One Identity Active Roles vs SailPoint Identity Security Cloud comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

One Identity Active Roles
Ranking in User Provisioning Software
5th
Average Rating
8.6
Number of Reviews
17
Ranking in other categories
Active Directory Management (3rd)
SailPoint Identity Security...
Ranking in User Provisioning Software
1st
Average Rating
8.2
Number of Reviews
64
Ranking in other categories
Identity Management (IM) (2nd), Identity and Access Management as a Service (IDaaS) (IAMaaS) (4th), Cloud Infrastructure Entitlement Management (CIEM) (1st)
 

Mindshare comparison

As of July 2024, in the User Provisioning Software category, the mindshare of One Identity Active Roles is 7.6%, up from 5.8% compared to the previous year. The mindshare of SailPoint Identity Security Cloud is 33.3%, up from 26.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Provisioning Software
Unique Categories:
Active Directory Management
6.8%
Identity Management (IM)
21.9%
Identity and Access Management as a Service (IDaaS) (IAMaaS)
8.5%
 

Featured Reviews

LA
Jul 12, 2023
Give us control over attributes a service desk analyst can change, and we can build in integrity rules
The Group Family feature is okay, but there are some issues around its use for creating objects automatically, based on HR attributes. Another issue is that it doesn't look like the hybrid connections are particularly mature. We haven't really used it much. We have a couple of guys setting it up who don't really like the way it's working. It uses a synchronization tool to do that. Native integration with the cloud would be better. Also, we're trying to manage Office 365 mailboxes and although it will create a mailbox in the cloud, it won't do shared mailboxes. That means we're having to write custom solutions for that. Another issue we have with the product is that we run a lot of custom tasks. You have to program them to run on one particular host and there's no automatic failover to a second host. If that host is down when a task is supposed to run, it has to wait until the next time it runs when that host is up. Some of their built-in functions will work off of both servers and I don't see why this shouldn't as well. Another similar gripe is that when you run custom Active Roles policies, they'll actually trigger on both hosts, not on one. In that scenario, it would be better if they would trigger on one host, unless it wasn't available. For example, if you're writing to the event log, you have a custom task and it will show up multiple times because it's being processed by multiple front-end hosts.
MM
Jul 20, 2022
Automated and integrates well with other platforms
In the past, we had a lot of problems with SailPoint IdentityIQ, particularly in providing access and provisioning. There were some gaps in the operation of the solution because they were manual rather than automated, and the users and administrators were given access directly via Active Directory, and it wasn't appropriate for us at the time to use. In terms of integration, we could provide a more automated solution after a minimum number of years, but not in the SailPoint IdentityIQ platform, but there were problems in the registration, for example, with putting information inside ADP, but in general, we were able to solve those problems, and after implementing SailPoint IdentityIQ we had increased evaluations.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Instead of deleting accounts, we like the deprovision option so that we can reverse any accidental deletions. It also gives a higher level of quality control in terms of enforcing any number of variables, such as making sure that an account has a description entered before the account can be created. We can backtrack and know the history of it that way."
"The solution is stable."
"Because of Active Roles, we're able to synchronize on an even more regular basis. It enables us to provide even more information to the Active Directory, which helped us to group our users in a more consistent manner."
"In comparison to native Active Directory tools, using Active Roles for delegation is so much better. It uses an access template and that makes it easy to see who can access what. In fact, you can do that for many objects as well."
"It provides automatic provisioning/update/deprovisioning workflows from a source system to a target system."
"The provisioning and deprovisioning saves a lot of time and skips a lot of errors."
"It's valuable to us in that it resembles the native tools that most people have grown accustomed to... Active Roles resembles traditional tools, such as from Microsoft. That is really good because it eases the way people interact with the tool."
"The biggest thing for us is Active Roles saves a lot of man-hours in keeping groups up-to-date manually or trying to write some sort of script that you have to run, so we don't have to reinvent the wheel. Instead of when every time somebody joins a department, then somebody has to remember to put in a request to add "meet user Joe" to this group, the solution does it automatically for us. Therefore, it saves our business and IT staff time because they do not have to process requests since Active Role can do it for them."
"The first valuable feature of the solution is its interface. The second feature of the solution is the level of flexibility it provides."
"This solution is great for providing control access across your environment."
"User provisioning and the role management features are good."
"I find the built-in connectors, lifecycle management, certification, and recertification features to be the most valuable."
"The tool's GUI is user-friendly."
"The solution is one of the main security products you need to control access and have visibility into what's happening in your organization. It helps with managing access to applications, ensuring governance, and obtaining certifications."
"We like the integration with other systems."
"It offers a single source of truth. Everything can be handled from one tier."
 

Cons

"When doing a workflow, we would like a bit better feedback on the screen, as we're trying to get it to work. For example, there is a "Find" function that you need set up in a workflow to do some of the automation. It is not the easiest to get a result from those finds when you're trying to do that. In the MMC, they have a couple different types of workflows. In this particular case, we use their workflow functionality to find all of X within the environment, then if you find it, do X, Y, and Z. You can have multiple steps. When you do that search function within that workflow, it's really hard to find out, "Is my search working?" It would be nice if there was some feedback on the screen so you could see if your search is working properly within the workflow."
"The initial setup was quite easy, but it was time-consuming. It took about three months."
"The user and group management in Azure AD could be better. Our focus these days is dynamic sharing with several on-prem Microsoft applications like SharePoint."
"Another issue we have with the product is that we run a lot of custom tasks. You have to program them to run on one particular host and there's no automatic failover to a second host. If that host is down when a task is supposed to run, it has to wait until the next time it runs when that host is up."
"Most of the time it just works."
"In terms of improvement, it could be made even more user-friendly for administrators when they need to create new workflows and rule sets."
"I've had a difficult time getting it to cooperate with Azure in the cloud and, while the support staff are very good and very knowledgeable, what they assist with just on a call doesn't go deep enough to help with a number of issues. The answer that comes back is that we'd have to start an engagement with Professional Services, which is fine but that takes time to schedule and it takes budget."
"The third area for improvement, which is the weakest portion of ARS, is the workflow engine, which was introduced a few years ago. It's slow and not very intuitive to use, so I would like to see improvement there."
"Scalability is hard, especially when you are doing it in real time."
"In the past, we had a lot of problems with SailPoint IdentityIQ, particularly in providing access and provisioning. There were some gaps in the operation of the solution because they were manual rather than automated, and the users and administrators were given access directly via Active Directory, and it wasn't appropriate for us at the time to use. In terms of integration, we could provide a more automated solution after a minimum number of years, but not in the SailPoint IdentityIQ platform, but there were problems in the registration, for example, with putting information inside ADP, but in general, we were able to solve those problems, and after implementing SailPoint IdentityIQ we had increased evaluations."
"Regarding the scope for improvement in the solution, reporting is an area that can be a bit more UI-oriented."
"The user interface could be slightly improved. It could be made simpler and more user-friendly, however, it is good enough right now."
"It is too technical. You need really good technical skills in Java and other technologies, which are hard to find. If they can make it easier so that things can be done with a few clicks, it will be great."
"The cost of this solution is high. The technical assistance center could be improved. They're very good, but considering the intricacies of the solution, they can further improve."
"There is a need for further enhancements, specifically in the multifactor authentication capabilities."
"I think that the onboarding framework could be improved."
 

Pricing and Cost Advice

"The licensing model is a simple user-based model, not that much complicated."
"It's expensive."
"It's fairly priced."
"The price is reasonable. It costs us about 1 million Danish kroner annually, and we also spend about half as much on consultants."
"The pricing is on the higher end."
"Usually, the cost of deploying about 5,000 licenses or 5,000 users, would be the equivalent to the cost of the license, which would be reaching up to around $90,000."
"The licensing fees are on a yearly basis."
"The product is expensive. I rate its pricing an eight out of ten."
"I rate the solution a seven on a scale where one is cheap and ten is too expensive. In short, the solution falls under the higher side of pricing."
"This is an expensive solution. I would rate it a two and a half out of five for pricing."
"You do pay one price for the license but that price depends on what you choose to include as far as the optional modules go."
"The pricing is a little bit higher than other tools."
"The product is expensive. People need to opt for a licensing plan for one year or three years."
report
Use our free recommendation engine to learn which User Provisioning Software solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
11%
Healthcare Company
9%
Government
9%
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
10%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for One Identity Active Roles?
The solution is fairly priced. That said, I have nothing to compare it to.
What needs improvement with One Identity Active Roles?
The solution has not enabled us to reduce password reset times. It has not automated provisioning. The group attestation could be improved. It was a feature that was available in version 5. You can...
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about SailPoint IdentityIQ?
The first valuable feature of the solution is its interface. The second feature of the solution is the level of flexibility it provides.
What is your experience regarding pricing and costs for SailPoint IdentityIQ?
The product is expensive. People need to opt for a licensing plan for one year or three years.
 

Also Known As

Quest Active Roles
IdentityIQ, IdentityNow, Cloud Infrastructure Entitlement Management
 

Overview

 

Sample Customers

City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Adobe, AXA Technology Services, Cuna Mutual Group, Equifax, ING Direct, Orrstown Bank, Rockwell Automation, SallieMae, Spirit Aerosystems, TEL
Find out what your peers are saying about One Identity Active Roles vs. SailPoint Identity Security Cloud and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.