Half your web apps speak SAML and half never will. Your users shouldn’t need a password for each — NetIQ Access Manager signs users in once across SAML, OpenID Connect and WS-Federation apps, puts a reverse-proxy gateway in front of the apps that cannot federate, and runs on servers you choose — in India if you need it.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers OpenText NetIQ Access Manager — single sign-on and the Access Gateway, with Advanced Authentication and Identity Foundation as context. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
One identity server signs users in once and vouches for them to every app, while a gateway covers apps that cannot federate.
What consolidation actually replaces, dimension by dimension.
| Dimension | A login per app, resets by ticket | OpenText NetIQ Access Manager |
|---|---|---|
| Passwords per user | One per app, reset by the help desk | One sign-in across federated and proxied apps |
| Apps with no SAML | Left out of SSO, own login forms | Fronted by the Access Gateway reverse proxy |
| Risk checks | A password at the door, then nothing | Nine rule types re-scored through the session |
| Where identity data lives | Scattered across each app’s database | On the cluster you run, in your own DC |
| Leaver access | Hunt down every app account | Disable once and federated access ends |
| What it is NOT | — | A SaaS IdP, an MFA product, or a published price |
The cheapest test is one legacy web app behind the Access Gateway: if it joins single sign-on unchanged, the rest of the business case follows.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The identity provider: it authenticates users against your directory and issues SAML, OAuth, OpenID Connect or WS-Federation tokens to each connected app.
A reverse proxy in front of web apps that have no federation or security model of their own, injecting identity so they join single sign-on unchanged.
Rebuilt on Angular in 5.1 with iManager removed; REST APIs and a Swagger test page let you script Identity Server configuration, and changes are audited.
A built-in engine scores each request in context, not only at login; step-up factors come from Advanced Authentication, a separately licensed product.
An identity server for the apps that federate — a reverse-proxy gateway for the ones that never will, all on servers you run.
NetIQ Access Manager gives every web app one sign-in, whether the app federates or sits behind the gateway.
SAML, OAuth, OpenID Connect, WS-Federation and WS-Trust from one Identity Server, so old and new apps share a login.
Out-of-the-box integrations sign users into Microsoft SharePoint and Microsoft 365 Enterprise through the same policies.
OAuth token exchange swaps a broad user token for a narrower one before a call reaches a downstream service or API.
Nine rule types score each request by user and context throughout the session, not just at the moment of sign-in.
Paired with Advanced Authentication, a risky request can demand FIDO2, OATH tokens, biometrics or a smartwatch approval.
The SecureCredentialsAuthClass added in 5.1 uses the Web Crypto API to encrypt the password before it reaches the server.
A reverse proxy protects web apps with no security model, and OpenText claims 100% SSO coverage with plug-in or desktop agent.
Published APIs let developers build a mobile gateway for one-touch access to legacy web apps, which OpenText says takes hours.
Administrators design and brand the sign-in and app-launch portal without writing front-end code for each change.
Token exchange in Access Manager, then the separately licensed Advanced Authentication on a smartwatch, for remote access and over RADIUS.
How Access Manager narrows a token before it is passed on to an API.
The separately licensed MFA layer approving a sign-in from a watch.
Advanced Authentication guarding remote access; recorded before the 2025 renaming.
Adding MFA to RADIUS-based VPN and network sign-ins, from 2023.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Access Manager is installed, not rented. It runs as Docker containers with Helm charts for Kubernetes, as a soft-appliance ISO on SLES or RHEL, or in a single-tenant private cloud. Tokens, sessions and audit trails sit wherever you put the cluster, which settles the residency question before a lawyer has to ask it.
Most estates have apps that will never speak SAML. The Access Gateway sits in front of them as a reverse proxy and supplies identity for them, and a browser plug-in or desktop agent covers the rest; OpenText claims 100% SSO coverage that way. Cloud-only identity providers usually reserve that job for a premium tier.
The built-in risk engine has nine rule types and keeps scoring the user’s requests in context after sign-in. When a score rises, Advanced Authentication can step the user up to one of 30+ methods, FIDO2 and OATH among them. WS-Federation and WS-Trust support keeps older Microsoft-style apps in scope as well.
There is no public price and no self-serve trial, and real MFA means buying Advanced Authentication too. You run, patch and scale it: NVD lists June 2026 flaws fixed only in 5.1.3, and CVE-2021-22506 in pre-5.0 builds is on CISA’s KEV list. The 5.1 Analytics Dashboard is deprecated, and no analyst ranking is cited.
List each web app, how it signs users in today — SAML, OIDC, WS-Fed or a form — and which ones can never federate.
Pick Kubernetes with Helm charts, the soft appliance or private cloud, in your Indian DC, and size the cluster for peak sign-ins.
Connect the directory, then bring Microsoft 365 and two SAML apps under one login before touching anything legacy.
Front one non-federating app with the Access Gateway, test header injection, and write risk rules that trigger step-up MFA.
Move the remaining apps in waves, upgrade to 5.1.3 or later, and set a routine for applying OpenText security fixes.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our core banking portal had no SAML at all. The Access Gateway put it behind the same login as M365 without a code change.”
“We have to keep identity data on our own racks, so a product we install ourselves was the only option that passed review.”
“Running it on Kubernetes with the Helm charts beat the old appliance builds, but plan for proper staging before upgrades.”
“WS-Federation support kept two ageing .NET apps in SSO that our cloud IdP shortlist would have left out entirely.”
“The REST APIs in 5.1 let us script config across environments. The older console was much slower to work in.”
“Strong product, but MFA is a second licence and the quote took weeks. Budget for Advanced Authentication from day one.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the access management market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only; self-hosted, with MFA licensed separately.
The grid nobody publishes — how much of the stack you can run yourself, India included, vs how many kinds of app it can bring into single sign-on.
Self-hosted; five federation standards plus a reverse-proxy gateway.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Okta Single Sign-On, Cisco Duo, miniOrange SSO, Fortinet FortiAuthenticator and ManageEngine AD360 — on deployment, legacy apps, MFA, price, limits and India.
| Dimension | OpenText NetIQ Access Manager | Okta Single Sign-On | Cisco Duo | miniOrange SSO | Fortinet FortiAuthenticator | ManageEngine AD360 |
|---|---|---|---|---|---|---|
| What it is | Self-run SSO + gateway | Cloud identity provider | MFA first, SSO added | Cloud or on-prem IAM | Auth server appliance | AD-centred IAM bundle |
| Deployment | Containers or appliance | SaaS only | SaaS, gateway on-prem | Cloud or on-premise | Hardware or VM | Self-hosted install |
| Federation standards | SAML, OIDC, WS-Fed + | SAML, OIDC, SWA, SCIM | SAML and OIDC | SAML, OAuth, OIDC | SAML, RADIUS, LDAP | Via ADSelfService Plus |
| Apps without federation | Gateway, plug-in, agent | Gateway in top suite | Network Gateway, Premier | In-house apps from $3 | Network access focus | Federated apps only |
| MFA and adaptive risk | Risk engine; MFA extra | Adaptive from $14 | Risk-based from $6 | Adaptive from $3 | FortiToken and FIDO2 | MFA via ADSelfService |
| Pricing model | Quote only | Per user, five suites | Per user, four editions | Per user, three plans | Appliance + user licence | Per component unit |
| Published entry price | Not published | $6/user/month | Free up to 10 users | $2/user/month | Not published | Store calculator |
| Included vs add-on | MFA licensed apart | Gateway in Enterprise | Remote access, Premier | Legacy apps, Enterprise | Tokens bought apart | Pick components |
| Scale and limits | No ceiling published | 7,000+ integrations | Free tier caps at 10 | 5,000+ integrations | 1,500 or 8,000 base | Sized by domain/users |
| Directories and integrations | M365, SharePoint, APIs | Universal Directory | Duo Directory or any IdP | AD, LDAP, SCIM | AD/LDAP, Fabric | AD, M365, Exchange |
| India data location | Your own data centre | India tenants, 2026 | Mumbai data centre | On-prem, Pune vendor | Your appliance | Your own server |
| Support and trial | No self-serve trial | 30-day free trial | 30-day trial | 30-day trial, all plans | Trial via Fortinet | Downloadable trial |
| Lock-in and exit | Standards out, rules in | Okta-run tenant | Sits beside your IdP | Same plans, two forms | Tied to Fortinet | Tied to AD |
| Best fit | Self-hosted web estates | Cloud-first, SaaS-heavy | Fast MFA over any IdP | Budget, cloud or on-prem | Fortinet network estates | AD and M365 shops |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
OpenText NetIQ Access Manager is one of 26 iam, sso & mfa products TechBag carries. The IAM, SSO & MFA guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (employees who sign in; employee-hour cost). Estimates model time lost to separate logins, lockouts and password resets at an assumed 1.5 hours per employee a year, with 70% of it removed by single sign-on across federated and gateway-fronted apps. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: OpenText prints no price for Access Manager, Advanced Authentication or the SaaS Identity Foundation, and there is no INR rate card. Budget for two licences if you need MFA beyond the risk engine, plus the servers and people to run the cluster. TechBag gets both quoted together, then converts to INR with GST.
Best for self-hosted SSO and legacy web apps
Best for a broader rollout
Best when risk rules must step up to MFA
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which apps federate over SAML, OIDC or WS-Fed, and which need the Access Gateway or a desktop agent instead?
Will it run on Kubernetes with Helm charts, as the soft-appliance ISO, or in a single-tenant private cloud?
Which Indian data centre holds the cluster, and where do logs and audit trails get shipped after that?
Is Advanced Authentication in the same quote, and which of its 30+ methods will users actually enrol?
Which of the nine risk-rule types will you use, and what score should trigger a step-up or a block?
Are you on 5.1.3 or later, past CVE-2026-11877, and who applies OpenText fixes and on what schedule?
Would OpenText’s SaaS sibling, Identity Foundation, suit some users, given no India region was found for it?
Does the quote state the licence metric, support level and term? Ask for INR with GST and the renewal uplift.
Map which of your apps federate and which need the gateway first, or let a TechBag advisor scope a pilot that puts one legacy app behind single sign-on.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.