One Identity Active Roles delivers automated user account and group management that overcomes the shortcomings of native Microsoft Active Directory and Azure Active Directory tools. These enhanced identity-management capabilities enable you to do your job more efficiently, more accurately, and with less manual intervention. Active Roles is designed with a modular architecture, so your organisation can easily meet your business requirements today and in the future. With Active Roles, you can automate tedious and error-prone administrative tasks and solve security issues by protecting and controlling all-important administrative access.

Key benefits


  • Automate AD/AAD administration

  • Regulate admin access

  • Overcome native AD tool limitations

  • Expand AD control beyond Windows


Hybrid AD ready

Active Roles is optimised to serve the needs of both on-prem AD and Azure AD in a hybrid deployment. It offers a single console, unified workflows and a consistent administrative experience across your entire hybrid environment. With support for multi-tenant, Active Roles eliminates the cumbersome, error-prone, and unnecessary challenges that come with using separate native tools and manual processes.

Secure access

Active Roles provides comprehensive privileged account management for Active Directory and Azure Active Directory, enabling you to control access through delegation using a least-privilege model. Based on defined administrative policies and associated permissions, it generates and strictly enforces access rules, eliminating the errors and inconsistencies common with native approaches to hybrid AD management. Along with modern authentication using OAUTH, Active Roles has robust and personalised approval procedures establish an IT process and oversight consistent with business requirements, with responsibility chains that complement the automated management of directory data.

Automate account administration

Active Roles automates a wide variety of tasks, including:


  • Creating user accounts and groups in AD and AAD

  • Extending AD/AAD-based account administrative actions to non-Windows systems and SaaS applications

  • Creating mailboxes in Exchange and Exchange Online

  • Populating groups across AD and AAD

  • Assigning resource in Windows

It also automates the process of reassigning and removing user access rights in AD, AAD and AD-joined systems (including user and group de-provisioning) to ensure an efficient and secure administrative process over the user and group lifecycles. When a user’s access needs to be changed or removed, updates are made automatically across all relevant systems and applications in the hybrid AD/AAD environment, as well as AD-joined systems, including UNIX, Linux, Mac OS X rich (replace ‘as well as’ with ‘and’) and a growing collection of popular SaaS applications via the One Identity Starling Connect solution.

Day to day directory management

With Active Roles, you can easily manage all of the following for both the on-premise and Azure AD environments:

  • Exchange recipients, including mailbox/OCS assignment, creation, movement, deletion, permissions and distribution list management

  • Groups

  • Computers, including shares, printers, local users and groups

  • Active Directory and Azure Active Directory

Active Roles includes intuitive interfaces to optimise day-to- day administration and help-desk operations of the hybrid AD/AAD environment via both an MMC snap-in and a web interface.


Extend the administrative scope

Active Roles supports the SCIM standard, which allows any SCIM-enabled SaaS application (via One Identity Starling Connect) to be embraced in the AD-based account and group administration capabilities of Active Roles.

Manage groups and users in a hosted environment

Synchronise AD domain clients with host AD domain in hosted environments. Active Roles enables user and group account management from the client domain to the hosted domain, while also synchronising attributes and passwords. Utilise out-of-the-box connectors to synchronise your on-premises AD accounts to Microsoft Office 365, Lync Online / Skype for Business and SharePoint Online.

Consolidate management points through integration

Active Roles complements your existing technology and IAM strategy. It simplifies and consolidates management points by ensuring easy integration with many One Identity products, including Identity Manager, Safeguard, Authentication Services, Password Manager and ChangeAuditor. Active Roles also automates and extends the capabilities of PowerShell, ADSI, SPML and customisable web interfaces.