Overview

Deploy Active Roles from AWS Marketplace
Active Roles allows you to manage and protect user and group accounts using automated task provisioning on directory objects, going above and beyond what is offered by native tools. Active Roles provides automation for consistent enforcement of corporate policies, an administrative model that allows you to delegate permissions based on role, and flexible, rule-based views across your entire AD identity environment via a consolidated single console. These features and more create a reliable and secure environment for distributed administration and account provisioning, allowing you to do your job faster.
Highlights
- Delegate least-privilege permissions based on role to ensure all identities and groups have proper privileges
- Consolidate all AD domains with Entra ID and M365 tenants onto a single console, ensuring better visibility and control over your entire AD/Entra ID/M365 environment
- Use automation to ensure accuracy and consistency of policy creation and enforcement and track changes to support your auditing and compliance reporting needs
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
All fees are non-refundable and non-cancellable except as required by law.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Additional details
Usage instructions
To access the application launch a new EC2 instance from this AMI and connect to it via RDP.
For more information, see the Active Roles Quick Start Guide: https://support.oneidentity.com/technical-documents/active-roles/8.1.5/quick-start-guide
Resources
Support
Vendor support
Once contacted Sales, follow the steps in the link below under the section 'Installing and configuring Active Roles on the EC2 instance':
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Delegated administration has simplified routine tasks and improves governance and compliance
What is our primary use case?
We are using One Identity Active Roles to simplify our Active Directory administration, such as controlling delegation access and automating routine tasks including user management activities.
What is most valuable?
One Identity Active Roles offers many valuable features that function very smoothly, including delegation administration, automated user management, approval workflows, and auditing details. These are the best features based on my experience.
What stands out the most in One Identity Active Roles is its ability to securely delegate routine Active Directory tasks without granting full administrative privileges. Combining this with automation and policy-based control really helps us reduce manual efforts.
One Identity Active Roles has positively impacted many areas within our organization by simplifying Active Directory administration and reducing manual efforts. It improves operational efficiency with the help of automation and delegated administration, leading to very positive outcomes.
In terms of governance and security, One Identity Active Roles provides very valuable add-on features, offering strong governance while not being heavily AI focused. It helps us enforce least privileged access and improves accountability while mitigating the risk of unauthorized changes within our Active Directory environment.
The accuracy and reliability of output from One Identity Active Roles are very high, as it provides very accurate results.
We use the fine-grained permission control feature of One Identity Active Roles, which has been very effective in supporting our least privilege strategy. For example, help desk staff can perform password resets and account unlocks without receiving full Active Directory administrative rights, providing security and reducing the number of highly privileged accounts in the environment.
My impression of the automation capabilities of One Identity Active Roles has been very positive. User account creation, group membership assignments, and account updates can be automated through predefined policies and workflows, allowing the correct attributes, permissions, and groups to be applied automatically based on organizational requirements.
One Identity Active Roles helps improve our compliance processes by enhancing control, visibility, and accountability within Active Directory, strengthening governance, and simplifying the audit and compliance process.
What needs improvement?
I believe the initial setup could be more simplified to allow for better and faster deployment.
For how long have I used the solution?
I have been using One Identity Active Roles for almost two years.
What do I think about the stability of the solution?
One Identity Active Roles is a stable solution.
What do I think about the scalability of the solution?
One Identity Active Roles is a very scalable solution that can handle organizational growth over time.
How are customer service and support?
Customer support for One Identity Active Roles is very responsive and effective. Whenever we face technical issues, we raise a ticket and they are ready to provide support.
How was the initial setup?
I believe the initial setup could be more simplified to allow for better and faster deployment.
What was our ROI?
We are seeing a very good return on investment with One Identity Active Roles by reducing manual efforts, which in turn saves us time and money. This solution provides a significant benefit, allowing us to complete tasks forty to sixty percent faster than before.
What other advice do I have?
My advice to any organization considering using One Identity Active Roles is to deploy it, as it will be a great decision. During the deployment phase, I recommend identifying the Active Directory tasks that consume the most administrative time and focusing on automating those processes while taking advantage of all the useful features. I rate One Identity Active Roles nine out of ten because it is a very powerful solution providing great features and a smooth operational process.
Automation has simplified user lifecycle management and has ensured consistent access control
What is our primary use case?
One Identity Active Roles is our main solution for simplifying Active Directory management through automation, detection, and efficient user account administration.
When a new employee joins, One Identity Active Roles automatically creates the user account, assigns the correct group, and applies the required permission based on their role, reducing manual efforts and ensuring consistency.
What is most valuable?
One Identity Active Roles offers automation, automation of users, provisioning, role-based delegation, centralized Active Directory management, and streamlined user lifecycle management as its best features.
The most valuable feature in my day-to-day work is automation. It helps reduce manual efforts by automatically creating user accounts, assigning permissions, and managing user lifecycle tasks, which saves time and improves consistency.
Another feature I appreciate is role-based delegation. It allows different teams to manage specific tasks securely without giving full administrative access, which improves both efficiency and security.
One Identity Active Roles has positively impacted my organization by improving efficiency through automating routine tasks, reducing administrative workload, and helping maintain consistent access management across the organization.
The automation capabilities provided by One Identity Active Roles are among the strongest aspects of the product. For example, when a new employee joins, One Identity Active Roles can automatically create the user account, assign the appropriate group, and apply permissions based on the user's roles. It significantly reduced the complexity of Active Directory administration by automating routine tasks and making user and access management much easier for our IT team.
What needs improvement?
One improvement for One Identity Active Roles would be simplifying the initial setup and configuration process. A more intuitive interface and easier onboarding for new administrators would make deployment and management even smoother. The reason it is not a ten is the initial setup and configuration.
For how long have I used the solution?
I have been using One Identity Active Roles for approximately five years.
What do I think about the stability of the solution?
One Identity Active Roles has been very stable in our environment. In my experience, One Identity Active Roles is highly reliable and consistent in its automation and access management processes. It performs tasks accurately based on the defined policies and workflows, which helps reduce manual errors and improve operational efficiency.
What do I think about the scalability of the solution?
One Identity Active Roles is highly scalable. It can efficiently manage a growing number of users, groups, and administrative tasks. It is suitable for both small and large organizations.
How are customer service and support?
Customer support has been good. The support team is very responsive, knowledgeable, and helpful. They are quick to resolve issues and provide guidance when needed.
Which solution did I use previously and why did I switch?
We did not use a dedicated solution before One Identity Active Roles.
How was the initial setup?
We saw a noticeable reduction in manual efforts and provisioning errors since implementing One Identity Active Roles. Tasks that previously took several minutes per user can now be completed automatically, helping the IT team save time and maintain consistency across user account management. The initial setup required some planning, but once deployed, the product delivered good value through automation and improved administrative efficiency.
What was our ROI?
We have seen a positive return on investment. The biggest benefit has been time savings through automation, reducing manual administrative work, and helping the IT team manage user accounts more efficiently.
What's my experience with pricing, setup cost, and licensing?
The pricing and licensing of One Identity Active Roles were reasonable for our requirements.
Which other solutions did I evaluate?
We evaluated a few alternatives, including native Active Directory tools. We selected One Identity Active Roles because of its strong automation, delegation, and centralized management.
What other advice do I have?
I would advise clearly defining your Active Directory management and delegation requirements before deployment. Take advantage of the automation and role-based access features as they can significantly improve efficiency, security, and consistency. One Identity Active Roles integrates well with our existing Active Directory environment, and the available workflow and management features help streamline administration with minimal disruption.
We use fine-grained permission control to delegate specific administrative tasks to different teams without full Active Directory privileges. This has helped us implement least privilege principles more effectively, improving security while maintaining operational efficiency. I would rate this review as a nine out of ten.
Automation has streamlined user lifecycle management and improved access governance and audits
What is our primary use case?
One Identity Active Roles streamlines Active Directory operation and maintains better control over user accounts, groups, and administrative commissions on a day-to-day basis.
Whenever a new employee joins the organization, changes departments, or leaves the organization, One Identity Active Roles helps automate account updates and access changes without requiring any manual intervention, which is helpful to keep user access accurate and up to date.
What is most valuable?
The best features One Identity Active Roles offers are centralized Active Directory administration, access delegation, and user life cycle management.
Centralized administration is helpful because from different tools, I can get visibility from a single console, and the access delegation capability is very useful.
Since using this solution, there has been a great positive impact within the organization, achieving simplified user administration, faster execution of access changes for employees, and very good visibility into administrative actions.
The faster execution has reduced errors because access changes are automatically done by the solution instead of being changed manually, which saves significant time.
One Identity Active Roles provides strong governance and security through rule-based administration and approval workflows, which ensures changes and control are audited.
In terms of accuracy and reliability of output, One Identity Active Roles provides consistent output, and the automated workflow and access management process work very accurately, helping to reduce manual errors.
Fine-grained permission control is helpful for implementing the principle of least privilege; an administrator receives only the specific information that is required for the job function instead of assigning broad administrator rights.
The ease of integrating One Identity Active Roles with existing IT infrastructure and directory services is very smooth; it is a process-by-process step, so there are no issues with this integration.
My impression of the automation capabilities provided by One Identity Active Roles is very positive; it addresses repetitive administrative tasks and maintains consistency. For example, when new employees join, it can automatically create the user account, assign the appropriate group members, and apply naming standards.
The impact of One Identity Active Roles on compliance efforts is very positive; there is a compliance-ready environment because of good visibility, and every administrative action is tracked. Approval workflows help ensure that access changes follow established policies, making audits easier.
One Identity Active Roles has streamlined and simplified the complexity and workload of administrative tasks related to Active Directory because of its ability to automate routine tasks and provide dedicated administration.
My experience with the delegation of administrative tasks through One Identity Active Roles has made the process easier since most tasks are automated, allowing specific responsibilities to be assigned to different teams without giving them full Active Directory privilege, which has significantly improved security.
What needs improvement?
The initial setup of One Identity Active Roles could be simplified because it requires effort in designing workflows, delegation policies, and the administrative process, which necessitates expertise for this solution.
For how long have I used the solution?
I have been using One Identity Active Roles for more than two years.
What do I think about the stability of the solution?
One Identity Active Roles is stable.
What do I think about the scalability of the solution?
The scalability of One Identity Active Roles is very good; it is a very scalable solution.
How are customer service and support?
The customer support for One Identity Active Roles has resolution within timeline.
Which solution did I use previously and why did I switch?
One Identity Active Roles has been used since the beginning; there was no switch from a different solution.
How was the initial setup?
The initial setup of One Identity Active Roles could be simplified because it requires effort in designing workflows, delegation policies, and the administrative process, which necessitates expertise for this solution.
What was our ROI?
There have been great money savings and time savings with One Identity Active Roles.
What's my experience with pricing, setup cost, and licensing?
The experience regarding pricing, setup cost, and licensing is handled by a different team.
Which other solutions did I evaluate?
Other options were not evaluated before choosing One Identity Active Roles.
What other advice do I have?
My advice for others looking into using One Identity Active Roles is to start with the POC, get hands-on experience with all feature sets, and after that, proceed with the solution. Before implementation, define Active Directory administration and delegation requirements, and start by automating repetitive tasks such as user provisioning and password resets. I would rate this product a 9.
Automation has transformed onboarding and delegated access and now streamlines daily governance
What is our primary use case?
My main use case for One Identity Active Roles is user provisioning and group administration, workflow automation, access management, and employee onboarding and offboarding processes. When a new employee joins, One Identity Active Roles automatically creates the account, applies the correct policies, assigns role-based security groups, and routes approval if required.
The main focus of how I use One Identity Active Roles is user management through onboarding and offboarding, lifecycle management, access control, and reducing manual administrative effort through automation.
The automation capabilities are one of the strongest features of One Identity Active Roles. I mainly use them for user onboarding, offboarding, group assignments, and access approval workflows. For example, when a new employee joins, the account creation and non-role-based group assignments happen automatically through predefined workflows, reducing manual work, improving consistency, and helping minimize provisioning errors, making identity management much more efficient and controlled.
The main use case is automation of processes such as employee user management, onboarding, and offboarding. The automation process makes these tasks smooth and fast, allowing administrative work to be reduced and time to be saved.
What is most valuable?
The best features One Identity Active Roles offers in my experience include workflow automation, delegated administrations, user provisioning, de-provisioning, role-based access control, auditing, and hybrid Active Directory management. A workflow engine is especially valuable because it automates repetitive tasks such as onboarding, offboarding, and access requests, which saves time and reduces manual errors. I also appreciate the delegated administration features because they allow teams to handle specific tasks without giving full AD privileges, improving both security and efficiency, while the auditing and reporting capabilities are very useful for compliance.
Workflow automation has reduced repetitive manual work through onboarding, access requests, and account management, while delegated administrations allow support teams to handle routine tasks without full AD access. This has improved efficiency, reduced bottlenecks, and strengthened security through better access control and auditing.
I would like to highlight the auditing and reporting features of One Identity Active Roles because they provide good visibility into changes and help with compliance and troubleshooting. The fine-grained delegation and centralized management across Active Directory and cloud environments are also very valuable in our day-to-day activity.
One Identity Active Roles has impacted our organization positively because the biggest benefit has been reducing manual administration through automation and standardized workflows. Tasks such as onboarding, offboarding, group assignments, and access requests are now much faster and more consistent than before, thus helping create a more structured identity management process across the organization.
There are several positive outcomes since implementing One Identity Active Roles. Overall, the biggest gains have been time saving, improved consistency, reduced manual error, and better operational efficiency rather than a direct headcount reduction.
What needs improvement?
There is room for improvement in One Identity Active Roles. Based on my experience using it for the last two years, I see potential for a more modern UI, simpler workflow customization, and easier reporting. While the product is very capable, managing complex workflows and hybrid environments can sometimes require deeper expertise than expected, so better cloud integration and troubleshooting visibility would also be valuable improvements.
In terms of needed improvements, I would like to see enhancements around the reporting dashboard and cloud-focused management features. While the core functionality is strong, most of the improvements I would like to see are around usability, visibility, cloud management, and making advanced features easier to configure and maintain rather than major gaps in the product itself.
For how long have I used the solution?
I have been using One Identity Active Roles for the last two years.
What do I think about the stability of the solution?
One Identity Active Roles is stable.
What do I think about the scalability of the solution?
One Identity Active Roles is definitely scalable. I purchased this for its scalability and have seen its ability to handle increasing numbers of users, groups, access requests, and administrative tasks without major issues. The automation and delegation administration features help a lot because they reduce the workloads on administrators.
How are customer service and support?
Customer support is quite good.
Which solution did I use previously and why did I switch?
Before switching to One Identity Active Roles, user and access management was mainly handled through native Active Directory tools, manual processes, and a few scripts. As the environment grew, those methods became hard to manage and audit, so I adopted One Identity Active Roles to automate routine tasks, improve delegations, strengthen governance, and reduce manual effort.
How was the initial setup?
I would say the integration of One Identity Active Roles with our existing IT infrastructure and directory services was very straightforward overall, especially because our environment was already based on Active Directory and Microsoft services. The initial integration with Active Directory was relatively smooth, and One Identity Active Roles fit well into our existing identity management process, designed to work across AD, Entra ID, and Microsoft 365, which helped simplify administrations in our hybrid environment.
What about the implementation team?
I did not purchase One Identity Active Roles through AWS Marketplace , as I use AWS as a part of our hybrid cloud environment, but the licensing and procedure were done directly through our organization's standard software procurement process rather than through the AWS Marketplace .
What was our ROI?
I have seen a positive return on investment mainly through time savings and operational efficiency. While I do not have exact financial figures, a good example is onboarding and user provisioning. Before One Identity Active Roles, creating accounts, assigning groups, and validating permissions was largely manual work, taking around twenty to thirty minutes per user, but with automated workflows, that process now takes just a few minutes for standard requests.
I have utilized the fine-grained permissions control and delegated administration features quite extensively. One of the biggest impacts has been supporting the least privileged principle by allowing users and teams to perform only the specific administrative tasks they need without giving broad Active Directory access. For example, help desk teams can handle password resets and account unlocks, while application owners can manage only their own groups and resources.
What's my experience with pricing, setup cost, and licensing?
In my experience, the pricing is at an enterprise level, but the setup and licensing were justified by the automation and governance features. Setup required planning and configuration, but licensing was straightforward, and the long-term operational benefits provided good value.
Which other solutions did I evaluate?
I evaluated Microsoft Native Active Directory tools, ManageEngine ADManager Plus , and some identity governance platforms such as SailPoint. I selected One Identity Active Roles because of its automation, delegation administration, auditing, and strong Active Directory management capabilities.
What other advice do I have?
For others considering One Identity Active Roles, my advice would be to first check your user management process and how onboarding and access management would be taken care of before deployment, starting with key automation use cases. If implemented properly, One Identity Active Roles can save a lot of administrative effort while improving security and compliance, so it is important to clearly define your governance model, roles, and approval processes before deployment.
My experience with delegated administration has been very positive. Before One Identity Active Roles, most routine requests had to go through senior Active Directory administrators, which often created delays and bottlenecks. Now, with delegated administrations, I can assign specific responsibilities to help desk teams, application owners, or business units without giving them full AD privileges. For instance, help desk staff can handle password resets and account unlocks, while certain teams can manage their own group's membership, significantly improving workflow because routine requests are resolved faster, reducing the workload on senior administrators and controlling access more securely through the least privilege model.
One Identity Active Roles offers automation capabilities that are among the strongest features available. I mainly use them for user onboarding, offboarding, group assignments, and access approval workflows. For example, when a new employee joins, the account creation and non-role-based group assignments happen automatically through predefined workflows, reducing manual work, improving consistency, and helping minimize provisioning errors, making identity management much more efficient and controlled.
This review has received an overall rating of eight out of ten.
Role-based access control has strengthened governance and simplifies secure user provisioning
What is our primary use case?
One Identity Active Roles simplifies the administration of Active Directory and automates user management tasks.
What is most valuable?
One Identity Active Roles automatically creates user accounts based on predefined templates and places users in the correct group.
The best features One Identity Active Roles offers are role-based administration, user provisioning automation, and Active Directory delegation.
The most valuable feature is delegation administration, which allows the help desk team to perform routine tasks without giving them full access or privileged access.
One Identity Active Roles has reduced the administrative workload significantly, resulting in faster user provisioning and better governance over Active Directory changes.
What needs improvement?
The initial setup of One Identity Active Roles could be more simplified.
For how long have I used the solution?
I have been using One Identity Active Roles for more than two years.
What other advice do I have?
One Identity Active Roles strengthens system security, administration, and governance by enforcing role-based access control.
One Identity Active Roles is consistent with the features to delegate identity management tasks.
I rate One Identity Active Roles eight out of ten because the product has excellent control permissions and is secure for Active Directory administration. Apart from the initial complex setup, everything is perfect.