Identity Governance and Administration (IGA) unifies identity provisioning and access governance to manage end-to-end identity lifecycle processes, entitlements, workflows, policies, roles, access certification, segregation-of-duties (SoD) analysis, reporting, and access intelligence. Identity provisioning handles access fulfillment and entitlement administration across the lifecycle, while access governance equips the business—often via self-service—to manage workflows, run reports, execute certification campaigns, and perform SoD checks. An emerging access intelligence layer adds analytics and machine learning-driven pattern recognition for process optimization, role design, automated reviews, and anomaly detection. Weak IGA foundations increase exposure to risks such as identity theft, unauthorized changes, access creep, role bloat, delayed fulfillment, orphaned accounts/roles, and SoD conflicts that can enable internal fraud.
IGA tools consolidate identity data from systems of record (e.g., HR, ERP) and correlate accounts, entitlements, and attributes across connected targets for centralized management of identities, groups, and roles. Demand is rising for integrations with IT Service Management tools to unify access requests and password functions within broader helpdesk portals, and with Privileged Access Management and Data Access Governance for broader governance coverage, including unstructured data.
One Identity Manager—core to One Identity’s portfolio within Quest Software—offers a mature, modular IGA suite with strong provisioning and access governance, flexible workflow customization, and support for joiner/mover/leaver processes. It provides on-premises and cloud-related deployment options, including managed single-tenant and private data center models, plus extensions via the Starling SaaS platform. Distinguishing capabilities include SAP-certified integration (including SAP S/4HANA) and a shopping-cart access request model with entitlement/role change simulation. It also offers Data Governance for unstructured repositories (e.g., NTFS, NAS, SharePoint, OneDrive) and integrates tightly with Safeguard privileged access management. Strengths center on usability, connector breadth, advanced role/SoD support, and integration depth; challenges include training needs, partial Docker-based components without cloud-native architecture, and a limited but growing services network.
See All Locations
See All Locations