No more typing reviews! Try our Samantha, our new voice AI agent.
PeerSpot user
Managing Director at a tech services company with 51-200 employees
Real User
Top 20
Jul 9, 2018
Single solution for AD and Exchange RBAC, User Life Cycle Management, User Self-Service with complete audit trail.
Pros and Cons
  • "Heavily Automates - it will automate the entire provisioning, re-provisioning, de-provisioning and undo-de-provisioning tasks Complete Audit Trail - it gives an audit trail for each and every activity Increase in accountability – various tasks can be enabled for approval."
  • "Web console – it should have more customization options in terms of look and feel of the landing page."

What is our primary use case?

RBAC for AD and Exchange

Provisioning, Re-provisioning, De-provisioning and Undo-De-Provisioning of user accounts

User Self Service

Virtual AD firewall

How has it helped my organization?

  • Heavily Automates - it will automate the entire provisioning, re-provisioning, de-provisioning and undo-de-provisioning tasks
  • Complete Audit Trail - it gives an audit trail for each and every activity
  • Increase in accountability – various tasks can be enabled for approval.
  • Virtual Firewall against AD/Exchange - it helps protect Active Directory and Exchange exposure to administrators and engineers
  • Escalations – it helps escalates tasks if not acted upon in a stipulated time frame
  • Security –
    • it helps in increased security as every employee will have correct resource access depending upon the business policies
    • user account is disabled and user is removed from the security groups which prevent misuse of user credentials

What is most valuable?

  • Role Based Access Control
  • Provisioning, Re-provisioning, De-provisioning and Undo-De-provisioning policies
  • Data validation policies
  • Workflows
    • If Then Else statements
    • Approval Workflows
    • Schedule Workflows
    • Escalation
  • Virtual Schema
  • Virtual OU’s
  • Web console with easy customization option
  • Integration and data synchronization with SQL, Office 365, Lync etc.
  • Event handlers

What needs improvement?

  • Web console – it should have more customization options in terms of look and feel of the landing page
  • Workflow policies – Additional policies for folder access provisioning
  • Bring back attestation – Attestation feature is dropped from ARS. This should be brought back
Buyer's Guide
One Identity Active Roles
March 2026
Learn what your peers think about One Identity Active Roles. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and support?

Customer Service:

It's good.

Technical Support:

It's good. In fact, the One Identity (Quest) support team has easy access to the One Identity (Quest) product developers. In case of any technical issues which has something to do with the product architecture or a bug, the support engineer brings in the developer in a remote session so that the developer understands the issue. The developer(s) then work on a patch to address the issue.

Which solution did I use previously and why did I switch?

I did not use any other solution.

How was the initial setup?

The initial setup is pretty straightforward. It's not at all complex.

What about the implementation team?

Our company, Amal IT Solutions, is a One Identity (Quest) partner. Our consultancy has 10+ years of experience with this solution.

What was our ROI?

I won’t be able to provide ROI from commercial perspective, but from the below points one should be able to figure it out:

  1. User provisioning/De-provisioning – this activity, which takes anywhere from one day to three or four days manually, is done in minutes without any IT resource intervention and so increases efficiency and productivity

  2. Notifications – respective stake holders/business owners are notified immediately upon an activity performed, and no follow-up emails or phone calls required

  3. Data consistency – it helps to maintain data consistency in AD which eliminates a data clean-up activity which IT department has to undertake regularly

  4. Data synchronization – it synchronizes data between HR application and AD/Exchange or other applications and AD/Exchange relieving HR and other application owners from day to day tasks of co-ordination or creating/modifying/deleting application user accounts

  5. Automation – Most of the IT tasks are automated which in turn reduces work load on IT department. IT resources could be better utilized for some other useful activities

What's my experience with pricing, setup cost, and licensing?

It’s a gentleman’s agreement.

Licensing is based on Enabled User Accounts in AD. This should include user accounts, application accounts and service accounts.Temporary accounts could be excluded, but no one from vendors really challenge the user count which the customer provides. Some customer’s find the price bit on higher side but, for me, the price is competitive compared to other products with similar functionality and considering the ROI.

The product functionality does not cease if the customer exceeds the license count. The vendor does not want to force the customer to stop using the product if the license count increases. Instead, customers can buy additional licenses without hampering the day to day work.

Which other solutions did I evaluate?

We didn't evaluate other products.

What other advice do I have?

This product has tremendous potential. It can be used to automate a lot of day to day activities. I always tell my customers, list down all your requirements, pain areas, and day to day tasks. Prioritize them, and use this tool to automate these tasks as per priority.

Disclosure: My company has a business relationship with this vendor other than being a customer. Our company, Amal IT Solutions, is a Quest Software partner. Our consultancy team has 10+ years of experience with this solution.
PeerSpot user
PeerSpot user
Senior Solution Consultant at a tech services company with 51-200 employees
Consultant
Oct 29, 2017
It has very powerful native policies and scripts
Pros and Cons
  • "It provides automatic provisioning/update/deprovisioning workflows from a source system to a target system."
  • "Active Roles provided us to do all these operations automatically and reduced our workload very significantly."
  • "For ActiveRoles, it would be good if the product supports multi-scripting language. You can use only VBScript."
  • "For ActiveRoles, it would be good if the product supports multi-scripting language."

How has it helped my organization?

When a new employee is hired, we create a new Active Directory (AD) user in a related department (Organizational Unit) with a random generated password, then give that user some AD rights. Also, we create an exchange mail user for this user on cloud or on-prem and inform that user by sending a notification mail or SMS. We did similar things in other systems and did all the process manually before Active Roles. That means lots of workload and manual processes. Active Roles provided us to do all these operations automatically and reduced our workload very significantly.

What is most valuable?

  • It provides automatic provisioning/update/deprovisioning workflows from a source system to a target system.
  • It allows you to easily monitor all workflow processes.
  • It has very powerful native policies and scripts, which allow you to create your own custom policies, scripts, and virtual attributes.
  • In addition to using the console (MMC interface), it also gives you management from the web interface.

What needs improvement?

For ActiveRoles, it would be good if the product supports multi-scripting language. You can use only VBScript.

VB.net , C#, or Powershell scripting would be a good choice for the product.

For how long have I used the solution?

Almost five years.

What do I think about the stability of the solution?

No issues.

What do I think about the scalability of the solution?

No issues.

How are customer service and technical support?

Technical support replies really promptly. The support team is very experienced and focused on the product. On the other hand, there is a community portal and you can find every piece of knowledge on there.

Which solution did I use previously and why did I switch?

We have not used any similar products before. We did all related operations manually.

How was the initial setup?

It was very straightforward.

What's my experience with pricing, setup cost, and licensing?

The licensing model is a simple user-based model, not that much complicated.

Which other solutions did I evaluate?

We evaluated and researched other options, such as NetIQ, FIM, Oracle, CA, IBM, and SailPoint.

However, Active Roles is most suitable for us.

What other advice do I have?

It is very important to come together with system owners who will be integrated at the beginning of the project to clarify all the rules and determine the work to be done. Test environments of the systems to be integrated must be requested. Test environments are so necessary.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
One Identity Active Roles
March 2026
Learn what your peers think about One Identity Active Roles. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.
reviewer708018 - PeerSpot reviewer
Solution Architect at a tech services company with 51-200 employees
Consultant
Aug 30, 2017
Offers automatic provisioning for multiple applications/systems and a virtual directory structure
Pros and Cons
  • "Operational issues are much easier and more reliable with Quest ActiveRoles's directory layer and portal."
  • "Scripting options in different languages."

How has it helped my organization?

  • Automation of manual identity management operations (provisioning and deprovisioning).
  • Solving security and compliance issues is easy.
  • Operational issues are much easier and more reliable with Quest ActiveRoles's directory layer and portal.

What is most valuable?

It provides automatic provisioning for many applications and systems, including in-house applications and cloud applications. Also, it offers a virtual directory structure and a new directory layer between users and physical directories. Management and monitoring become easier.

What needs improvement?

Scripting options in different languages.

For how long have I used the solution?

Under four years.

What do I think about the stability of the solution?

Not yet.

What do I think about the scalability of the solution?

No.

How are customer service and technical support?

It is excellent. Quick and useful answers.

They also have a large community portal where you can find a lot of information.

Which solution did I use previously and why did I switch?

I didn't use any other solution, but I evaluated many solutions.

How was the initial setup?

It was simple. I didn't have a problem. It took half a day.

What's my experience with pricing, setup cost, and licensing?

There is a simple user-based licensing model. Not complicated.

Which other solutions did I evaluate?

Yes. NetIQ, FIM, Oracle, CA, IBM, and SailPoint.

What other advice do I have?

Choose your project team well. Remember that analysis of all processes is very important. Don't forget that testing is also very important after each development.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free One Identity Active Roles Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free One Identity Active Roles Report and get advice and tips from experienced pros sharing their opinions.