Azure Active Directory = Microsoft Entra ID
Updated June 05, 2024
Azure Active Directory = Microsoft Entra ID

Score 9 out of 10
Vetted Review
Verified User
Overall Satisfaction with Microsoft Entra ID
We currently use Microsoft Entra ID (Azure Active Directory) for several of our companies, some are hybrid and some are Entra only. Entra provides us with a trusted and proven directory solution that works well with our other suites (such as M365) since they are all Microsoft products. With Entra, we have the flexibility to support our existing configurations (on-prem AD) while also providing support for our newest configurations (Cloud-only).
Pros
- Microsoft Entra integrates and functions very well with other applications/tools since it was developed by Microsoft.
- Entra provides us the abilities to implement conditional access policies to require additional verifications (or lack thereof if needed) before granting access to a resource.
- The ability to implement passwordless logins via Windows Hello or Authenticator sign-ins is extremely useful as companies transition to Zero Trust
Cons
- Sometimes navigation in Entra ID can be challenging because (due to all the features) options are often buried deep in the site. This can slow up technicians until they get familiar with exactly what section they need to navigate to in order to perform a specific function/task.
- To further expand on the above statement, Microsoft has a history of moving and/or renaming functions and products so it can be a challenge to find features at times.
- Due to the sheer amount of features that Entra ID offers, it has a very steep learning curve to fully understand everything it can do....and how to use/configure each function.
- Our organization covers Cyber Security insurance and as part of the review/auditing, we are able to save on insurance premiums since we implement the security features of Entra ID.
- The ability to use conditional access policies helps us to increase security without negatively impacting our users. For example, we can require additional verifications based on geographic location of sign-in attempts. This means that users on our internal network can sign-in with MFA, but sign-in attempts from outside of the network require additional factors before being authenticated.
We are a holdings company that has approximately 30 companies under our umbrella. Some of our companies are using an on-prem (hybrid) domain and some are cloud-only. The intent is to move all of our companies to cloud-only in the near future, but in the meantime Entra provides us the flexibility to manage all of our companies regardless of their location.
Yes, we currently have implemented Meraki sign-ins into Entra ID. This enables us to leverage security groups to grant access to the administration portal for the Meraki devices. This application shows up when a user logs into their M365 dashboard (after the app has been assigned to them). They can simply launch the application/dashboard right from their list of apps.
We are using Team Dynamix (TDX) as a project management and ticketing system currently as a SaaS application. Yes, we do have several on-premises applications connected via Entra ID. Our SIEM tool (LogRhythm) is an on-prem appliance that we have configured to SSO via the Entra ID.
As with any change that gets implemented, end users will typically have an adjustment period. I believe that inherently people don't like change, so adoption of new products/processes can cause confusion or frustrations. Overall, we had some initial grumblings about changes to the sign-in process, but the increased security and convenience of SSO has ultimately been overall welcomed.
I was not part of the research or decision-making (evaluation) of Okta vs Entra ID. In fact, we are currently utilizing both products at this time, so I'm not quite sure you really need to select one over the other. Having so many companies and differences between them, sometimes it makes more sense to use Entra ID whereas other companies may find Okta to be a better fit.
Do you think Microsoft Entra ID delivers good value for the price?
Yes
Are you happy with Microsoft Entra ID's feature set?
Yes
Did Microsoft Entra ID live up to sales and marketing promises?
I wasn't involved with the selection/purchase process
Did implementation of Microsoft Entra ID go as expected?
Yes
Would you buy Microsoft Entra ID again?
Yes
Microsoft Entra ID Feature Ratings
Using Microsoft Entra ID
1200 - We currently have about 1200 end users in our organization, all of which have accounts in Entra ID, but as far as administration goes....we have about 35 people using Entra ID. The range of end users using Entra ID, they range from mechanics and brick layers all the way up to the owners/CEO level.
35 - With very few exceptions, most of our entire IT department have access to Entra ID and assist with the administration of it. The IT Security Team and the IT Service Desk Team do the "heavy lifting" for Entra ID, in regards to daily operations. Entra ID is relatively intuitive and easy to use with minimal skill levels required.
- We use SSO for most of our applications via app registrations and Entra ID provides us the means by which to allow this access.
- The ability to configure Conditional Access policies is also very important to our organization.
- We utilize Entra ID as a stand-alone directory for a few of our companies, while we use a Hybrid setup for others. This flexibility allows us to ensure we can administer in a variety of different scenarios.
- Our organization has not yet needed to be "creative" in using Entra ID, because the default configurations/settings have been sufficient for us.
- We plan on implementing Zero Trust shortly, and Entra ID will be vital to helping ensure our goals of Zero Trust.
Evaluating Microsoft Entra ID and Competitors
- Cloud Solutions
- Scalability
- Integration with Other Systems
- Ease of Use
With a shift to Cloud computing/hosting, choosing Microsoft Entra ID was easy. We believe that on-prem data centers are going to be a thing of the past eventually and we need to ensure we don't get left behind. Our ability to easily transition to cloud and the scalability it provides is critical to ensuring we can stay ahead of the game.
If anything, we would likely have tried to transition to Entra ID sooner had we been aware of how easy, useful, and powerful it is.
Microsoft Entra ID Support
| Pros | Cons |
|---|---|
Quick Resolution Good followup Knowledgeable team Problems get solved Kept well informed No escalation required Immediate help available Support understands my problem Support cares about my success Quick Initial Response | None |
We have not purchased premium support at this time. We operate on a fairly tight budget and our IT Department is very capable of resolving almost any issue that has arisen. Since we rarely need to engage Microsoft Support, it is more affordable to only pay for their services when absolutely needed rather than all the time.
I have not needed to engage support for Entra ID, so I cannot truthfully answer this question.
Using Microsoft Entra ID
| Pros | Cons |
|---|---|
Like to use Technical support not required Well integrated Quick to learn Familiar | Inconsistent |
- User account administration is relatively easy to use and fairly intuitive.
- Application registrations are a frequent need of ours and once you have configured one, adding others is pretty standard/similar so you can easily breeze through it. But the first one takes a little bit of "learning curve".
- Configuring IAM/permissons can be a little difficult at times. This is mainly because the level of granularity by which you are able to set permissions. Making sure that you are following least privilege policy is a challenge because you need to ensure that you are granting access to only the object/subscription you need.
Yes - The mobile interface works pretty well for me, however the limitations I have with it are based on my screen size. This is NOT an issue with their implementation but rather with the overall small screen size on my iPhone device. It is quite convenient to have the ability to make changes while on the go via the mobile interface though.


Comments
Please log in to join the conversation