Try our new research platform with insights from 80,000+ expert users

Microsoft Entra ID vs Microsoft Entra ID Governance comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 2, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Entra ID
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
1st
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
219
Ranking in other categories
Single Sign-On (SSO) (1st), Authentication Systems (1st), Identity Management (IM) (1st), Access Management (1st), Microsoft Security Suite (2nd)
Microsoft Entra ID Governance
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
15th
Average Rating
7.4
Reviews Sentiment
7.0
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of April 2025, in the Identity and Access Management as a Service (IDaaS) (IAMaaS) category, the mindshare of Microsoft Entra ID is 28.4%, down from 29.0% compared to the previous year. The mindshare of Microsoft Entra ID Governance is 1.3%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Identity and Access Management as a Service (IDaaS) (IAMaaS)
 

Featured Reviews

Aaron Liang - PeerSpot reviewer
Has significantly improved secure access to applications and resources in our environment
Microsoft Entra ID has helped by simplifying our management of permissions for APIs. We are not directly exposing credentials, as we use tokens instead. It has made management easier and more secure, especially in a multi-user environment. The implementation of Microsoft Entra ID significantly improved secure access to applications and resources in our environment, primarily through the widespread use of single-sign-on. Managing API permissions became much easier, as application registration often involves calling an API to utilize services without directly exposing credentials, relying instead on token-based authentication. This streamlined approach benefits end-users by simplifying access while remaining transparent to them. Ultimately, my role focuses on ensuring a smooth and user-friendly experience, even if the underlying technology remains unseen by the end-users. Our company strongly emphasizes passwordless authentication, primarily through device-bound passkeys in Microsoft Authenticator. While administrators with high-privileged accounts utilize YubiKeys and passwords for tasks like accessing Microsoft Graph, we are actively transitioning all other users towards passwordless methods such as Windows Hello biometrics. This approach streamlines authentication and enhances security. Though initial deployment in 2022 presented challenges due to hardware limitations and the lingering effects of the COVID-19 pandemic, the technology has significantly improved and provides a simple and effective user experience.
William Kox - PeerSpot reviewer
Great policies and timelines for streamlined compliance
There are some areas where improvements are necessary. Even though we have almost the full package, there are some bugs. I cannot directly perform some tasks from the portal. First, I have to go to the policy, change it, and then return to the package to add it. I cannot do it directly from the package. Workarounds are needed, so that can be improved. At the moment, that is the only issue we are facing that needs enhancement.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Azure Active Directory has many automation capabilities, and you can apply policies on top. You can do a lot of things with these combinations and integrate other tools like PingFederate."
"The best thing about Active Directory is its compatibility. It works with lots of third-party vendors. We're using multiple products, and they're all integrated with our Active Directory."
"The security features, such as attack surface rules and conditional access rules, are the most valuable aspects of Azure AD."
"The ability to speed up ability is an asset."
"It enhances security, especially for unregistered devices. It 1000% has security features that help to improve our security posture. It could be irritating at times, but improving the security posture is exactly what the Authenticator app does."
"It offers good Microsoft integration capabilities."
"Microsoft Entra ID Protection and Microsoft Sentinel are both excellent monitoring features for Microsoft Entra ID."
"Federated identity management is a great feature for the zero-trust model."
"I am very happy with the solution."
"It is compliant with our RVRT and CSV guidelines."
"The most valuable feature of Microsoft Entra ID Governance is access reviews."
"The most valuable features are multifactor authentication and account creation for the Exchange environment in Office 365."
"The solution gives me the capability to automatically move guest accounts from the tenant without any manual intervention."
"The product's most valuable features are the robust audit trail capabilities."
"The platform's most valuable feature is the single sign-on service."
"The most valuable feature of Microsoft Entra ID Governance for identity management is multi-factor authentication."
 

Cons

"The product takes at least ten minutes to activate privilege identity management roles."
"The permission management is a mess."
"The frequent changes in branding cause confusion among customers who struggle to keep track of product names and functions."
"The technical support has its downsides and upsides. While they are fast, it can take time to get the right person because there are many steps to reach the appropriate team member at Microsoft support, which can be somewhat annoying."
"I would like to see some additional attributes for user objects in Microsoft Entra, especially for tasks such as users and account validation, including guest users and guest accounts."
"Microsoft Authenticator is as easy as Google Authenticator, but it is not open to all types of applications. Google Authenticator is integrated with other third-party platforms and applications, whereas Microsoft Authenticator is not. It should have more integration with third-party platforms and applications."
"Active Directory could always be more secure. Right now, we've got two-factor authentications. All services based on Active Directory have a username and password. If somebody hacked our username, they could easily get all the data from our side. So I want two-factor authentication and a stronger password policy from Active Directory. The domain controllers should be more secure as well."
"Entra ID needs to improve its application credentials and use of ID permissions. There are challenges with the management layer."
"The solution lacks the feature to work well with third-party applications."
"Even though we have almost the full package, there are some bugs."
"Bridging between on-premises and cloud services has the potential for improvement. For instance, it would be beneficial to be able to synchronize traditional directory schemas with Azure. I need to maintain an on-premises Active Directory server for certain required services."
"One area for improvement in Microsoft Entra ID Governance could be providing more granular control over security policies."
"Microsoft Entra ID Governance should improve its capability to manage identities and access from a single console."
"The platform's configuration process needs improvement."
"The product's workflow approval process needs improvement."
"Microsoft has done a commendable job with RPAX. However, Microsoft should prioritize enhancing its ABAC (Attribute-Based Access Control) capabilities. Currently, Microsoft's ABAC offering falls behind AWS in comparison."
 

Pricing and Cost Advice

"Everything needs to be considered for the requirements and if it is within the budget, then you can come up with a solution, whether it is SaaS, PaaS, or IaaS."
"Its price is per user. It is also based on the type of user that you're synchronizing up there."
"The product is relatively affordable, especially compared to Okta, a pricey solution."
"I'm not sure about the specific costs or how they're calculated, but essentially, the costs go up based on the level of security that is required by the organization."
"This product is sold as part of the enterprise package and our licensing fees are paid on a yearly basis."
"The pricing for Azure Active Directory is affordable; I would rate the cost a six out of ten."
"There are four different levels of subscription including the free level, one that includes the Office 365 applications, the Premium 1 (P1) level, and the Premium 2 (P2) level."
"There are add-on components and services, such as identity services, that we have to add to our Azure subscription. Only then can I actually say it's on par with the on-prem server edition. Why should I pay for a component? It should be included in my subscription."
"There are no additional costs besides the standard licensing fees."
"While other products give the pricing for their application, Microsoft Entra ID Governance has a per-user-based license model."
"The solution's pricing is not low but reasonable."
"In the education sector where I work, the annual cost for my Google and Microsoft environments is approximately $35,000. This covers the needs of 3,400 students and 800 faculty and staff members."
report
Use our free recommendation engine to learn which Identity and Access Management as a Service (IDaaS) (IAMaaS) solutions are best for your needs.
846,617 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
32%
Computer Software Company
10%
Financial Services Firm
8%
Manufacturing Company
6%
Computer Software Company
21%
Manufacturing Company
11%
Financial Services Firm
9%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Duo Security compare with Microsoft Authenticator?
We switched to Duo Security for identity verification. We’d been using a competitor but got the chance to evaluate Duo for 30 days, and we could not be happier. Duo Security is easy to configure a...
What do you like most about Azure Active Directory?
It is very simple. The Active Directory functions are very easy for us. Its integration with anything is very easy. We can easily do third-party multifactor authentication.
What is your experience regarding pricing and costs for Azure Active Directory?
Microsoft Entra ID is reportedly quite expensive for each user regarding security features. The renewal cost is particularly high according to the teams managing purchases.
What do you like most about Microsoft Entra ID Governance?
The most valuable feature of Microsoft Entra ID Governance is access reviews.
What needs improvement with Microsoft Entra ID Governance?
There are some areas where improvements are necessary. Even though we have almost the full package, there are some bugs. I cannot directly perform some tasks from the portal. First, I have to go to...
What is your primary use case for Microsoft Entra ID Governance?
We use it throughout the company. My colleagues and I are utilizing it, and we are creating access packages and so forth. We are using it for the entire company to manage access.
 

Also Known As

Azure AD, Azure Active Directory, Azure Active Directory, Microsoft Authenticator
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Microsoft Entre ID is trusted by companies of all sizes and industries including Walmart, Zscaler, Uniper, Amtrak, monday.com, and more.
Information Not Available
Find out what your peers are saying about Microsoft Entra ID vs. Microsoft Entra ID Governance and other solutions. Updated: March 2025.
846,617 professionals have used our research since 2012.