OpenText NetIQ
OpenText NetIQ: Identity and Access Management (IAM) platform. Access Manager, Identity Governance, Privileged Access, Advanced Authentication. Enterprise identity management.

Key Features
- Access Manager - SSO, federation, web access management
- Identity Governance - access certification, compliance
- Privileged Access Manager - privileged account control
- Advanced Authentication - MFA, biometrics, risk-based
- Identity Manager - provisioning, lifecycle management
Table of Contents
What is OpenText NetIQ?
OpenText NetIQ (formerly Micro Focus NetIQ) is an Identity and Access Management (IAM) platform - a comprehensive solution for managing identities, access, and permissions in an organization. From SSO through MFA to governance and PAM.
Main components:
- Access Manager - Single Sign-On, federation, web access
- Identity Governance - access certification, compliance, SoD
- Privileged Access Manager - admin account control
- Advanced Authentication - MFA, biometrics, adaptive
- Identity Manager - provisioning, lifecycle
What problem does it solve?
flowchart LR
subgraph Without IAM
A[User remembers 20 passwords] --> B[Passwords on sticky notes]
B --> C[No MFA]
C --> D[Breach]
end
subgraph With NetIQ
E[Single SSO login] --> F[MFA everywhere]
F --> G[Governance]
G --> H[Security]
end
style A fill:#dc2626,stroke:#b91c1c,color:#fff
style B fill:#dc2626,stroke:#b91c1c,color:#fff
style C fill:#dc2626,stroke:#b91c1c,color:#fff
style D fill:#dc2626,stroke:#b91c1c,color:#fff
style E fill:#22c55e,stroke:#16a34a,color:#fff
style F fill:#22c55e,stroke:#16a34a,color:#fff
style G fill:#22c55e,stroke:#16a34a,color:#fff
style H fill:#22c55e,stroke:#16a34a,color:#fff
Common problems:
- Users have dozens of accounts and passwords
- No central SSO - each application separately
- MFA only selectively or not at all
- Audit: “Who has access to what?” - no answer
- Privileged accounts without control
NetIQ Components
Access Manager
SSO and Web Access
- Single Sign-On (SSO)
- SAML, OAuth, OIDC federation
- Web Access Management
- API Gateway security
Identity Governance
Compliance and certification
- Access certification campaigns
- Segregation of Duties (SoD)
- Access request workflows
- Compliance reporting
Privileged Access Manager
PAM - admin accounts
- Password vault
- Session recording
- Just-in-time access
- Credential rotation
Advanced Authentication
MFA and biometrics
- Multi-factor authentication
- Biometrics (fingerprint, face)
- FIDO2 / WebAuthn
- Risk-based / adaptive MFA
Identity Manager
Provisioning
- Automated provisioning
- HR-driven lifecycle
- Role-based access
- Self-service portal
Data Access Governance
Data access
- File share permissions
- Unstructured data access
- Data owner workflows
- Access analytics
Architecture
flowchart TD
A[User] --> B[Access Manager]
B --> C{Authentication}
C --> D[Advanced Authentication]
D --> E[MFA Challenge]
E --> F{Authorized?}
F -->|Yes| G[Applications]
F -->|No| H[Denied]
I[Identity Manager] --> J[Provisioning]
J --> G
K[Identity Governance] --> L[Certification]
L --> M[Access Reviews]
style A fill:#6366f1,stroke:#4f46e5,color:#fff
style B fill:#8b5cf6,stroke:#7c3aed,color:#fff
style D fill:#f59e0b,stroke:#d97706,color:#fff
style F fill:#f59e0b,stroke:#d97706,color:#fff
style G fill:#22c55e,stroke:#16a34a,color:#fff
style H fill:#dc2626,stroke:#b91c1c,color:#fff
Access Manager - SSO
Single Sign-On for all applications:
| Protocol | Use case |
|---|---|
| SAML 2.0 | Enterprise apps, cloud SaaS |
| OAuth 2.0 | API authorization |
| OpenID Connect | Modern web/mobile apps |
| Kerberos | Windows domain apps |
| Header-based | Legacy web apps |
flowchart LR
A[User] --> B[Access Manager]
B --> C[App 1 - SAML]
B --> D[App 2 - OIDC]
B --> E[App 3 - Header]
B --> F[API - OAuth]
style A fill:#6366f1,stroke:#4f46e5,color:#fff
style B fill:#f59e0b,stroke:#d97706,color:#fff
style C fill:#22c55e,stroke:#16a34a,color:#fff
style D fill:#22c55e,stroke:#16a34a,color:#fff
style E fill:#22c55e,stroke:#16a34a,color:#fff
style F fill:#22c55e,stroke:#16a34a,color:#fff
Advanced Authentication - MFA
Authentication methods:
Something you know
Password, PIN, Security questions
Something you have
TOTP, Push, SMS, Hardware token, Smart card
Something you are
Fingerprint, Face, Voice, Iris
Risk-based
Location, Device, Behavior, Time
Who is it for?
NetIQ MAKES sense when:
- • You have 500+ users and many applications
- • You need SSO for hybrid (on-prem + cloud)
- • Compliance requires MFA and access certification
- • You have legacy apps without native federation
- • You need PAM for administrators
NetIQ DOESN'T make sense when:
- • Small company - Azure AD / Okta may suffice
- • 100% cloud - native cloud IAM simpler
- • Only MFA - standalone MFA cheaper
NetIQ vs competition
| Aspect | NetIQ | Okta | Microsoft Entra | Ping Identity |
|---|---|---|---|---|
| SSO | Yes | Yes | Yes | Yes |
| MFA | Advanced Auth | Yes | Yes | Yes |
| IGA | Identity Governance | Add-on | Basic | No |
| PAM | Yes | No | No | No |
| On-prem | Yes | No | Limited | Yes |
| Legacy apps | Header-based | Limited | Limited | Yes |
| Price | Competitive | Premium | M365 included | Premium |
NetIQ advantage:
- Complete IAM portfolio in one place
- On-premises option for regulated industries
- Header-based SSO for legacy apps
- PAM integrated with IAM
Specifications
| Parameter | Value |
|---|---|
| Deployment | On-premises, SaaS, Hybrid |
| Directory | AD, LDAP, eDirectory, Azure AD |
| Protocols | SAML, OAuth, OIDC, Kerberos, RADIUS |
| MFA methods | TOTP, Push, SMS, Biometrics, FIDO2 |
| Connectors | 200+ out-of-box |
| Compliance | SOX, HIPAA, PCI DSS, GDPR |
FAQ
How does it differ from Azure AD? Azure AD is cloud-native IAM for Microsoft ecosystem. NetIQ is enterprise IAM for hybrid environments with strong support for legacy apps and on-prem.
Can I use only MFA? Yes. Advanced Authentication can work standalone or with Access Manager.
How does it work with Active Directory? NetIQ integrates with AD as a directory. Can extend AD with SSO, MFA, governance without replacement.
What about legacy applications? Access Manager supports header-based SSO for applications that don’t support SAML/OIDC natively.
How long does implementation take? Basic SSO: 2-4 weeks. Full IAM with governance: 3-6 months.
Does nFlo implement NetIQ? Yes. Access Manager, Advanced Authentication, Identity Governance deployments, application integrations.
Inquire about OpenText NetIQ
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
CIS Security Audit
Cybersecurity
Harden system configurations with CIS Benchmarks. Block 85% of common attacks.
Cloud Security Audit and Protection
Cybersecurity
Check AWS/Azure/GCP security before attackers find misconfigurations. CSPM + manual review.
Web Application Penetration Testing
Cybersecurity
One SQL injection = access to entire database. Find vulnerabilities before hackers do.
From Our Knowledge Base
Articles related to this solution
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Cyber threat landscape 2026: a report for Polish companies in the NIS2 era
Poland is the most digitally attacked EU country. Explore the 2026 cyber threat landscape in numbers, the three most dangerous attack vectors and the NIS2/KSC obligations for Polish companies.
Deepfake, vishing and CEO fraud: how to protect your company from AI-powered scams
A deepfake on a video call, voice cloning and AI-powered CEO fraud mean real losses in the millions. Learn how these scams work and the proven defenses, including second-channel verification.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist