What is our primary use case?
Safeguard by One Identity is primarily used for privileged access management, which helps us securely manage administrator accounts, store and rotate privileged passwords, control access to critical servers and network devices, and monitor user sessions for security and compliance.
When a new system administrator needs to access a production server, instead of sharing the administrator password, they request access through Safeguard by One Identity, which securely provides the credentials or starts a monitored session, logging all activity. This has helped our team improve security, simplify audits, and ensure privileged passwords are never shared directly.
Safeguard by One Identity has become an important part of our privileged access workflow by enforcing security policies, reducing the risk of unauthorized access, and maintaining a compliance audit trail. It has made managing privileged accounts more secure and efficient for our IT team.
How has it helped my organization?
Since implementing Safeguard by One Identity, we have improved the security of privileged accounts by eliminating the need to share passwords and enforcing controlled access. We have also reduced the time spent managing privileged credentials through automation tasks such as password rotation. During security audits, having a complete session log and access records has made it much easier to demonstrate compliance and investigate privileged activity when needed, enhancing our security and audit readiness.
Before Safeguard by One Identity, privileged passwords were managed manually, which increased the risk of passwords being shared. Now, administrators access systems through the password vault, and passwords are rotated automatically, reducing manual effort, strengthening security, and making audits much easier since all privileged access and user sessions are logged and can be reviewed whenever needed.
We do not have exact metrics, but we have definitely seen an improvement since using Safeguard by One Identity, as password management is much faster without the need for administrators to manually share or update privileged credentials. Security has improved through automated password rotation and controlled access, while audit preparation takes much less time because all privileged sessions and access records are available in one place.
What is most valuable?
Safeguard by One Identity's best features are secure password vaulting, automatic password rotation, and privileged session monitoring.
Safeguard by One Identity's password vaulting feature keeps privileged passwords in a secure, encrypted vault, so administrators do not need to know or share the actual credentials, allowing team members to request access when needed and automatically rotate the password after use. This reduces the risk of password leaks, improves automation, and saves time since we do not have to manually manage privileged credentials.
Another feature I appreciate from Safeguard by One Identity is the session recording and auditing, which provides a complete record of privileged activity, very helpful for troubleshooting, security investigations, and compliance audits. Safeguard by One Identity's centralized management interface also makes it easier to manage privileged accounts across different systems from a single place.
What needs improvement?
Overall, we are satisfied with Safeguard by One Identity, but there are a few areas for improvement. Safeguard by One Identity's user interface could be more modern and intuitive, especially for new administrators, and the initial deployment and configuration can be complex.
Another improvement would be having more detailed documentation and step-by-step deployment guides, particularly for complex environments. Better performance on large-scale deployments, enhanced search and filtering in audit logs, and more flexible notification and approval workflows would also improve the overall experience, making administration simpler and reducing the learning curve.
For how long have I used the solution?
I have been using Safeguard by One Identity for about two years, but I have used Safeguard for one year.
What do I think about the stability of the solution?
Safeguard by One Identity is now stable.
What do I think about the scalability of the solution?
Our experience with Safeguard by One Identity's scalability has been positive. It has scaled well as we have added more users, servers, and privileged accounts, continuing to perform reliably without requiring major changes to the deployment. Safeguard by One Identity's centralized management and role-based access control have made it easier to support growth while maintaining consistent security policies.
How are customer service and support?
Our experience with customer support has been positive, with the support team being responsive when we needed assistance with configuration and troubleshooting, and their technical guidance being generally helpful.
Which solution did I use previously and why did I switch?
We did not use a dedicated privileged access management solution before Safeguard by One Identity. We mainly relied on manual password management and built-in administrative controls.
How was the initial setup?
Safeguard by One Identity's deployment took about two to three weeks, with most time spent on planning, integration with Active Directory, configuring privileged accounts and policies, and testing and validating access before moving into production.
What about the implementation team?
Administrators required a few days of training to learn the deployment, policy configuration, password vaulting, and session management features of Safeguard by One Identity. For end users, the learning curve was much smaller, typically requiring just a short training session or documentation to understand how to request and use privileged access, with the platform being straightforward once the initial setup and onboarding were complete.
What was our ROI?
We have seen a positive return on investment from Safeguard by One Identity, mainly through improved security and operational efficiency. We do not track exact financial metrics, but administrators spend less time managing privileged passwords and preparing for audits because password rotation, session logging, and access control are automated.
What's my experience with pricing, setup cost, and licensing?
Safeguard by One Identity's pricing is on the higher side, but it remains reasonable considering the security and privileged access management capabilities it provides. Safeguard by One Identity's licensing model is straightforward once understood, although planning the required licenses takes some time, and the initial setup requires an investment in deployment and configuration. However, after implementation, the solution delivers good value by improving security, simplifying privileged access management, and reducing administrative effort.
Which other solutions did I evaluate?
Before selecting Safeguard by One Identity, we evaluated other privileged access management solutions, including CyberArk, BeyondTrust, and Delinea. We chose Safeguard by One Identity because it offered the features we needed for privileged access management along with strong security controls, straightforward integration with our existing environment, and a good balance between functionality and cost.
What other advice do I have?
I rate Safeguard by One Identity a 9 out of 10 overall.
This rating of 9 out of 10 reflects that it offers strong privileged access management with features such as secure password vaulting, session monitoring, and auditing. Safeguard by One Identity is not rated a 10 because the initial deployment can be complex, and the user interface and reporting could be more intuitive.
From what I have seen, Safeguard by One Identity's governance and security are strong overall, with role-based access control and detailed audit trails. If the AI features follow the same security model, I expect them to provide a good level of governance and protection.
We have not used the AI capabilities enough to fairly evaluate their accuracy or reliability, so I cannot comment from first-hand experience, especially since most of our users focus on privileged access management, password vaulting, and session monitoring rather than AI features.
Overall feedback from users regarding Safeguard by One Identity's usability and functionality has been positive, with users appreciating that privileged access is centralized and secure, as well as not having to manage or remember privileged passwords. Administrators find Safeguard by One Identity's audit and session recording features especially useful. Safeguard by One Identity's main feedback has been that the interface can take some time to learn and that some administrative tasks could be more intuitive.
I advise others looking into using Safeguard by One Identity to spend time planning the deployment and defining privileged access policies before implementation. Involving the security and infrastructure teams early to start with a small pilot before rolling it out across the organization is important. Providing basic training to administrators and end-users is also essential to ensure smooth adoption. When configured properly, Safeguard by One Identity is a strong solution for improving privileged access security and simplifying compliance.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.