Softwr

Cybersecurity · head to head

Entrust Identity as a Service vs One Identity

Entrust Identity as a Service logo

Entrust Identity as a Service

Cybersecurity

Workforce and customer authentication from a certificate authority

From
$2/month
Rated
-
One Identity logo

One Identity

Cybersecurity

Quest-owned identity governance, PAM and Active Directory management

From
On request
Rated
-

The short version

  • Each has a real cost: Entrust Identity as a Service the application integration catalogue is smaller than that of the dedicated identity vendors, so uncommon SaaS applications more often need custom SAML configuration rather than a template.; One Identity the portfolio is assembled from separate acquisitions, so components are separately licensed, separately administered and do not present one console, which raises operational cost.
  • They diverge on capability: Entrust Identity as a Service covers Multi-factor authentication, One Identity covers Identity Manager.
  • Prices and features above were last checked on 1 September 2026.

Where they differ

Only the attributes on which Entrust Identity as a Service and One Identity actually diverge.

Attributes where Entrust Identity as a Service and One Identity differ
AttributeEntrust Identity as a ServiceOne Identity
Starting price$2/monthOn request
Pricing modelPer user per monthquote
PlatformsWeb, iOS, Android, Windows, LinuxWeb, Windows, Linux

Identical on both: free tier (No), user rating (Not yet rated), category (Cybersecurity).

What each one covers

Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.

Only in Entrust Identity as a Service

  • Multi-factor authentication
  • Single sign-on
  • Adaptive authentication
  • Passwordless login
  • Credential lifecycle
  • Derived PIV credentials
  • Directory integration

Only in One Identity

  • Identity Manager
  • Safeguard
  • Active Roles
  • OneLogin
  • Password Manager
  • syslog-ng
  • Starling connectors

What people use each for

The jobs each tool is most often brought in to do.

Entrust Identity as a Service

  • A government agency needing derived mobile credentials from an existing PIV smart card estatenot One Identity
  • A bank that must support hardware tokens for corporate treasury users alongside push authentication for staffnot One Identity
  • An organisation already buying Entrust certificates that wants credential issuance and authentication from one vendornot One Identity
  • A defence supplier required to use certificate-based authentication that mainstream cloud identity products handle poorlynot One Identity

One Identity

  • An organisation whose authoritative directory will remain on premises Active Directory and needs delegated administration with attribute-level controlnot Entrust Identity as a Service
  • A government or defence environment requiring privileged session management on a hardened physical appliance rather than a cloud servicenot Entrust Identity as a Service
  • A manufacturer with SAP and Active Directory needing provisioning governed under one certification processnot Entrust Identity as a Service
  • An enterprise consolidating Active Directory after an acquisition and needing automated account lifecycle across both forestsnot Entrust Identity as a Service

Where each one falls short

Documented limitations, not opinions. Every one is a constraint you would hit in normal use.

Entrust Identity as a Service

  • The application integration catalogue is smaller than that of the dedicated identity vendors, so uncommon SaaS applications more often need custom SAML configuration rather than a template.
  • Developer experience for customer identity use cases is behind the specialists, and teams building consumer signup flows will find the APIs and documentation less complete.
  • Advanced capabilities including adaptive authentication and credential management sit above the published entry price, so the two dollar figure rarely reflects what a regulated buyer actually spends.
  • There are two overlapping products, Identity as a Service and Identity Enterprise, and choosing wrongly at the start means a migration later rather than a licence change.
  • Identity governance, access certification and privileged access are not covered, so an organisation with audit-driven access review requirements needs a second vendor alongside it.

One Identity

  • The portfolio is assembled from separate acquisitions, so components are separately licensed, separately administered and do not present one console, which raises operational cost.
  • Identity Manager implementations are customisation-heavy and commonly run over a year, with the services spend exceeding the licence cost in the first year.
  • Quest has changed private equity ownership more than once since the Dell separation, and buyers should ask directly about product investment commitments before signing a multi-year deal.
  • Product documentation and support sit behind a customer portal, which makes independent evaluation before purchase harder than with vendors that publish openly.
  • The cloud-native and developer experience trails the pure-play identity vendors, so organisations moving decisively to SaaS applications find the on premises heritage becomes a constraint rather than an asset.

Pricing, plan by plan

Entrust Identity as a Service

$2/month
  • Workforce Standard$2/month
    • Multi-factor authentication
    • Single sign-on
    • Directory integration
  • Higher tiers$undefined/month
    • Adaptive risk-based authentication
    • Certificate and smart card credential management
    • Derived PIV credentials

One Identity

On request
  • Identity Manager$undefined/year
    • Priced per managed identity
    • On premises or hosted
    • Access certification and provisioning
  • Safeguard$undefined/year
    • Priced per privileged user or per appliance
    • Hardened appliance option for session management
    • Licensed separately from Identity Manager
  • Active Roles$undefined/year
    • Priced per managed Active Directory account
    • Delegated administration and automated provisioning
    • Licensed separately

Which should you pick?

Choose Entrust Identity as a Service if

  • You need multi-factor authentication.
  • You work on Web, iOS, Android, Windows, Linux.
  • You also want single sign-on.

Choose One Identity if

  • You need identity manager.
  • You work on Web, Windows, Linux.
  • You also want safeguard.

Questions people ask

Is Entrust Identity as a Service or One Identity better?
Neither clearly leads. Entrust Identity as a Service starts at $2/month and One Identity at On request, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
Which is cheaper, Entrust Identity as a Service or One Identity?
Entrust Identity as a Service starts at $2/month and One Identity at On request.
Does Entrust Identity as a Service or One Identity run on more platforms?
Entrust Identity as a Service runs on Web, iOS, Android, Windows, Linux. One Identity runs on Web, Windows, Linux.
What is Entrust Identity as a Service best used for?
Entrust Identity as a Service is most often used for a government agency needing derived mobile credentials from an existing piv smart card estate, a bank that must support hardware tokens for corporate treasury users alongside push authentication for staff, an organisation already buying entrust certificates that wants credential issuance and authentication from one vendor, a defence supplier required to use certificate-based authentication that mainstream cloud identity products handle poorly. Of those, a government agency needing derived mobile credentials from an existing piv smart card estate and a bank that must support hardware tokens for corporate treasury users alongside push authentication for staff are not what One Identity is typically brought in for.
What can Entrust Identity as a Service do that One Identity cannot?
Entrust Identity as a Service covers Multi-factor authentication, Single sign-on, Adaptive authentication, Passwordless login. One Identity covers Identity Manager, Safeguard, Active Roles, OneLogin.

Answered from the vendors’ own pages

Entrust Identity as a Service: Is MFA included or extra?

Multi-factor authentication is included in the workforce bundles rather than sold separately, which is not true of every competitor. Adaptive risk-based authentication sits in higher tiers.

One Identity: Is One Identity the same company as Quest?

Yes. One Identity is Quest Software's identity and access management business unit, not a separate vendor.

Entrust Identity as a Service: Does it do identity governance?

No. Access certification, role mining and joiner-mover-leaver governance require a separate product such as SailPoint or Saviynt.

One Identity: Does it include privileged access?

Safeguard provides it, but it is licensed separately from Identity Manager. Neither includes the other.

Entrust Identity as a Service: Why choose this over Okta or Entra ID?

Almost always because of PKI, smart cards or derived credentials. Without that requirement the mainstream platforms are the stronger general purpose choice.

One Identity: Why choose this over SailPoint or Saviynt?

Almost always because of Active Directory depth via Active Roles or an appliance requirement for privileged sessions. For cloud-first estates the specialists are the stronger choice.

Share

Related pages

Other head to heads