Safeguard for Privileged Sessions
Centralized controls have strengthened privileged access and simplified compliant auditing
What is our primary use case?
My main use case for Safeguard by One Identity is to manage a secure privileged account and access a critical system. It helps us to control who can access sensitive resources and monitor privileged sessions, and also reduce the risk of unauthorized access. We mainly improve the security that maintains better control over privileged access across our environment.
A typical example of how I use Safeguard by One Identity to manage privileged accounts or access critical systems is when an administrator needs access to a critical server or application. Instead of giving them permanent privileged credentials, I can use Safeguard to control and manage the access. The user gets the required access for a specific period and the activity can be monitored and recorded. This gives us better control over privileged accounts and also provides an audit trail if we need to review the activity later.
Another important use case I have is managing access from different administrators and making sure that it has only the level of privilege necessary through actual need. Safeguard by One Identity helps us to centralize privileged account management and monitor our activity to maintain proper control over sensitive systems. This is especially useful for compliance and auditing, as we can have a clear record for privileged access and activities.
How has it helped my organization?
Safeguard by One Identity has had a positive impact on my organization by giving us better control and visibility over privileged access. It helps to reduce the risk of unauthorized access and makes it easier to monitor administrator activity. It has also improved our auditing process because we have a clear record of privileged sessions and access. Overall, it makes managing sensitive accounts more secure, which benefits our team.
While we have not measured a specific financial saving or percentage improvement, we have seen clear effective benefits. The centralized management and privileged account processes save time for our security team, especially when reviewing access or investigating administrator activities. The session recording and audit trails make compliance reviews easier because we can quickly provide evidence of who accessed which system and what they did. Overall, it has reduced manual efforts and improved our control over privileged access.
What is most valuable?
The features I find most useful in Safeguard by One Identity are privileged account management, session monitoring and recording, and rules for access control. I also appreciate the ability to manage privileged credentials, centralize and provide control, time-limited access, and auditing and reporting for compliance, as well as the capacity to provide better visibility into access and the actions performed.
The session monitoring and recording feature gives my team better visibility into when administrators access critical systems. If there is any unusual activity or error, we can review the session to understand exactly what happened. It also helps with audits because we have a clear record of privileged activity. In daily operations, it provides us with more control and confidence when managing sensitive systems.
One thing I would highlight is that Safeguard by One Identity is not just about managing privileged passwords. The session monitoring, access control, and auditing features are equally valuable.
What needs improvement?
I think Safeguard by One Identity could be improved by making the user interface a little simpler and more intuitive, especially for new administrators. Some configurations and advanced features take time to understand, and better reporting customization along with more automation around routine access management would also be useful. Additionally, these changes would make day-to-day management easier while enhancing the core security capabilities.
I think better interaction with other security identification management tools would make the experience smoother and save valuable time with more guidance, workflow, and clear documentation for complex configurations. A more customizable dashboard and various reporting options would save additional time for our security team. Overall, these improvements would make an already useful solution easier to manage.
For how long have I used the solution?
I have been using Safeguard by One Identity for the last two years.
What do I think about the stability of the solution?
Safeguard by One Identity is stable. I would say that Safeguard by One Identity is very stable based on my experience. It has been reliable for managing privileged accounts and controlling access to critical systems. We have not faced any major stability or scalability issues, and it performs consistently in our organization.
How are customer service and support?
Customer support has been good overall. The support team is responsive, valuable, knowledgeable, and especially helpful in configuration and troubleshooting. For example, resolving complex issues can take longer if there are ongoing cases, but overall, it has been a positive experience with our support team.
Which solution did I use previously and why did I switch?
We were using a different access management solution before switching to Safeguard by One Identity. We decided to switch because we needed stronger centralized control, better session monitoring, and more robust privileged account management. Safeguard by One Identity also offers better visibility into historical activity and fits our security requirements more closely, so we felt it was a better solution overall for our environment.
How was the initial setup?
The deployment of Safeguard by One Identity took around two to three weeks in our environment.
The deployment was not very disruptive for privileged users. There were some initial adjustments because they had to follow new access and approval processes, but the impact was minimal. In fact, having controlled access and a clear approval process made privileged access more secure without significantly affecting our day-to-day work.
What was our ROI?
We have seen a positive return on investment, mainly through time savings and improved efficiency rather than reducing headcount. Safeguard by One Identity has reduced the amount of manual work involved in managing privileged accounts, access approvals, and audit reviews. For example, tasks that previously took several hours of manual coordination can now be handled much faster through centralized control and automation. I don't have specific financial saving figures, but it has reduced administrative efforts and provided strong security control offering good value for us.
What's my experience with pricing, setup cost, and licensing?
Our experience with the pricing and licensing was generally positive. The initial setup costs were reasonable considering the security and access control benefits we are getting. The licensing model was straightforward, although understanding the different options and requirements took some time during the evaluation. Overall, we felt the cost was justified by the value that Safeguard by One Identity provides in managing privileged access security.
Which other solutions did I evaluate?
We evaluated a few PAM solutions before selecting Safeguard by One Identity. The main options we considered were CyberArk and BeyondTrust. We compared them based on privileged access management, session control, integration capabilities, and overall cost. Safeguard by One Identity offers a good balance of features and fits well in our existing environment, which was the main reason we chose it.
What other advice do I have?
I would recommend Safeguard by One Identity to organizations that need stronger control and visibility for privileged access. My advice would be to clearly identify previous account and access requirements before deploying and to plan the integration properly. Initially configuring it can take some time, but once set up, it significantly improves security, monitoring, and compliance. I would also recommend spending some time training administrators so they can fully utilize the platform.
We use the cloud assistant feature. It provides an extra layer of security for critical privileged passwords and helps us maintain better control over access. At the same time, the approval process remains straightforward and does not add significant delays to day-to-day operations. Overall, it gives us better security without complicating the access process unnecessarily.
We have integrated Safeguard by One Identity with various parts of our business, mainly our identity and access management infrastructure. This helps us centralize privileged access and apply the same security controls across different systems. We also use it for our cloud and server environments.
The integration with our identity and access management provider and cloud server environments was relatively straightforward overall. There was some initial configuration and testing required, especially around connecting with our identity management and cloud environments. Once the integration was set up, day-to-day management became much easier. The documentation and support were helpful during the setup, although some of the more advanced configurations took a little extra effort.
From a security perspective, I think the AI capabilities need a strong control over access, data handling, and monitoring. In my experience, I am comfortable using AI as support for security operations, but I would still prefer to keep human review for important privileged access decisions. Overall, I would say the governance and security approach is good, provided AI security is properly configured and monitored.
I would say the AI output is generally accurate and useful for supporting security operations. It can help identify patterns and provide useful insights, but I still validate results before making important security or privileged decisions. I regard AI as a useful support tool rather than something to rely on completely without human review.
Overall, I have had a positive experience with Safeguard by One Identity. The biggest benefit for us is strong control over privileged access, along with session monitoring and auditing capabilities. It has helped improve security and streamline privileged account management. There are still areas that could improve, such as the user interface and advanced configurations, but I find the overall solution relevant and effective. I would rate this review a 9 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Privileged access has been secured and daily audits now run with automated workflows
What is our primary use case?
I have been using Safeguard by One Identity for a couple of years now. My main use case for Safeguard by One Identity is managing and securing privileged access across the organization, which includes password vaulting, session management, and controlling access to critical systems.
A specific example of how I use it day-to-day involves session monitoring, recording, audits, and password rotation, as all those things help manage and secure access.
How has it helped my organization?
Safeguard by One Identity has positively impacted my organization as it automated the solution, making the process smoother, cheaper, and reliable. I believe it has reduced the time spent on the process by 20%, and it also reduced costs.
What is most valuable?
The best features Safeguard by One Identity offers include privileged access, privileged password management, session monitoring and recording, alerting feature, password vaulting, session recording, and automated access workflow.
The automated access workflow saves time, makes the process automated, and reduces risk and defects for my team day-to-day.
What needs improvement?
Improving usability and simplifying configuration would be beneficial to enhance Safeguard by One Identity.
For how long have I used the solution?
I have been working in my current field for over 15 years.
What do I think about the stability of the solution?
Safeguard by One Identity is a stable solution overall.
What do I think about the scalability of the solution?
Safeguard by One Identity's scalability is strong as it scales well in the enterprise environment, allowing systems to scale beyond the limit of one application, with the ability to add multiple nodes for password management.
How are customer service and support?
The customer support for Safeguard by One Identity is quite positive, offering good documentation and reliable response times with consistent support. I would rate the customer support an eight on a scale of one to ten.
Which solution did I use previously and why did I switch?
I have not previously used a different solution.
How was the initial setup?
The deployment of the solution took about eight weeks. The deployment was a smooth process with a short learning curve for our privileged users. Very small to moderate training was required to start using the solution as a short walkthrough and quick documentation check was enough to understand and begin using it.
What about the implementation team?
We have not integrated Safeguard by One Identity with any other parts of our business yet, but it is something we would be looking at in the future.
What was our ROI?
I have seen a return on investment as it saved approximately 25% of the manual effort that was required before and also saved about 15 to 20% of the cost of implementation.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is mostly positive as I find it quite cost-effective and it has a good licensing structure.
Which other solutions did I evaluate?
Before choosing Safeguard by One Identity, I evaluated other options such as CyberArk and BeyondTrust, but Safeguard by One Identity clearly stands out among them.
What other advice do I have?
My advice for others looking into using Safeguard by One Identity is to have a planned plan before implementation, identify what your systems are and the privileged accounts, and prioritize those needs, along with getting all the approvals for session policies, password rotation, approval workflows, and session monitoring.
I would rate this review a nine on a scale of one to ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Privileged access has become more controlled while support and web integration still need improvement
What is our primary use case?
My main use case for Safeguard by One Identity involves the management of domain privileged accounts, therefore integrations with Active Directory, specifically for applying these to Windows and Linux servers, where RDP and SSH sessions are monitored, along with password management via the SPP module of Safeguard. Recordings are carried out through SPS, and so far it has never happened that we had to implement restrictive policies that customized the standard connection policy.
In addition, we have also implemented SPS with the SIEM for sending reports and monitoring functionalities, as well as security alerts and notifications. We have also implemented access via OAuth 2.0 for SPP access and, on some occasions, have implemented web applications through the insertion of an RDP application on a server.
A specific example of a project where Safeguard by One Identity played a central role is when there was no management of privileged accounts and access occurred without monitoring, resulting in direct access to critical systems. The customer requested the implementation of Safeguard by One Identity to resolve this situation, so we implemented both modules, SPP and SPS, importing the entire pool of privileged accounts needing maintenance, which included password management.
We also included all the most critical targets requiring SPS to record all activities performed on the machine. We added all the users needing access to these targets with these accounts and configured the various entitlements, allowing for much cleaner and more controlled governance of privileged accounts.
So far, all cases have been fairly simple and have been fully covered. There was one instance where a customer needed to integrate the SIEM not via the standard connection provided by One Identity but requested integration via APIs, which are not yet currently available. On the other hand, we encountered some critical situations regarding web applications, which were handled by customizing the script using AutoIt. It would be beneficial if One Identity implemented web application management more similarly to how CyberArk does.
What is most valuable?
In my experience, the best features offered by Safeguard by One Identity are quite basic for a PAM product, though there are certainly aspects that can be improved. For example, making RDP application integration a more integral part of the product would help, as it currently requires fairly heavy customizations done externally to Safeguard. Overall, all the basic functionalities are there.
The main positive aspect of Safeguard by One Identity is that privileged account management is delegated to SPP, making it much more difficult for credential thefts to succeed. If they did occur, SPP would neutralize all the efforts made to retrieve the passwords within a day since passwords are rotated daily, for example. Moreover, undesired access is reduced to a minimum because it would be reported immediately, allowing for the reconstruction of events thanks to the recordings made by SPS.
Safeguard by One Identity has had a positive impact on my organization and my clients' projects, as several customers ended up satisfied after implementation and continued to use the product. There have never been any complaints, which indicates that the customer's needs were effectively addressed.
What needs improvement?
Based on my experience, Safeguard by One Identity could be improved by having stronger integration, perhaps starting with the ability to add API connections for the SIEM. It would also be beneficial to have a stronger implementation of RDP applications for web applications. Adding more supported platforms or updating the list could be helpful.
Regarding features and usability, we had a customer who needed to implement AS/400 systems, which were not supported. We attempted to establish privileged connections, but it was not possible, even after requesting support from One Identity, who were unable to solve the situation. It might be appropriate to either remove AS/400 from the supported platforms or address this issue.
For how long have I used the solution?
I have been using Safeguard by One Identity since 2021, starting with theoretical courses provided by One Identity, during which I spent three months studying the product. Starting from February 2022, I began implementing the solutions for various customers who needed a PAM solution.
What do I think about the stability of the solution?
Based on my experience, Safeguard by One Identity is quite stable. We have never encountered issues.
What do I think about the scalability of the solution?
Safeguard by One Identity excels in terms of scalability. From that standpoint, it is very scalable and quite easy to increase the numbers, always within license constraints. No issues were encountered during expansion of Safeguard by One Identity. If any slowdowns arose, we addressed them by increasing the appliance's resources.
How are customer service and support?
Unfortunately, my experience with Safeguard by One Identity's customer support is not very positive. They tend to respond slowly, generally do not find solutions effectively, and it is challenging to request calls that could resolve issues more quickly. From this perspective, support could improve significantly. Customer support is not very active, not very fast, nor efficient, which indicates they should work on enhancing efficiency.
Which solution did I use previously and why did I switch?
Before choosing Safeguard by One Identity, I had used CyberArk, which I must say is a bit more complete and more user-oriented, especially concerning support.
How was the initial setup?
I implemented Safeguard by One Identity in both ways. There are customers who wanted an on-demand solution, which we integrated without any issues, and then there are customers who preferred on-premise installations, where we downloaded the required ISOs, installed them on virtual machines, configured the appliances, and set up the clusters independently.
Generally, it takes about five to six months to achieve full operability with all systems active, though this timeframe is mainly due to delays on the customer side.
In terms of the deployment's effect on privileged users, the transition was quite smooth. No one complained about the change, as the management process did not change much. Instead of going directly through SSH and RDP clients, they simply had to use the interface with the connection package already prepared.
The amount of training needed to start using Safeguard by One Identity amounts to a couple of weeks for both those who manage it and end users.
What about the implementation team?
The company I work for is a One Identity partner.
What was our ROI?
I do not know if a return on investment has been obtained with Safeguard by One Identity, as I only deal with implementation. I imagine customers have seen improvements in security, but I am unaware of cost savings.
Which other solutions did I evaluate?
Before selecting Safeguard by One Identity, we typically evaluate CyberArk or Delinea as the main solutions to consider. This was the first PAM solution used by these customers, as it was the first option and the initial solution.
What other advice do I have?
Safeguard by One Identity has had a positive impact on my organization and my clients' projects, as several customers ended up satisfied after implementation and continued to use the product. There have never been any complaints, which indicates that the customer's needs were effectively addressed.
My advice to others considering using Safeguard by One Identity is that if you are looking for a product that handles the basics at a fairly low price, then it is appropriate for your needs. However, if you are looking for a product that allows for a lot of customization, perhaps it is not the most suitable choice. I would rate this product a seven out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized vaulting has secured privileged access and simplifies automated credential rotation
What is our primary use case?
I have been working with Safeguard by One Identity platform for the last one year, which is the PAM solution. We are using it as a Privileged Access Management solution as a point of security, as the first point of security towards managing PAM and PIM. We use it for securely managing privileged credentials, controlling administration access, and monitoring privileged sessions. We also monitor the vaults for compliance of the logs, which have been forwarded to our SIEM platform for further security controls and monitoring.
We use it for our privileged sessions, which has been acting as a centralized password vaulting and automated credential rotation platform. The automated credential rotation feature is the best feature I have used, and I have never seen it in different products as of now.
The onboarding was seamless. We have onboarded approximately 500 to 1000 users to the PIM. Certain users have certain accesses that need to be limited over specific time frames and as per their administrative requirements. This has been managed through that platform, and we have not observed any kind of issues.
Secure Remote Access feature is for our hybrid and remote employees, safeguarding our environment from external threat actors and preventing attackers from trying to access our network by using this Remote Access Privileged Access feature.
The integration was quite easy. We have FortiGate and FortiClient VPN in place, and it has been a seamless integration with this platform, enabling us to get access to the Remote Access feature over OneLogin. We are now managing and getting access to our critical systems by using the jump host available with this feature.
This integration has improved our enhanced security. It has been acting as a centralized vault which reduces our risk of credential theft, misuse of credentials, and prevents compromised hosts and privileged accesses to our critical hosts through this integration.
I would rate this at eight.
What is most valuable?
The features I find most valuable are the password vaulting and the auto-rotation features like password security complexities and the OWASP Top 10 vulnerabilities. It is suggested to rotate the password into certain time frames which are recommended by the security team, and this has been performed by using this application. We have been monitoring session monitoring via the SIEM tool. These logs have been forwarded there. MFA integration is also available, which has been helped by One Identity. We have managed OneLogin and One Identity implementations into our organization, and these real-time privilege alerts and vault alerts are being monitored. These are quite valuable things for us.
The features I liked the most about Safeguard by One Identity are the password vaulting and the automatic password rotation feature. MFA integration with the OneLogin platform was seamless as the organization is the same for them. Detailed audit logs are also available while clearing our audits. While troubleshooting, we need those audit logs, which have been forwarded over the SIEM, with reports sent to the admin team to get those reviewed if there are any certain changes made by the team which are not known to them.
Privileged users and systems are getting protected by using these solutions, and all privileged users access this portal with their credentials quite easily. It has been eliminating their overhead to manage this manually or access manually. Admin overhead gets reduced due to it, and the overall efforts are reduced.
There were no negatives observed. All observations were positives like the self-service access granted to users. Users can request privileged access to the portal, reducing dependencies on administration for every request. Built-in approval workflows are also available, so all these efforts have been reduced from manual ones.
What needs improvement?
I would like to highlight a couple of points, which are UI modernization. In the new world of AI, we are thinking about how AI can be helpful for detection capabilities in PAM solutions and easier reporting flexibility. There should be a chatbot feature in Safeguard by One Identity so we can easily find out the SOPs and documentations. By using chatbots, we can directly ask queries to them, and they can respond with the solution or steps.
The chatbot is the only suggestion I have as of now.
What do I think about the stability of the solution?
I have not observed any stability issues.
What do I think about the scalability of the solution?
As of now, we have implemented it for more than 250 users, and there have been no issues observed. It has been scalable.
How are customer service and support?
The setup was quite simple and easy for us, with help from the support team, which has been quite helpful for us in implementing this feature.
The vendor support was with us during the implementation phase. They helped us with the initial implementation and all of the documentations.
For end users, we have rolled out SOPs on how to manage and access the tools which are in the environment and critical servers. The SOPs have been built for that. For management, training sessions have been introduced by this vendor like OneLogin.
The team was there to support us in terms of integrations.
Which solution did I use previously and why did I switch?
This is our first PAM solution.
How was the initial setup?
The setup was quite simple and easy for us, and getting help from the support team, which has been quite helpful for us in implementing this feature.
Regarding the setup, it was quite easy and intuitive for us to get to know how we can onboard it. All the SOPs and the documentations are available on their portal, so it was easy.
What about the implementation team?
The vendor support was with us during the implementation phase. They helped us with the initial implementation and all of the documentations.
This has been integrated with our SIEM platform, which is the central monitoring platform for the SOC environment for cybersecurity. The team has built certain use cases related to the threat environment for abnormality detection, unusual logins, and false logins. Such use cases have been built into the SIEM platform. This is the external integration.
The integration into the SIEM platform was supported by the syslog method, which has forwarded these logs. It was supported so that all of these details have been transferred to the SIEM easily, and all the fields and logs have been mapped as per the supported mechanism.
What was our ROI?
It took approximately three months to go into production.
Which other solutions did I evaluate?
I was not part of the admin team evaluating alternate solutions, so I am unable to answer this question. I am the user of this product as of the date.
What other advice do I have?
Regarding the usability and functionality, the UI is quite intuitive and simple to handle for new users. Whenever new users are getting access to it, with the help of the documentations which are cleaner in format and easy to access, all of the things are in place with the help of the initial dashboards. We get to know what all of the functionalities are there.
While considering Safeguard by One Identity, customers can do the POCs if they want to, but however, in terms of feature-wise, it is a good product to have. It has all of the features required for a PAM solution. I rate this solution at eight out of ten.
Privileged access has become streamlined while cloud and legacy support still need improvement
What is our primary use case?
My main use case for Safeguard by One Identity is privileged identity access management, session monitoring, and password management.
In my day-to-day work, we onboard the most powerful accounts and privileged accounts across the applications, platforms, and network elements into the PAM system, which is Safeguard by One Identity, and it has the inbuilt capability that supports session management, password management, and analytics.
What is most valuable?
Safeguard by One Identity offers simple web GUI, easy onboarding and management, and less complex architecture as its best features.
The web GUI and easy onboarding help my team because even less trained people can easily navigate it, and trained individuals can start using the tool easily without requiring any development or additional skills; it is easy to navigate and work on.
Safeguard by One Identity has positively impacted my organization, as in the past, we were using TPAM, the older product from the same vendor of the Fab solution, but this is a new version, a new generation tool which supports most of the new version products and new protocols, and it works well.
What needs improvement?
Safeguard by One Identity has been built most of the time to support the most recent products and versions in the environment, but sometimes in real-time scenarios, companies might be running with legacy systems or applications; during that time, you might need to build a custom solution that is not flexible enough, and I think additional efforts are needed to build solutions to support legacy systems.
I chose a rating of seven because I believe the product still has improvements that need to be made in terms of supportability for new applications, such as SaaS solutions, and it does not have any native method of managing cloud-based applications, which I believe is an area to improve.
Regarding Safeguard by One Identity's AI capabilities, I do not believe it has really good governance and security; I think it probably needs to be upgraded to incorporate all AI agents or AI-specific security-related features which have not been covered in the current version.
For how long have I used the solution?
I have been working in my current field for more than fifteen years.
I have been using Safeguard by One Identity for more than five years.
What do I think about the stability of the solution?
In terms of Safeguard by One Identity's reliability, I believe it is fine, and we do not see any major problems with it.
What do I think about the scalability of the solution?
Since switching to this newer version, it improved compliance, the onboarding time reduced significantly, and it supports API calls and automation processes, so overall onboarding time has been significantly reduced.
What other advice do I have?
I would advise others looking into using Safeguard by One Identity to consider it if they are looking for a budget-friendly option, easy installation, and quick setup; however, if companies require many custom solutions and support for legacy environments, it might not be a good fit, and they may need to explore other options. If any environment is trying to work with newer tools or AI-specific protections, this tool is probably not evolved to that level, so I believe you need to assess your requirements first. I would rate this product a 7.5 out of 10.
Centralized vaulting has improved privileged access security and simplifies audit readiness
What is our primary use case?
When a new system administrator needs to access a production server, instead of sharing the administrator password, they request access through Safeguard by One Identity, which securely provides the credentials or starts a monitored session, logging all activity. This has helped our team improve security, simplify audits, and ensure privileged passwords are never shared directly.
Safeguard by One Identity has become an important part of our privileged access workflow by enforcing security policies, reducing the risk of unauthorized access, and maintaining a compliance audit trail. It has made managing privileged accounts more secure and efficient for our IT team.
How has it helped my organization?
Before Safeguard by One Identity, privileged passwords were managed manually, which increased the risk of passwords being shared. Now, administrators access systems through the password vault, and passwords are rotated automatically, reducing manual effort, strengthening security, and making audits much easier since all privileged access and user sessions are logged and can be reviewed whenever needed.
We do not have exact metrics, but we have definitely seen an improvement since using Safeguard by One Identity, as password management is much faster without the need for administrators to manually share or update privileged credentials. Security has improved through automated password rotation and controlled access, while audit preparation takes much less time because all privileged sessions and access records are available in one place.
What is most valuable?
Safeguard by One Identity's password vaulting feature keeps privileged passwords in a secure, encrypted vault, so administrators do not need to know or share the actual credentials, allowing team members to request access when needed and automatically rotate the password after use. This reduces the risk of password leaks, improves automation, and saves time since we do not have to manually manage privileged credentials.
Another feature I appreciate from Safeguard by One Identity is the session recording and auditing, which provides a complete record of privileged activity, very helpful for troubleshooting, security investigations, and compliance audits. Safeguard by One Identity's centralized management interface also makes it easier to manage privileged accounts across different systems from a single place.
What needs improvement?
Another improvement would be having more detailed documentation and step-by-step deployment guides, particularly for complex environments. Better performance on large-scale deployments, enhanced search and filtering in audit logs, and more flexible notification and approval workflows would also improve the overall experience, making administration simpler and reducing the learning curve.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
How was the initial setup?
What about the implementation team?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
This rating of 9 out of 10 reflects that it offers strong privileged access management with features such as secure password vaulting, session monitoring, and auditing. Safeguard by One Identity is not rated a 10 because the initial deployment can be complex, and the user interface and reporting could be more intuitive.
From what I have seen, Safeguard by One Identity's governance and security are strong overall, with role-based access control and detailed audit trails. If the AI features follow the same security model, I expect them to provide a good level of governance and protection.
We have not used the AI capabilities enough to fairly evaluate their accuracy or reliability, so I cannot comment from first-hand experience, especially since most of our users focus on privileged access management, password vaulting, and session monitoring rather than AI features.
Overall feedback from users regarding Safeguard by One Identity's usability and functionality has been positive, with users appreciating that privileged access is centralized and secure, as well as not having to manage or remember privileged passwords. Administrators find Safeguard by One Identity's audit and session recording features especially useful. Safeguard by One Identity's main feedback has been that the interface can take some time to learn and that some administrative tasks could be more intuitive.
I advise others looking into using Safeguard by One Identity to spend time planning the deployment and defining privileged access policies before implementation. Involving the security and infrastructure teams early to start with a small pilot before rolling it out across the organization is important. Providing basic training to administrators and end-users is also essential to ensure smooth adoption. When configured properly, Safeguard by One Identity is a strong solution for improving privileged access security and simplifying compliance.
Privileged sessions have been secured and audits are now simplified with transparent monitoring
What is our primary use case?
Our main use case for One Identity Safeguard is privileged access management, where we need to secure control and monitor highly sensitive privileged accounts.
We use One Identity Safeguard for password storage and management for all privileged accounts, including admin accounts and service accounts. We also use it for Just-in-Time privileged access to provide the least privilege access possible for users.
What is most valuable?
One Identity Safeguard offers excellent features such as smart session auditing and forensics, transparent session proxy, password injection with no exposure, and real-time command and video blocking.
We rely most on smart session logging, smart session auditing, and forensics, which are valuable for our day-to-day tasks, along with password injection, which helps us securely pull passwords and automatically inject them into sessions, enhancing our security and aiding in auditing.
Regarding session proxy, One Identity Safeguard can sit on the network similar to a router, remaining completely transparent to both the user and the destination server while silently managing and injecting passwords and recording sessions in the background.
One Identity Safeguard has positively impacted our organization by contributing to a significant drop in compliance and audit overhead, aiding in the preparation of security audits that were previously chaotic, making the process much simpler now, and improving operational efficiency and admin satisfaction.
What needs improvement?
One Identity Safeguard could be improved by providing a unified management experience, as historically it has been split into logical units, and it would be beneficial if they could provide out-of-the-box reports and visualization, addressing the high resource overhead for privileged analytics.
Regarding One Identity Safeguard's AI capabilities, I believe they are still in the transformation phase, particularly with session monitoring, and once implemented fully, the advanced role mining and peer group analysis provided will help us improve further.
I cannot provide feedback on the accuracy and reliability of One Identity Safeguard's AI capabilities because we are not currently using the AI version; we may be deploying it next year.
For how long have I used the solution?
I have been using One Identity Safeguard for more than six years.
What do I think about the stability of the solution?
In my experience, One Identity Safeguard is stable.
What do I think about the scalability of the solution?
One Identity Safeguard's scalability works effectively in our large organization, as it successfully handles everything we need.
How are customer service and support?
The customer support for One Identity Safeguard is very good, providing timely responses based on the SLA, with high-priority tickets receiving responses within an hour. I would rate the customer support around eight.
Which solution did I use previously and why did I switch?
Before switching to One Identity Safeguard, we were using Thycotic Server, which was not as user-friendly, leading us to switch to One Identity Safeguard.
How was the initial setup?
The deployment of One Identity Safeguard was very quick, taking only one or two days.
The deployment affected our privileged users smoothly, as we transitioned from another solution where users adapted quickly due to One Identity Safeguard being user-friendly.
What about the implementation team?
We provided training for users that took approximately one week, plus one month of training for administrators, which was very helpful for getting everyone on board.
Which other solutions did I evaluate?
Before choosing One Identity Safeguard, we evaluated CyberArk, but it was more costly, which influenced our decision to consider One Identity Safeguard due to its lower cost.
What other advice do I have?
My advice for others considering One Identity Safeguard is to define the architecture early, as it will be helpful, and to consider using One Identity Manager alongside it, as they can integrate effectively. I would rate this solution an eight overall.
Centralized credential vault has strengthened secure remote access and simplified audits
What is our primary use case?
Currently, for our business case, we have multiple scenarios with One Identity Safeguard, but I haven't used the transparent mode much. The transparent mode that I am aware of is that One Identity Safeguard privileged sessions have that transparent mode where the administrator and target server allow users to continue connecting to servers exactly as they would normally, which can be useful.
This is a good feature to have.
I use the secure remote access for privileged users.
I do not use any physical appliances, virtual appliances, or on-demand versions with One Identity Safeguard. The primary business use case we have for it is secure privileged account management, including credential vaulting, enforcing password rotation, and providing secure privileged session access. These are the proper business use cases on which we implement it. It helps us reduce the risk associated with privileged credentials while supporting compliance and security monitoring.
This is how we utilize it.
What is most valuable?
The best features of One Identity Safeguard are multiple features similar to any PAM solution that we use for our security purposes. The strongest feature of One Identity Safeguard is a centralized privileged credential vault, which eliminates the need for administrators to know or manually manage privileged passwords. The automated password rotation and secure checkout process significantly reduce credential exposure.
This is the best aspect that I have experienced, along with another feature that is session management. The session recording and replay provide excellent visibility for investigation, compliance audits, and insider threat monitoring. These features are the best in One Identity Safeguard that I have seen compared to multiple other PAM solutions.
One Identity Safeguard has improved our organization from the security perspective, which is the main aspect that we have seen in it. VPN elimination and reduced credential exposure have helped us manage credentials in a more secure way. We work in a Security Operations Center, and it has helped us significantly from a SOC perspective.
What needs improvement?
One area that has room for improvement in One Identity Safeguard is native integration with newer cloud platforms and SaaS applications and security tools. We have a SOAR application in our environment, which is Cortex XSOAR, and it would be better if One Identity Safeguard could have native integration with this application so that anyone executing playbooks through the SOAR could request One Identity Safeguard access through it. This would be one improvement that we suggest regarding native integration with newer cloud platforms.
Reporting and dashboard customization with One Identity Safeguard should be better improved. While it is already present, monitoring multiple servers and technologies that we have integrated with One Identity Safeguard could be managed better if more reporting and dashboard customization options were available.
For how long have I used the solution?
I have been using the solution for one and a half years.
What do I think about the stability of the solution?
From a stability perspective, I rate One Identity Safeguard as being stable in our production environment and it performs reliably with minimal unplanned downtime. I would rate it 8 out of 10.
What do I think about the scalability of the solution?
The scalability of One Identity Safeguard is that the solution scales in the enterprise environment with multiple privileged accounts, servers, and administrators. It overall supports growth without any significant performance issues. When deployed according to best practices, I would rate it 9 out of 10.
How are customer service and support?
I use the regular support for One Identity Safeguard. I rate support from 1 to 10 overall as 9 because compared to other customer PAM solutions that we have like iRage PAM and Commvault PAM, this is superior and offers a more advanced procedure.
What other advice do I have?
I use the secure remote access for privileged users.
One Identity Safeguard provides VPN-less remote access where administrators, vendors, and third-party users can securely connect with privileged resources without using traditional VPN. This is the main advantage because having VPN connectivity between these three user types would otherwise present a vulnerability. Additionally, the clientless browser-based access allows users to connect through a web browser without installing client software, which simplifies onboarding and remote administration.
It is not important to me that secure remote access with One Identity Safeguard does not use VPN, because it already eliminates VPN-related risks for privileged users and it was very helpful. VPN usage would be a key concern when connecting in such cases, but this particular secure access eliminates VPN-related risks and provides a complete audit trail for remote administrative activities.
I compare One Identity Safeguard with other vendors based on the features that I have mentioned, such as stability and customer support, as well as scalability. This is the best product that I can recommend. It would be an excellent tool for the medium to large enterprise looking for a mature privileged access management solution. Compared to other solutions, it has a better feature set and better capabilities, which makes it a superior tool.
I am not aware of the pricing for One Identity Safeguard because I am an end user of this product. The pricing must be handled by our finance team, so I am not informed about this aspect.
The deployment of One Identity Safeguard did not disruptively affect my privileged users in any way.
I have integrated One Identity Safeguard with multiple options available, such as our Active Directory.
My experience with integration of One Identity Safeguard was not difficult. The integration with Active Directory or any enterprise infrastructure was straightforward. However, configuring the policies and onboarding privileged assets required careful planning and workflow understanding. Overall, it was straightforward and simple with no complex details.
The amount of training required to start using One Identity Safeguard is minimal. Because in our environment we have multiple PAM solutions or other integrated solutions, One Identity Safeguard was much easier in comparison.
I rate this review 9 out of 10.
Centralized session monitoring has strengthened privileged access control and simplified audits
What is our primary use case?
One Identity Safeguard is used to securely manage privileged accounts and protect administrative credentials sessions across our IT environment. It helps control access to critical systems and enforce security.
A common scenario involves system administrators who need temporary access to Windows or Linux production servers for maintenance or troubleshooting. Instead of sharing privileged passwords, they request access through One Identity Safeguard. One Identity Safeguard securely stores these credentials, grants time-limited access after approval, records the entire privileged session, and automatically revokes access once the maintenance is complete. This reduces the risk of credential exposure while maintaining security.
What is most valuable?
The best features of One Identity Safeguard are its secure password vault, automated password rotation, and privileged session monitoring. I also appreciate the approval workflow for granting temporary privileged access, which helps ensure least privilege policies. The session recording and searchable audit logs are especially useful during security reviews and compliance audits, as they provide clear visibility into who accessed critical systems, when they were accessed, and what actions were performed.
The session recording and search features are straightforward to use. Every privileged session is automatically recorded in user activity and commands, so there is no need for manual intervention. When investigating an incident or reviewing administrative actions, I can search sessions using filters such as user, target, system, date, or time range. Finding a specific session usually takes only a few minutes, and the playback feature makes it easy to see exactly what happened during the session. This has been very helpful for troubleshooting, internal audits, and compliance reviews.
What needs improvement?
One Identity Safeguard is a strong privileged access management solution, though there are a few areas in which it could be improved. The initial deployment and configuration can be complex, especially for organizations with larger hybrid environments. The user interface could be more intuitive, particularly for first-time administrators, and some reporting and dashboard customization options could be more flexible. I would also like to see broader native integration with cloud platforms and DevOps tools to simplify privileged access management across modern infrastructure.
For how long have I used the solution?
I have been using One Identity Safeguard for the last eight months.
What do I think about the stability of the solution?
One Identity Safeguard is stable.
What do I think about the scalability of the solution?
The scalability of One Identity Safeguard has been good for our environment. As more systems and privileged users have been added, expanding the deployment has been straightforward without requiring major changes to the existing setup. The virtual appliance architecture has made it easy to grow as needed, and I have not experienced any significant performance issues while onboarding additional servers or accounts. Overall, One Identity Safeguard has scaled well to meet our current requirements.
How are customer service and support?
Customer support is definitely outstanding. I would rate the customer support a ten out of ten.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
The initial deployment took almost three weeks. Most of the time was spent on planning, configuration, policies, integration with other existing directory services, testing privileged access workflows, and validating session recording before rolling it out to the administrators. Once the initial setup was complete, onboarding additional systems and users was relatively straightforward.
The deployment of One Identity Safeguard caused very little disruption to our privileged users. During the rollout, administrators had to learn the new access request and approval process, which required a short adjustment period. After that, the workflow became routine. Instead of using shared administrator passwords, users simplified the request for access through One Identity Safeguard and received time-limited access when approved. Overall, the transition was smooth, and the improved security and accountability outweighed the small learning curve.
What about the implementation team?
The administrators who manage One Identity Safeguard required approximately two to three days of training to become comfortable with the deployment, policy configuration, and ongoing administration. End-users, such as system administrators requesting privileged access, needed only a short onboarding session of around one to two hours to understand the access request processes, approval workflow, and how to start a privileged session. After the initial training, most users were able to use the solution without significant issues.
What was our ROI?
I have seen a positive return on investment from One Identity Safeguard, mainly through time savings and improved operational efficiency rather than reduced headcount. Before implementing One Identity Safeguard, collecting privileged access records for security reviews and audits was a manual process that often took several hours. With centralized audit logs and session recording, I have reduced the effort by approximately thirty to forty percent, and in many cases, I can gather the required evidence in about an hour. I also spend less time managing shared administrator passwords and investigating privileged activities because everything is centrally recorded and searchable. While I have not reduced staff, I have been able to spend more time on proactive security work instead of administrative tasks.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been overall positive. One Identity Safeguard is positioned as an enterprise product, so the licensing cost is not inexpensive, but I felt it was justified by the security features and compliance benefits it provides. The licensing process was straightforward, and there were no unexpected setup costs beyond the time required for deployment and configuration. Overall, the total cost of ownership has been reasonable for the value it delivers in securing privileged access.
Which other solutions did I evaluate?
I did not evaluate other options before choosing One Identity Safeguard.
What other advice do I have?
One Identity Safeguard has been deployed in a hybrid environment. The core privileged access management components are hosted on-premises to manage access to critical internal systems, while they also integrate with cloud-based resources. This setup gives us the flexibility to secure both traditional infrastructure and cloud workloads from a single privileged access management platform.
Microsoft Azure is primarily used for our cloud-based resources.
The virtual appliance deployment was chosen because it was easier to deploy in our existing virtualized infrastructure, required less hardware management than physical appliances, and offered the flexibility to scale as our environment grows. It also simplified backup, maintenance, and software updates while providing the same core privileged access management capabilities we needed.
Overall, the feedback from our users regarding One Identity Safeguard's usability and functionality has been positive. Administrators appreciate that they no longer need to know or share privileged passwords, and the approval workflow is straightforward once they become familiar with it. The session recording and audit features are also well-received because they make troubleshooting and compliance review much easier. The main feedback has been that the interface has a learning curve for new users, and the initial setup and policy configuration can be a bit complex. However, after onboarding, most users find the platform reliable and easy to use for their day-to-day privileged access tasks.
At this stage, One Identity Safeguard has not been integrated with DevOps pipelines, RPA platforms, or other advanced business systems. It is primarily used for privileged access management, secure credential storage, password rotation, and session monitoring for our infrastructure.
My advice for others looking into using One Identity Safeguard would be to spend enough time planning the deployment before implementation. Identify your privileged accounts, define clear access policies and approval workflows, and involve both the security and infrastructure teams early in the project. Start with a small group of critical systems to validate the configuration and user experience before expanding across the environment. Also, provide basic training for administrators and end-users so they can understand the new privileged access process. Taking this approach makes the rollout smoother and helps you get the most value from the solution. I rate this solution a ten out of ten overall.
Centralized controls have secured privileged access and improve audit readiness every day
What is our primary use case?
One Identity Safeguard is used primarily to secure privileged accounts and control administrative access to critical systems. On a day-to-day basis, it is used for password vaulting, access approval, and monitoring privileged sessions to ensure secure and compliant access management.
Password vaulting is a key function in daily operations. When a server administrator needs temporary access to a production system, they request access through One Identity Safeguard, receive approval, and the activity is logged automatically. This approach has improved security and made it significantly easier to track privileged access during audits and reviews.
How has it helped my organization?
Improved control over privileged access across the organization has been achieved. Before One Identity Safeguard, managing administrative credentials and tracking privileged activities involved more manual effort, but after implementation, access became more secure and easier to audit. It has helped reduce the risk of unauthorized access and improved the overall security and compliance posture.
What is most valuable?
The most valuable features of One Identity Safeguard are password vaulting, session monitoring, and approval-based access controls. These features help secure privileged accounts, improve visibility into administrative activities, and ensure that access to critical systems is properly controlled and audited.
Session monitoring has been particularly useful during troubleshooting and audit reviews. When a question arose about a configuration change on a critical server, the recorded session could be reviewed to quickly understand what actions were performed. The approval workflow is another significant feature, as it ensures that privileged access is granted only when needed and follows the appropriate authorization process, which strengthens governance and accountability.
Centralized password management is also greatly appreciated, as it reduces the need for administrators to know or store privileged credentials directly, which improves security and simplifies access management. One Identity Safeguard brings access control, auditing, and credential management together in a single solution, making day-to-day administration more efficient.
One Identity Safeguard has had a very positive impact on operations because it is used in daily activities. Improved control over privileged access across the organization has been achieved. Before One Identity Safeguard, managing administrative credentials and tracking privileged activities involved more manual effort, but after implementation, access became more secure and easier to audit. It has helped reduce the risk of unauthorized access and improved the overall security and compliance posture.
What needs improvement?
There is room for improvement in One Identity Safeguard in several areas. One area for improvement would be reporting and analytics. While the available reports are useful, having more customizable dashboards and deeper insights into privileged access trends would help security teams make faster decisions. A more streamlined user experience for access requests and approvals would be beneficial, especially in large environments where many privileged access requests are processed daily.
Integration and reporting flexibility represent another area where One Identity Safeguard could improve. While the existing capabilities are solid, having more out-of-the-box integrations and easier customization options would reduce administrative effort. More proactive insights around privileged access, users, and security trends would help security teams identify potential risks faster and improve overall visibility across the environment.
More proactive alerting and recommendations would be a valuable addition. Highlighting unusual privileged access patterns or providing suggestions for policy optimization would help administrators respond faster. Additional dashboard customization options would allow teams to tailor views and reports based on their specific operational and security requirements.
For how long have I used the solution?
One Identity Safeguard has been in use for one and a half years.
What do I think about the stability of the solution?
One Identity Safeguard is a stable and dependable platform. It has been used regularly for privileged access management and has performed consistently with very few issues. Most challenges were related to configuration changes or integrations rather than product stability itself.
What do I think about the scalability of the solution?
One Identity Safeguard is scalable. Additional systems, privileged accounts, and users were able to be onboarded without major changes to the platform. The centralized management approach helped keep administrative efficiency even as privileged access requirements expanded.
How are customer service and support?
Customer support for One Identity Safeguard is good.
Which solution did I use previously and why did I switch?
A different solution was used previously. Native administrative tools and manual processes were primarily relied upon for managing privileged accounts and credentials. The switch to One Identity Safeguard was made because stronger security controls, centralized credential management, better auditing, and more visibility into privileged access activities across the environment were needed.
How was the initial setup?
The deployment of One Identity Safeguard took approximately two to three months from initial planning to full production rollout. Most of the time was spent on requirements gathering, onboarding critical systems, configuring access policies, and testing workflows. The actual installation was relatively quick, but proper planning and validation were important for a successful deployment.
What about the implementation team?
The integration of One Identity Safeguard with existing systems was fairly straightforward. Since established identity and infrastructure systems were already in place, connecting One Identity Safeguard to those environments was not particularly difficult. The main effort was around planning access policies, onboarding privileged accounts, and testing workflows. Once configured, the integration worked smoothly and provided a more centralized approach to privileged access management.
What was our ROI?
A return on investment is evident with One Identity Safeguard. A specific benefit has been the reduction in time spent managing privileged credentials and access requests. Before One Identity Safeguard, access approvals and credential management involved more manual coordination. After implementation, this process became centralized and automated, which reduced administrative efforts and improved response times. While headcount was not reduced, the team spent less time on routine access management tasks and more time on security and operational improvements.
What's my experience with pricing, setup cost, and licensing?
Pricing for One Identity Safeguard is at an enterprise level. There is an investment involved, but the security, auditing, and privileged access management capabilities justify the cost. From a setup perspective, the deployment was manageable. Most of the effort was spent on planning access policies, onboarding systems, and configuring workflows rather than the installation itself.
Which other solutions did I evaluate?
Different options were evaluated before selecting One Identity Safeguard. PAM solutions, including CyberArk Privilege Access Manager and BeyondTrust Privileged Remote Access, were considered. One Identity Safeguard was selected because it offered a good combination of privileged access controls, password vaulting, auditing capabilities, and ease of administration that matched the requirements.
What other advice do I have?
One Identity Safeguard provides many helpful benefits. Improved visibility into privileged activities has been achieved, and having a centralized platform for managing access requests, credentials, and session records has made administration more organized and reduced the amount of manual tracking required by the team. It has also helped follow security and compliance requirements more consistently.
For organizations looking into using One Identity Safeguard, the recommendation is to start by clearly defining privileged access policies and identifying the most critical accounts and systems. This makes the implementation process much smoother. Starting with a smaller deployment, validating workflows and access controls, and then expanding gradually is also recommended. This helps users adapt to the platform while allowing the team to realize value quickly.
The deployment of One Identity Safeguard had minimal disruption for privileged users because the solution was introduced in phases. There was a short adjustment period while users became familiar with the new access request and approval process. After the initial onboarding, most users appreciated the centralized access management and improved security controls. Overall, the transition was smooth and did not significantly impact day-to-day operations. The review rating for One Identity Safeguard is eight out of ten.