What is our primary use case?
My main use case for One Identity Safeguard is that it serves as a secure, strong PAM solution, and we are using it for PAM authentication.
In daily work, we use One Identity Safeguard for privilege access management, including secure PAM authentication, password vaulting, access request approval, session monitoring, and automatic password rotation for privileged accounts and service servers.
Apart from PAM authentication, we also use One Identity Safeguard for secure privileged session management, auditing, compliance, tracking, and centralized control for critical administrative accounts. It helps to improve security, accountability, and operational efficiency in daily infrastructure management.
How has it helped my organization?
One Identity Safeguard has improved our organization's security posture by providing centralized privileged access management, secure password vaulting, and session monitoring. It has helped to reduce manual password handling, improve compliance and audit tracking, and increase accountability for privileged access activities. Overall, it enhances operational security, streamlines access management, and reduces risks related to privileged accounts.
We have seen improvements in multiple areas. It helped reduce risks related to privileged account misuse by enforcing secure password management and session monitoring. We also saved operational time through automated password rotation and centralized access control. From a compliance perspective, auditing and session recording made it easier during security reviews and audit processes, improving overall accountability and traceability.
What is most valuable?
One Identity Safeguard offers several strong features for PAM. The best ones are password vaulting, automatic password rotation, privileged session monitoring and recording, role-based access control, and approval workflows. I also appreciate the centralized log management, auditing and compliance reporting, and integration with Active Directory and enterprise environments. Features such as session playback, real-time monitoring, and REST API support are very useful for daily administration and security operations.
The feature that has had the biggest impact on my daily operations is the password vaulting and automatic password rotation. It has significantly improved security by eliminating manual password sharing and reducing the risk of unauthorized access. It also saves operational time because administrators can securely request access through One Identity Safeguard without knowing the actual password. Session monitoring and auditing also help a great deal during troubleshooting and compliance reviews.
One additional advantage is that it provides centralized control and complete audit visibility for privileged access activities.
What needs improvement?
One Identity Safeguard is a strong PAM solution, but there are some areas for improvement. The initial deployment and integration process can be complex in large enterprise environments. The user interface and reporting can be improved to make administration and troubleshooting easier. More simplified integration with cloud platforms and third-party tools would also help.
For how long have I used the solution?
I have been using One Identity Safeguard for the last three years.
What do I think about the stability of the solution?
One Identity Safeguard is a stable and reliable PAM solution in our experience. We have seen good performance with minimal downtime, especially for password vaulting, session monitoring, and privileged access workflows. It handles enterprise environments well when properly configured and maintained.
What do I think about the scalability of the solution?
One Identity Safeguard is highly scalable and works well for enterprise environments. It supports scaling through clustering, distributed architecture, and high availability options, which helps handle growing numbers of privileged accounts, sessions, and users efficiently. In our experience, it has managed increasing workloads and integration without major performance issues.
How are customer service and support?
Customer support has generally been good in our experience. The support team is knowledgeable and helpful, especially for One Identity Safeguard's standard deployment, configuration, and troubleshooting issues. Response times are usually reasonable, although complex enterprise-level issues can sometimes take longer to resolve and require escalation.
Which solution did I use previously and why did I switch?
Earlier, we were using a more manual approach along with basic privileged account management processes. We moved to One Identity Safeguard to improve centralized privileged access control, password vaulting, session monitoring, compliance, and overall security management in a more scalable and enterprise-ready way.
How was the initial setup?
The initial deployment of One Identity Safeguard took a few weeks, including setup, integration with Active Directory, policy configuration, onboarding asset accounting, testing, and user access validation. The timeline mainly depended on the environment size and security requirements.
What about the implementation team?
One Identity Safeguard has been integrated with Active Directory, cloud platforms such as AWS and Azure, and various Windows and Linux servers for privileged access management. It also supports integration with enterprise applications, SIEM, log monitoring tools, and automation workflows to improve security and centralize access control.
The integrations were manageable overall, especially with Active Directory and standard Windows and Linux environments. Cloud integration with AWS and Azure required additional planning and configuration, but the documentation and available connectors helped. Some advanced integration and custom workflows were more complex and required careful testing and coordination with security and infrastructure teams.
A moderate level of training was required initially, mainly for administrators handling deployment, policy management, integration, and troubleshooting. For end-users, only basic guidance was needed for the access request and password retrieval workflows. Overall, the team adapted quickly after hands-on usage.
What was our ROI?
We have seen a positive return on investment. One Identity Safeguard helped reduce the manual effort for password management and privileged access handling, which saves operational time for administrators. It also improved compliance and audit readiness, reducing time spent during security reviews. While it did not directly reduce headcount, it improved efficiency and centralized control and reduced security risks related to privileged accounts.
What's my experience with pricing, setup cost, and licensing?
One Identity Safeguard is positioned as an enterprise-grade PAM solution, so the cost is on the higher side.
Which other solutions did I evaluate?
During the evaluation phase, we also looked at other PAM solutions such as CyberArk, BeyondTrust, and Delinea. We compared them on security features, integration, deployment complexity, session monitoring, password vaulting, scalability, and overall operational requirements before selecting One Identity Safeguard.
What other advice do I have?
The deployment was relatively smooth with minimal disruption for privileged users. Initially, users needed some adaptation to the access request and approval workflow. After onboarding and training, the process became streamlined and improved overall security.
The integration improved operational efficiency and security by centralizing privileged access management, reducing manual password handling, and improving visibility through auditing and session monitoring. It also helps streamline access workflows across multiple platforms and environments.
The advice would be to properly plan the PAM implementation before deployment, especially around privileged account discovery, access policies, integration, and user onboarding. Start with the critical systems first and then gradually expand across the environment. Also, involve security, infrastructure, and compliance teams early in the process. I have given this review an overall rating of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.