Overview
One Identity Safeguard for Privileged Passwords automates, controls and secures the process of granting privileged credentials with role-based access management and automated workflows. Deployed on a hardened appliance, Safeguard for Privileged Passwords eliminates concerns about secured access to the solution itself, which helps to speed integration with your systems and simplifies management. Plus, its user-centered design means a small learning curve and the ability to manage passwords from anywhere and with nearly any device. The result is a privileged password management solution that secures your enterprise and enables your privileged users with a new level of freedom and functionality.
Highlights
- Release control - Manages user password requests via a secure web browser connection with support for mobile devices.
- Discovery - Quickly discover any privileged account or system on your network with host, directory and network-discovery options.
- Approval Anywhere - Leveraging One Identity Starling, you can approve or deny any request without being on the VPN.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
All fees are non-refundable and non-cancellable except as required by law.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Additional details
Usage instructions
Right click Safeguard AWS image. Select "Launch" Select you preferred disk size. For testing 100Gb is fine. For production environments, you will want 1Tb or greater. Choose your preferred network NIC/network etc. review and accept Image will deploy. You can see a progress of the image that is deploying by navigating to the deploying image, "right-click instancesettings -> Get System Log. Instance will deploy and then Safeguard will deploy. This will take several minutes. System log will show the percentage of Safeguard deploy progress. Finished when reaches 100% Compete instructions: https://support.oneidentity.com/technical-documents/one-identity-safeguard-for-privileged-passwords/7.0%20lts/appliance-setup-guide/4#TOPIC-1820747
Resources
Vendor resources
Support
Vendor support
One Identity offers an extensive range of services from online resources, 24x7 and premier support. One Identity support provides solution support to suit any business organization.
https://support.oneidentity.com/essentials/support-offerings
Contact support at
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products

Customer reviews
Privileged access has become streamlined while cloud and legacy support still need improvement
What is our primary use case?
My main use case for Safeguard by One Identity is privileged identity access management, session monitoring, and password management.
In my day-to-day work, we onboard the most powerful accounts and privileged accounts across the applications, platforms, and network elements into the PAM system, which is Safeguard by One Identity , and it has the inbuilt capability that supports session management, password management, and analytics.
What is most valuable?
Safeguard by One Identity offers simple web GUI, easy onboarding and management, and less complex architecture as its best features.
The web GUI and easy onboarding help my team because even less trained people can easily navigate it, and trained individuals can start using the tool easily without requiring any development or additional skills; it is easy to navigate and work on.
Safeguard by One Identity has positively impacted my organization, as in the past, we were using TPAM , the older product from the same vendor of the Fab solution, but this is a new version, a new generation tool which supports most of the new version products and new protocols, and it works well.
What needs improvement?
Safeguard by One Identity has been built most of the time to support the most recent products and versions in the environment, but sometimes in real-time scenarios, companies might be running with legacy systems or applications; during that time, you might need to build a custom solution that is not flexible enough, and I think additional efforts are needed to build solutions to support legacy systems.
I chose a rating of seven because I believe the product still has improvements that need to be made in terms of supportability for new applications, such as SaaS solutions, and it does not have any native method of managing cloud-based applications, which I believe is an area to improve.
Regarding Safeguard by One Identity's AI capabilities, I do not believe it has really good governance and security; I think it probably needs to be upgraded to incorporate all AI agents or AI-specific security-related features which have not been covered in the current version.
For how long have I used the solution?
I have been working in my current field for more than fifteen years.
I have been using Safeguard by One Identity for more than five years.
What do I think about the stability of the solution?
In terms of Safeguard by One Identity's reliability, I believe it is fine, and we do not see any major problems with it.
What do I think about the scalability of the solution?
Since switching to this newer version, it improved compliance, the onboarding time reduced significantly, and it supports API calls and automation processes, so overall onboarding time has been significantly reduced.
What other advice do I have?
I would advise others looking into using Safeguard by One Identity to consider it if they are looking for a budget-friendly option, easy installation, and quick setup; however, if companies require many custom solutions and support for legacy environments, it might not be a good fit, and they may need to explore other options. If any environment is trying to work with newer tools or AI-specific protections, this tool is probably not evolved to that level, so I believe you need to assess your requirements first. I would rate this product a 7.5 out of 10.
Centralized vaulting has improved privileged access security and simplifies audit readiness
What is our primary use case?
When a new system administrator needs to access a production server, instead of sharing the administrator password, they request access through Safeguard by One Identity , which securely provides the credentials or starts a monitored session, logging all activity. This has helped our team improve security, simplify audits, and ensure privileged passwords are never shared directly.
Safeguard by One Identity has become an important part of our privileged access workflow by enforcing security policies, reducing the risk of unauthorized access, and maintaining a compliance audit trail . It has made managing privileged accounts more secure and efficient for our IT team.
How has it helped my organization?
Before Safeguard by One Identity, privileged passwords were managed manually, which increased the risk of passwords being shared. Now, administrators access systems through the password vault, and passwords are rotated automatically, reducing manual effort, strengthening security, and making audits much easier since all privileged access and user sessions are logged and can be reviewed whenever needed.
We do not have exact metrics, but we have definitely seen an improvement since using Safeguard by One Identity, as password management is much faster without the need for administrators to manually share or update privileged credentials. Security has improved through automated password rotation and controlled access, while audit preparation takes much less time because all privileged sessions and access records are available in one place.
What is most valuable?
Safeguard by One Identity's password vaulting feature keeps privileged passwords in a secure, encrypted vault, so administrators do not need to know or share the actual credentials, allowing team members to request access when needed and automatically rotate the password after use. This reduces the risk of password leaks, improves automation, and saves time since we do not have to manually manage privileged credentials.
Another feature I appreciate from Safeguard by One Identity is the session recording and auditing, which provides a complete record of privileged activity, very helpful for troubleshooting, security investigations, and compliance audits. Safeguard by One Identity's centralized management interface also makes it easier to manage privileged accounts across different systems from a single place.
What needs improvement?
Another improvement would be having more detailed documentation and step-by-step deployment guides, particularly for complex environments. Better performance on large-scale deployments, enhanced search and filtering in audit logs, and more flexible notification and approval workflows would also improve the overall experience, making administration simpler and reducing the learning curve.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
How was the initial setup?
What about the implementation team?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
This rating of 9 out of 10 reflects that it offers strong privileged access management with features such as secure password vaulting, session monitoring, and auditing. Safeguard by One Identity is not rated a 10 because the initial deployment can be complex, and the user interface and reporting could be more intuitive.
From what I have seen, Safeguard by One Identity's governance and security are strong overall, with role-based access control and detailed audit trails. If the AI features follow the same security model, I expect them to provide a good level of governance and protection.
We have not used the AI capabilities enough to fairly evaluate their accuracy or reliability, so I cannot comment from first-hand experience, especially since most of our users focus on privileged access management, password vaulting, and session monitoring rather than AI features.
Overall feedback from users regarding Safeguard by One Identity's usability and functionality has been positive, with users appreciating that privileged access is centralized and secure, as well as not having to manage or remember privileged passwords. Administrators find Safeguard by One Identity's audit and session recording features especially useful. Safeguard by One Identity's main feedback has been that the interface can take some time to learn and that some administrative tasks could be more intuitive.
I advise others looking into using Safeguard by One Identity to spend time planning the deployment and defining privileged access policies before implementation. Involving the security and infrastructure teams early to start with a small pilot before rolling it out across the organization is important. Providing basic training to administrators and end-users is also essential to ensure smooth adoption. When configured properly, Safeguard by One Identity is a strong solution for improving privileged access security and simplifying compliance.
Privileged sessions have been secured and audits are now simplified with transparent monitoring
What is our primary use case?
Our main use case for One Identity Safeguard is privileged access management, where we need to secure control and monitor highly sensitive privileged accounts.
We use One Identity Safeguard for password storage and management for all privileged accounts, including admin accounts and service accounts. We also use it for Just-in-Time privileged access to provide the least privilege access possible for users.
What is most valuable?
One Identity Safeguard offers excellent features such as smart session auditing and forensics, transparent session proxy, password injection with no exposure, and real-time command and video blocking.
We rely most on smart session logging, smart session auditing, and forensics, which are valuable for our day-to-day tasks, along with password injection, which helps us securely pull passwords and automatically inject them into sessions, enhancing our security and aiding in auditing.
Regarding session proxy, One Identity Safeguard can sit on the network similar to a router, remaining completely transparent to both the user and the destination server while silently managing and injecting passwords and recording sessions in the background.
One Identity Safeguard has positively impacted our organization by contributing to a significant drop in compliance and audit overhead, aiding in the preparation of security audits that were previously chaotic, making the process much simpler now, and improving operational efficiency and admin satisfaction.
What needs improvement?
One Identity Safeguard could be improved by providing a unified management experience, as historically it has been split into logical units, and it would be beneficial if they could provide out-of-the-box reports and visualization, addressing the high resource overhead for privileged analytics.
Regarding One Identity Safeguard's AI capabilities, I believe they are still in the transformation phase, particularly with session monitoring, and once implemented fully, the advanced role mining and peer group analysis provided will help us improve further.
I cannot provide feedback on the accuracy and reliability of One Identity Safeguard's AI capabilities because we are not currently using the AI version; we may be deploying it next year.
For how long have I used the solution?
I have been using One Identity Safeguard for more than six years.
What do I think about the stability of the solution?
In my experience, One Identity Safeguard is stable.
What do I think about the scalability of the solution?
One Identity Safeguard's scalability works effectively in our large organization, as it successfully handles everything we need.
How are customer service and support?
The customer support for One Identity Safeguard is very good, providing timely responses based on the SLA, with high-priority tickets receiving responses within an hour. I would rate the customer support around eight.
Which solution did I use previously and why did I switch?
Before switching to One Identity Safeguard, we were using Thycotic Server, which was not as user-friendly, leading us to switch to One Identity Safeguard.
How was the initial setup?
The deployment of One Identity Safeguard was very quick, taking only one or two days.
The deployment affected our privileged users smoothly, as we transitioned from another solution where users adapted quickly due to One Identity Safeguard being user-friendly.
What about the implementation team?
We provided training for users that took approximately one week, plus one month of training for administrators, which was very helpful for getting everyone on board.
Which other solutions did I evaluate?
Before choosing One Identity Safeguard, we evaluated CyberArk, but it was more costly, which influenced our decision to consider One Identity Safeguard due to its lower cost.
What other advice do I have?
My advice for others considering One Identity Safeguard is to define the architecture early, as it will be helpful, and to consider using One Identity Manager alongside it, as they can integrate effectively. I would rate this solution an eight overall.
Centralized privileged access has transformed password management and supports compliant auditing
What is our primary use case?
One Identity Safeguard is primarily utilized in my organization for managing the company's privileged accounts.
I use One Identity Safeguard to record and audit privileged sessions in order to meet regulatory requirements.
What is most valuable?
The best features that One Identity Safeguard offers is the centralized approach to managing privileged accounts. Specifically, the centralized approach has helped us significantly reduce the time spent on managing privileged account passwords.
One Identity Safeguard has positively impacted my organization. After implementation, we were able to reduce the time spent on security incidents related to compromised passwords. Before using One Identity Safeguard, two administrators spent approximately twenty hours a month on manual credential management, and after implementation, this time was reduced to about five hours a month, which represented a savings of thirty hours per month.
What needs improvement?
I think the aspects that could be improved in One Identity Safeguard include the learning curve, since the installation is complex and expert guidance is required in the first steps.
The upgrade process could also be simpler.
For how long have I used the solution?
I have been using One Identity Safeguard for one year.
What do I think about the stability of the solution?
One Identity Safeguard is a stable solution.
What do I think about the scalability of the solution?
I perceive the scalability of One Identity Safeguard as good, as it adapts well to the growth of my organization.
We have been able to continue adding more credentials and more users to the tool.
How are customer service and support?
My experience with One Identity Safeguard's customer support has been positive, as the team usually responds within reasonable time frames and shows a good level of technical knowledge.
I would rate customer support eight out of ten.
Which solution did I use previously and why did I switch?
Before implementing One Identity Safeguard, we did not have another tool.
How was the initial setup?
One Identity Safeguard is implemented on a local server in my organization.
The implementation of One Identity Safeguard took about eight months in our organization.
What about the implementation team?
The implementation affected privileged users with a learning curve, since they had to start using the tool, but it was resolved over time.
One month of training and another month of support was needed for both administrators and end users to use the tool efficiently.
What was our ROI?
I have seen a return on investment with the platform, having experienced a reduction of around thirty working hours per month for privileged credential management.
What's my experience with pricing, setup cost, and licensing?
My experience with the licensing, installation, and pricing of One Identity Safeguard was within expectations since that was taken into account when evaluating the tool.
What other advice do I have?
Users have told us that the interface is intuitive, that the team becomes familiar with the platform, and the integration with Windows environments is quite complete.
For the moment, we have not integrated the platform with other areas of our business, as we are still working on that.
I would advise other companies that are considering implementing One Identity Safeguard to thoroughly review their internal processes so they can adapt them to the tool.
I have given this review an overall rating of nine.
Centralized credential vault has strengthened secure remote access and simplified audits
What is our primary use case?
Currently, for our business case, we have multiple scenarios with One Identity Safeguard , but I haven't used the transparent mode much. The transparent mode that I am aware of is that One Identity Safeguard privileged sessions have that transparent mode where the administrator and target server allow users to continue connecting to servers exactly as they would normally, which can be useful.
This is a good feature to have.
I use the secure remote access for privileged users.
I do not use any physical appliances, virtual appliances, or on-demand versions with One Identity Safeguard. The primary business use case we have for it is secure privileged account management, including credential vaulting, enforcing password rotation, and providing secure privileged session access. These are the proper business use cases on which we implement it. It helps us reduce the risk associated with privileged credentials while supporting compliance and security monitoring.
This is how we utilize it.
What is most valuable?
The best features of One Identity Safeguard are multiple features similar to any PAM solution that we use for our security purposes. The strongest feature of One Identity Safeguard is a centralized privileged credential vault, which eliminates the need for administrators to know or manually manage privileged passwords. The automated password rotation and secure checkout process significantly reduce credential exposure.
This is the best aspect that I have experienced, along with another feature that is session management. The session recording and replay provide excellent visibility for investigation, compliance audits, and insider threat monitoring. These features are the best in One Identity Safeguard that I have seen compared to multiple other PAM solutions.
One Identity Safeguard has improved our organization from the security perspective, which is the main aspect that we have seen in it. VPN elimination and reduced credential exposure have helped us manage credentials in a more secure way. We work in a Security Operations Center , and it has helped us significantly from a SOC perspective.
What needs improvement?
One area that has room for improvement in One Identity Safeguard is native integration with newer cloud platforms and SaaS applications and security tools. We have a SOAR application in our environment, which is Cortex XSOAR , and it would be better if One Identity Safeguard could have native integration with this application so that anyone executing playbooks through the SOAR could request One Identity Safeguard access through it. This would be one improvement that we suggest regarding native integration with newer cloud platforms.
Reporting and dashboard customization with One Identity Safeguard should be better improved. While it is already present, monitoring multiple servers and technologies that we have integrated with One Identity Safeguard could be managed better if more reporting and dashboard customization options were available.
For how long have I used the solution?
I have been using the solution for one and a half years.
What do I think about the stability of the solution?
From a stability perspective, I rate One Identity Safeguard as being stable in our production environment and it performs reliably with minimal unplanned downtime. I would rate it 8 out of 10.
What do I think about the scalability of the solution?
The scalability of One Identity Safeguard is that the solution scales in the enterprise environment with multiple privileged accounts, servers, and administrators. It overall supports growth without any significant performance issues. When deployed according to best practices, I would rate it 9 out of 10.
How are customer service and support?
I use the regular support for One Identity Safeguard. I rate support from 1 to 10 overall as 9 because compared to other customer PAM solutions that we have like iRage PAM and Commvault PAM, this is superior and offers a more advanced procedure.
What other advice do I have?
I use the secure remote access for privileged users.
One Identity Safeguard provides VPN-less remote access where administrators, vendors, and third-party users can securely connect with privileged resources without using traditional VPN. This is the main advantage because having VPN connectivity between these three user types would otherwise present a vulnerability. Additionally, the clientless browser-based access allows users to connect through a web browser without installing client software, which simplifies onboarding and remote administration.
It is not important to me that secure remote access with One Identity Safeguard does not use VPN, because it already eliminates VPN-related risks for privileged users and it was very helpful. VPN usage would be a key concern when connecting in such cases, but this particular secure access eliminates VPN-related risks and provides a complete audit trail for remote administrative activities.
I compare One Identity Safeguard with other vendors based on the features that I have mentioned, such as stability and customer support, as well as scalability. This is the best product that I can recommend. It would be an excellent tool for the medium to large enterprise looking for a mature privileged access management solution. Compared to other solutions, it has a better feature set and better capabilities, which makes it a superior tool.
I am not aware of the pricing for One Identity Safeguard because I am an end user of this product. The pricing must be handled by our finance team, so I am not informed about this aspect.
The deployment of One Identity Safeguard did not disruptively affect my privileged users in any way.
I have integrated One Identity Safeguard with multiple options available, such as our Active Directory.
My experience with integration of One Identity Safeguard was not difficult. The integration with Active Directory or any enterprise infrastructure was straightforward. However, configuring the policies and onboarding privileged assets required careful planning and workflow understanding. Overall, it was straightforward and simple with no complex details.
The amount of training required to start using One Identity Safeguard is minimal. Because in our environment we have multiple PAM solutions or other integrated solutions, One Identity Safeguard was much easier in comparison.
I rate this review 9 out of 10.