Try our new research platform with insights from 80,000+ expert users

One Identity Active Roles vs SailPoint Identity Security Cloud vs Symantec Identity Governance and Administration comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.4
One Identity Active Roles enhances efficiency and security, reduces workload and risks, delivering quick returns and increased user satisfaction.
Sentiment score
7.4
SailPoint Identity Security Cloud automates access, reduces costs, enhances security, boosts compliance, and offers ROI within 14-18 months.
Sentiment score
7.6
Symantec Identity Governance boosts ROI by streamlining onboarding, enabling self-service, and automating user management, enhancing IT efficiency.
One Identity Active Roles provides excellent reporting and auditing functionality, allowing administrators to track permissions, actions, and responsibilities effectively.
It has saved 90% of the time compared to before.
 

Customer Service

Sentiment score
7.7
One Identity Active Roles support is responsive and effective, with occasional delays; users rate it between seven and ten.
Sentiment score
6.7
SailPoint Identity Security Cloud has strong support and knowledgeable staff but faces critiques for slow response times and costs.
Sentiment score
6.2
Symantec's customer service is praised for responsiveness but needs improvement in geographical support and complex issue expertise.
One Identity's support is great.
I rate customer service and support as a seven because, although they are helpful when needed, there can be delays in responding to tickets and finding necessary fixes.
Sometimes having a fix for a bug takes too much time.
SailPoint's team consists of specialists who handle tickets without needing to depend on other teams.
Sometimes, the support is slow, and they often suggest resorting to expert services.
Technical support is very good.
 

Scalability Issues

Sentiment score
7.8
One Identity Active Roles is scalable for large user bases, efficiently managing multiple directories and automating tasks.
Sentiment score
7.2
SailPoint excels in scalability and identity management for enterprises, though needs careful resource planning, especially on virtual platforms.
Sentiment score
7.3
Symantec Identity Governance scales well and adapts to organizational needs, though some face customization and resource challenges.
It is very beneficial for large and complex environments.
If you are a major enterprise customer, it is a matter of scaling out on resources with more memory, disk, and CPU power.
The solution is highly scalable, with a scalability rating of nine.
The solution scales well as long as we provide the necessary resources.
The solution is scalable and can be upgraded to accommodate increased user counts.
SailPoint is scalable, though challenges exist in terms of workflow and user interface design.
 

Stability Issues

Sentiment score
7.4
One Identity Active Roles is generally stable with minimal maintenance, but occasional performance lags and updates are needed.
Sentiment score
7.9
SailPoint Identity Security Cloud is praised for its reliable performance and stability, handling complex environments effectively with minimal issues.
Sentiment score
6.6
Symantec Identity Governance's stability is generally satisfactory, with performance issues arising under heavy loads or improper tuning.
There were no major problems with One Identity Active Roles.
We haven't had any glitches.
I would rate the stability as a seven because there are sometimes performance issues, which require restarting the services.
IdentityIQ deserves a rating of 12 out of ten for stability.
The version I use now is very stable, especially compared to previous versions like eight point zero and eight point one.
 

Room For Improvement

One Identity Active Roles needs better web interface customization, scripting support, integration, user interface scalability, and improved workflows and security.
SailPoint Identity Security Cloud is costly with limited customization, challenging usability, and insufficient integration and support, needing feature improvements.
Symantec Identity Governance needs improvements in UI, integration, documentation, security, cloud performance, scalability, and user-friendliness.
A way to connect to various directories and integrate with cloud directories would be beneficial.
Enhancements to the console are also necessary because it is more confusing than the web interface.
The user interface needs to be more modern and scalable.
SailPoint lacks some features like privileged account management and access management features found in products like Okta.
I find raising a ticket to be too complex, which could be improved for better user-friendliness.
We have also put our enhancement request, and the SailPoint team has accepted that the feature is not available and plans to include it going forward.
 

Setup Cost

One Identity Active Roles uses a user-based licensing model with high costs but offers significant ROI and flexibility.
SailPoint Identity Security Cloud's pricing is high but valued for enterprise needs; smaller companies may find it less affordable.
Symantec Identity Governance pricing is mid-range, seen as expensive, with flexible licensing but time-consuming implementation.
It is quite expensive, costing more than 50 euros per identity.
The pricing is high.
The pricing of One Identity Active Roles is expensive, but the return on investment justifies the cost, allowing for savings in other areas.
SailPoint is cheaper than ServiceNow, which is very expensive.
The pricing of SailPoint could be better.
The costs are slightly higher than SailPoint IQ due to included charges for maintenance.
 

Valuable Features

One Identity Active Roles enhances security and management with robust access control, automation, integration, and centralized directory management.
SailPoint Identity Security Cloud excels with a user-friendly interface, strong governance, customizable workflows, and robust integration for businesses.
Symantec Identity Governance streamlines provisioning, access control, and policy compliance with flexible integration and user-friendly self-service features.
It's improved our security posture. It has limited access to our crown jewels, where all our identities lie within Active Directory.
It helps in removing custom Active Directory delegation, which enhances security by eliminating unnecessary privileges, addressing identity-based breaches by reducing the number of Active Directory delegations.
It is very intuitive and close to the native tools.
The automation of provisioning and deprovisioning, managing contractors, temporary users, and the overall automation factor is fantastic.
The solution can be customized to adapt the workflow to our industry, offering considerable flexibility.
From a project management point of view, the tool supports audit success with features to segregate permanent and contractor employees, integrate with HR systems, and indicate other sources for contractors.
 

Mindshare comparison

As of May 2025, in the User Provisioning Software category, the mindshare of One Identity Active Roles is 4.3%, up from 4.3% compared to the previous year. The mindshare of SailPoint Identity Security Cloud is 32.4%, up from 29.4% compared to the previous year. The mindshare of Symantec Identity Governance and Administration is 3.0%, up from 2.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Provisioning Software
 

Featured Reviews

Grzegorz Kosela - PeerSpot reviewer
Task automation simplifies user and delegation management while offering a customizable interface
Currently, task automation, like provisioning, deprovisioning, and reprovisioning, is very effective. When a user moves from one organization to another, it automatically changes their group membership and performs similar functions. Secondly, the granular delegation feature is very nice and much simpler and easier than it is natively in Microsoft. Two years ago, One Identity Active Roles was under Dell. It was quite poor. However, now, there have been notable improvements, such as faster system processing, better logging, enhanced information, and a more user-friendly interface. Once it was sold by Dell, things got better. The interface became a bit more user-friendly. The Angular user interface is much more flexible for adjusting to customer needs, and a completely new and customizable one can be created, aligning with all settings and scripts required by a customer. The ease of managing on-prem and cloud-based directories through a single pane of glass is good. I'd rate it nine out of ten. The solution's ability to provision and deprovision resources and directories like Azure AD is very simple, especially when you can integrate with the HR system and grab some data from HR. It's actually fully automatic. I don't need to even touch it. It's helped increase operational efficiency by 50%. It's helped decrease security problems around privileged accounts. We were able to decrease the number of privileged accounts and have been able to delegate more effectively. We decreased the number of high-level permissions that administrators had. For example, if someone is a DNS administrator, he has access only as far as the specific actions he needs to handle. We don't need to give away such high privileges for such a daily job. It's helped clarify roles and access. It's helped reduce identity-based breaches. If someone leaves a company, we can easily undo provisioning and close accounts. We can generate reports to see which people have which permissions and at what times. We've just integrated with our HR system. It helps us follow activated and deactivated users. I'd rate the granular controls on offer ten out of ten. We've saved on manpower in terms of the work of the administrators. There's good reporting and functionality, and it's very transparent. You can connect more than one directory and manage everything from one pane. You can do many things from one interface.
Praveen Jalumuru - PeerSpot reviewer
Enhanced automation and AI-driven integration offer significant time savings
The most valuable features include its ability to integrate with AI and machine learning, the automation of reports, and the built-in connectors that enable easy connection with both legacy and cloud-based applications. Its code-less drag-and-drop functionality allows for easier adjustments, and it provides strong support with reduced SLAs compared to SailPoint IQ.
Efrén Yanez - PeerSpot reviewer
Identifies, debugs and models the privileges of your organization, adapting it to business strategies.
* Identifies, debugs and models the privileges of your organization, adapting it to business strategies. * Helps discover roles based on available patterns ("basic roles" / "Iterated Search" / "Characteristic Roles" / "Rule Hierarchies Roles" / "User Hierarchy Based Roles" / "Structured Search" / "Obvious Roles"). * Enables review campaigns to certify user privileges, roles and resources, activating the RACI model in the process. * Identity Governance comes with Connector Xpress but if you have Identity Manager you can use the integration between them and import the information that comes from CA Identity Manager and its connectors. * Allows the construction of segregation of rights (SoD) rules by definition of the client and enables “detective" and "corrective" levels for violations of business rules policies. * Provides a set of SoD rules for SAP in order to apply "best practices" to this type of "endpoint" (more than 3,000 rules / Consult CA Technologies if available in last version). * Helps to analyze privileges to find points of cleaning and improvement (Similar Roles / Roles Hierarchy / dual link / Suspect connections / Collectors, etc.). * Regulatory compliance is one of the objectives of the solution. * Covers the life cycle of enterprise privileges and maintains the role model "shallow" or "deep" / "functional" or "granular per application". * Helps you take advantage of the Identity Governance on the portal but better if you integrate with Identity Suite (best user experience). * You can enable LDAP authentication (AD/others) or integrate with CA Single Sign-On for portal access. * Real integration between CA Identity Manager and CA Identity Governance for better use of compliance approved roles, data exchange, and improved customer experience. * Data Transformation available using PDI (Pentaho Data Integration) * New functionality when integrating with Identity Portal.
report
Use our free recommendation engine to learn which User Provisioning Software solutions are best for your needs.
851,604 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
12%
Manufacturing Company
7%
Healthcare Company
7%
Financial Services Firm
18%
Computer Software Company
14%
Manufacturing Company
10%
Insurance Company
6%
Computer Software Company
28%
Financial Services Firm
18%
Manufacturing Company
9%
Real Estate/Law Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for One Identity Active Roles?
The product is expensive, but if you want to save money, the delegation set-up process is quite easy. After setting u...
What needs improvement with One Identity Active Roles?
One area for improvement would be the Entra ID side, including better delegation for Entra ID objects and more granul...
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to m...
What is your experience regarding pricing and costs for SailPoint IdentityIQ?
The product is expensive. People need to opt for a licensing plan for one year or three years.
What advice do you have for others considering SailPoint IdentityIQ?
You can use SailPoint Atlas to take identity security to the next level. In SailPoint IIQ, writing a custom connector...
What do you like most about Symantec Identity Governance and Administration?
The product’s most valuable feature is flexibility. It can be customized as per the customer’s requirements.
What is your experience regarding pricing and costs for Symantec Identity Governance and Administration?
The pricing has been very reasonable, but licensing costs vary based on the customer. It follows a user-based licensi...
What needs improvement with Symantec Identity Governance and Administration?
Symantec should develop a SaaS solution for cloud environments to make the solution available in various marketplaces...
 

Also Known As

Quest Active Roles
IdentityIQ, IdentityNow, Cloud Infrastructure Entitlement Management, Intello
CA Identity Suite, Symantec IGA, Layer7 Identity Suite, CA Identity Manager (CA IDM), CA Identity Minder, CA IAM, CA Identity Manager (CA IDM), CA Identity Governance
 

Overview

 

Sample Customers

City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
Adobe, AXA Technology Services, Cuna Mutual Group, Equifax, ING Direct, Orrstown Bank, Rockwell Automation, SallieMae, Spirit Aerosystems, TEL
Acciona, Core Blox, DBS
Find out what your peers are saying about SailPoint, One Identity, Omada and others in User Provisioning Software. Updated: April 2025.
851,604 professionals have used our research since 2012.