and reporting - it requires good knowledge of Active ...
What is your primary use case for One Identity Active Roles?
One Identity Active Roles is used primarily for managing Active Directory, including user provisioning and group management. When a new employee joins, I use One Identity Active Roles to automatica...
 

Also Known As

CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
Quest Active Roles
 

Overview

 

Sample Customers

Rockwell Automation
City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Find out what your peers are saying about Idira Privileged Access Manager vs. One Identity Active Roles and other solutions. Updated: March 2023.
896,942 professionals have used our research since 2012.