The FreeRADIUS project, the open source implementation of RADIUS, is an IETF protocol for AAA (Authorisation, Authentication, and Accounting).
N/A
Microsoft Entra ID
Score 8.8 out of 10
N/A
Microsoft Entra ID (formerly Microsoft Azure Active Directory or Azure AD) is a cloud-based identity and access management (IAM) solution supporting restricted access to applications with Azure Multi-Factor Authentication (MFA) built-in, single sign-on (SSO), B2B collaboration controls, self-service password, and integration with Microsoft productivity and cloud storage (Office 365, OneDrive, etc) as well as 3rd party services.
Back in the days when our company was primarily Linux and tiny we used to use free radius from Linux for our basic authentication. We only had around 3-4 Microsoft devices then and a few apple devices. But we outgrew the solution as soon as we started growing. We stuck with …
FreeRADIUS is completely scalable and supports both large and small user databases. Because it doesn't take up a lot of server resources, FreeRADIUS is well-suited for organizations with small budgets (it's in the name!) and limited networking hardware. While there is a port of it for Windows, FreeRADIUS is native to Linux so that would be a limitation for many companies who don't use it.
Overall, the Microsoft Entra ID platform is best utilized by people looking to have one platform that manages all interactions between other platforms. The Microsoft Entra ID platform allows for a seemless SSO integration, and can also integrate with Intune for MDM. Additionally, and probably the most easy to understand integration, is the integration with Active Directory, and controls associated with that.
Application integration is really good for single sign-on and managing identity overall. The correlation with Active Directory on-prem is really good, so we can manage it in a single place. It's easy to manage the users and integrate other Microsoft products. It is the base of everything else.
I would like more risk policy suggestions. I guess that situation where we had outsourced employees in a country where somehow their location was changing too often, that we would have room to go, “Hey, this needs to be a lower risk.” Or maybe having easier options to let people log in when they're deemed high risk. It’s tricky because I feel like it’s really easy to do that wrong, but it’s the main area that I think could be improved. I guess also a little bit tighter administrative integration with other Microsoft products.
MSFT Entra ID has been essential for managing our geographically dispersed team. We're confident that it will scale with us as grow, and we'll be able to take advantage of additional security and ID management features as they become necessary. Being able to centrally manage our user access from anywhere with a small support team is such a relief.
From a user perspective, 10. From an admin perspective, 7 or 8. From the user perspective, it's very easy to use, but from the admin perspective, there's a lot of things that are not easily clear, testable, or verifiable without just trying a whole bunch of scenarios.
I have not needed to engage support for anything at this time. I have been able to find the answers either online or in a knowledgebase. I tried to skip the question but it would not let me, so I rated a 9 based on other interactions with Microsoft support I have had
Make sure you use a good partner. Our implementation was a bit longer and more problematic than we expected. Our partner got it done, but, in my opinion, some of their inexperience and staffing issues were evident.
We've done stuff with Okta for Identity and Duo. Those would probably be the two big ones that I would say that people would recognize and stuff. There's some other smaller players we've talked to, but those are the two big ones that we play with. We're still using it. So, because it was integrated into everything we've already done, it just made it almost indispensable.
Microsoft Professional Services' technical knowledge is appreciable as consultants design the solution as per customer requirements. Mapping of features per user specifications and assisting Customer IT engineers to implement so they can manage and administer the services.
We previously used Microsoft Network Policy Server for our RADIUS authentication which works ok but was pretty clunky and requires Windows Server. Switching to FreeRADIUS brought our cost down to zero.
Because FreeRADIUS works natively in Linux it's easy to setup and works with all distros.
FreeRADIUS allows us to have user authentication for wifi which is much more secure than a simple shared password solution.
We are doing a lot of sign-ins and working on it, and it worked quite well. We do have Microsoft support, so yes, we can handle all of the small issues we are sometimes having. But if you want to define it, I would say yes, we like it. Overall positive.