Talk to us
by OpenTextTechBag Intel Page

OpenText NetIQ Identity Governance

Your auditor asks who approved each person’s access. A spreadsheet is not an answer — OpenText NetIQ Identity Governance builds one catalog of who has what, runs the reviews and SoD checks auditors ask for, and hands every change to Identity Manager — on your own servers or as OpenText’s SaaS.

One catalog, reviewed and enforcedSelf-hosted or SaaSPer managed identity, on quote

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Licensed per managed identity; OpenText prints no figure for either edition
Quote
Analysts
Overall Leader in KuppingerCole’s 2024 IGA Leadership Compass; no 2025 edition found
KC Leader 2024
SaaS target
Availability objective in the January 2025 service description, measured each quarter
99.9%
India
Run it on your own servers in India; the SaaS service description names no India region
Self-host

Quick answer

OpenText NetIQ Identity Governance gathers every identity and entitlement into one catalog, then runs access reviews, request approvals, segregation-of-duties checks and risk scores over it; NetIQ Identity Manager, folded in here, does the provisioning. It runs on your servers or as OpenText’s SaaS, licensed per managed identity on quote. Self-hosting keeps the catalog in India; OpenText names no India location for the SaaS. Read more ↓ Show less ↑
Part 01 · Orient

The OpenText platform family

This page covers OpenText NetIQ Identity Governance — access governance, with NetIQ Identity Manager for provisioning. The rest:

OpenText Content Management
Enterprise content management, formerly Extended ECM.
View page →
OpenText Fortify
Application security testing: SAST, DAST and SCA.
View page →
NetIQ Identity Governance
This page.
You’re here
NetIQ Access Manager
Single sign-on, federation and adaptive MFA.
View page →
NetIQ Privileged Access Manager
Privileged session control and credential vaulting.
View page →
OpenText Voltage SecureData
Format-preserving encryption and tokenisation.
View page →
OpenText Enterprise Security Manager
Real-time SIEM correlation, formerly ArcSight.
View page →
OpenText Service Management
ITSM and asset management, formerly SMAX.
View page →
OpenText AI Operations Management
Event and performance monitoring, formerly Operations Bridge.
View page →
OpenText ZENworks
Endpoint management, patching and disk encryption.
View page →
OpenText Data Protector
Enterprise backup for servers, VMs and applications.
View page →
OpenText Availability
Real-time replication and failover, formerly Carbonite.
View page →
OpenText Cloudally Backup
Microsoft 365, Google, Salesforce, Box and Dropbox backup.
View page →
OpenText Performance Engineering
Load and performance testing, formerly LoadRunner.
View page →
OpenText Functional Testing
Automated functional testing, formerly UFT One.
View page →
OpenText Core Endpoint Protection
Cloud endpoint security for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core DNS Protection
DNS filtering for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core Email Threat Protection
Email security and encryption, ex-Zix.
View page →

Quick facts

30-second orientation
Product
Access reviews, requests, SoD and risk over one identity catalog; Identity Manager provisions
Maker
Open Text Corporation, Waterloo, Ontario (NASDAQ/TSX: OTEX); CEO Ayman Antoun since April 2026
Lineage
A NetIQ product that came to OpenText with Micro Focus, acquired for about US$6 billion in January 2023
Releases
Self-hosted docs list 24.3 (v4.3.1); the SaaS release notes run to 25.1 (v4.5)
Licence
Per managed identity; Identity Manager’s limited licence covers the catalog, not reviews
Price
Not published; quoted by OpenText and its partners
Deployment
Self-hosted on Tomcat with PostgreSQL or Oracle, or SaaS with a Cloud Bridge agent
Analysts
Overall Leader, KuppingerCole IGA Leadership Compass 2024; Gartner runs no IGA Magic Quadrant
India
Self-hosted, the catalog stays on your servers; no India location is named for the SaaS
In India via
TechBag — connector scoping, quote in INR with GST, first review campaign
Part 02 · Learn

Understand identity governance before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is identity governance?

It answers who should have what, asks the right people to confirm it on a schedule, and keeps the evidence.

Spreadsheet reviews and ticketed leavers vs governed access — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionSpreadsheet reviews, ticketed leaversOpenText NetIQ Identity Governance
Who has whatExports from each app, merged by handOne published catalog of identities and permissions
Periodic reviewSpreadsheets emailed to managersReview campaigns with reasons and an audit trail
Toxic combinationsFound by the auditor, after the factSoD policies checked at request and in the catalog
LeaversA ticket, if HR remembers to raise itIdentity Manager removes access from the HR event
Proof the change happenedThe admin says it was doneNext collection verifies each fulfilled item
What it is NOT—PAM, single sign-on, or a published price list

The cheapest test is one review: collect your directory and one risky application, run it in preview with two managers, and see what it finds.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where identities and entitlements land

Catalog

Collectors, publication and the identity catalog

Collectors pull identities, accounts and permissions from AD, Entra ID, SAP, Workday and other sources; you publish each collection into one catalog that every review reads.

02
Where access is judged

Governance

Reviews, SoD, risk and roles

Review definitions, segregation-of-duties policies, risk scoring and technical or business roles all run against the published catalog, with data policies watching for drift.

03
How people ask for more

Requests

Access Request and the Workflow Engine

A self-service Access Request app routes each ask through approval policies and SoD checks; a separate Workflow Engine runs custom approvals and remediation steps.

04
How decisions reach the systems

Fulfilment

Identity Manager, connectors and Cloud Bridge

Approved changes go to Identity Manager, ServiceNow, SCIM, REST or a manual fulfiller; in the SaaS edition a Cloud Bridge agent per data centre carries the traffic.

One catalog from many collectors — reviews, SoD and risk on top, and Identity Manager carrying out each change.

Part 03 · Evaluate

Twelve capabilities. Collect, govern, fulfil.

NetIQ Identity Governance proves who should have what, and Identity Manager makes it so.

Collect
Collectors

Templates for common sources

Collector templates cover AD and eDirectory, Entra ID, SAP, Workday, Salesforce, Google, ServiceNow, JDBC, SCIM and CSV feeds.

Collect
Change events

Catch changes between runs

Identity and application sources can collect change events, so the catalog updates on a move or leave without a full re-collection.

Collect
Data policies

Flag drift as it appears

Data policies detect added or removed entities and attribute changes in published data, then trigger a remediation or a review.

Govern
Reviews

Campaigns with business context

Review definitions cover user access, accounts, permissions and roles, with preview mode before a live run and reasons on each decision.

Govern
Micro-certification

Small reviews on an event

A policy violation can open a focused review of only the affected items, run beside the scheduled campaign instead of a full re-run.

Govern
SoD

Toxic pairs, as cases

Separation-of-duties policies flag conflicting permissions at request time and in the catalog, opening cases an owner must approve or resolve.

Govern
Risk

Scores you can weight

Risk levels combine factors such as open SoD violations and permission risk into a score per user, recalculated on a schedule you set.

Govern
Role mining

Roles from real access

Automatic or visual mining proposes technical-role candidates from who holds what, up to a thousand suggestions, for you to edit and promote.

Govern
Business roles

Access by job, with approvals

Business roles bundle permissions by job or team, carry their own approval policy, and can provision or remove access as membership changes.

Fulfil
Access Request

A catalog people can shop

Users request applications, permissions or roles; approval policies route each ask and check SoD before anything is granted.

Fulfil
Fulfilment

Changes sent, then verified

Changesets go to Identity Manager, ServiceNow, SCIM, REST or a person, and the next collection confirms the change really happened.

Fulfil
Identity Manager

Joiner, mover, leaver

NetIQ Identity Manager 25.2 provisions and deprovisions accounts from HR events, with drivers for Workday, SAP, Epic and Microsoft.

See it, don’t just read it

Watch NetIQ Identity Governance in action

Running a user access review, comparing two users’ permissions, the SaaS catalog, and governing OpenText Content Management access.

NetIQ Unplugged (OpenText, official)·Demo, March 2026 · 11:47

Configuring and Executing a User Access Review (Demo): OpenText Identity Governance (NetIQ)

Builds a user access review definition, runs it and works through the reviewer’s screen.

NetIQ Unplugged (OpenText, official)·Short, March 2026 · 2:40

Using permission comparisons for quick entitlement assessment | Identity governance

Compares two users’ permissions side by side to spot access one of them should not hold.

NetIQ Unplugged (OpenText, official)·Walkthrough, March 2026 · 8:10

Identity Governance Catalog Walkthrough: OpenText Core Identity Foundation

The governance catalog as it appears inside OpenText’s SaaS identity service.

NetIQ Unplugged (OpenText, official)·Demo, March 2026 · 5:49

Governing OpenText Content Management (Extended ECM) Access with OpenText Identity Governance

Brings permissions from OpenText Content Management under the same reviews as other apps.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why OpenText NetIQ Identity Governance

Access piles up with every move and project. Identity Governance makes someone answer for it.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Governance and provisioning from one vendor

Identity Governance decides who should have what; NetIQ Identity Manager 25.2 creates and removes the accounts from HR events, with drivers for Workday, SAP, Epic and Microsoft. A revoked review item becomes a removed account, and the next collection proves it.

02

Your servers, or OpenText’s SaaS

The self-hosted edition runs on Tomcat with PostgreSQL or Oracle inside your own data centre. The SaaS edition comes with a production and a staging tenant, and a Cloud Bridge agent reaches on-premises systems. Few IGA products still offer both.

03

Reviews that react to change

Data policies watch the catalog for added, removed or changed entries, and a violation can open a micro-certification of just those items. Medica, a US health plan, says its access audit took 13 business days. OpenText was an Overall Leader in KuppingerCole’s 2024 IGA compass.

04

Where it stops

There is no public price, and self-hosting means you patch Tomcat and the database. The SaaS keeps certification data in the console for 90 days and caps data at 500 GB. Identity Manager Advanced Edition carried CVE-2024-12799, rated 10.0. Privileged sessions need a PAM product.

The idea
One catalog, reviewed and enforced
The residency
Self-host on your servers in India
The price
Per managed identity, on quote
Proof, not promises

The numbers behind the platform

13 business days
for Medica’s whole access audit, by its IT risk manager’s account on OpenText’s page
— Customer
80000 users
managed with NetIQ Identity Manager at VINCI Energies, as OpenText’s page reports
— Customer
15 template families
of collector and fulfilment templates, from AD and SAP to Workday, GitHub and SCIM
— Vendor
2-hour RPO
the recovery point the SaaS service description sets, with replicas kept in one compliance boundary
— Vendor
14 days
how long OpenText keeps each daily backup of SaaS data before it is gone
— Vendor
3 years
the SaaS reporting archive; export it before then if your auditor wants longer
— Vendor

What your NetIQ Identity Governance rollout looks like

Week 1Model

Decide what the gap really is

Separate the leaver problem from the review problem; if Identity Manager or HR feeds are missing, plan provisioning first.

Week 2Decide

Pick the deployment and count

Choose self-hosted or SaaS, count the managed identities for the licence, and list the five systems auditors ask about.

Weeks 3–6Pilot

Collect, clean and publish

Build collectors for the directory, HR and those five systems, clean entitlement names, then publish the first catalog.

Month 2Prove

Run one review in preview

Run a user access review in preview mode with two managers, fix confusing items, then go live with evidence export.

Month 3Commit

Add SoD, risk and fulfilment

Load SoD policies and risk factors, connect fulfilment through Identity Manager or ServiceNow, and turn on micro-certs.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
46+ reviews*
79% would recommend
Review campaigns4.3
SoD and risk4.1
Provisioning with IDM4.2
Ease of setup3.5
Value for money3.8
5★
38%
4★
41%
3★
14%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our quarterly access review used to be forty spreadsheets. Now managers get one task list and the evidence exports itself.”
IT Risk Manager
BFSI
Insurance
“We already ran Identity Manager, so leavers were handled. Governance added the certification trail our auditor wanted.”
IAM Lead
Insurance
Manufacturing
“Micro-certification is the useful part: a toxic SAP pair opens a small review that day, not at the half-year campaign.”
SAP Security Analyst
Manufacturing
Telecom
“Role mining proposed sensible starting roles, but cleaning entitlement names before collection took longer than mining.”
Identity Architect
Telecom
Public Sector
“Self-hosting kept everything in our data centre, which settled the regulator question. Patching Tomcat is now ours.”
Infrastructure Head
Public Sector
Healthcare
“Capable, but the first collectors needed a specialist partner, and the quote took rounds to settle the identity count.”
Head of IT
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the identity governance market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Identity Governance Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
OpenText NetIQ Identity GovernanceThis page

KuppingerCole’s 2024 Overall Leader in IGA; quote-only.

Grid 02 · The architecture

Deployment Choice × Governance Depth

The grid nobody publishes — how many ways it can be run, India included, vs how deep the reviews, SoD and role mining go.

Deep but one way to runDeep, run it your wayLight, cloud onlyFlexible but lighter
OpenText NetIQ Identity GovernanceThis page

Self-hosted or SaaS; micro-certs, SoD cases, role mining.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

NetIQ Identity Governance vs the identity governance field

Against SailPoint Identity Security Cloud, SailPoint IdentityIQ, One Identity Manager, Okta Identity Governance and Idira Identity Governance — on deployment, connectors, price, reviews, India and exit.

DimensionOpenText NetIQ Identity GovernanceSailPoint Identity Security CloudSailPoint IdentityIQOne Identity ManagerOkta Identity GovernanceIdira Identity Governance
What it isIGA + NetIQ IDMSailPoint’s SaaS IGASailPoint, self-hostedGovernance-first IGAIGA on the Okta platformZilla-based, Palo Alto
DeploymentSelf-hosted or SaaSSaaS onlySelf-hosted onlyOn-prem or On DemandSaaS onlySaaS only
Connectors15 template familiesHundreds of appsBroad, carries acrossSAP CertifiedBroad, via OktaAuto-discovery
Pricing modelPer managed identitySuites, per identityLicence + your infraPer identityPer user, monthlyPer identity, yearly
Published entry priceNot publishedNot publishedNot publishedNot published$17/user/monthNot published
Included vs add-onIDM licensed apartSAP SoD is extraYou add the infraGovernance in oneBundled in EssentialsPAM sold separately
Scale and limits500 GB SaaS capIdentity-based suitesSized by your serversNot publishedSmall floorNot published
Reviews and SoDMicro-certs + SoD casesDeep, documentedFlexible rules engineAttestation + SoDCampaigns + SoDAI-assisted reviews
Role miningAutomatic or visualDocumentedDocumentedDocumentedDocumentedDocumented
IntegrationsIDM, ServiceNow, SCIMBroad catalogSame model as ISCOneLogin, SafeguardWorkflows, Slack, TeamsIdira PAM, secrets
India storageSelf-host in IndiaAWS MumbaiYour data centreOn-prem in IndiaIndia tenants, 2026Not documented
Support24x5, Sev 1 on-callTerms in the quoteSupported, no EOLTiered offerings99.99% uptimeTerms in the quote
Lock-in and exitYour databaseSaaS, IIQ path back2–3 year migrationChoose either modelTied to OktaTied to Idira
Best fitIDM shops, self-hostedLarge regulated SaaSMust stay on-premSAP-heavy, either modelOkta already in placeIdira PAM customers
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose NetIQ Identity Governance if…

  • ✓You already run NetIQ Identity Manager and want certification, SoD and risk on top of the provisioning you have
  • ✓A regulator or board wants the governance system on servers you run in India, not in a vendor’s cloud
  • ✓You want event-driven micro-certifications rather than waiting for the half-yearly campaign

Compare alternatives if…

  • ✓You want an India cloud region documented in writing — SailPoint runs in AWS Mumbai and Okta announced Indian tenants
  • ✓You need a price before the first call — Okta lists Essentials at $17 a user a month
  • ✓Privileged accounts must sit in the same campaign as everyone else — Idira pairs governance with its own PAM

Do not expect…

  • ✓A published price, or an India region for the SaaS edition
  • ✓Privileged session control or single sign-on; those are separate NetIQ products
  • ✓A Gartner Magic Quadrant placement — Gartner publishes no IGA Magic Quadrant

OpenText NetIQ Identity Governance is one of 22 identity governance products TechBag carries. The Identity Governance guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do manual access reviews cost you?

Drag the sliders (identities in scope; reviewer-hour cost). Estimates model the time managers and IT spend gathering access lists, chasing review sign-offs and handling leavers at an assumed 1.5 hours per identity a year, with 70% of it removed by automated collection, reviews and fulfilment. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual access-review cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: OpenText licenses Identity Governance per managed identity and quotes both the self-hosted and the SaaS edition. Identity Manager is a separate licence, and its limited Governance entitlement covers catalog features only, not reviews. TechBag counts the identities first, then quotes in INR with GST.

Self-hosted

Best where data must stay on your servers

  • Per managed identity, on quote
  • Tomcat with PostgreSQL or Oracle
  • You run upgrades and recovery

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

SaaS

Best for teams that do not want to run it

  • Per managed identity, on quote
  • Production and staging tenants, 99.9% target
  • No India region named; confirm in writing

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
The real gap

Is the audit finding about missing reviews, or about leavers keeping access? The second is an Identity Manager job first.

2
Identity count

How many managed identities, including contractors and service accounts, will the per-identity licence count?

3
Deployment

Self-hosted in your Indian data centre, or the SaaS edition with a Cloud Bridge agent in each data centre?

4
Connectors

Which systems hold the risky access — core banking, SAP, HRMS — and is there a collector template for each?

5
Fulfilment

Will changes go out through Identity Manager, ServiceNow, SCIM or a manual fulfiller, and who confirms them?

6
SoD rules

Who writes the toxic-pair rules, and who owns each SoD case when a violation is found?

7
Retention

SaaS keeps certification data 90 days in the console and reports 3 years; does your auditor need more?

8
Quote

Does the quote split Governance from Identity Manager, name the edition and term, and come in INR with GST?

FAQ

Questions buyers ask

It is OpenText’s identity governance and administration product. Collectors build a catalog of every identity, account and permission; on it you run access reviews, request approvals, SoD checks, risk scoring and role mining. Changes go out through NetIQ Identity Manager or another target.

Ready to evaluate NetIQ Identity Governance?

Count the identities and the systems your auditor asks about first, or let a TechBag advisor scope a pilot that runs one access review in preview mode.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.