Softwr

Cybersecurity · head to head

IDnow vs One Identity

IDnow logo

IDnow

Cybersecurity

Identity verification and qualified electronic signature for regulated European markets

From
On request
Rated
-
One Identity logo

One Identity

Cybersecurity

Quest-owned identity governance, PAM and Active Directory management

From
On request
Rated
-

The short version

  • Each has a real cost: IDnow agent-led video identification costs several times an automated check and depends on agent availability, so peak-time queues push abandonment up at exactly the moment conversion matters.; One Identity the portfolio is assembled from separate acquisitions, so components are separately licensed, separately administered and do not present one console, which raises operational cost.
  • They diverge on capability: IDnow covers VideoIdent, One Identity covers Identity Manager.
  • Prices and features above were last checked on 1 September 2026.

Where they differ

Only the attributes on which IDnow and One Identity actually diverge.

Attributes where IDnow and One Identity differ
AttributeIDnowOne Identity
PlatformsWeb, iOS, Android, APIWeb, Windows, Linux

Identical on both: starting price (On request), pricing model (quote), free tier (No), user rating (Not yet rated), category (Cybersecurity).

What each one covers

Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.

Only in IDnow

  • VideoIdent
  • AutoIdent
  • eSign
  • eID and NFC
  • Bank identification
  • EU data processing

Only in One Identity

  • Identity Manager
  • Safeguard
  • Active Roles
  • OneLogin
  • Password Manager
  • syslog-ng
  • Starling connectors

What people use each for

The jobs each tool is most often brought in to do.

IDnow

  • A German bank opening regulated accounts where BaFin requires a recognised identification methodnot One Identity
  • An insurer needing a qualified electronic signature that will survive challenge in a European courtnot One Identity
  • A telecom operator meeting national SIM registration identity rules across several EU statesnot One Identity
  • A lender wanting automated checks for low-risk applicants and video identification only for high-value casesnot One Identity

One Identity

  • An organisation whose authoritative directory will remain on premises Active Directory and needs delegated administration with attribute-level controlnot IDnow
  • A government or defence environment requiring privileged session management on a hardened physical appliance rather than a cloud servicenot IDnow
  • A manufacturer with SAP and Active Directory needing provisioning governed under one certification processnot IDnow
  • An enterprise consolidating Active Directory after an acquisition and needing automated account lifecycle across both forestsnot IDnow

Where each one falls short

Documented limitations, not opinions. Every one is a constraint you would hit in normal use.

IDnow

  • Agent-led video identification costs several times an automated check and depends on agent availability, so peak-time queues push abandonment up at exactly the moment conversion matters.
  • Pricing is quoted with an annual volume commitment, so the accreditation advantage comes with a floor you pay whether or not you use it.
  • The product is optimised for European regulatory regimes, so buyers verifying users in North America, Asia or Africa will find coverage and cost less competitive than global specialists.
  • Qualified electronic signature is a separate licence from identity verification, which surprises buyers who assumed the accredited identity check made the signature capability included.
  • Integration for the regulated flows is heavier than a simple SDK drop-in because the compliant journey, including consent and recording requirements, constrains the user experience you can build.

One Identity

  • The portfolio is assembled from separate acquisitions, so components are separately licensed, separately administered and do not present one console, which raises operational cost.
  • Identity Manager implementations are customisation-heavy and commonly run over a year, with the services spend exceeding the licence cost in the first year.
  • Quest has changed private equity ownership more than once since the Dell separation, and buyers should ask directly about product investment commitments before signing a multi-year deal.
  • Product documentation and support sit behind a customer portal, which makes independent evaluation before purchase harder than with vendors that publish openly.
  • The cloud-native and developer experience trails the pure-play identity vendors, so organisations moving decisively to SaaS applications find the on premises heritage becomes a constraint rather than an asset.

Pricing, plan by plan

IDnow

On request
  • IDnow Platform$undefined/year
    • Per-identification pricing that differs sharply between automated and agent-led methods
    • Annual volume commitment typically required
    • Qualified electronic signature licensed separately

One Identity

On request
  • Identity Manager$undefined/year
    • Priced per managed identity
    • On premises or hosted
    • Access certification and provisioning
  • Safeguard$undefined/year
    • Priced per privileged user or per appliance
    • Hardened appliance option for session management
    • Licensed separately from Identity Manager
  • Active Roles$undefined/year
    • Priced per managed Active Directory account
    • Delegated administration and automated provisioning
    • Licensed separately

Which should you pick?

Choose IDnow if

  • You need videoident.
  • You work on Web, iOS, Android, API.
  • You also want autoident.

Choose One Identity if

  • You need identity manager.
  • You work on Web, Windows, Linux.
  • You also want safeguard.

Questions people ask

Is IDnow or One Identity better?
Neither clearly leads. IDnow starts at On request and One Identity at On request, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
Which is cheaper, IDnow or One Identity?
IDnow starts at On request and One Identity at On request.
Does IDnow or One Identity run on more platforms?
IDnow runs on Web, iOS, Android, API. One Identity runs on Web, Windows, Linux.
What is IDnow best used for?
IDnow is most often used for a german bank opening regulated accounts where bafin requires a recognised identification method, an insurer needing a qualified electronic signature that will survive challenge in a european court, a telecom operator meeting national sim registration identity rules across several eu states, a lender wanting automated checks for low-risk applicants and video identification only for high-value cases. Of those, a german bank opening regulated accounts where bafin requires a recognised identification method and an insurer needing a qualified electronic signature that will survive challenge in a european court are not what One Identity is typically brought in for.
What can IDnow do that One Identity cannot?
IDnow covers VideoIdent, AutoIdent, eSign, eID and NFC. One Identity covers Identity Manager, Safeguard, Active Roles, OneLogin.

Answered from the vendors’ own pages

IDnow: Why choose it over a cheaper automated vendor?

Because in some European regimes the cheaper vendor is not legally permitted for the transaction. This is an eligibility question, not a quality one.

One Identity: Is One Identity the same company as Quest?

Yes. One Identity is Quest Software's identity and access management business unit, not a separate vendor.

IDnow: Is the electronic signature included?

No. Qualified electronic signature under eIDAS is licensed separately from identity verification.

One Identity: Does it include privileged access?

Safeguard provides it, but it is licensed separately from Identity Manager. Neither includes the other.

IDnow: Where is the data processed?

In European data centres, which is a requirement rather than a preference for many of its regulated customers.

One Identity: Why choose this over SailPoint or Saviynt?

Almost always because of Active Directory depth via Active Roles or an appliance requirement for privileged sessions. For cloud-first estates the specialists are the stronger choice.

Share

Related pages

Other head to heads