What is our primary use case?
One Identity Manager serves as our main platform for identity governance and lifecycle management, especially automating user provisioning, role-based access control, and ensuring compliance through access reviews and audit reporting.
We use One Identity Manager to automatically provision access when a new employee joins. Once HR creates a user record, the system assigns roles and app access based on job function, and later runs periodic access reviews where managers approve or revoke permissions to keep compliance tight.
We also use One Identity Manager for access certification campaigns and role mining, which helps us regularly clean up excessive permissions and design more accurate role structures based on actual user behavior.
What is most valuable?
The best features of One Identity Manager in my experience are automated user provisioning and de-provisioning, role-based access control (RBAC), access certification, attestation campaigns, and strong compliance reporting, all from a single centralized identity governance platform.
The biggest impact from One Identity Manager has been automated user provisioning because it removes the need for manual account creation and access setup, which makes onboarding and offboarding much faster and reduces errors in assigning permissions.
Another valuable feature is the access certification and attestation campaigns, which help us keep permissions clean because managers regularly review and approve or revoke a user's access, and it improves compliance without adding extra manual tracking work for IT.
The biggest positive impact of One Identity Manager has been improved control and visibility over user access across the organization because it automates the entire identity lifecycle from onboarding to role changes and offboarding, while also strengthening compliance through regular access reviews and audit-ready reporting. In day-to-day work, it has reduced manual provisioning effort for IT, minimized access-related errors, and made it much easier to prove compliance during audits since everything is centrally tracked and governed.
What needs improvement?
Several improvements for One Identity Manager that came up often in real-world use are around usability, performance, and cloud experience. The UI could be more intuitive and modern because new admins usually find the navigation and configuration quite complex, especially during initial setup.
Reporting and dashboards could also be more flexible and easier to customize for audits without heavy configuration effort.
Another area is performance and scalability tuning in large environments. While it scales well overall, some teams still face slower response times during large access reviews or heavy provisioning cycles. Stronger out-of-the-box, cloud-native integrations and simpler deployment options would make it easier to manage hybrid and multi-cloud environments without so much manual configuration.
Another improvement area that comes up in real-world usage is around documentation, support, and integrations. The documentation could be clearer and more consistent, especially when working with advanced APIs or complex provisioning scenarios. We sometimes had to rely on trial and error or community input to fully understand certain workflows, which slows down implementation.
On the support side, basic issues are handled well, but more complex identity or workflow problems sometimes require escalation and longer resolution times, especially when custom configurations are involved. Integration works well with major enterprise systems, but cloud-native and modern DevOps-style integrations, such as API-first or CI/CD-driven identity workflows, could be more out-of-the-box instead of requiring additional customization effort. Overall, it is powerful, but improving these areas would make onboarding and long-term administration much smoother.
For how long have I used the solution?
I have been working in my current field for one year.
What do I think about the stability of the solution?
One Identity Manager is generally considered stable in enterprise environments, but with a few practical caveats. From real-world user feedback and reviews, most users rate it between 7 and 10 out of 10 for stability, describing it as reliable with minimal downtime. It is widely seen as stable in production once properly configured, especially for Active Directory automation, user provisioning, de-provisioning, and role-based delegation. Many report no major outages or crashes even in large enterprise deployments.
That said, there are some common drawbacks people mention such as occasional slow performance or lag, especially in large environments, and minor bugs that sometimes require service restarts. Some issues are more about configuration complexity than core instability. The UI and workflow can feel dated, which sometimes gives an impression of instability even when backend services are performing well.
What do I think about the scalability of the solution?
Scalability of One Identity Manager is very strong and it supports large enterprise environments with thousands to millions of identities. It is designed for enterprise-scale deployments and works well in complex hybrid setups.
Regarding limitations, it needs proper architecture and tuning. Performance depends on databases and configuration. The scaling is not fully plug-and-play, which requires experienced IAM admins for smooth scaling. The overall view is that scalability is strong, but the best results come with good design and maintenance.
How are customer service and support?
Overall, customer support is good and responsive, especially for complex
IAM issues. Standard support can be slow, and resolution time varies for complex tickets. Premium support is faster and more reliable with direct access to technical experts. Our overall view is decent enterprise-level support, but it is not always consistent in speed or depth.
Which solution did I use previously and why did I switch?
Before adopting One Identity Manager, we were using a mix of manual Active Directory management and basic scripts, along with a lightweight
IAM tool that did not fully support governance or advanced access reviews. We switched mainly because manual provisioning was error-prone and time-consuming, there was limited visibility into who had access to what, and audit and compliance reporting required considerable manual effort. Role-based access control and lifecycle automation were not strong enough. Moving to One Identity Manager helped us centralize identity governance, automate provisioning, and significantly improve compliance and access visibility across systems.
How was the initial setup?
I advise others looking into using One Identity Manager to start with a solid design and clean identity data before implementation. Spend time on role modeling, workflow design, and connector setup. Avoid over-customization and follow a phased rollout approach. Do not skip proper planning, as most issues come from poor implementation, not the tool. Invest in skilled
IAM engineers, as the tool performs best when well architected.
What about the implementation team?
We are only a customer using the product and have no partnerships or reseller role. Our relationship is pure user engagement without any commercial or partner involvement.
What was our ROI?
Organizations using One Identity Manager often see strong ROI, but it usually shows up more in time savings and operational efficiency than direct cost-cutting alone. From real-world IAM benchmarks and identity governance studies, a fully automated IAM setup can deliver 300% ROI over three years due to reduced manual provisioning, access management, and support overhead. IAM automation such as provisioning and de-provisioning can save thousands of IT hours annually, especially in onboarding and offboarding in heavy environments.
In our case, we have achieved measurable improvements that include onboarding time reduced significantly because user provisioning is automated through HR-driven workflows from hours to minutes per user. Access request handling workload dropped since approvals and role assignments are automated. Fewer manual IT tickets occur, especially for access creation, changes, and deactivation. Audit preparation time has been reduced because access reviews and reports are generated automatically instead of being compiled manually.
The ROI is mainly seen in less IT manpower spent on repetitive IAM tasks, fast onboarding and offboarding cycles, lower risk, and reduced audit effort, which also saves costs indirectly. Overall, the biggest ROI impact is not just saved money, but that the IT team shifts from manual access handling to more strategic security work.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup cost, and licensing experience for One Identity Manager is typically enterprise-style and quote-based, so it is not very transparent upfront and depends heavily on user count, modules, and deployment complexity. In our experience, the initial setup and licensing cost was on the higher side, mainly because it is a full identity governance platform and requires professional services for proper implementation and integration. The licensing model is flexible but can become complex since different components such as provisioning, governance, and connectors may be licensed separately. Overall, while the cost is significant and not always easy to predict at the start, we found it justified by the long-term savings in automation, reduced manual IAM effort, and improved compliance visibility.
Which other solutions did I evaluate?
Before selecting One Identity Manager, we evaluated several major identity governance platforms in the market. The main alternatives we looked at included various solutions, and we also briefly reviewed Microsoft-based options such as Entra ID governance since we already use Microsoft tools. We ultimately chose One Identity Manager because it gave us a strong balance of on-premise plus cloud integration, deeper role-based access control, and more flexible customization for complex enterprise workflows, especially for hybrid environments with legacy systems.
What other advice do I have?
One Identity Manager is a powerful IAM solution, especially strong in large enterprise environments. It offers good automation, flexible role-based access control, and strong integration with Active Directory. Regarding challenges, the complex setup requires skilled resources to manage effectively. Overall, my view is that it is a very capable product but best suited for organizations ready to invest in proper implementation and governance. I have rated this review at 8 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.