Try our new research platform with insights from 80,000+ expert users
PeerSpot user
PreSales Engineer at a tech vendor with 201-500 employees
Real User
It offers four-eye and gateway authentication with a real-time audit capability.

What is most valuable?

Monitoring and controls privileged access to remote server/appliances for RDP/SSH/HTTP/ICA/VNC protocols

Four-eye authentication and gateway authentication with real-time audit capability

Credential storage and user mapping policies

Inband destination selection with DNS resolve/mapping internal resources

Detailed audit search capability into proprietary video stream for all protocols supported with keylog functions

How has it helped my organization?

  • Improved security
  • Detailed audits for support/maintenance activities done by admin/technician and third-party engineers
  • Drastically reduced unauthorized and improper use of systems and servers

What needs improvement?

The only improvement would be to manage more concurrent sessions.

For how long have I used the solution?

I have been using it for four years.

Buyer's Guide
One Identity Safeguard
March 2025
Learn what your peers think about One Identity Safeguard. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
845,485 professionals have used our research since 2012.

What do I think about the stability of the solution?

I have not encountered any stability issues.

What do I think about the scalability of the solution?

I have encountered scalability issues. The system needs to be properly analysed before putting it into production. Supported protocols have different needs in terms of computing power, and this directly impacts the number of concurrent sessions that can be managed.

How are customer service and support?

Customer Service:

absolutely perfect

Technical Support:

Technical support is 10/10, absolutely.

Which solution did I use previously and why did I switch?

I did not previously use a different solution.

How was the initial setup?

The initial setup is straightforward, but you need to have a pre-defined plan, know how to implement authentication or the authentication store if used, and also how to do network integration.

What's my experience with pricing, setup cost, and licensing?

I don't know about pricing, but licensing is based on concurrent session through SCB.

Which other solutions did I evaluate?

Before choosing this product, I did not evaluate other options.

Disclosure: My company has a business relationship with this vendor other than being a customer: i'm working as system integrator, for Balabit products in Italy.
PeerSpot user
reviewer2687787 - PeerSpot reviewer
Business Line Manager - IGA & PAM at a tech services company with 201-500 employees
Real User
Simplified implementation and robust security infrastructure enhance user experience
Pros and Cons
  • "The scalability of One Identity Safeguard is perfect, scoring ten out of ten."
  • "I rate customer support six out of ten. It needs improvement as it can significantly impact customer access."

What is our primary use case?

I am not a customer; I am a partner. Therefore, I assist clients in implementing One Identity Safeguard to manage privileged account access and their passwords. The primary aim is to reduce the attack surface of those accounts.

What is most valuable?

The best feature of One Identity Safeguard is its infrastructure simplicity compared to other solutions. Joining two clusters together makes it easy and robust at the same time. The interface is robust and secure, and with recent releases, it has become more stable. Implementation is straightforward, and user experience is simple.

What needs improvement?

There is room for improvement in integration between modules. The native integration between SPP and SPS, which is currently based on a plugin, could be enhanced. Customization for lookup passwords could also be made easier.

For how long have I used the solution?

I have been working with One Identity Safeguard since 2019.

What was my experience with deployment of the solution?

Most of my users have been using the on-premises solution. There was a customer who used the physical appliance, but most installations involved virtual appliances. Deployment for my clients takes from three to eight months.

What do I think about the stability of the solution?

In terms of stability, I rate One Identity Safeguard nine to ten out of ten. It is a fairly stable solution with improvements over time.

What do I think about the scalability of the solution?

The scalability of One Identity Safeguard is perfect, scoring ten out of ten. It is suitable for medium to enterprise-level clients.

How are customer service and support?

I rate customer support six out of ten. It needs improvement as it can significantly impact customer access. It would be beneficial to have a more direct route to second-level support from partners.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I am aware of CyberArk. Compared to CyberArk, One Identity Safeguard could be more mature. However, it is a good solution in terms of cost-benefit.

How was the initial setup?

The initial setup is relatively simple compared to other solutions. It is straightforward for most users.

What was our ROI?

While it does not directly reduce costs in terms of personnel, One Identity Safeguard offers increased security, especially in password management.

What's my experience with pricing, setup cost, and licensing?

The pricing of One Identity Safeguard is fairly priced and cheaper than other solutions of the same enterprise level. It provides a good cost-benefit ratio.

Which other solutions did I evaluate?

I have knowledge of CyberArk as an alternative solution.

What other advice do I have?

I recommend One Identity Safeguard because it is valuable in terms of cost-benefit. It is simple to implement, and its infrastructure costs are lower than other solutions. It provides a flexible approach, offering both on-premises and cloud solutions. Overall, I rate One Identity Safeguard eight out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
PeerSpot user
Buyer's Guide
One Identity Safeguard
March 2025
Learn what your peers think about One Identity Safeguard. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
845,485 professionals have used our research since 2012.
reviewer2679786 - PeerSpot reviewer
Team Lead / Consultant at a computer software company with 5,001-10,000 employees
Consultant
Fairly priced and easier to implement and administer than others
Pros and Cons
  • "There is ease of implementation. Compared to other PAM solutions, it is easy to implement and use from an administrator's point of view."
  • "There is ease of implementation."
  • "We should be able to create customized connectors in a better way. For ad hoc or special use cases, I sometimes find we have limitations. Improving the way we develop new connectors for non-typical systems would be beneficial."
  • "Improving the way we develop new connectors for non-typical systems would be beneficial."

What is our primary use case?

We are using it internally because I work in a consultancy company. I use it both for our internal privileged accounts. We have different systems like Google Cloud, some internal servers, data centers, etc. To secure those privileged accounts, like the administrator accounts and root accounts, I use One Identity Safeguard to rotate passwords, authorize sessions, and more. The second use case is that we also implement One Identity Safeguard for different customers.

How has it helped my organization?

The most significant benefit is that in the past, we saved passwords in Notepad files or Excel files. Now, we do not, and we have more security. We do not have saved passwords or plain text passwords in different places within the organization. That is probably the most significant benefit regarding security.

In terms of integrations, we have basic integrations for our Windows and Unix servers. We do the transparent connection for LDP and SSH, and that is all. The integration is simple overall for this kind of connection. However, if we want to integrate different consoles or different systems, it is a bit more complex because it is not so much out of the box, but for our current systems, it was very easy.

End-users require just a couple of training sessions and some documentation, and they are ready to go. They can start using the tool as an end user in a week or less. Managers or administrators require a technical specialist training workshop, which is a full-week course. After that, they need one to three months of training with laboratories and documentation. They would need at least three months to work well with the platform.

What is most valuable?

There is ease of implementation. Compared to other PAM solutions, it is easy to implement and use from an administrator's point of view. That is the most important benefit. It is very simple to implement and use.

What needs improvement?

We should be able to create customized connectors in a better way. For ad hoc or special use cases, I sometimes find we have limitations. Improving the way we develop new connectors for non-typical systems would be beneficial. 

Another area for improvement could be the threat detection capabilities, like those seen in other PAM vendors. The ability to detect strange behaviors during a transparent connection or detect risky sessions and respond immediately would also be a good improvement.

We have had good feedback about One Identity Safeguard, but for LDP and SSH sessions, when we have to connect to a different console, such as a web console, the customers sometimes complain about the efficiency of the sessions. It takes extra time, and the user experience is not so good when you are using different connectors than normal ones.

For how long have I used the solution?

I have been using it since 2020, so about five years now.

What do I think about the stability of the solution?

I would rate it a nine out of ten for stability. It is like a black box. It is an appliance. It is difficult for things to go wrong.

What do I think about the scalability of the solution?

It is scalable. I would rate it a nine out of ten for scalability. It is easy if you need to implement resources.

In our organization, we have 15-20 people working with this solution. Our clients are medium enterprises.

How are customer service and support?

We use their partner support. It is usually okay. When I have day-to-day incidents and problems, the response is good enough in terms of time and quality. However, with complex problems, the response is not as fast.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have experience with CyberArk. I would say CyberArk is a more complex solution in terms of implementation, day-to-day administration, and maintenance. It is more complex and difficult in some ways, but for advanced or difficult connectors, CyberArk has more capabilities to develop customized connectors. It can cover more special or ad hoc use cases, but at the price of more complexity overall.

One Identity Safeguard is at the top level because it covers almost all the general PAM use cases. It covers password rotation, transparent connections, threat detection, isolation, etc. It can cover the needs of most organizations. We have also been able to better cover more complex use cases with One Identity Safeguard than with other PAM solutions.

How was the initial setup?

We have a virtual appliance. We chose the virtual appliance because we were already using a virtual machine infrastructure, so it was easy for us. Our implementation is not complex. We do not have a lot of regulations. It does not matter if we lose connectivity. It is not the end of the world, so for us, a virtual appliance was good enough. It was easier to implement. We do not need to rely on physical devices.

To implement and be functional, it takes days, probably one week, but when I go to a customer and need to do all the configuration and integrate systems, it can take a couple of months overall. It takes days to implement, but configuring and integrating everything can take some months.

In terms of maintenance, it requires less maintenance compared to other PAM solutions. There is not much maintenance regarding the infrastructure. They are, black boxes or appliances, but they do require maintenance in terms of day-to-day configuration, permissions, and connectors.

What was our ROI?

We did not cover many use cases regarding efficiency and cost reduction, so we did not see ROI directly. However, being more secure makes it less probable that we will suffer an attack or data loss, which is a cost reduction, but I did not see much time reduction. There is about 10% savings.

What's my experience with pricing, setup cost, and licensing?

It is cheaper than CyberArk. Its price is fair.

What other advice do I have?

We use the solution’s transparent mode feature for privileged sessions. There was an impact on the users with the roll-out of this feature because we changed the way people were connecting to systems and faced some problems like communication and networking problems. People did not have the correct permissions at the time. That was a bit of a problem, but we now have a seamless integration. It took us a couple of months to have everything working.

I will recommend it to some customers because it is easy to deploy, administer, and configure. The price is fair. The scalability is also good.

Overall, I would rate it an eight out of ten. It covers pretty much all use cases, but sometimes there is a lack of customization.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
PeerSpot user
Systems Administrator at a university with 10,001+ employees
Real User
Provides secure and centralized access to on-prem and cloud servers
Pros and Cons
  • "It provides secure and centralized access to both on-prem and cloud servers, which we did not have before. Previously, there were myriad ways to access our servers, so this centralizing feature is beneficial."
  • "The auditing and approval mechanisms are features we did not have before and are greatly appreciated."
  • "We are still in the onboarding phase, and it seems very manual. Ideally, a single interface to integrate all these processes would be useful."
  • "We have not had any issues with the core product itself, but there is an add-on called SCALUS, which is quite critical to the user experience, and that does not work. They have been having issues with that for quite a long time, like months. That is not great at all."

What is our primary use case?

We use it to handle secure access to our Windows and Linux servers and also to manage some of our user accounts. This includes password rotation, JIT, and disabling accounts when they are not in use.

We use their physical appliance.

How has it helped my organization?

I look after the backend, but I am also a user of it. In general, users do not love it because there are extra steps to what they are used to, but it is an intuitive service. The approval workflows work particularly well with their integration into Teams. From a backend point of view, it is not too bad. There are a few places where the interface could be slightly different, but mostly, it is fairly intuitive.

The Approval Anywhere feature provides an approval process. We use it for our external contractors. It is nice and easy once things are set up from their point of view, and it provides the university with an additional layer or multiple layers of security, which we did not have before.

We have integrated it with Identity Manager, which is another One Identity product. We have not integrated it with anything else. We thought about integrating it with ServiceNow to have a one-stop shop from ServiceNow to make API calls and requests from there. However, we wanted to keep things a bit simpler at this point. The interface is pretty nice. Asking users to go via the Safeguard method works well.

What is most valuable?

It provides secure and centralized access to both on-prem and cloud servers, which we did not have before. Previously, there were myriad ways to access our servers, so this centralizing feature is beneficial. 

The auditing and approval mechanisms are features we did not have before and are greatly appreciated.

What needs improvement?

I do not have any integrations at the moment, and I also do not use the API to automate this. I have to set up user accounts, then privilege accounts, and then linked accounts, and do some association there. There are many steps. We are still in the onboarding phase, and it seems very manual. Ideally, a single interface to integrate all these processes would be useful.

A couple of missing features that I have seen are about to come out, and I am happy they are addressing customer feedback with exactly what I wanted.

For how long have I used the solution?

I have used the solution for probably about 18 months to 2 years.

What do I think about the stability of the solution?

We have not had any issues with the core product itself, but there is an add-on called SCALUS, which is quite critical to the user experience, and that does not work. They have been having issues with that for quite a long time, like months. That is not great at all.

What do I think about the scalability of the solution?

Scalability is fine. We have a cluster of SPPs and a cluster of SPSs, and we can add a node to that cluster without much fuss. We did it on one of the clusters, so it is all good.

How are customer service and support?

They are quick to acknowledge a call or case, possibly due to SLA requirements. Overall, it is a hit-and-miss. Sometimes, I get a very helpful response and they address issues on a call. Other times, I am politely informed they cannot help.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I did not use any similar solution previously.

How was the initial setup?

It was a little bit of stop-and-start. Quite a few people were involved, but we had One Identity's professional service's help as well. We had something working within a week.

It does require maintenance. It is not a SaaS service. It is not a hosted service, so I have to resolve any issues that come along. I have to deal with any feature enhancements and patching.

What about the implementation team?

We had One Identity's professional service. We had probably four people from our side.

What's my experience with pricing, setup cost, and licensing?

We bought their other products, so it was not that expensive. It is one of those where the more you buy, the cheaper it is.

What other advice do I have?

I would rate One Identity Safeguard an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free One Identity Safeguard Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2025
Buyer's Guide
Download our free One Identity Safeguard Report and get advice and tips from experienced pros sharing their opinions.