No more typing reviews! Try our Samantha, our new voice AI agent.

One Identity Active Roles vs SAP Identity Management comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

One Identity Active Roles
Ranking in User Provisioning Software
3rd
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
84
Ranking in other categories
Active Directory Management (1st), Non-Human Identity Management (NHIM) (2nd)
SAP Identity Management
Ranking in User Provisioning Software
7th
Average Rating
7.8
Reviews Sentiment
5.9
Number of Reviews
14
Ranking in other categories
Identity Management (IM) (16th)
 

Mindshare comparison

As of May 2026, in the User Provisioning Software category, the mindshare of One Identity Active Roles is 5.8%, down from 6.2% compared to the previous year. The mindshare of SAP Identity Management is 4.8%, down from 6.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Provisioning Software Mindshare Distribution
ProductMindshare (%)
One Identity Active Roles5.8%
SAP Identity Management4.8%
Other89.4%
User Provisioning Software
 

Featured Reviews

Varun Mehra - PeerSpot reviewer
Collaboration Support Engineer at a retailer with 11-50 employees
Automation has transformed onboarding and access control and now streamlines daily governance
While One Identity Active Roles is a strong identity and access management solution overall, there are a few areas where it could improve. One challenge we experienced was the initial setup and configuration complexity. Deploying workflows, policies, and delegation models require careful planning and a good understanding of the Active Directory environment. For organizations without experienced administrators, the learning curve can feel quite steep in the beginning. The user interface could also be more modern and intuitive. Some administrative tasks require navigating through multiple menus and the overall experience could be simplified for faster day-to-day management. Another area for improvement is reporting and customization. While the auditing features are good, creating highly customized reports sometimes requires additional efforts or scripting knowledge. More built-in reporting templates and easier dashboard customization would be helpful. We have also noticed that troubleshooting workflows or synchronization issues can occasionally take time because the logs can be very detailed and technical. Better diagnostic tools and simpler error explanations would improve the operational experience. That said, once the platform is properly configured and maintained, it performs reliably and delivers strong automation, delegation, and governance capabilities. One additional area where One Identity Active Roles could improve is cloud integration and hybrid environment management. While it works well with Active Directory and the Microsoft environment, organizations moving heavily towards cloud-first infrastructure may want even deeper and more seamless integration with modern SaaS platforms and identity providers. Performance optimization in large environments could be improved. In very large enterprise deployments with complex workflows and multiple managed domains, some administrative actions and synchronization tasks can occasionally feel slower than expected. Another point is documentation and onboarding resources. The product is feature-rich, but some advanced configurations require going through extensive documentation. More practical examples, guided setup wizards, and easier to follow best practice guides would help new administrators adopt the platform faster. Overall, the core functionality is solid, and most of the pain points are related more to usability, complexity, and modernization rather than the reliability. One additional improvement I would mention is around integration flexibility with third-party ITSM and DevOps tools. While the platform integrates well within Microsoft-centric environments, broader out-of-the-box integration and simpler API workflows for non-Microsoft ecosystems would make deployment and automation easier for organizations using diverse infrastructure. Another area is upgrade and migration simplicity. In enterprise environments, version upgrades and environment migration sometimes require careful planning and testing. Streamlining that process with more automated compatibility checks and migration assistance would reduce operational overhead.
FM
Sales Executive at Minsait
Identity management enhances connectivity and productivity with streamlined access and robust security, offering time-saving processes and facilitating seamless integration with other BI tools
One area that could be improved with SAP Identity Management, other than support, is user engagement from an implementation perspective. It would be beneficial for SAP to extend their events and workshops that are currently performed for partners to their final customers, as many customers want to know what's new and what else they can do without solely depending on the partners. For SAP support in Brazil, everything is in English, which poses a difficulty for many customers. The support could be improved for the specific needs in Brazil, as many customers have difficulty accessing the support center due to the language barrier. This feedback is specific to Brazil, though it's unclear if SAP receives similar feedback from other countries. It could certainly be enhanced with Portuguese documents, among other improvements.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Active Roles provided us to do all these operations automatically and reduced our workload very significantly."
"The AD and AAD management features of this solution are really good... They offer added value by showing more fields such as password age and the statuses of some things that we normally wouldn't see."
"Another good feature is the change history. It's centralized in a single place and allows us to manage people's Active Directory domains from a central location. We can also drill down into individual objects in a troubleshooting or even an auditing situation. We can show evidence to auditors by drilling down into the individual history. It gives you all the history of what happened around an individual object. That is something that would be almost impossible to do in Active Directory, or extremely complicated."
"One Identity Active Roles has positively impacted our organization by improving the efficiency, security, and consistency of identity and access management operations within the Active Directory environment."
"One Identity Active Roles absolutely helps reduce identity-based breaches, making it very seamless for our user base to ensure that folks in specific positions have the least privileged access possible across our for-profit healthcare conglomerate with thirty states and over fifty community hospitals under a single Active Directory domain."
"One Identity Active Roles has significantly reduced both the complexity and workload of administrative tasks related to Active Directory; many repetitive tasks are automated, so admins spend much less time on routine activities."
"Overall, One Identity Active Roles has led to roughly a 40 to 60 percent reduction in AD-related service desk tickets and manual effort, with user onboarding tasks dropping from 15 to 20 minutes down to just a few minutes through automation and templates, adding up to dozens of IT hours saved every month and enabling the same team to manage more users without additional headcount."
"Instead of deleting accounts, we like the deprovision option so that we can reverse any accidental deletions. It also gives a higher level of quality control in terms of enforcing any number of variables, such as making sure that an account has a description entered before the account can be created. We can backtrack and know the history of it that way."
"IBM really gives you the power to implement a lot of functionality outside the current implementation if you know how to build the functionality you want."
"Rather than implement a basic SSO, this solution assisted us with setting up two-factor authentication."
"The most valuable feature is the user experience for managing information."
"The most valuable features of SAP Identity Management are business roles and automated user provisioning."
"I find it an excellent tool for data synchronization and cleansing."
"The most valuable features of SAP Identity Management are business roles and automated user provisioning."
"With SAP IDM we have stopped manually managing all changes in user accounts after his/her transferring between organizational units."
"Some processes that they used to perform in two to three days now take one to two hours, which has been really beneficial for them regarding the time saved."
 

Cons

"The third area for improvement, which is the weakest portion of ARS, is the workflow engine, which was introduced a few years ago. It's slow and not very intuitive to use, so I would like to see improvement there."
"I did not rate One Identity Active Roles at the highest level because areas such as user interface modernization, workflow complexity, troubleshooting experience, reporting capabilities, and cloud integration still have room for improvement."
"The initial setup of One Identity Active Roles could be simplified because it requires effort in designing workflows, delegation policies, and the administrative process, which necessitates expertise for this solution."
"One area that could be improved in One Identity Active Roles is the user interface and initial configuration process, as some advanced workflows and policy settings can be complex for new administrators."
"When doing a workflow, we would like a bit better feedback on the screen, as we're trying to get it to work. For example, there is a "Find" function that you need set up in a workflow to do some of the automation. It is not the easiest to get a result from those finds when you're trying to do that. In the MMC, they have a couple different types of workflows. In this particular case, we use their workflow functionality to find all of X within the environment, then if you find it, do X, Y, and Z. You can have multiple steps. When you do that search function within that workflow, it's really hard to find out, "Is my search working?" It would be nice if there was some feedback on the screen so you could see if your search is working properly within the workflow."
"Additional documentation about the Angular web interface is needed."
"Web console – it should have more customization options in terms of look and feel of the landing page."
"The ability to send logs to a SIEM would be very beneficial."
"Research and marketing need to be improved."
"What needs improvement in SAP Identity Management is its compatibility with third-party applications. We'd like to get connectors or plugin settings to make it easier to manage other applications, whether SAP or non SAP applications. As SAP Identity Management is not compatible with non SAP applications, some of the clients are looking for other IDM applications such as SalePoint and Saviynt, so this is an issue we've observed in the solution."
"A lack of startup connectors to different systems, and could have better connectors for SAP IDM."
"I find SAP Identity Management complicated to use. Maintaining it is also complex."
"I find SAP Identity Management complicated to use. Maintaining it is also complex."
"The current functionality allows you only to change one user at a time. There is no option to maintain the business roles from the UI using standard validation or imports, so you have to build your business roles one by one."
"The standard one is not friendly and very time-consuming for elementary operation."
"It needs to have the SSO for the HANA modules that SAP is releasing."
 

Pricing and Cost Advice

"The pricing for Active Roles is expensive but not as expensive as other solutions like Okta."
"The price is reasonable. It costs us about 1 million Danish kroner annually, and we also spend about half as much on consultants."
"The licensing model is a simple user-based model, not that much complicated."
"It's expensive."
"The pricing is high. I have not been involved with the renewal or cost aspect, but I know it is not cheap by any means. However, it is very useful for our environment."
"The pricing is on the higher end."
"It's fairly priced."
"When evaluating the price of any product, I first look at how it meets my business requirements and if it meets requirements adequately and predictively. Currently, I don't see this from SAP Identity Management, so pricing for it is expensive, in my opinion."
"I rate the solution's pricing a four out of ten."
"The licensing cost varies depending on the specific requirements and deployment size."
report
Use our free recommendation engine to learn which User Provisioning Software solutions are best for your needs.
896,510 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
20%
Financial Services Firm
8%
Computer Software Company
8%
Manufacturing Company
6%
Manufacturing Company
13%
Energy/Utilities Company
8%
Comms Service Provider
6%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business89
Midsize Enterprise15
Large Enterprise40
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise3
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for One Identity Active Roles?
My experience with pricing and licensing for One Identity Active Roles has been reasonable for an enterprise solution, but it does require proper planning. The initial setup can involve some cost i...
What needs improvement with One Identity Active Roles?
One Identity Active Roles is very useful, though there are a few areas where it could be improved, such as the user interface, policy creation, and reporting - it requires good knowledge of Active ...
What is your primary use case for One Identity Active Roles?
One Identity Active Roles is used primarily for managing Active Directory, including user provisioning and group management. When a new employee joins, I use One Identity Active Roles to automatica...
What needs improvement with SAP Identity Management?
One area that could be improved with SAP Identity Management, other than support, is user engagement from an implementation perspective. It would be beneficial for SAP to extend their events and wo...
What is your primary use case for SAP Identity Management?
The use cases for SAP Identity Management include the logistics company, and we also have a beverage company that is using SAP Identity Management. We did not make the migration for them, but we im...
What advice do you have for others considering SAP Identity Management?
My clients use SAP Identity Management for managing access rights efficiently based on user roles. I have experience with other IAM tools, having worked for Oracle three or four years ago, but I ca...
 

Also Known As

Quest Active Roles
SAP NetWeaver Identity Management, NetWeaver Identity Management
 

Overview

 

Sample Customers

City of Frankfurt, Moore Public Schools, George Washington University, Transavia Airlines, Howard County, MD. See all stories at OneIdentity.com/casestudies
State of Indiana, Automotive Resources International (ARI), Alliander N.V., Chemion Logistik GmbH, Seoul National University Bundang Hospital (SNUBH)
Find out what your peers are saying about One Identity Active Roles vs. SAP Identity Management and other solutions. Updated: April 2026.
896,510 professionals have used our research since 2012.