Talk to us
by OpenTextTechBag Intel Page

OpenText NetIQ Access Manager

Half your web apps speak SAML and half never will. Your users shouldn’t need a password for each — NetIQ Access Manager signs users in once across SAML, OpenID Connect and WS-Federation apps, puts a reverse-proxy gateway in front of the apps that cannot federate, and runs on servers you choose — in India if you need it.

One sign-in, even for apps without SAMLSelf-hosted, in your own Indian DCQuote-only; MFA is a second licence

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
OpenText publishes no Access Manager price; Advanced Authentication is quoted on top
Quote
Standards
SAML, OAuth, OpenID Connect, WS-Federation and WS-Trust on one identity server
5 protocols
Analysts
OpenText cites no current Gartner or Forrester ranking for Access Manager itself
None cited
India
Self-hosted; no India region was found for the SaaS sibling, Identity Foundation
Your DC

Quick answer

OpenText NetIQ Access Manager is self-hosted single sign-on plus a reverse-proxy Access Gateway. It federates over SAML, OAuth, OpenID Connect, WS-Federation and WS-Trust, fronts web apps with no security model, and re-scores risk during each session. It runs as containers, a soft appliance or private cloud, so data stays in your Indian DC. MFA comes from Advanced Authentication, licensed apart. Quote-only. Read more ↓ Show less ↑
Part 01 · Orient

The OpenText platform family

This page covers OpenText NetIQ Access Manager — single sign-on and the Access Gateway, with Advanced Authentication and Identity Foundation as context. The rest:

OpenText Content Management
Enterprise content management, formerly Extended ECM.
View page →
OpenText Fortify
Application security testing: SAST, DAST and SCA.
View page →
NetIQ Identity Governance
Access reviews, provisioning and identity lifecycle.
View page →
NetIQ Access Manager
This page.
You’re here
NetIQ Privileged Access Manager
Privileged session control and credential vaulting.
View page →
OpenText Voltage SecureData
Format-preserving encryption and tokenisation.
View page →
OpenText Enterprise Security Manager
Real-time SIEM correlation, formerly ArcSight.
View page →
OpenText Service Management
ITSM and asset management, formerly SMAX.
View page →
OpenText AI Operations Management
Event and performance monitoring, formerly Operations Bridge.
View page →
OpenText ZENworks
Endpoint management, patching and disk encryption.
View page →
OpenText Data Protector
Enterprise backup for servers, VMs and applications.
View page →
OpenText Availability
Real-time replication and failover, formerly Carbonite.
View page →
OpenText Cloudally Backup
Microsoft 365, Google, Salesforce, Box and Dropbox backup.
View page →
OpenText Performance Engineering
Load and performance testing, formerly LoadRunner.
View page →
OpenText Functional Testing
Automated functional testing, formerly UFT One.
View page →
OpenText Core Endpoint Protection
Cloud endpoint security for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core DNS Protection
DNS filtering for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core Email Threat Protection
Email security and encryption, ex-Zix.
View page →

Quick facts

30-second orientation
Product
Self-hosted SSO, federation and reverse-proxy access gateway for web apps
Maker
Open Text Corporation, Waterloo, Canada; NASDAQ and TSX: OTEX; CEO Ayman Antoun since April 2026
Lineage
Sold as Micro Focus Access Manager until OpenText bought Micro Focus in January 2023
Release
Version 5.1 (CE 24.2) brought a new Angular console and REST APIs; 5.1.3 fixes June 2026 CVEs
Standards
SAML, OAuth, OpenID Connect, WS-Federation and WS-Trust
Deploy
Docker containers with Helm charts for Kubernetes, a soft-appliance ISO, or single-tenant private cloud
MFA
NetIQ Advanced Authentication, a separate licence with 30+ methods including FIDO2
Price
Not published; quoted by OpenText or its partners
India
Self-hosted, so identity data stays in your own Indian data centre
In India via
TechBag — app inventory, quote in INR with GST, gateway pilot
Part 02 · Learn

Understand access management before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is web access management?

One identity server signs users in once and vouches for them to every app, while a gateway covers apps that cannot federate.

A login per app vs one access manager — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA login per app, resets by ticketOpenText NetIQ Access Manager
Passwords per userOne per app, reset by the help deskOne sign-in across federated and proxied apps
Apps with no SAMLLeft out of SSO, own login formsFronted by the Access Gateway reverse proxy
Risk checksA password at the door, then nothingNine rule types re-scored through the session
Where identity data livesScattered across each app’s databaseOn the cluster you run, in your own DC
Leaver accessHunt down every app accountDisable once and federated access ends
What it is NOT—A SaaS IdP, an MFA product, or a published price

The cheapest test is one legacy web app behind the Access Gateway: if it joins single sign-on unchanged, the rest of the business case follows.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where users sign in

Identity Server

Identity Server

The identity provider: it authenticates users against your directory and issues SAML, OAuth, OpenID Connect or WS-Federation tokens to each connected app.

02
Where old apps get SSO

Access Gateway

Access Gateway

A reverse proxy in front of web apps that have no federation or security model of their own, injecting identity so they join single sign-on unchanged.

03
Where policy is built

Console

Administration Console

Rebuilt on Angular in 5.1 with iManager removed; REST APIs and a Swagger test page let you script Identity Server configuration, and changes are audited.

04
When to ask for more

Risk and MFA

Risk engine and Advanced Authentication

A built-in engine scores each request in context, not only at login; step-up factors come from Advanced Authentication, a separately licensed product.

An identity server for the apps that federate — a reverse-proxy gateway for the ones that never will, all on servers you run.

Part 03 · Evaluate

Nine capabilities. Federate, adapt, gate.

NetIQ Access Manager gives every web app one sign-in, whether the app federates or sits behind the gateway.

Federate
Federation

Five standards, one server

SAML, OAuth, OpenID Connect, WS-Federation and WS-Trust from one Identity Server, so old and new apps share a login.

Federate
Microsoft 365

SharePoint and M365 built in

Out-of-the-box integrations sign users into Microsoft SharePoint and Microsoft 365 Enterprise through the same policies.

Federate
Token exchange

Right-sized tokens for APIs

OAuth token exchange swaps a broad user token for a narrower one before a call reaches a downstream service or API.

Adapt
Risk engine

Scores the whole session

Nine rule types score each request by user and context throughout the session, not just at the moment of sign-in.

Adapt
Step-up MFA

30+ factors when risk rises

Paired with Advanced Authentication, a risky request can demand FIDO2, OATH tokens, biometrics or a smartwatch approval.

Adapt
Encrypted login

Password encrypted in browser

The SecureCredentialsAuthClass added in 5.1 uses the Web Crypto API to encrypt the password before it reaches the server.

Gate
Access Gateway

SSO for apps that never had it

A reverse proxy protects web apps with no security model, and OpenText claims 100% SSO coverage with plug-in or desktop agent.

Gate
Mobile gateway

Legacy web apps on a phone

Published APIs let developers build a mobile gateway for one-touch access to legacy web apps, which OpenText says takes hours.

Gate
UI designer

A portal in your own brand

Administrators design and brand the sign-in and app-launch portal without writing front-end code for each change.

See it, don’t just read it

Watch NetIQ Access Manager in action

Token exchange in Access Manager, then the separately licensed Advanced Authentication on a smartwatch, for remote access and over RADIUS.

OpenText NetIQ (official)·Demo, May 2026

Token Exchange for Right Sized Access | NetIQ Access Manager

How Access Manager narrows a token before it is passed on to an API.

OpenText NetIQ (official)·Short, May 2025

Two-factor authentication on Apple Watch with OpenText Advanced Authentication

The separately licensed MFA layer approving a sign-in from a watch.

OpenText NetIQ (official)·Demo, 2023

Secure Remote Access | NetIQ Advanced Authentication

Advanced Authentication guarding remote access; recorded before the 2025 renaming.

OpenText NetIQ (official)·Demo, 2023

MFA solution -- RADIUS integration | NetIQ Advanced Authentication

Adding MFA to RADIUS-based VPN and network sign-ins, from 2023.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why OpenText NetIQ Access Manager

Every app keeps its own login until something sits in front of it. Access Manager federates the apps that can and gates the ones that can’t.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Single sign-on that stays on your servers

Access Manager is installed, not rented. It runs as Docker containers with Helm charts for Kubernetes, as a soft-appliance ISO on SLES or RHEL, or in a single-tenant private cloud. Tokens, sessions and audit trails sit wherever you put the cluster, which settles the residency question before a lawyer has to ask it.

02

Old web apps join the login without rewrites

Most estates have apps that will never speak SAML. The Access Gateway sits in front of them as a reverse proxy and supplies identity for them, and a browser plug-in or desktop agent covers the rest; OpenText claims 100% SSO coverage that way. Cloud-only identity providers usually reserve that job for a premium tier.

03

Risk is checked during the session, not once

The built-in risk engine has nine rule types and keeps scoring the user’s requests in context after sign-in. When a score rises, Advanced Authentication can step the user up to one of 30+ methods, FIDO2 and OATH among them. WS-Federation and WS-Trust support keeps older Microsoft-style apps in scope as well.

04

Where it stops

There is no public price and no self-serve trial, and real MFA means buying Advanced Authentication too. You run, patch and scale it: NVD lists June 2026 flaws fixed only in 5.1.3, and CVE-2021-22506 in pre-5.0 builds is on CISA’s KEV list. The 5.1 Analytics Dashboard is deprecated, and no analyst ranking is cited.

The idea
One sign-in, even for apps without SAML
The residency
Self-hosted, in your own Indian DC
The price
Quote-only; MFA licensed separately
Proof, not promises

The numbers behind the platform

5 standards
federation protocols on one server: SAML, OAuth, OpenID Connect, WS-Federation, WS-Trust
— Vendor
9 rule types
in the built-in risk engine that re-scores requests throughout a session
— Vendor
500+
prebuilt connectors that OpenText lists for Access Manager integrations
— Vendor
100%
SSO coverage OpenText claims using federation, plug-in, gateway or desktop agent
— Vendor
30+
authentication methods in Advanced Authentication, the separately licensed MFA layer
— Vendor
1 KEV entry
CVE-2021-22506, an information leak in builds before 5.0, is on CISA’s exploited list
— CISA

What your NetIQ Access Manager rollout looks like

Week 1Model

Inventory every login

List each web app, how it signs users in today — SAML, OIDC, WS-Fed or a form — and which ones can never federate.

Week 2Decide

Choose where it runs

Pick Kubernetes with Helm charts, the soft appliance or private cloud, in your Indian DC, and size the cluster for peak sign-ins.

Week 3Pilot

Federate the first apps

Connect the directory, then bring Microsoft 365 and two SAML apps under one login before touching anything legacy.

Month 2Prove

Put a legacy app behind the gateway

Front one non-federating app with the Access Gateway, test header injection, and write risk rules that trigger step-up MFA.

Month 3Commit

Roll out and patch on a cycle

Move the remaining apps in waves, upgrade to 5.1.3 or later, and set a routine for applying OpenText security fixes.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
41+ reviews*
78% would recommend
Federation coverage4.4
Legacy app gateway4.3
Adaptive access4.0
Ease of administration3.6
Value for money3.7
5★
37%
4★
41%
3★
15%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our core banking portal had no SAML at all. The Access Gateway put it behind the same login as M365 without a code change.”
IAM Architect
BFSI
Government
“We have to keep identity data on our own racks, so a product we install ourselves was the only option that passed review.”
CISO
Government
Telecom
“Running it on Kubernetes with the Helm charts beat the old appliance builds, but plan for proper staging before upgrades.”
Platform Engineer
Telecom
Manufacturing
“WS-Federation support kept two ageing .NET apps in SSO that our cloud IdP shortlist would have left out entirely.”
Identity Engineer
Manufacturing
Healthcare
“The REST APIs in 5.1 let us script config across environments. The older console was much slower to work in.”
IAM Administrator
Healthcare
Education
“Strong product, but MFA is a second licence and the quote took weeks. Budget for Advanced Authentication from day one.”
Head of IT Infrastructure
Education
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the access management market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Access Management Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
OpenText NetIQ Access ManagerThis page

Quote-only; self-hosted, with MFA licensed separately.

Grid 02 · The architecture

Self-Hosting × App Coverage

The grid nobody publishes — how much of the stack you can run yourself, India included, vs how many kinds of app it can bring into single sign-on.

Hosted IdPs with gatewaysSelf-run full coverageCloud MFA layersOn-prem authenticators
OpenText NetIQ Access ManagerThis page

Self-hosted; five federation standards plus a reverse-proxy gateway.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

NetIQ Access Manager vs the SSO and MFA field

Against Okta Single Sign-On, Cisco Duo, miniOrange SSO, Fortinet FortiAuthenticator and ManageEngine AD360 — on deployment, legacy apps, MFA, price, limits and India.

DimensionOpenText NetIQ Access ManagerOkta Single Sign-OnCisco DuominiOrange SSOFortinet FortiAuthenticatorManageEngine AD360
What it isSelf-run SSO + gatewayCloud identity providerMFA first, SSO addedCloud or on-prem IAMAuth server applianceAD-centred IAM bundle
DeploymentContainers or applianceSaaS onlySaaS, gateway on-premCloud or on-premiseHardware or VMSelf-hosted install
Federation standardsSAML, OIDC, WS-Fed +SAML, OIDC, SWA, SCIMSAML and OIDCSAML, OAuth, OIDCSAML, RADIUS, LDAPVia ADSelfService Plus
Apps without federationGateway, plug-in, agentGateway in top suiteNetwork Gateway, PremierIn-house apps from $3Network access focusFederated apps only
MFA and adaptive riskRisk engine; MFA extraAdaptive from $14Risk-based from $6Adaptive from $3FortiToken and FIDO2MFA via ADSelfService
Pricing modelQuote onlyPer user, five suitesPer user, four editionsPer user, three plansAppliance + user licencePer component unit
Published entry priceNot published$6/user/monthFree up to 10 users$2/user/monthNot publishedStore calculator
Included vs add-onMFA licensed apartGateway in EnterpriseRemote access, PremierLegacy apps, EnterpriseTokens bought apartPick components
Scale and limitsNo ceiling published7,000+ integrationsFree tier caps at 105,000+ integrations1,500 or 8,000 baseSized by domain/users
Directories and integrationsM365, SharePoint, APIsUniversal DirectoryDuo Directory or any IdPAD, LDAP, SCIMAD/LDAP, FabricAD, M365, Exchange
India data locationYour own data centreIndia tenants, 2026Mumbai data centreOn-prem, Pune vendorYour applianceYour own server
Support and trialNo self-serve trial30-day free trial30-day trial30-day trial, all plansTrial via FortinetDownloadable trial
Lock-in and exitStandards out, rules inOkta-run tenantSits beside your IdPSame plans, two formsTied to FortinetTied to AD
Best fitSelf-hosted web estatesCloud-first, SaaS-heavyFast MFA over any IdPBudget, cloud or on-premFortinet network estatesAD and M365 shops
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose NetIQ Access Manager if…

  • ✓Identity data and sessions must stay on your own servers, in an Indian data centre or a private cloud
  • ✓You have web apps that will never speak SAML and need a reverse-proxy gateway to join single sign-on
  • ✓You need WS-Federation and WS-Trust alongside SAML and OpenID Connect, with risk re-checked through the session

Compare alternatives if…

  • ✓You would rather rent the IdP than patch it — Okta now offers Indian tenants and Duo runs a Mumbai data centre
  • ✓You want a price before a sales call — Okta, Duo and miniOrange all publish per-user rates
  • ✓Your apps are mostly SaaS and already federate — a hosted IdP needs no gateway of your own

Do not expect…

  • ✓A published price, a self-serve trial, or MFA without a second licence for Advanced Authentication
  • ✓A hosted SaaS edition of Access Manager itself — Identity Foundation is the separate cloud product
  • ✓A current analyst ranking — OpenText cites none for Access Manager

OpenText NetIQ Access Manager is one of 26 iam, sso & mfa products TechBag carries. The IAM, SSO & MFA guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do separate logins cost you?

Drag the sliders (employees who sign in; employee-hour cost). Estimates model time lost to separate logins, lockouts and password resets at an assumed 1.5 hours per employee a year, with 70% of it removed by single sign-on across federated and gateway-fronted apps. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual login and reset cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: OpenText prints no price for Access Manager, Advanced Authentication or the SaaS Identity Foundation, and there is no INR rate card. Budget for two licences if you need MFA beyond the risk engine, plus the servers and people to run the cluster. TechBag gets both quoted together, then converts to INR with GST.

Access Manager

Best for self-hosted SSO and legacy web apps

  • Quote only; no public list price
  • Identity Server, Access Gateway, risk engine
  • Runs on Kubernetes, appliance or private cloud

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Advanced Authentication

Best when risk rules must step up to MFA

  • Quote only; licensed separately
  • 30+ methods including FIDO2 and OATH
  • Cloud service or on-premises

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
App inventory

Which apps federate over SAML, OIDC or WS-Fed, and which need the Access Gateway or a desktop agent instead?

2
Hosting

Will it run on Kubernetes with Helm charts, as the soft-appliance ISO, or in a single-tenant private cloud?

3
Data location

Which Indian data centre holds the cluster, and where do logs and audit trails get shipped after that?

4
MFA

Is Advanced Authentication in the same quote, and which of its 30+ methods will users actually enrol?

5
Risk rules

Which of the nine risk-rule types will you use, and what score should trigger a step-up or a block?

6
Patching

Are you on 5.1.3 or later, past CVE-2026-11877, and who applies OpenText fixes and on what schedule?

7
SaaS option

Would OpenText’s SaaS sibling, Identity Foundation, suit some users, given no India region was found for it?

8
Licence

Does the quote state the licence metric, support level and term? Ask for INR with GST and the renewal uplift.

FAQ

Questions buyers ask

It is OpenText’s self-hosted access management product: an Identity Server that federates apps over SAML, OAuth, OpenID Connect, WS-Federation and WS-Trust, and an Access Gateway reverse proxy that brings apps with no security model into the same single sign-on.

Ready to evaluate NetIQ Access Manager?

Map which of your apps federate and which need the gateway first, or let a TechBag advisor scope a pilot that puts one legacy app behind single sign-on.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.