# one-identity

Source: https://startwithidentity.com/vendors/iga/one-identity/
Last updated: 2026-09-20
License: content by Start with Identity. Cite the source URL.

---

## Overview

One Identity offers a broad identity governance ([IGA](https://startwithidentity.com/guides/fundamentals/what-is-iga/)) portfolio spanning Identity Manager for governance and provisioning, Safeguard for privileged access, Active Roles for Active Directory management, and OneLogin for workforce access. Its position is built on breadth: covering several identity disciplines under one vendor rather than excelling at a single one. It reports more than 7,500 customers managing over 125 million identities as of May 2025.

The structural picture is changing. On 24 June 2026 One Identity [announced it will become an independent company](https://natlawreview.com/press-releases/one-identity-become-independent-company-new-global-hq-cork-ireland) with a new global headquarters in Cork, Ireland, under CEO Praerit Garg, with over 80 percent of engineering based in Europe. The separation was described as progressing through 2026 and we could not confirm it has closed. Post-separation ownership has not been disclosed: no investor, valuation, or deal structure has been published. Parent Quest Software still described itself as Clearlake-backed in September 2026, in a release that did not mention One Identity at all. Buyers signing multi-year deals should ask where the contract lands.

## What it is good at

Provisioning and lifecycle depth are genuine strengths, with mature role management, certification, and connector coverage suited to complex enterprises. The real advantage is consolidation: governance, [PAM](https://startwithidentity.com/vendors/pam/one-identity-safeguard/), and AD management from one vendor give a unified story for procurement and audit, and the Microsoft and Active Directory integration is deep, which fits the many enterprises still anchored on AD. Development is active across the line, with Identity Manager shipping 9.x and Cloud PAM Essentials offering SaaS privileged access with no appliance. Identity Manager 8.1 achieved NIAP Common Criteria certification in April 2020, a credential few IGA vendors hold, though it applies to a version six releases behind current.

## Where it falls short

The breadth comes at the cost of modern polish. Cloud-native organisations expecting the interface quality of newer governance tools often find the experience dated, and deployments can be heavy. Teams wanting a single best-of-breed governance product rather than a suite will find more focused depth elsewhere.

Two practical cautions. Safeguard for Privileged Passwords carried CVE-2024-45488, a CVSS 9.8 unauthorized-access flaw, though it affects virtual appliance installations only and no One Identity CVE appears in the CISA KEV catalog. And the ownership transition above adds genuine procurement uncertainty that competitors do not carry right now.

## Pricing

Quote-based with nothing published, even on AWS Marketplace where Safeguard directs buyers to a separate billing relationship. One reseller SKU suggests Cloud PAM Essentials licenses per managed identity user rather than per managed account. Model the all-in cost with the [TCO calculator](https://startwithidentity.com/tools/tco-calculator/).

## Best for, and who should look elsewhere

Choose One Identity when unifying IGA, PAM, and AD management under one vendor in a Microsoft-heavy enterprise is the goal, and you are comfortable with the pending separation. For the category leaders, compare [SailPoint vs Saviynt](https://startwithidentity.com/compare/sailpoint-vs-saviynt/); for modern cloud-first governance, see [ConductorOne](https://startwithidentity.com/vendors/iga/conductorone/) and [Lumos](https://startwithidentity.com/vendors/iga/lumos/); for access visibility, see [Veza](https://startwithidentity.com/vendors/iga/veza/).

## Bottom line

A broad, consolidation-friendly governance suite strongest for Microsoft-heavy enterprises wanting IGA, PAM, and AD management from one vendor, now carrying the added question of who will own it.
