“I would recommend One Identity Active Roles based on its ability to manage domains from a single interface and provide minimal required access based on work requirements.”
"One Identity Active Roles helps us keep accounts consistent. For instance, when somebody leaves the company, all associated accounts get removed, which helps us eliminate unwanted accounts.
For Active Directory, the provisioning and de-provisioning capabilities work exceptionally. The de-provision feature allows account disconnection without disabling it, enabling quick reconnection with automatic group additions. This feature significantly speeds up the process compared to disabling and re-adding to groups.
The comprehensive group membership management feature is exceptional because it offers two features not available in Active Directory directly: adding multiple secondary owners and dynamic groups. The latter is only available for Azure AD, not for on-premise AD.
The best features of One Identity Active Roles include managing multiple domains from a single interface. I don't need to log into jump servers, making it very easy to log in from the web and manage it. Dynamic groups are also one of the best features, eliminating the need to add or manage members manually. The management unit is another excellent feature, which we can use as a virtual OU to identify missing elements."
LSEG uses Active Roles to view ad protect all oftheir AD domains from a single console, dramatically simplifying identity management. With Active Roles they identified and cleaned up their privileged accounts and used automation to evaluate and optimizetheir environment. Active Roles enabled LSEG to reduce their attack surface, improve identity security and streamline directory management.