Microsoft Entra ID (formerly Microsoft Azure Active Directory or Azure AD) is a cloud-based identity and access management (IAM) solution supporting restricted access to applications with Azure Multi-Factor Authentication (MFA) built-in, single sign-on (SSO), B2B collaboration controls, self-service password, and integration with Microsoft productivity and cloud storage (Office 365, OneDrive, etc) as well as 3rd party services.
$6
per user/per month
Oracle ESSO
Score 10.0 out of 10
N/A
Oracle Enterprise Single Sign-On is a single sign-on (SSO) solution, originally named Passlogix and owned and supported by Oracle since 2010.
Overall, the Microsoft Entra ID platform is best utilized by people looking to have one platform that manages all interactions between other platforms. The Microsoft Entra ID platform allows for a seemless SSO integration, and can also integrate with Intune for MDM. Additionally, and probably the most easy to understand integration, is the integration with Active Directory, and controls associated with that.
Application integration is really good for single sign-on and managing identity overall. The correlation with Active Directory on-prem is really good, so we can manage it in a single place. It's easy to manage the users and integrate other Microsoft products. It is the base of everything else.
I'm not quite sure what they could do to improve, but I guess they can make it more user-friendly. It's very directed at admin staff, and perhaps there could be some better self-service features so that the admins don't have to do everything. We can let the users do some more of the work. Perhaps that'd be a good one.
This tool is essentially a hack, making the user experience pretty weak. For example, we use it in an application which has a box to type your password. Every time you enter some data, ESSO steals the focus and types your password into the box, even if you aren't about to submit the form requiring the password.
This tool creates a 2nd CN in the directory and this broke some of our applications which were only expecting a single CN per user in the directory. Why can't it use a traditional database instead?
This tool caused performance issues with Putty. It would peg our CPUs at 100% if the user had Putty running. It took a very long time to resolve the issue.
MSFT Entra ID has been essential for managing our geographically dispersed team. We're confident that it will scale with us as grow, and we'll be able to take advantage of additional security and ID management features as they become necessary. Being able to centrally manage our user access from anywhere with a small support team is such a relief.
Because there are things you can improve somewhere. Sometimes you set up something that the Microsoft Manager doesn't work with. It could be a security boundary. And then let me say the basic security boundary is not set up as we would like, though. I think it's a better approach to set it up at a different level to be highly secure, and then we can change it whenever we need it because not many people are aware of some of the functionality. A user can create a security group and create the Microsoft Entra ID. Guests can invite guests in the beginning, which is extremely hard to track later, especially if we have pre-tier and we do not send the diagnostics data anywhere else. But within the enterprise environment, it's quite okay because most companies don't go with the security defaults because we do have a premium license. So probably, I hope we are sending data somewhere else. This is why nine. Maybe information about new changes or new functionality that are coming could be better. Because when we have to go to the Microsoft admin portal to get the message information, which is extremely hard because most admins don't do that. And there are lots of notifications. So going through them and identifying the risk and overall functionality, especially the new ones, is extremely hard.
I have not needed to engage support for anything at this time. I have been able to find the answers either online or in a knowledgebase. I tried to skip the question but it would not let me, so I rated a 9 based on other interactions with Microsoft support I have had
Make sure you use a good partner. Our implementation was a bit longer and more problematic than we expected. Our partner got it done, but, in my opinion, some of their inexperience and staffing issues were evident.
We've done stuff with Okta for Identity and Duo. Those would probably be the two big ones that I would say that people would recognize and stuff. There's some other smaller players we've talked to, but those are the two big ones that we play with. We're still using it. So, because it was integrated into everything we've already done, it just made it almost indispensable.
There's no substitute for properly developed applications that delegate authentication to an external system like Active Directory or a cloud identity provider. That way, the issues with screen scraping and constantly-breaking integration are solved permanently.
Microsoft Professional Services' technical knowledge is appreciable as consultants design the solution as per customer requirements. Mapping of features per user specifications and assisting Customer IT engineers to implement so they can manage and administer the services.
So I would say all of that, especially when we look at deploying our Federation, or I would say our SSO stuff now, helps out tremendously with that. When we deploy applications to specific users, we can control that. That's a great option as well. So I would say we got a good ROI on that.
We spent a lot of time implementing it on different applications. However, because it uses screen scraping, every time our apps upgraded, it broke the integration with ESSO, so we had to keep fixing the integration. After a few years, we have stopped integrating new apps with it due to this headache.