Overview
One Identity Safeguard for Privileged Passwords automates, controls and secures the process of granting privileged credentials with role-based access management and automated workflows. Deployed on a hardened appliance, Safeguard for Privileged Passwords eliminates concerns about secured access to the solution itself, which helps to speed integration with your systems and simplifies management. Plus, its user-centered design means a small learning curve and the ability to manage passwords from anywhere and with nearly any device. The result is a privileged password management solution that secures your enterprise and enables your privileged users with a new level of freedom and functionality.
Highlights
- Release control - Manages user password requests via a secure web browser connection with support for mobile devices.
- Discovery - Quickly discover any privileged account or system on your network with host, directory and network-discovery options.
- Approval Anywhere - Leveraging One Identity Starling, you can approve or deny any request without being on the VPN.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
All fees are non-refundable and non-cancellable except as required by law.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Additional details
Usage instructions
Right click Safeguard AWS image. Select "Launch" Select you preferred disk size. For testing 100Gb is fine. For production environments, you will want 1Tb or greater. Choose your preferred network NIC/network etc. review and accept Image will deploy. You can see a progress of the image that is deploying by navigating to the deploying image, "right-click instancesettings -> Get System Log. Instance will deploy and then Safeguard will deploy. This will take several minutes. System log will show the percentage of Safeguard deploy progress. Finished when reaches 100% Compete instructions: https://support.oneidentity.com/technical-documents/one-identity-safeguard-for-privileged-passwords/7.0%20lts/appliance-setup-guide/4#TOPIC-1820747
Resources
Vendor resources
Support
Vendor support
One Identity offers an extensive range of services from online resources, 24x7 and premier support. One Identity support provides solution support to suit any business organization.
https://support.oneidentity.com/essentials/support-offerings
Contact support at
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products

Customer reviews
Centralized control of privileged access has improved security, auditing, and daily operations
What is our primary use case?
My main use case for Safeguard by One Identity is managing privileged access across Windows and Linux environments on a day-to-day basis. I use it to securely store privileged credentials, rotate passwords, broker privileged sessions, and provide controlled access to administrators without exposing the actual credentials. I onboard privileged accounts into Safeguard by One Identity and configure automatic password rotation after check-in or on a scheduled basis. Administrators can also submit access requests through Safeguard by One Identity, and according to the policy, the access is automatically approved or requires some manager or security approval. The access is granted only for the approved time window. I launch RDP or SSH sessions directly through Safeguard by One Identity, and the sessions are recorded and can be reviewed later for auditing or investigations. I regularly use the reporting features to verify who accessed privileged accounts, when they accessed them, and what actions were performed during the recorded sessions. This is particularly useful for compliance requirements such as PCI DSS or NIST. I have also integrated Safeguard by One Identity with Active Directory for user authentication and role-based access control, allowing permissions to be managed through the AD groups.
What is most valuable?
The best features Safeguard by One Identity offers, in my opinion, are its password vaulting, session management, just-in-time access, and auditing capabilities. Together, they reduce the risk associated with privileged accounts while simplifying compliance. In most cases, every time we have auditing, the fact that all the accounts are secured and managed through Safeguard by One Identity is always seen as a good choice and a good thing to do.
One of my favorite features is the automatic password rotation because users will never know their effective password or what the passwords originally are. Another of my favorite features is the session management. The fact that it launches the RDP or SSH and records all the sessions, which can be monitored or replayed, ensures that all activities are recorded in the account page. This allows for a quick answer to, for instance, SOC colleagues that need to know what happened, when, and from whom.
I integrated Safeguard by One Identity with Active Directory so that administrators authenticate using their existing domain accounts. I leverage AD security groups to assign access rights, which made user provisioning and deprovisioning much easier. When someone joined or left the team, I only needed to update their AD group membership, and Safeguard by One Identity would automatically enforce the correct permissions. It also improves security because every privileged action is linked to an individual identity, while privileged passwords remain hidden and are rotated automatically after use.
What needs improvement?
In my opinion, the biggest challenge is that I do not have exact organization-wide metrics to share, but I think they should improve the overall use for new users and people who are not very familiar with PAM or IAM . They should facilitate the overall training. Perhaps on their website, they could improve their training and the certification process.
From my experience, the AI capabilities of Safeguard by One Identity generally produce relevant and useful insights, particularly for highlighting potentially risky privileged activity or surfacing information that deserves further investigation. I have not encountered major accuracy issues, but I also would not rely on AI alone for security decisions. In a PAM solution, AI should support analysts, while policy enforcement and final access decisions remain governed by established controls and human review.
The integration with those internal tools and ticketing services was initially difficult because of the documentation. It was somewhat difficult to interpret it properly and apply it to our infrastructure, but through modern tools such as AI, I was able to implement it properly.
For how long have I used the solution?
I have been using Safeguard by One Identity every day for my working tasks since I started working in the cybersecurity field, approximately three to four years ago.
What do I think about the stability of the solution?
Safeguard by One Identity is stable.
What do I think about the scalability of the solution?
Safeguard by One Identity's scalability is straightforward because it scales very effectively for enterprise environments. The platform is designed to manage a large number of privileged accounts, assets, and users while maintaining centralized control over credentials, access workflows, and session monitoring.
How are customer service and support?
The customer support for Safeguard by One Identity is quite good. I would rate the customer support an 8 out of 10 since the support team is knowledgeable and helpful, especially when dealing with technical issues or complex configurations. The main areas for improvement would be faster resolution times for some advanced cases and more proactive guidance, but overall, the support experience has been positive.
Which solution did I use previously and why did I switch?
Before Safeguard by One Identity, I had a more manual approach, relying on a combination of password management processes, spreadsheets, scripts, and existing administrative controls. I moved to Safeguard by One Identity because I needed a more centralized and mature PAM solution with strong governance, automation, and auditing capabilities.
How was the initial setup?
Most of the users are not PAM specialists, so at first glance, they always encounter some issues with the overall use. However, after some brief training and documentation, they are able to perform the daily business as usual tasks. During my work experience, I have managed both cloud and on-premise solutions, but in my company, Safeguard by One Identity is still on-premises.
What about the implementation team?
Aside from the Active Directory integration, I have integrated Safeguard by One Identity with SIEM so that the audit events are forwarded. I also use some automation and APIs for account onboarding, reporting, integration with internal tools, and integration with ticketing services.
What was our ROI?
I would say that I saw a positive return on investment with Safeguard by One Identity, although the biggest benefits were not just direct cost savings. The main return on investment came from reducing manual effort, improving security, and avoiding operational compliance costs associated with poorly controlled privileged access. I saved a lot of time, but before Safeguard by One Identity, a privileged access request could involve finding the right owner, confirming approval, sharing credentials securely, and later changing the password. Depending on the situation, this could take anywhere from 30 minutes to several hours. With Safeguard by One Identity, the same process could often be completed in a few minutes through an automated request and approval workflow, with the session launched directly from the platform.
What's my experience with pricing, setup cost, and licensing?
The fact that Safeguard by One Identity has been implemented has improved the overall company image according to auditing. Moreover, it has improved our security posture and operational efficiency. I have eliminated password sharing, automated password rotation, and recorded privileged sessions, which by default significantly improve the security aspect. At the same time, integrating it with Active Directory and using automated workflows streamline access management, so administrators could get the access they needed without compromising security.
Which other solutions did I evaluate?
I evaluated other options before choosing Safeguard by One Identity, looking into products that are recognized in the market such as Delinea, Thycotic, HashiCorp, BeyondTrust, and CyberArk.
What other advice do I have?
I would rate Safeguard by One Identity an 8 out of 10. It is much more reliable with strong capabilities around password vaulting, session management, privileged session recording, and automatic password rotation. It does a very good job of securing privileged accounts while remaining straightforward for an administrator.
When I think about Safeguard by One Identity's AI capabilities, my first association is governance and security rather than productivity. Any AI feature should enhance visibility, risk detection, and policy enforcement without compromising control over privileged access. AI is valuable when it helps identify risks, detect anomalous privileged activity, and improve visibility. Governance policies and human approval should continue to control privileged access.
First of all, I would advise you to take your time and read the manuals. For the overall implementation aspect, plan it carefully, focus on processes as much as technology. Start by identifying critical privileged accounts, define clear access policies, integrate with AD, and automate password management whenever possible. A phased rollout with good communication and training will help users adopt the platform and maximize security benefits.
I use Safeguard by One Identity's Cloud Assistant feature. The main benefits are that it strengthens protection for high-risk credentials without creating unnecessary friction for administrators. For highly sensitive passwords, such as domain administrator, root, or emergency or break-glass accounts, the Cloud Assistant adds an additional control before the access is granted. Instead of applying the same approval process for every privileged account, I can apply stronger controls only where they are needed most. Moreover, administrators can still get required access quickly while security controls run in the background, avoiding lengthy manual approval claims for routine access scenarios. The goal is not just to block access but to ensure that privileged access is controlled, monitored, and appropriate based on the risk level. Access activity can be tracked and audited, giving the security team better insights into how critical credentials are being used.
Privileged access has become more controlled while support and web integration still need improvement
What is our primary use case?
My main use case for Safeguard by One Identity involves the management of domain privileged accounts, therefore integrations with Active Directory, specifically for applying these to Windows and Linux servers, where RDP and SSH sessions are monitored, along with password management via the SPP module of Safeguard. Recordings are carried out through SPS, and so far it has never happened that we had to implement restrictive policies that customized the standard connection policy.
In addition, we have also implemented SPS with the SIEM for sending reports and monitoring functionalities, as well as security alerts and notifications. We have also implemented access via OAuth 2.0 for SPP access and, on some occasions, have implemented web applications through the insertion of an RDP application on a server.
A specific example of a project where Safeguard by One Identity played a central role is when there was no management of privileged accounts and access occurred without monitoring, resulting in direct access to critical systems. The customer requested the implementation of Safeguard by One Identity to resolve this situation, so we implemented both modules, SPP and SPS, importing the entire pool of privileged accounts needing maintenance, which included password management.
We also included all the most critical targets requiring SPS to record all activities performed on the machine. We added all the users needing access to these targets with these accounts and configured the various entitlements, allowing for much cleaner and more controlled governance of privileged accounts.
So far, all cases have been fairly simple and have been fully covered. There was one instance where a customer needed to integrate the SIEM not via the standard connection provided by One Identity but requested integration via APIs, which are not yet currently available. On the other hand, we encountered some critical situations regarding web applications, which were handled by customizing the script using AutoIt. It would be beneficial if One Identity implemented web application management more similarly to how CyberArk does.
What is most valuable?
In my experience, the best features offered by Safeguard by One Identity are quite basic for a PAM product, though there are certainly aspects that can be improved. For example, making RDP application integration a more integral part of the product would help, as it currently requires fairly heavy customizations done externally to Safeguard. Overall, all the basic functionalities are there.
The main positive aspect of Safeguard by One Identity is that privileged account management is delegated to SPP, making it much more difficult for credential thefts to succeed. If they did occur, SPP would neutralize all the efforts made to retrieve the passwords within a day since passwords are rotated daily, for example. Moreover, undesired access is reduced to a minimum because it would be reported immediately, allowing for the reconstruction of events thanks to the recordings made by SPS.
Safeguard by One Identity has had a positive impact on my organization and my clients' projects, as several customers ended up satisfied after implementation and continued to use the product. There have never been any complaints, which indicates that the customer's needs were effectively addressed.
What needs improvement?
Based on my experience, Safeguard by One Identity could be improved by having stronger integration, perhaps starting with the ability to add API connections for the SIEM. It would also be beneficial to have a stronger implementation of RDP applications for web applications. Adding more supported platforms or updating the list could be helpful.
Regarding features and usability, we had a customer who needed to implement AS/400 systems, which were not supported. We attempted to establish privileged connections, but it was not possible, even after requesting support from One Identity, who were unable to solve the situation. It might be appropriate to either remove AS/400 from the supported platforms or address this issue.
For how long have I used the solution?
I have been using Safeguard by One Identity since 2021, starting with theoretical courses provided by One Identity, during which I spent three months studying the product. Starting from February 2022, I began implementing the solutions for various customers who needed a PAM solution.
What do I think about the stability of the solution?
Based on my experience, Safeguard by One Identity is quite stable. We have never encountered issues.
What do I think about the scalability of the solution?
Safeguard by One Identity excels in terms of scalability. From that standpoint, it is very scalable and quite easy to increase the numbers, always within license constraints. No issues were encountered during expansion of Safeguard by One Identity. If any slowdowns arose, we addressed them by increasing the appliance's resources.
How are customer service and support?
Unfortunately, my experience with Safeguard by One Identity's customer support is not very positive. They tend to respond slowly, generally do not find solutions effectively, and it is challenging to request calls that could resolve issues more quickly. From this perspective, support could improve significantly. Customer support is not very active, not very fast, nor efficient, which indicates they should work on enhancing efficiency.
Which solution did I use previously and why did I switch?
Before choosing Safeguard by One Identity, I had used CyberArk, which I must say is a bit more complete and more user-oriented, especially concerning support.
How was the initial setup?
I implemented Safeguard by One Identity in both ways. There are customers who wanted an on-demand solution, which we integrated without any issues, and then there are customers who preferred on-premise installations, where we downloaded the required ISOs, installed them on virtual machines, configured the appliances, and set up the clusters independently.
Generally, it takes about five to six months to achieve full operability with all systems active, though this timeframe is mainly due to delays on the customer side.
In terms of the deployment's effect on privileged users, the transition was quite smooth. No one complained about the change, as the management process did not change much. Instead of going directly through SSH and RDP clients, they simply had to use the interface with the connection package already prepared.
The amount of training needed to start using Safeguard by One Identity amounts to a couple of weeks for both those who manage it and end users.
What about the implementation team?
The company I work for is a One Identity partner.
What was our ROI?
I do not know if a return on investment has been obtained with Safeguard by One Identity, as I only deal with implementation. I imagine customers have seen improvements in security, but I am unaware of cost savings.
Which other solutions did I evaluate?
Before selecting Safeguard by One Identity, we typically evaluate CyberArk or Delinea as the main solutions to consider. This was the first PAM solution used by these customers, as it was the first option and the initial solution.
What other advice do I have?
Safeguard by One Identity has had a positive impact on my organization and my clients' projects, as several customers ended up satisfied after implementation and continued to use the product. There have never been any complaints, which indicates that the customer's needs were effectively addressed.
My advice to others considering using Safeguard by One Identity is that if you are looking for a product that handles the basics at a fairly low price, then it is appropriate for your needs. However, if you are looking for a product that allows for a lot of customization, perhaps it is not the most suitable choice. I would rate this product a seven out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized vaulting has secured privileged access and simplifies automated credential rotation
What is our primary use case?
I have been working with Safeguard by One Identity platform for the last one year, which is the PAM solution. We are using it as a Privileged Access Management solution as a point of security, as the first point of security towards managing PAM and PIM . We use it for securely managing privileged credentials, controlling administration access, and monitoring privileged sessions. We also monitor the vaults for compliance of the logs, which have been forwarded to our SIEM platform for further security controls and monitoring.
We use it for our privileged sessions, which has been acting as a centralized password vaulting and automated credential rotation platform. The automated credential rotation feature is the best feature I have used, and I have never seen it in different products as of now.
The onboarding was seamless. We have onboarded approximately 500 to 1000 users to the PIM . Certain users have certain accesses that need to be limited over specific time frames and as per their administrative requirements. This has been managed through that platform, and we have not observed any kind of issues.
Secure Remote Access feature is for our hybrid and remote employees, safeguarding our environment from external threat actors and preventing attackers from trying to access our network by using this Remote Access Privileged Access feature.
The integration was quite easy. We have FortiGate and FortiClient VPN in place, and it has been a seamless integration with this platform, enabling us to get access to the Remote Access feature over OneLogin. We are now managing and getting access to our critical systems by using the jump host available with this feature.
This integration has improved our enhanced security. It has been acting as a centralized vault which reduces our risk of credential theft, misuse of credentials, and prevents compromised hosts and privileged accesses to our critical hosts through this integration.
I would rate this at eight.
What is most valuable?
The features I find most valuable are the password vaulting and the auto-rotation features like password security complexities and the OWASP Top 10 vulnerabilities. It is suggested to rotate the password into certain time frames which are recommended by the security team, and this has been performed by using this application. We have been monitoring session monitoring via the SIEM tool. These logs have been forwarded there. MFA integration is also available, which has been helped by One Identity. We have managed OneLogin and One Identity implementations into our organization, and these real-time privilege alerts and vault alerts are being monitored. These are quite valuable things for us.
The features I liked the most about Safeguard by One Identity are the password vaulting and the automatic password rotation feature. MFA integration with the OneLogin platform was seamless as the organization is the same for them. Detailed audit logs are also available while clearing our audits. While troubleshooting, we need those audit logs, which have been forwarded over the SIEM, with reports sent to the admin team to get those reviewed if there are any certain changes made by the team which are not known to them.
Privileged users and systems are getting protected by using these solutions, and all privileged users access this portal with their credentials quite easily. It has been eliminating their overhead to manage this manually or access manually. Admin overhead gets reduced due to it, and the overall efforts are reduced.
There were no negatives observed. All observations were positives like the self-service access granted to users. Users can request privileged access to the portal, reducing dependencies on administration for every request. Built-in approval workflows are also available, so all these efforts have been reduced from manual ones.
What needs improvement?
I would like to highlight a couple of points, which are UI modernization. In the new world of AI, we are thinking about how AI can be helpful for detection capabilities in PAM solutions and easier reporting flexibility. There should be a chatbot feature in Safeguard by One Identity so we can easily find out the SOPs and documentations. By using chatbots, we can directly ask queries to them, and they can respond with the solution or steps.
The chatbot is the only suggestion I have as of now.
What do I think about the stability of the solution?
I have not observed any stability issues.
What do I think about the scalability of the solution?
As of now, we have implemented it for more than 250 users, and there have been no issues observed. It has been scalable.
How are customer service and support?
The setup was quite simple and easy for us, with help from the support team, which has been quite helpful for us in implementing this feature.
The vendor support was with us during the implementation phase. They helped us with the initial implementation and all of the documentations.
For end users, we have rolled out SOPs on how to manage and access the tools which are in the environment and critical servers. The SOPs have been built for that. For management, training sessions have been introduced by this vendor like OneLogin.
The team was there to support us in terms of integrations.
Which solution did I use previously and why did I switch?
This is our first PAM solution.
How was the initial setup?
The setup was quite simple and easy for us, and getting help from the support team, which has been quite helpful for us in implementing this feature.
Regarding the setup, it was quite easy and intuitive for us to get to know how we can onboard it. All the SOPs and the documentations are available on their portal, so it was easy.
What about the implementation team?
The vendor support was with us during the implementation phase. They helped us with the initial implementation and all of the documentations.
This has been integrated with our SIEM platform, which is the central monitoring platform for the SOC environment for cybersecurity. The team has built certain use cases related to the threat environment for abnormality detection, unusual logins, and false logins. Such use cases have been built into the SIEM platform. This is the external integration.
The integration into the SIEM platform was supported by the syslog method, which has forwarded these logs. It was supported so that all of these details have been transferred to the SIEM easily, and all the fields and logs have been mapped as per the supported mechanism.
What was our ROI?
It took approximately three months to go into production.
Which other solutions did I evaluate?
I was not part of the admin team evaluating alternate solutions, so I am unable to answer this question. I am the user of this product as of the date.
What other advice do I have?
Regarding the usability and functionality, the UI is quite intuitive and simple to handle for new users. Whenever new users are getting access to it, with the help of the documentations which are cleaner in format and easy to access, all of the things are in place with the help of the initial dashboards. We get to know what all of the functionalities are there.
While considering Safeguard by One Identity, customers can do the POCs if they want to, but however, in terms of feature-wise, it is a good product to have. It has all of the features required for a PAM solution. I rate this solution at eight out of ten.
Privileged access has become streamlined while cloud and legacy support still need improvement
What is our primary use case?
My main use case for Safeguard by One Identity is privileged identity access management, session monitoring, and password management.
In my day-to-day work, we onboard the most powerful accounts and privileged accounts across the applications, platforms, and network elements into the PAM system, which is Safeguard by One Identity , and it has the inbuilt capability that supports session management, password management, and analytics.
What is most valuable?
Safeguard by One Identity offers simple web GUI, easy onboarding and management, and less complex architecture as its best features.
The web GUI and easy onboarding help my team because even less trained people can easily navigate it, and trained individuals can start using the tool easily without requiring any development or additional skills; it is easy to navigate and work on.
Safeguard by One Identity has positively impacted my organization, as in the past, we were using TPAM , the older product from the same vendor of the Fab solution, but this is a new version, a new generation tool which supports most of the new version products and new protocols, and it works well.
What needs improvement?
Safeguard by One Identity has been built most of the time to support the most recent products and versions in the environment, but sometimes in real-time scenarios, companies might be running with legacy systems or applications; during that time, you might need to build a custom solution that is not flexible enough, and I think additional efforts are needed to build solutions to support legacy systems.
I chose a rating of seven because I believe the product still has improvements that need to be made in terms of supportability for new applications, such as SaaS solutions, and it does not have any native method of managing cloud-based applications, which I believe is an area to improve.
Regarding Safeguard by One Identity's AI capabilities, I do not believe it has really good governance and security; I think it probably needs to be upgraded to incorporate all AI agents or AI-specific security-related features which have not been covered in the current version.
For how long have I used the solution?
I have been working in my current field for more than fifteen years.
I have been using Safeguard by One Identity for more than five years.
What do I think about the stability of the solution?
In terms of Safeguard by One Identity's reliability, I believe it is fine, and we do not see any major problems with it.
What do I think about the scalability of the solution?
Since switching to this newer version, it improved compliance, the onboarding time reduced significantly, and it supports API calls and automation processes, so overall onboarding time has been significantly reduced.
What other advice do I have?
I would advise others looking into using Safeguard by One Identity to consider it if they are looking for a budget-friendly option, easy installation, and quick setup; however, if companies require many custom solutions and support for legacy environments, it might not be a good fit, and they may need to explore other options. If any environment is trying to work with newer tools or AI-specific protections, this tool is probably not evolved to that level, so I believe you need to assess your requirements first. I would rate this product a 7.5 out of 10.
Centralized vaulting has improved privileged access security and simplifies audit readiness
What is our primary use case?
When a new system administrator needs to access a production server, instead of sharing the administrator password, they request access through Safeguard by One Identity , which securely provides the credentials or starts a monitored session, logging all activity. This has helped our team improve security, simplify audits, and ensure privileged passwords are never shared directly.
Safeguard by One Identity has become an important part of our privileged access workflow by enforcing security policies, reducing the risk of unauthorized access, and maintaining a compliance audit trail . It has made managing privileged accounts more secure and efficient for our IT team.
How has it helped my organization?
Before Safeguard by One Identity, privileged passwords were managed manually, which increased the risk of passwords being shared. Now, administrators access systems through the password vault, and passwords are rotated automatically, reducing manual effort, strengthening security, and making audits much easier since all privileged access and user sessions are logged and can be reviewed whenever needed.
We do not have exact metrics, but we have definitely seen an improvement since using Safeguard by One Identity, as password management is much faster without the need for administrators to manually share or update privileged credentials. Security has improved through automated password rotation and controlled access, while audit preparation takes much less time because all privileged sessions and access records are available in one place.
What is most valuable?
Safeguard by One Identity's password vaulting feature keeps privileged passwords in a secure, encrypted vault, so administrators do not need to know or share the actual credentials, allowing team members to request access when needed and automatically rotate the password after use. This reduces the risk of password leaks, improves automation, and saves time since we do not have to manually manage privileged credentials.
Another feature I appreciate from Safeguard by One Identity is the session recording and auditing, which provides a complete record of privileged activity, very helpful for troubleshooting, security investigations, and compliance audits. Safeguard by One Identity's centralized management interface also makes it easier to manage privileged accounts across different systems from a single place.
What needs improvement?
Another improvement would be having more detailed documentation and step-by-step deployment guides, particularly for complex environments. Better performance on large-scale deployments, enhanced search and filtering in audit logs, and more flexible notification and approval workflows would also improve the overall experience, making administration simpler and reducing the learning curve.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
How was the initial setup?
What about the implementation team?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
This rating of 9 out of 10 reflects that it offers strong privileged access management with features such as secure password vaulting, session monitoring, and auditing. Safeguard by One Identity is not rated a 10 because the initial deployment can be complex, and the user interface and reporting could be more intuitive.
From what I have seen, Safeguard by One Identity's governance and security are strong overall, with role-based access control and detailed audit trails. If the AI features follow the same security model, I expect them to provide a good level of governance and protection.
We have not used the AI capabilities enough to fairly evaluate their accuracy or reliability, so I cannot comment from first-hand experience, especially since most of our users focus on privileged access management, password vaulting, and session monitoring rather than AI features.
Overall feedback from users regarding Safeguard by One Identity's usability and functionality has been positive, with users appreciating that privileged access is centralized and secure, as well as not having to manage or remember privileged passwords. Administrators find Safeguard by One Identity's audit and session recording features especially useful. Safeguard by One Identity's main feedback has been that the interface can take some time to learn and that some administrative tasks could be more intuitive.
I advise others looking into using Safeguard by One Identity to spend time planning the deployment and defining privileged access policies before implementation. Involving the security and infrastructure teams early to start with a small pilot before rolling it out across the organization is important. Providing basic training to administrators and end-users is also essential to ensure smooth adoption. When configured properly, Safeguard by One Identity is a strong solution for improving privileged access security and simplifying compliance.