One Identity Identity Manager
One Identity Identity Manager: IGA (Identity Governance and Administration) platform. Provisioning automation, access certification, role-based access control. Enterprise identity management.

Key Features
- Provisioning/deprovisioning - automatic account creation and deletion
- Access certification - access recertification campaigns
- Role-based access control - business role management
- Self-service - portal for users and managers
- HR integration - synchronization with HR systems
Table of Contents
What is One Identity Identity Manager?
One Identity Identity Manager is an IGA (Identity Governance and Administration) platform - a system that manages identities in an organization: who has access to what, why, and whether they should still have it.
Main functions:
- Provisioning - automatic account creation in systems (AD, SAP, Oracle, cloud)
- Access Certification - periodic access reviews (“Does John still need access to SAP?”)
- RBAC - business roles instead of individual permissions
- Self-service - users request access themselves
What problem does it solve?
flowchart LR
subgraph Without IGA
A[New employee] --> B[Ticket to IT]
B --> C[Manual account creation]
C --> D[Days of waiting]
end
subgraph With Identity Manager
E[New employee in HR] --> F[Auto-provisioning]
F --> G[Accounts in AD, SAP, O365]
G --> H[Ready in minutes]
end
style A fill:#dc2626,stroke:#b91c1c,color:#fff
style B fill:#dc2626,stroke:#b91c1c,color:#fff
style C fill:#dc2626,stroke:#b91c1c,color:#fff
style D fill:#dc2626,stroke:#b91c1c,color:#fff
style E fill:#22c55e,stroke:#16a34a,color:#fff
style F fill:#22c55e,stroke:#16a34a,color:#fff
style G fill:#22c55e,stroke:#16a34a,color:#fff
style H fill:#22c55e,stroke:#16a34a,color:#fff
Typical problems:
- Onboarding takes weeks (waiting for accounts)
- Incomplete offboarding (former employee still has access)
- Audit: “Who has access to system X?” - no answer
- Orphaned accounts - accounts without owner
- Excessive permissions - people have more access than needed
How does Identity Manager work?
flowchart TD
A[HR System] --> B[Identity Manager]
B --> C{Event?}
C -->|New employee| D[Provisioning]
C -->|Department change| E[Access update]
C -->|Departure| F[Deprovisioning]
D --> G[AD / Azure AD]
D --> H[SAP]
D --> I[Office 365]
D --> J[Other systems]
E --> G
F --> G
style A fill:#6366f1,stroke:#4f46e5,color:#fff
style B fill:#8b5cf6,stroke:#7c3aed,color:#fff
style C fill:#f59e0b,stroke:#d97706,color:#fff
style D fill:#22c55e,stroke:#16a34a,color:#fff
style E fill:#22c55e,stroke:#16a34a,color:#fff
style F fill:#dc2626,stroke:#b91c1c,color:#fff
Main features
Provisioning
Automatic accounts
- Joiner - account creation for new
- Mover - change on transfer
- Leaver - deletion on departure
Access Certification
Access recertification
- Certification campaigns
- Manager review
- Automatic revoke
Role Management
RBAC - business roles
- Role mining
- Business roles
- SoD (Segregation of Duties)
Self-Service
User portal
- Request access
- Password reset
- Profile update
Workflows
Approval processes
- Multi-level approval
- Escalations
- Delegations
Compliance
Audit and reports
- Audit trail
- Compliance reports
- Policy violations
Integrations (Connectors)
Identity Manager connects to target systems through connectors:
Directory
Active Directory, Azure AD, LDAP, eDirectory
ERP
SAP, Oracle, PeopleSoft, Workday
Cloud
Office 365, Salesforce, ServiceNow, AWS
Database
Oracle DB, SQL Server, MySQL
For whom?
Identity Manager MAKES sense when:
- • Have 1000+ employees
- • Multiple systems to manage (AD, SAP, cloud)
- • Compliance requirements (SOX, GDPR, sector regulations)
- • Onboarding/offboarding is a problem
- • Auditors ask "who has access to what?"
Identity Manager DOESN'T make sense when:
- • Small company (<200 people) - overkill
- • Only AD - Azure AD P2 may be enough
- • Cloud-only - consider SaaS IGA (Okta, SailPoint)
Identity Manager vs competition
| Aspect | One Identity IM | SailPoint IdentityNow | Okta IGA | Microsoft Entra |
|---|---|---|---|---|
| Deployment | On-prem + SaaS | SaaS | SaaS | Cloud |
| SAP integration | Native | Connector | Connector | Limited |
| Complexity | Medium-high | Medium | Low | Low |
| Customization | High | Medium | Low | Low |
| Price | Competitive | Premium | Premium | Included in M365 |
One Identity advantage:
- Strong SAP integration
- Customization flexibility
- On-prem option for regulated industries
- Competitive price vs SailPoint
Specifications
| Parameter | Value |
|---|---|
| Deployment | On-premises, SaaS (One Identity Manager On Demand) |
| Database | SQL Server |
| Connectors | 100+ out-of-box |
| API | REST, SOAP, SCIM |
| Authentication | AD, SAML, OAuth, MFA |
| Compliance | SOX, GDPR, HIPAA, PCI DSS |
FAQ
What’s the difference between IGA and IAM? IAM = access at login time. IGA = governance - who should have access, why, recertification.
How long does deployment take? Basic: 3-6 months. Full with multiple systems: 6-12 months.
Can I start with one system? Yes. Typically you start with AD + HR, then add more systems.
What about SaaS applications? Identity Manager supports cloud apps through SCIM and dedicated connectors.
Does it require programming? 80% configuration. Advanced workflow customization may require .NET.
How does access certification work? Manager gets list of employees and their permissions. Approves or rejects. Unapproved are automatically revoked.
Does nFlo deploy Identity Manager? Yes. Deployments, connector configuration, migrations from other IGA, HR integrations.
Inquire about One Identity Identity Manager
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
CIS Security Audit
Cybersecurity
Harden system configurations with CIS Benchmarks. Block 85% of common attacks.
Cloud Security Audit and Protection
Cybersecurity
Check AWS/Azure/GCP security before attackers find misconfigurations. CSPM + manual review.
Web Application Penetration Testing
Cybersecurity
One SQL injection = access to entire database. Find vulnerabilities before hackers do.
From Our Knowledge Base
Articles related to this solution
CVE-2026-37637: An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the...
Security Alert - CVE-2026-37637. CVSS: 9.1 (critical).
CVE-2026-11374: In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus,...
Security Alert - CVE-2026-11374. CVSS: 9.0 (critical).
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist