Listing Thumbnail

    One Identity Active Roles

     Info
    Deployed on AWS
    Simplify Active Directory Security and Management with One Identity Active Roles.
    4.1

    Overview

    Play video

    Active Roles allows you to manage and protect user and group accounts using automated task provisioning on directory objects, going above and beyond what is offered by native tools. Active Roles provides automation for consistent enforcement of corporate policies, an administrative model that allows you to delegate permissions based on role, and flexible, rule-based views across your entire AD identity environment via a consolidated single console. These features and more create a reliable and secure environment for distributed administration and account provisioning, allowing you to do your job faster.

    Highlights

    • Delegate least-privilege permissions based on role to ensure all identities and groups have proper privileges
    • Consolidate all AD domains with Entra ID and M365 tenants onto a single console, ensuring better visibility and control over your entire AD/Entra ID/M365 environment
    • Use automation to ensure accuracy and consistency of policy creation and enforcement and track changes to support your auditing and compliance reporting needs

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Win2025 Windows Server 2025 Datacenter 24H2 26100.4946

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    One Identity Active Roles

     Info
    Pricing and entitlements for this product are managed through an external billing relationship between you and the vendor. You activate the product by supplying a license purchased outside of AWS Marketplace, while AWS provides the infrastructure required to launch the product. AWS Subscriptions have no end date and may be canceled any time. However, the cancellation won't affect the status of the external license.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    All fees are non-refundable and non-cancellable except as required by law.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Additional details

    Usage instructions

    To access the application launch a new EC2 instance from this AMI and connect to it via RDP.

    For more information, see the Active Roles Quick Start Guide: https://support.oneidentity.com/technical-documents/active-roles/8.1.5/quick-start-guide 

    Support

    Vendor support

    Once contacted Sales, follow the steps in the link below under the section 'Installing and configuring Active Roles on the EC2 instance':

    https://support.oneidentity.com/active-roles/8.2.1 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.1
    77 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    42%
    56%
    1%
    1%
    0%
    7 AWS reviews
    |
    70 external reviews
    External reviews are from G2  and PeerSpot .
    reviewer2827050

    Automated user lifecycle management has reduced manual tickets and strengthened access control

    Reviewed on May 28, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for One Identity Active Roles  is automating and controlling AD user lifecycle management with delegated administrator. When a new employee joins, instead of an admin manually creating the ID accounts, assigning groups and setting permissions, One Identity Active Roles  automatically takes care of the request from the HR system or service ticket, applies the naming convention and password policies, and sends approval workflows if elevated access is requested.

    Integrating One Identity Active Roles with my existing IT infrastructure and directory services is a plug and play solution. I need to enter the credentials inside the AD.

    My impression of the automation capabilities provided by One Identity Active Roles is positive, based on the user onboarding process automation. HR sends the request to the ticket service team, which gives the integration with One Identity Active Roles. HR alerts the support ticket administrator, who starts the process that will assign One Identity Active Roles automatically for a user based on this justification, which helps very easily.

    What is most valuable?

    The best features One Identity Active Roles offers include fine-grained delegated administrator, RBAC policies, lifecycle management, hybrid managed identity management, policy-based administration, and auditing, tracking, and changes.

    If I have to select one feature, lifecycle management has the biggest impact because it automates user onboarding, role changes, and offboarding, making access updates faster, consistent, and less error-prone while reducing the risk of orphaned accounts.

    One Identity Active Roles has positively impacted my organization by speeding up the user provisioning, reducing manual AD tickets, strengthening the security through consistent access control, and improving compliance.

    Based on our analysis, the solution saves around 30 to 60 minutes of time. Ticket reduction is around 50%, and I have seen fewer access errors.

    What needs improvement?

    I am very happy with the solution provided by One Identity Active Roles, so there is no need for improvement at this time. In the future, there will definitely be opportunities for improvement.

    For how long have I used the solution?

    I have been using One Identity Active Roles for almost one year.

    What other advice do I have?

    Regarding One Identity Active Roles's AI capabilities, I think its governance and security are very good. If they use a third party as an AI, the security may be compromised. However, if they are using their inbuilt assistance, it gives a very good result.

    Regarding One Identity Active Roles's AI capabilities, I cannot rely on the AI totally. At this time, it is 50-50 for me to give the answer because sometimes it gives me a really good answer and sometimes not the script that I have to check with them. It is very difficult to rely on the AI as well, so it is 60-40.

    I haven't used the fine-grained permission control feature of One Identity Active Roles, but it is in my license. In the future, I will be deploying this solution. I rate this product an 8 out of 10.

    reviewer2846799

    Automation has transformed delegated access and now streamlines our daily identity operations

    Reviewed on May 28, 2026
    Review provided by PeerSpot

    What is our primary use case?

    One Identity Active Roles  is used in our environment primarily for managing Active Directory operations such as user provisioning, password reset, account locks, group management, and delegated administration access.

    User provisioning is a heavily utilized function, where new employee onboarding includes automatic account creation, OU placement, group membership, and permission assignment based on department or role. The service desk team manages group membership requests and access changes through delegated administration without requiring full domain admin rights, which reduces manual efforts and improves security control.

    After implementing One Identity Active Roles , clear operational improvements are evident, including user provisioning time reduction from hours to minutes, a 40 to 50% drop in service desk workload, faster resolution of password reset and account-related requests through delegated administration, and fewer manual errors in group assignment and permission management.

    What is most valuable?

    The best feature of One Identity Active Roles is automation combined with delegated administration, which reduces repetitive Active Directory work such as user provisioning, group assignment, and account management while allowing the service desk team to handle routine tasks without granting full domain admin access.

    Automation simplifies daily operations by eliminating repetitive manual Active Directory tasks including user creation, group assignment, password reset, and account disablement. Onboarding and offboarding processes become much faster because account permissions and group membership are assigned automatically based on role or department.

    One Identity Active Roles has positively impacted productivity and user satisfaction by reducing delays in account provisioning, password reset, and access requests. Previously, many AD-related tasks were manual and heavily dependent on senior administrators, but after implementing automation and delegated administration, requests are completed much faster and with fewer errors.

    What needs improvement?

    One area where One Identity Active Roles can improve is simplifying complex workflow and approval management in large enterprise environments. Troubleshooting permission inheritance, synchronization issues, or customized workflows can still require considerable time and experienced administrator involvement.

    The UI experience, easier workflow customization, and better troubleshooting visibility for complex AD and hybrid identity environments require improvement. Identifying permission inheritance issues or synchronization problems still sometimes requires manual investigation.

    Complex workflow management and troubleshooting simplification in large enterprise environments remains an area for improvement.

    For how long have I used the solution?

    I have been using One Identity Active Roles for two years.

    What do I think about the stability of the solution?

    One Identity Active Roles has been very stable, with no major outages or performance problems experienced during normal operation.

    What do I think about the scalability of the solution?

    One Identity Active Roles handles our large Active Directory environment efficiently as the number of users, groups, and delegated administration tasks increases.

    How are customer service and support?

    Customer support for One Identity Active Roles is generally good, with the support team demonstrating strong technical knowledge, particularly regarding AD integration.

    Which solution did I use previously and why did I switch?

    Before implementing One Identity Active Roles, native Active Directory tools, manual administration, and PowerShell scripting were primarily used.

    What was our ROI?

    A good ROI was achieved with One Identity Active Roles through measurable operational improvements, including a 40 to 50% reduction in routine service desk workload.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is generally positive for an enterprise environment, as the initial investment can feel high but provides long-term value.

    Which other solutions did I evaluate?

    Before choosing One Identity Active Roles, Microsoft Identity Manager  and other tools were evaluated, with One Identity Active Roles selected for its strong integration with our existing Active Directory environment.

    What other advice do I have?

    Fine-grained permission control in One Identity Active Roles had a strong impact on least privilege implementation in our organization, as only specific tasks and privileges were delegated to users based on their job responsibilities.

    Integration of One Identity Active Roles with our existing infrastructure is relatively smooth because our environment is already heavily based on Active Directory and Microsoft technology, although the main challenge came during complex workflow customization.

    The automation capabilities of One Identity Active Roles are very positive, as they reduce repetitive tasks such as automatic user account creation during new employee onboarding.

    One Identity Active Roles reduces the complexity and workload of Active Directory by automating repetitive administrative tasks including user provisioning, group management, password resets, and account maintenance.

    Delegated administration through One Identity Active Roles is a very positive experience because it reduces dependency on senior administrators for routine tasks.

    One Identity Active Roles was purchased through another channel.

    I would rate this review a 9 out of 10.

    Mandar Shendye

    Automated onboarding has transformed access control and governance in daily directory operations

    Reviewed on May 28, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for One Identity Active Roles  is centered on Active Directory automation and delegated access management. It helps reduce manual AD administration, control, automated onboarding, offboarding, and simplifies compliance and auditing across the organization.

    One specific example of how I use One Identity Active Roles  for automation or delegated access management in my daily work is automated employee onboarding. When HR adds new employee details, One Identity Active Roles automatically creates their AD account, assigns them to the correct OU group membership, and applies permissions based on the department or role. This reduces manual effort and provisioning time significantly.

    What is most valuable?

    The best features One Identity Active Roles offers are automation, delegated administration, role-based access control, approval workflow, and centralized auditing. For me, automation and delegated administration made the biggest difference because they reduce manual Active Directory workload and improve security by limiting unnecessary privileged access.

    One area where One Identity Active Roles has positively impacted my organization is through automation and delegated administration. For example, instead of giving full domain admin rights to our service desk team, I delegate only specific tasks such as password reset, account unlock, or group management through our RBAC policies. On the automation side, when the employee leaves the organization, One Identity Active Roles automatically disables the account, removes group membership, and updates access policies, which reduces manual efforts.

    What needs improvement?

    Areas for improvement in One Identity Active Roles include UI modernization, workflow customization, flexibility in reporting, and troubleshooting visibility. This is particularly important in large environments when managing complex approval workflows.

    For how long have I used the solution?

    I have been using One Identity Active Roles for about four to five years.

    What do I think about the stability of the solution?

    One Identity Active Roles has been stable in my environment. Even with a large Active Directory environment and multiple delegated administration workflows, I did not face major stability issues. Most operational challenges were more related to workflow complexity or synchronization troubleshooting rather than product outages or crashes.

    What do I think about the scalability of the solution?

    One Identity Active Roles scales well in large enterprise environments. It can efficiently manage thousands of users, groups, OUs, and Active Directory administrative tasks through centralized automation and delegation. In my environment, with a large AD structure and multiple workflows, it scales reliably. Although in very complex hybrid environments, workflow performance and synchronization tuning can sometimes require additional tuning and planning.

    How are customer service and support?

    The support for One Identity Active Roles has generally been good in my experience. The support team has been technically knowledgeable, especially for Active Directory integration, RBAC, and workflow-related issues. For normal operational issues, the support team has been responsive and helpful, but for complex enterprise cases or advanced support, the escalation and resolution could sometimes take longer, depending on the environment complexity.

    I would rate customer support for One Identity Active Roles around 7 out of 10. The technical knowledge of the support team is good, especially for Active Directory and RBAC related issues, but sometimes response and escalation times for complex enterprise problems could be slower than expected.

    Which solution did I use previously and why did I switch?

    Before implementing One Identity Active Roles, I mainly relied on native Active Directory tools, manual administration, and some PowerShell scripting for user provisioning and permission management. As the environment grew, managing users, groups, and delegating permissions manually became time-consuming and harder to track from a governance and compliance perspective, which is why I moved to a more centralized and automated solution.

    How was the initial setup?

    Integrating One Identity Active Roles with my existing IT infrastructure was moderately easy overall. Since my environment was already heavily based on Active Directory and Microsoft technologies, the core integration was straightforward. The more challenging part was configuring complex workflows, delegated permissions, and integrating hybrid or customized environments, which required careful planning and testing.

    What was our ROI?

    I saw a good ROI with One Identity Active Roles. This was through reduced manual administration, faster user provisioning, and lower service desk workload. Routine tasks such as password resets, account unlocks, and group management became more automated, which saved significant operational time. I also saw fewer manual errors and better compliance visibility.

    What's my experience with pricing, setup cost, and licensing?

    Pricing, setup, and licensing for One Identity Active Roles were generally good for an enterprise environment. Although the initial setup and licensing can be high for a smaller deployment, it requires proper planning around the AD architecture, RBAC design, and workflow configuration. It reduced significant manual administration work and operational efficiency for tasks and compliance.

    Which other solutions did I evaluate?

    Before choosing One Identity Active Roles, I evaluated options such as Microsoft Identity Management  and SailPoint IdentityQ. I selected One Identity Active Roles mainly because of its strong Active Directory integration, delegated administration capabilities, automation features, and easier RBAC management for my environment.

    What other advice do I have?

    My impression of the automation capabilities provided by One Identity Active Roles is positive, especially for organizations heavily dependent on Active Directory administration and governance. The automation, delegated administration, and RBAC capabilities reduce significant manual operational work and improve security controls. At the same time, in large environments, workflow complexity and troubleshooting can still require experienced administrators. Proper planning and documentation are important for successful implementation.

    One Identity Active Roles has had a positive impact on my organization's compliance efforts by improving centralized auditing, enforcing RBAC and least privilege access, and providing better visibility into AD changes and administrative activities. Earlier, tracking permission changes and user activity was more manual and time-consuming, but One Identity Active Roles made audit and compliance reviews much easier through centralized reporting and approval workflows.

    One Identity Active Roles has had a strong impact on Active Directory operations by reducing manual administrative workload, improving access governance, and standardizing provisioning and permission management procedures. It also improved security because privileged access became more controlled through RBAC and delegation instead of using broad domain admin permissions for routine tasks.

    One strong feature in One Identity Active Roles is fine-grained permission control and least privilege implementation. Instead of giving full domain admin rights, I delegate only specific tasks such as password reset, account unlock, or group management to our service desk based on our RBAC policy.

    My advice to others considering One Identity Active Roles is to first design the RBAC model, delegation structure, and approval workflows properly before implementation. One Identity Active Roles gives strong automation and governance capabilities, but if the AD structure and access processes are not organized, complexity can increase later. I would also recommend starting with a phased rollout and involving both security and AD administrator teams early, especially in large enterprise environments. I would rate this product 8 out of 10 overall.

    Sachin-Yadav

    Automated identity lifecycle has reduced ad workload and simplifies delegated administration

    Reviewed on May 27, 2026
    Review provided by PeerSpot

    What is our primary use case?

    One Identity Active Roles  is mainly used for AD administrator and identity lifecycle management in my network. One Identity Active Roles  is primarily used for identity lifecycle management, such as automatic user management.

    Whenever a new employee joins, HR creates employee information, and One Identity Active Roles detects a new user and automatically creates an AD account, mailbox, home folder, and other necessary resources. Once login syncs the AD identity, the user automatically gets access.

    The most tightly used automation feature in my network is that it automatically creates AD accounts, assigns department-based groups, applies naming conventions, sets permissions, and triggers downstream provisioning.

    What is most valuable?

    The best feature of One Identity Active Roles is centered around AD automation, delegated administration, governance, and hybrid identity management. These are the main features that One Identity Active Roles provides.

    Delegated administration combined with automation is the feature I find most valuable in my day-to-day work because it solves two major enterprise problems simultaneously. For example, too many AD manual tasks and too many users with excessive admin rights make this feature best for me.

    One Identity Active Roles has had a positive impact by empowering automation security across identity management processes. Some of the biggest improvements are faster user onboarding, reduced administrative workload, and better security through delegations. Previously, I was handling a 100 percent workload, but after using One Identity Active Roles, 70 percent of my load has been resolved.

    What needs improvement?

    One Identity Active Roles does not require many improvements, but for upcoming or new users, there should be an easier initial setup and configuration. One Identity Active Roles is powerful, but deployment is somewhat complex. Common challenges include policy design, delegation setup, and synchronization tuning.

    While I appreciate most aspects of One Identity Active Roles, a few things need improvement. One is easier initial setup and configuration, and another is reporting and analytic enhancements that can be performed on the product.

    What other advice do I have?

    The ease of integrating One Identity Active Roles with my existing IT infrastructure and directory services is moderate.

    The overall impression of the automation capabilities provided by One Identity Active Roles is good. It is typically seen as reliable and enterprise-grade, deeply integrated with AD, governance-focused, and described as controlled identity automation with governance built in.

    One Identity Active Roles typically has a major simplifying effect on Active Directory administration, especially in large or hybrid environments. The effect is usually felt in two areas: task complexity reduction and overall workload reduction.

    I would advise enterprise companies to use One Identity Active Roles. It is truly useful for AD tasks.

    Dhiren Jethwa

    Automated workflows have reduced onboarding time and improve secure access control

    Reviewed on May 25, 2026
    Review from a verified AWS customer

    What is our primary use case?

    One Identity Active Roles  is used for automation, on-boarding, off-boarding workflows, managing group membership and permissions, role-based access control, auditing, and compliance in our hybrid AD environment with approval workflows.

    A practical example we are currently using is as follows. When HR creates a new employee record, One Identity Active Roles  automatically creates the AD account, assigns the correct OU based on the department location, adds predefined security groups, applies mailbox and licensing policies, and sets manager attributes and naming standards. For access control, we use dedicated administrators so the L1 helpdesk team can reset passwords or unlock accounts without receiving full domain admin rights. Access is restricted through role-based permissions and approval workflows, which improves security and reduces the risk of unauthorized AD changes.

    This use case fits our organization well.

    What is most valuable?

    One Identity Active Roles offers workflow automation, role-based access control, dynamic group management, hybrid AD and Microsoft 365 management, approval workflows, policy enforcement, and auditing.

    The feature that stands out and has had the biggest impact is the dedicated administrator combined with workflow automation. Before implementing One Identity Active Roles, routine AD tasks required senior administrators with elevated privileges. Now L1 and L2 support teams can safely handle tasks such as password resets, account unlocks, group modifications, and basic user provisioning through controlled RBAC policies. This helps us by reducing dependence on domain admin access, lowering the risk of accidental and unauthorized changes, speeding up user on-boarding and support requests, standardizing AD operations across teams, and reducing manual efforts and workload. Onboarding previously took around thirty to forty minutes, and now it takes just two to three minutes.

    One Identity Active Roles has improved our organization by automating AD tasks, reducing manual errors, improving security through dedicated access control, and speeding up user onboarding and off-boarding. It has also helped reduce admin workload and improved our compliance tracking.

    What needs improvement?

    One Identity Active Roles is very strong for AD automation, dedicated administration, and governance, especially in a large enterprise environment. The main areas that could be improved are UI modernization and reporting flexibility. These improvements could help the product achieve a higher rating.

    For how long have I used the solution?

    I have been using One Identity Active Roles for almost a year.

    What was our ROI?

    Based on our analysis and reporting, there is approximately fifty to seventy percent reduction in manual effort. Onboarding time has been reduced from twenty to thirty minutes to five minutes. There is a significant decrease in configuration errors due to the automation workflow templates.

    Which other solutions did I evaluate?

    One Identity Active Roles currently satisfies my use case, and I am happy with the solution. There is no need for improvements right now. However, when time passes, I will conduct research and development with other competitors as well. When I determine that the product needs improvement, I will update my feedback accordingly.

    What other advice do I have?

    The features that stand out are currently working as expected. One Identity Active Roles is performing as anticipated. My overall rating for this product is eight out of ten.

    View all reviews