Try our new research platform with insights from 80,000+ expert users

Microsoft Entra Permissions Management vs One Identity Manager comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Entra Permissions...
Average Rating
7.0
Reviews Sentiment
7.0
Number of Reviews
2
Ranking in other categories
Microsoft Security Suite (31st), Cloud Infrastructure Entitlement Management (CIEM) (7th)
One Identity Manager
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
119
Ranking in other categories
User Provisioning Software (1st), Identity Management (IM) (3rd)
 

Mindshare comparison

Microsoft Entra Permissions Management and One Identity Manager aren’t in the same category and serve different purposes. Microsoft Entra Permissions Management is designed for Cloud Infrastructure Entitlement Management (CIEM) and holds a mindshare of 7.0%, down 22.4% compared to last year.
One Identity Manager, on the other hand, focuses on Identity Management (IM), holds 6.1% mindshare, down 7.0% since last year.
Cloud Infrastructure Entitlement Management (CIEM)
Identity Management (IM)
 

Featured Reviews

Sameer Bhat - PeerSpot reviewer
Provides resource-based access and security, but time-bound access can be a problem
Entra ID is the core of the identity management that we have. This is the key product that we are using. I am currently also looking into Entra Private Access because we are planning to deploy about 50,000 desktops into Azure and use Azure Virtual Desktop. We would like to give access to the users from the desktop to on-premises applications. I learned that Entra Private Access is a good solution. That is not yet GA, but that is what we are looking for. Entra provides a single pane of glass for managing user access, but because our company also integrates with Nebula API, only administrators use Entra's pane. A normal person who wants to get onboarded can do self-service using Nebula. The features for whitelisting and other things are definitely there. That is what we use specifically. Application IDs, enterprise applications, and all those things are already there, so we have more efficiency. There is also security because we usually do not allow user identities to get direct access to Azure resources. Usually, we use the service principles from Entra ID, so this way, it increases security. Entra has helped to save time for our IT administrators. We tend to automate a lot of things. We can do automation using Graph APIs and save time. It is hard to quantify the time savings, but there has been a medium amount of time savings. Entra has helped to save our organization money. We care about security and risk more than money, but it also saves money. We are premium customers, and because we have a commit-to-consume contract with Microsoft of multi-million dollars, the money does not come into it because we have to consume those resources.
Ranjan Mishra - PeerSpot reviewer
Enables our organization to manage accounts across multiple target systems from a central identity management solution
The One Identity Manager web portal needs simplification. While a new Angular portal was introduced with version 8.2, the knowledge base lacks sufficient information and resources. Even with an Angular developer or a One Identity specialist, a knowledge gap exists due to the combination of AngularJS and One Identity schema expertise required. This makes it difficult to find resources that can effectively utilize the portal, highlighting the need for a more user-friendly interface. One Identity Manager currently offers Long Term Support only for version 9.0. All other versions have a two-year lifecycle with extended support. For organizations managing a complex environment with numerous connected systems, users, and assignments, upgrading every two years is impractical. Extending support for regular versions by one or two years would benefit clients in this situation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution integrates well with our infrastructure and other systems without any issues."
"Multifactor authentication is valuable."
"The most valuable features are centralized Identity Management, robust Access Governance, and One Identity Manager workflow automation."
"The most valuable feature is the JML. Unlike other identity manager tools, the JML is more customizable, making it easier to find."
"One of the valuable features is that it is relatively organized. I definitely appreciate that aspect. It is also relatively simple to use with a very easy flow to the GUI. The user interface is really top-notch."
"For the recertification and segregation of duties, it's easier to know all the information about our employees. If we need to delete some information, we can do it from a central point, then it can be deleted on all our searches. This is very good for GDPR."
"What I like the most is the flexibility or configurability."
"We no longer keep users who shouldn't exist."
"Quest One IDM allows for large customization."
"The most valuable features are the behavior, configuration, and customization options."
 

Cons

"We use a third-party API called Nebula API to integrate the account for authorization. The time-bound access area in Entra can be a problem. It can be improved in terms of the granularity of the permissions."
"The solution's pricing and support services need improvement."
"The policy and role management features are a bit hard to scale. The whole model for who can do what and how to set it up is not so well-governed for a larger organization. The demos are always shown for a 100 or a 1000 people, but when it is a large number, it is quite difficult to maintain."
"The product's GUI could be more user-friendly."
"Integration with various applications should be made smoother. It is very difficult right now for regular implementers. Access reviews are another thing that is not that good in the solution. It needs improvement."
"There is a small area inside of the administrator's GUI that could be a little bit more organized."
"The initial setup was quite complex because you run into some existing policies that the company already had. There was some trouble with some inconsequential policies."
"I would like to have more extensive out-of-the-box reports."
"The documentation I found in their repository is neither interactive nor engaging."
"We would like the product to integrate with ServiceNow, since One Identity Manager and ServiceNow are two of our better tools."
 

Pricing and Cost Advice

"We are a Fortune 500 company, so we always negotiate with Microsoft."
"The product cost is in the mid to high range."
"We are using a self-built solution. It would cost too much to get that up to the standard of what we need. In the long-term, it is cheaper to buy a solution that has what we need. Though, we are still running the previous solution, as we are still in the implementation phase."
"On-premises, it is cheap. It is way cheaper than others. The cost of the hosted one varies. They do offer a hosted one, and its cost varies, but it is not that expensive. You have a license for employees and a license for support."
"Prices in Turkey are high due to inflation, a challenge we've heard about from our customers."
"There are old processes that are really great for some people and look like pieces of artwork. However, the maintenance of them is really expensive."
"I am aware of the cost. For us, it is quite cost-efficient. We have a good enterprise license agreement, and we are very happy with what we get for the price we pay for it."
"One Identity Manager is fairly priced."
"One Identity Manager has a reasonable price point."
"We pay yearly and per active user. One of the reasons that we chose One Identity Manager is because of the pricing. It is reasonable and affordable compared to other products which we considered before choosing this solution for the company."
report
Use our free recommendation engine to learn which Cloud Infrastructure Entitlement Management (CIEM) solutions are best for your needs.
860,711 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
14%
Government
10%
Manufacturing Company
8%
Computer Software Company
17%
Financial Services Firm
15%
Manufacturing Company
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Microsoft Entra Permissions Management?
The product cost is in the mid to high range. You need to have a good budget to implement it, so it is considered fairly expensive for our market. I rate the pricing a seven out of ten.
What needs improvement with Microsoft Entra Permissions Management?
The solution's pricing and support services need improvement.
What do you like most about One Identity Manager?
The One Identity birthright process has helped generate user accounts more accurately and quickly.
What is your experience regarding pricing and costs for One Identity Manager?
One Identity Manager is positioned as a premium product. It falls between middle and high in terms of cost, approximately a six to seven if ten is expensive.
What needs improvement with One Identity Manager?
The user experience has been a concern in the past, particularly with the web interface, but improvements are expected with the transition to Angular. The support from One Identity is very poor. Th...
 

Also Known As

CloudKnox Permissions Management
Quest One Identity Manager
 

Overview

 

Sample Customers

Information Not Available
Texas A&M, Sky Media, BHF Bank, Swiss Post, Union Investment, Wayne State University. More at OneIdentity.com/casestudies
Find out what your peers are saying about SailPoint, CrowdStrike, Trend Micro and others in Cloud Infrastructure Entitlement Management (CIEM). Updated: June 2025.
860,711 professionals have used our research since 2012.