Our primary use cases are to join devices to Azure AD.
Managing Director at a tech services company with 1-10 employees
Provides greater clarity on business operations and enables devices to join Azure AD seamlessly
Pros and Cons
- "The benefits of using this solution were realized straightaway."
What is our primary use case?
How has it helped my organization?
Entra ID provides more clarity regarding what's happening in the business. The benefits of using this solution were realized straightaway.
It helped save time for our IT administrators or HR department. Azure ID has positively affected the employee user experience in our organization.
What is most valuable?
We use features like a single pane of glass for managing user access to a certain degree. The admin center for managing all identity and access tasks is also good.
Moreover, we also use the conditional access feature to enforce fine-tuned and adaptive access controls. Any new user would have to go through the MFA process due to the conditional access policy. So no one gets left out. This is because of the zero-trust strategy for verifying users.
The biggest benefit of using Azure AD is that it allows us to access the information on-premise servers and also for devices that just joined Azure AD.
What needs improvement?
In future releases, I would like to see an attack simulator incorporated, especially for some of the business plans.
Buyer's Guide
Microsoft Entra ID
September 2026
Learn what your peers think about Microsoft Entra ID. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,654 professionals have used our research since 2012.
For how long have I used the solution?
I've been working with Azure AD for two years.
How was the initial setup?
The initial setup was complex, but we overcame the complexity.
What's my experience with pricing, setup cost, and licensing?
The pricing is fine. It is what it is.
What other advice do I have?
Overall, I would rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
General Manager at Kaleyra
Has good support, is easy to set up, and is stable
Pros and Cons
- "Privilege identity management is the most valuable feature."
- "The licensing and support are expensive and have room for improvement."
What is our primary use case?
We use the solution for single sign-on, provisioning, de-provisioning, conditional access, and identity governance.
How has it helped my organization?
The access governess feature improves our compliance.
What is most valuable?
Privilege Identity Management is the most valuable feature.
What needs improvement?
The licensing and support are expensive and have room for improvement.
For how long have I used the solution?
I have been using the solution for five years.
What do I think about the stability of the solution?
I give the stability a nine out of ten.
What do I think about the scalability of the solution?
I give the scalability a nine out of ten.
How are customer service and support?
The support is really good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was straightforward. The time required for deployment will vary depending on the features that we plan to use. Typically, two to three weeks should be sufficient for deployment.
What about the implementation team?
The implementation was completed in-house.
What was our ROI?
We have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
I give the cost a three out of ten. The licensing is expensive.
Which other solutions did I evaluate?
We evaluated Google Cloud Identity.
What other advice do I have?
I give the solution a nine out of ten.
Two to three engineers are required for the Maintenance. The majority of the maintenance is completed by Microsoft.
I recommend the solution to others.
We deployed the solution across multiple geographical areas.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Microsoft Entra ID
September 2026
Learn what your peers think about Microsoft Entra ID. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,654 professionals have used our research since 2012.
Professional ICT Consultant at ZenaConsult
Saved time for our IT administrators and HR departments, particularly when they need to reset their own passwords or grant permissions to other people
Pros and Cons
- "The most valuable feature is the ease with which a person can log in remotely using only a password or pin without creating a profile or policy."
- "The permission management is a mess."
What is our primary use case?
We use Azure AD which enables our customers to remotely access the shared machines within their office, allowing them to work from any location.
How has it helped my organization?
Our primary customer transitioned from using a local cluster to utilizing Azure. They initially utilized Hyper-V and have now combined Azure AD with SharePoint Office 365. This new setup has proven to be much more convenient for them compared to their previous local arrangement, which did not work well. With Azure AD, I was able to exert greater control over the content on their machine.
Azure AD saved time for our IT administrators and HR departments, particularly when they need to reset their own passwords or grant permissions to other people within the group by themselves. This saved around 60 hours in total.
Azure AD helped save around 18,000 euros.
Azure AD significantly improved the employee user experience in the company by providing them with enhanced accessibility to their information and facilitating seamless login and logout from their machines while working from home. This is a significant shift from the previous system that relied on a local username and VPN connection and was limited to a fixed cluster.
What is most valuable?
The most valuable feature is the ease with which a person can log in remotely using only a password or pin without creating a profile or policy.
What needs improvement?
The permission management is a mess because it is not centralized, especially when we go back from Azure, which is quite big to SharePoint. This is not really well done and has room for improvement.
I would appreciate it if Azure AD could provide an option to simplify its interface by removing unnecessary features for small companies with a maximum of 50 users. This would make it more user-friendly for our customers who find the current interface overwhelming due to its numerous options.
For how long have I used the solution?
I have been using the solution for almost 12 years.
What do I think about the stability of the solution?
Azure AD is a stable solution.
What do I think about the scalability of the solution?
Although Azure AD is intended to be scalable, we have not yet verified its scalability by adding more users.
How was the initial setup?
The initial setup is straightforward. The deployment required around six hours. I only had to import to write the existing users into Azure.
What about the implementation team?
The implementation was completed in-house.
What's my experience with pricing, setup cost, and licensing?
The solution can be cheaper.
Which other solutions did I evaluate?
I evaluated Google Workspace but I prefer Microsoft.
What other advice do I have?
I give the solution a nine out of ten.
The only maintenance required for Azure AD is to modify certain parts on Windows by using policies.
The usefulness of Azure AD depends on several factors such as our intended use, the current system, the number of users, and organizational size. While Azure AD is an excellent choice for larger companies, it may not be beneficial for individuals.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. customer/partner
Director of Business Operations & Program Management at a healthcare company with 11-50 employees
A stable, scalable product offering excellent permissions management
Pros and Cons
- "The features around permissions are excellent."
- "The ease of use regarding finding audit information for users could also be improved."
What is our primary use case?
The solution acted as a source of truth for everyone internally and those we collaborated with externally. We deployed it in the cloud, so many of our users are remote and spread across the country.
What is most valuable?
The features around permissions are excellent.
What needs improvement?
The general usability of the site could be improved.
The ease of use regarding finding audit information for users could also be improved.
We want to see better integration with other Microsoft 365 products; it's a separate tool, but they all need to work together.
For how long have I used the solution?
We've been using Azure Active Directory for about four years.
What do I think about the stability of the solution?
The product is very stable; I rate it nine out of ten for stability.
What do I think about the scalability of the solution?
Azure AD is very scalable; I rate it nine out of ten for scalability.
How are customer service and support?
The customer service needs improvement; it takes a long time to open a ticket and get it resolved.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We previously used Google G Suite and switched to Azure AD for better security, and to match the platform our clients are using to allow easier collaboration with them.
How was the initial setup?
The initial deployment was straightforward, although we initially found it challenging to understand how to use Azure AD to manage access and permissions with external parties. We carried out the setup using three staff; myself and the IT team.
What was our ROI?
We have seen an ROI with the solution; the ability to collaborate with external partners provided tremendous value.
Which other solutions did I evaluate?
I evaluated Okta some years ago, so that information isn't fresh.
What other advice do I have?
I rate the product nine out of ten, and I recommend it.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
A turnkey solution with excellent boards for task tracking, but the UI and UX need improvement
Pros and Cons
- "The boards for task tracking are a valuable feature."
- "Many of the features are outdated, so the UI and UX could be improved."
What is our primary use case?
The primary use cases are task tracking and technical documentation, but I'm a project manager, so I also use the product for other jobs.
We have around 15 total users, with a couple of admins.
What is most valuable?
The boards for task tracking are a valuable feature.
Azure AD is a turnkey solution; it provides many features for developers to use in one place.
What needs improvement?
Many of the features are outdated, so the UI and UX could be improved.
The wiki is hard to use as it's more of a repository for technical information, but when I'm writing a PRD, I need more tools for writing.
It would be good if the UI were more visually appealing, as it looks dated compared to other products on the market. It works fine for the dev team, but the navigation could be improved, especially for managers.
For how long have I used the solution?
I've been using the solution for around two years.
What do I think about the stability of the solution?
The stability is okay overall.
What do I think about the scalability of the solution?
The product is highly scalable; it's enormous and has many features.
Which solution did I use previously and why did I switch?
I previously used a variety of solutions for task management, including Asana, Teamwork from Microsoft, Jira, and so on.
How was the initial setup?
I wasn't involved in the deployment; the solution was already in place when I arrived. It doesn't require any maintenance that I'm aware of.
What's my experience with pricing, setup cost, and licensing?
The product is relatively affordable, especially compared to Okta, a pricey solution.
Azure AD helped save my organization money, as it's a turnkey solution for dev management, though I can't say precisely how much as I'm not involved in the financial side.
What other advice do I have?
I rate the solution six out of ten.
I don't use Azure AD's Verified ID, but I'm considering an identity management solution. I'm hesitant about which one to choose, and the choice is between a product from Okta and the one from Azure AD.
I use the Permission Management feature, which I look for when choosing an identity management product, but I'm still in the research phase with this feature.
Most of our staff are okay with the quality of the end-user experience within our organization, but it could be more comfortable to use for managers. It's a challenging solution to implement for every department or team because not everyone likes the UX, and it's pretty outdated when it comes to product document writing. I had an unpleasant experience when we had a power cut, and I lost two pages of documentation, as there is no autosave feature. This is important from a manager's perspective but less so for developers.
For those considering the solution, talk to your dev team to determine if it covers their needs. If so, use it, as it has many features and is very scalable.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Hybrid Cloud Services Identity & Access Management at a financial services firm with 10,001+ employees
Offers excellent security features and management options
Pros and Cons
- "Privileged Identity Management (PIM), managed identities, dynamic groups, and extension and security attributes are all great features."
- "Better integration with external governance products would be a welcome addition to Azure AD."
How has it helped my organization?
The solution strengthened our security posture by providing fine-grained access based on attributes, standardized names, and values. Azure AD reduced our time to market for products based on improved security.
The product also improved our service desk overhead.
Azure AD positively affected our end-user experience via reduced time to market, being an identity product for our workforce.
What is most valuable?
Privileged Identity Management (PIM), managed identities, dynamic groups, and extension and security attributes are all great features.
What needs improvement?
Better integration with external governance products would be a welcome addition to Azure AD.
For how long have I used the solution?
We've been using the solution for four years.
What do I think about the stability of the solution?
The solution is stable but can be improved, especially regarding response times.
What do I think about the scalability of the solution?
Azure AD is a cloud-based solution operating from a worldwide tenant, so scalability isn't an issue, especially from an identity perspective. We have 300,000 total end users.
How are customer service and support?
We have yet to interact with technical support, so I can't speak to that.
Which solution did I use previously and why did I switch?
We previously used standard AD.
How was the initial setup?
The setup is mixed; the startup is fast, but configuring requires the knowledge of a consultant or technical resource. Basic deployment can be completed in a day, but our greenfield deployment took a relatively long time as we're a large organization. A greenfield deployment should take at most two weeks, but implementing Azure AD into a functional environment is a project unto itself. It could take months, depending on the use cases.
Regarding maintenance, we're a global organization, and each feature has its own operating team. At our scale, a group of 25 is responsible for managing and maintaining the identity part of the solution.
What's my experience with pricing, setup cost, and licensing?
The pricing depends on the use case and can be negotiated based on volume.
What other advice do I have?
I rate the solution eight out of ten.
My advice to others evaluating the product is to do good due diligence beforehand to determine a clear set of requirements, as with any identity tool or access management solution.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Microsoft Teams Senior Engineer at a financial services firm with 10,001+ employees
Enhances security, especially for unregistered devices, and is straightforward to set up for the admins
Pros and Cons
- "It enhances security, especially for unregistered devices. It 1000% has security features that help to improve our security posture. It could be irritating at times, but improving the security posture is exactly what the Authenticator app does."
- "For the end users, it can be confusing if they have worked for another company that had the Authenticator app. It is tricky if they have already had the Authenticator app and then work somewhere else. If they have to download it again and use it again on their phone, it is something that gets complicated. I know how to get through it. They just need to uninstall and reinstall the application, but for them, sometimes, it is confusing."
- "For the end users, it can be confusing if they have worked for another company that had the Authenticator app."
What is our primary use case?
Identity verification would be the number one use case. It also factors into mobile device management for devices that aren't registered to the company. We use MFA, and the Authenticator app is a component for multifactor authentication. So, that's why we use it.
How has it helped my organization?
You can set policies to specify where users will have to use the Authenticator app to log into particular applications.
It makes all junior users accountable. There is no excuse for someone else logging into anything because of the multifactor authentication and Authenticator app. You have to verify your identity to log in to specific applications that contain confidential information, especially in a HIPAA-compliant environment.
What is most valuable?
It enhances security, especially for unregistered devices. It 1000% has security features that help to improve our security posture. It could be irritating at times, but improving the security posture is exactly what the Authenticator app does.
What needs improvement?
For the end users, it can be confusing if they have worked for another company that had the Authenticator app. It is tricky if they have already had the Authenticator app and then work somewhere else. If they have to download it again and use it again on their phone, it is something that gets complicated. I know how to get through it. They just need to uninstall and reinstall the application, but for them, sometimes, it is confusing. You can have the Authenticator app for multiple services on your phone, and that's what drives them crazy. They get a code and say "I'm using the code for the Authenticator app, but I can't get in." I tell them that it is because they already had it in, but it is for something else. They now have to add. They don't like that at all. You could be on the phone for 45 minutes trying to figure out what their problem is because they don't.
Instead of authenticating by getting a passcode or answering the phone, fingerprint identification should be added to the Authenticator app. Currently, with the Authenticator app, you have to reply to the email, enter a code, or answer the phone. It can just call my phone and then I just press the button to verify that this is me.
For how long have I used the solution?
I have been using this solution for at least six years.
What do I think about the stability of the solution?
It is very stable. If the Authenticator app is set up, you're not going to get into anything without it. It definitely works.
I'm not aware of any bugs or glitches. We usually run updates for the whole environment at a time. I'm not familiar with having run into specific bugs with the Authenticator app. I haven't had any problems over the years.
What do I think about the scalability of the solution?
I've managed over a hundred thousand users in total, but right now, there are about 10,000 users. We are HIPAA compliant. So, everybody has to use it for everything. They have to use it to log into everything under the Office 365 environment, but in other companies or other places where I worked, it was only for specific applications. So, that's based on company needs.
How are customer service and support?
I never had to call technical support for this.
Which solution did I use previously and why did I switch?
We were using normal MFA, which is similar. The Authenticator app is for mobile devices per se, but normal multifactor authentication doesn't have to focus on mobile devices. You can try and log in to, for example, SharePoint Online, and if MFA is activated, you would have to just scroll to your email and click, "Hey. Yeah, this is me." The Authenticator app is just for mobile devices in my eyes.
How was the initial setup?
It is straightforward for the admins, but end users hate it. On the admin side, it takes 20 minutes at the most.
The Authenticator app wants you to have all your prerequisites designed for whatever environment you want. If you're going through Azure, you can pick the particular applications on which you want this. You can also pick the users for whom you want it to be effective. You can pick the type of ways they authenticate through the Authenticator app. Those are the simple steps.
One person is enough for its deployment and maintenance. I do that. That's not even a role. It depends on who you are, but that's not a role. That's not something for which I would employ a person. I wouldn't employ an IT person or an administrator just to focus on this.
What's my experience with pricing, setup cost, and licensing?
I don't pay for it. Going by how I feel, I see the prices for any MFA solution going down because the more different alternatives there are, the cheaper things should be. Microsoft Authenticator app would be the preferred application, but there are too many ways to implement MFA. I don't know how much it cost, but the price should go down.
What other advice do I have?
It is pretty seamless for the end users, besides the end users having an issue setting up at times.
It is a seamless transition. It is straightforward on the admin side to set up. As a consultant, my advice to any company is that when it comes to big changes, manage end-user pain or frustration. Communicate with the end users and let them know what's going to happen. Explain to them that they're going to be frustrated, but explain why this exists.
I understand why it exists. So, it doesn't bother me, but our end users just hate it. I understand that they don't like it. Nobody likes it, but it is needed. You are never going to meet an end user who likes any type of MFA, but you need to be more clear about its purpose.
I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Architect at a financial services firm with 10,001+ employees
Helps with provisioning access to internal and external teams
Pros and Cons
- "It has things like conditional access. For example, if someone is accessing sensitive information, then we could force them to do multi-factor authentication. Therefore, we can stop access if it is coming from a location that we did not expect."
- "Azure AD has massively affected our end-user experience; it provided a single sign-on for all our partners, they don't have to remember their password, and requesting access is much better since it is all automated."
- "Compared to what we can do on-prem, Azure AD lacks a feature for multiple hierarchical groups. For example, Group A is part of group B. Group B is part of group C. Then, if I put someone into group A, which is part of already B, they get access to any system that group B has access to, and that provisioning is automatically there."
- "Compared to what we can do on-prem, Azure AD lacks a feature for multiple hierarchical groups."
What is our primary use case?
We use it for various things in the organization:
- Provisioning access to systems in the cloud for either internal teams or our partners' external teams.
- We use Azure AD for Windows device management with Azure AD Intune. We use them for the management of devices. We have company devices, laptops, or tablets all using Azure AD.
- Within Microsoft Azure, we use various services, e.g., Office 365, for granting the right level of access to the right people.
I am directly involved in the project. I know what is happening and being done by developers. I have also done some hands-on work in a test environment, using my own account, just to learn.
How has it helped my organization?
In our previous organization, we had to give continuous system access to users from external teams, who were not employed by our organization. This solution certainly helped with provisioning access to them, providing them with single sign-on access. It also monitored giant movers and leavers, which was helpful.
Azure AD has massively affected our end-user experience. It provided a single sign-on for all our partners. They don't have to remember their password. They might be accessing 10 of our systems and don't really need to remember all 10 different user IDs and passwords. In most of cases, they are accessing our systems with their own organization's identity, so they don't need to remember a second user ID and password in addition to their organization's credentials. Requesting access is much better since it is all automated.
What is most valuable?
Their connection to the on-prem AD is a strong point. A lot of organizations already use on-prem Active Directory. That easily lends to using Azure AD compared to other providers.
I like the automated provisioning of access, either for internal teams or external teams.
It has things like conditional access. For example, if someone is accessing sensitive information, then we could force them to do multi-factor authentication. Therefore, we can stop access if it is coming from a location that we did not expect.
What needs improvement?
Compared to what we can do on-prem, Azure AD lacks a feature for multiple hierarchical groups. For example, Group A is part of group B. Group B is part of group C. Then, if I put someone into group A, which is part of already B, they get access to any system that group B has access to, and that provisioning is automatically there.
Geo-filtering is not that strong in Azure AD, where we need it to identify and filter out if a request is coming unexpectedly from a different country.
For how long have I used the solution?
I have been using it for five and a half years on multiple projects.
What do I think about the stability of the solution?
It is very stable. In the last five years, we only had two major incidents on Azure AD. This is key for Azure services. If your Azure AD is down, then it brings down a lot of other services within Azure.
What do I think about the scalability of the solution?
It is very scalable.
My previous organization, which did power plant construction, had hundreds of partners at any time and about 10,000 internal staff.
The product is extensively used. Many times, we have changed the way that we design based on new features introduced by Azure AD, so that drives what we do and how we design. Therefore, if they introduce a new feature, we send it straight on to be researched, then determine where we can use it.
How are customer service and support?
I am not directly in touch with technical support. I have never been on the other end calling Microsoft for technical support.
Which solution did I use previously and why did I switch?
We didn't use another solution prior to Active Directory, which has been in place for a long time (20 to 30 years).
When we started using this feature, it saved time when provisioning access to users. Critically, it removed access to users who did not need access to the system. That was a significant improvement. Time-wise, we saved about tenfold. Its day-to-day maintenance is also much easier than without it.
We chose Azure AD when going to the cloud. It was key for us to maintain security within the organization. I don't think we could imagine securing our cloud without identity management as strong and rich as Azure AD. It is a key player in anything that we do on the cloud to secure resources and a critical element that determines our security.
How was the initial setup?
I have set up test environments. The setup is easy, not difficult at all. This is one of the solution's strong points.
A lot of people already have on-prem Active Directory. It is a natural step to extend it to Azure.
Compared to other products in the market, the Azure AD deployment is the fastest. Depending on the size of the organization, it could take weeks or months to deploy.
What about the implementation team?
For an organization of 10,000 users, there might be a team of five to six people supporting AD for day-to-day things.
What's my experience with pricing, setup cost, and licensing?
Pricing-wise, they offer a stepladder approach. You can start with the lowest level features, then start increasing based on new requirements.
Which other solutions did I evaluate?
I have not really tried any other products, so I wouldn't be able to compare it with other stuff.
What other advice do I have?
Start small, then expand it. When your organization wants to add Azure AD, you can try it on a smaller scale first.
I would rate it as eight out of 10. I am unfamiliar with other products in this market. That is why I am compelled to give it eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Principal at a computer software company with 51-200 employees
It allows us to issue a single credential to every employee and not worry about managing a lot of passwords
Pros and Cons
- "Azure AD allowed us to get rid of servers and other hardware running at our offices. We moved everything to the cloud. Once we set up roles and permissions, it's only a matter of adding people and removing people from different groups and letting permissions flow through."
- "Azure AD is essential to how the business runs."
- "I would like to see a better delegation of access. For instance, we want to allow different groups within the company to manage different elements of Azure AD, but I need more granularity in delegating access."
What is our primary use case?
Azure AD manages the identities of all our employees.
How has it helped my organization?
Azure AD allowed us to get rid of servers and other hardware that run at our offices. We moved everything to the cloud. Once we set up roles and permissions, it's only a matter of adding people and removing people from different groups and letting permissions flow through.
It also saved us some money. Our IT group is tiny, so any automation we can do is valuable. We haven't had to grow the team beyond three. The employee reaction to Microsoft Entra has been positive. People like to have a single credential for accessing all our Microsoft and non-Microsoft apps.
What is most valuable?
I like Azure AD's single sign-on and identity federation features. It allows us to issue a single credential to every employee and not worry about managing a lot of passwords. Microsoft Entra provides a single pane of glass for managing user access, and we're pleased with it.
Entra's conditional access feature enables us to set policies up based on the location and risk score of the account and the device they use to access the network. Permission management lets us assign roles for various Azure functions based on functions people perform in the company. It helps us bundle access to different things by associating it with a given role at the company.
What needs improvement?
I would like to see a better delegation of access. For instance, we want to allow different groups within the company to manage different elements of Azure AD, but I need more granularity in delegating access.
For how long have I used the solution?
We've been using Azure AD for 10 years.
What do I think about the stability of the solution?
I rate Azure AD nine out of ten for stability. They've had issues in the past, but it's been quite some time. It has been nearly two years since the last availability problem.
What do I think about the scalability of the solution?
We only have 100 employees at the company, so we're nowhere near the maximum limits. I know of a massive company that adopted Azure AD. I imagine it's scalable well beyond the size of our company.
How are customer service and support?
The support is decent. I always manage to find what I'm looking for. If it's not in the documentation, there are lots of blog posts that third parties have written, and I always seem to find what I need. I rate Microsoft support nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used the on-premises version of Active Directory, but we switched to the cloud to get rid of all of our hardware. We don't run any servers in the officer anymore.
How was the initial setup?
Setting up Azure AD was straightforward. It's all delivered online, so it's only a matter of filling in the parameters for our organization. After that point, it scales easily.
There's no traditional maintenance. We have to perform audits on accounts to ensure that people and permissions are still online. There isn't product or data maintenance.
What was our ROI?
Azure AD is essential to how the business runs. We're only investing more in the whole Microsoft Suite.
What's my experience with pricing, setup cost, and licensing?
We're a Microsoft partner, so we get partner benefits. We pay almost nothing, and it's massively valuable to us.
Which other solutions did I evaluate?
We didn't look at anything else because we're committed to Office 365, and we need to be on Active Directory for Office 365. It's a well-known, trusted solution so we never did an analysis of alternatives.
What other advice do I have?
I rate Azure Active Directory nine out of ten. I'm sure there are some areas for improvement, but it's extremely valuable to us and the way that we operate.
Since we began to use Active Directory, I've learned a lot about industry best practices, particularly digital identity and its role in zero trust. By using a major mainstream identity provider, we're able to move toward the whole zero-trust model that's popular right now.
If you implement Azure AD, you need to consider the third-party apps you want to integrate. If they support competitors like Okta, Ping, and SailPoint, then they will almost certainly support Azure AD legacy applications. However, older software applications don't integrate well with Azure AD.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Cloud Architect
Offers fine-grained control through conditional access policies, facilitates review of suspicious sign-ins, and the support is good
Pros and Cons
- "The most valuable feature is the conditional access policies. This gives us the ability to restrict who can access which applications or the portal in specific ways."
- "Using this product has also had a positive effect on our end-user experience."
- "If your organization requires additional security then the subscription will be more expensive."
What is our primary use case?
We use this solution to authenticate to the portal. There are also some VMs that are not domain-joined, so we use Azure users that we create natively in the portal.
We also use it for our applications. The accounts that we create natively in Azure are used for application authentication.
We have a hybrid deployment model where some accounts are primarily native in Azure, whereas others are on-premises. We also have accounts that are synchronized between our on-premises servers and Azure.
How has it helped my organization?
Azure AD has features that have helped to improve our security posture. We have a service called Azure AD Privileged Identity Management, where instead of our administrators having permanent access or permanent admin assignment, they can now activate admin roles only when they need to perform administrative-level tasks.
This means that instead of using permanent assignments, our administrators activate the specific roles that they need at the moment that they need them. After the task is complete, the administrative access expires. This has definitely improved our security posture.
Using this product has also had a positive effect on our end-user experience. The self-service password reset is something that has definitely improved our end-user experience. Instead of having to call our service desk, users can now reset their own passwords.
This is important because due to our multi-factor authentication, we no longer have policies where we have to have periodic password changes. We have three and four-factor stages of authentication, which makes our logins more secure. This is why users don't have to change or reset their passwords on a regular basis.
One of the ways that Azure AD has improved the way our organization functions is to help cut down on service desk requests. If I have an issue with my password, in the past, I would have had to log a ticket with the service desk. With most of us working remotely, this would've posed a challenge. It would have required the service desk to verify that I am who I say I am, for example. Now, because users set up their own profiles and are able to change passwords for themselves, at any moment that their account is compromised, they're able to change their own password.
Overall, this solution has definitely improved our organization's security posture. We no longer have permanent administrative permission assignments, and we are also able to restrict who is able to log in to certain applications. Finally, we are able to see and review any risky or suspicious sign-ins.
Specifically, in the infrastructure team, we now have managed identities. Instead of having to create service accounts, we have managed identities that are directly linked to our resources that support them. All of that is managed by Azure Active Directory.
Another way that this solution has improved how we do our work is that we no longer have to keep a record of all service accounts or use one service account for multiple services. Now, each service that supports managed identities can have its own service account, and that is managed by Azure AD.
What is most valuable?
The most valuable feature is the conditional access policies. This gives us the ability to restrict who can access which applications or the portal in specific ways. We are able to define access based on job roles. For example, I'm primarily in the infrastructure team and only certain people should be able to connect to the Resource Manager. We can also define which IP addresses or locations those people can connect from before they can access the portal.
What needs improvement?
If your organization requires additional security then the subscription will be more expensive.
For how long have I used the solution?
I have been using Azure Active Directory for approximately five years, since 2016.
What do I think about the stability of the solution?
In terms of stability, Azure Active Directory is definitely an improvement from what we used in the past. I'm happy so far with the offerings and we hardly ever have any service disruptions.
What do I think about the scalability of the solution?
We have a lot of different people using this solution. We have normal users and we have administrators. It's a large organization.
How are customer service and support?
So far, I've been happy with the technical support.
There are very few service disruptions and also, because of our agreement with Microsoft, we are able to get escalated support.
We hardly ever have any downtime. When we do need support, it's normally escalated and our service is restored in a reasonable timeframe.
I would rate the technical support a nine out of ten.
Which solution did I use previously and why did I switch?
Prior to this solution, we used the on-premises version of Active Directory.
The switch was part of our cloud migration strategy. For us to be able to use our apps and workloads in the cloud, we had to have Identity Management as part of our migration scope. It's linked to our cloud migration strategy.
How was the initial setup?
I was not involved with the initial setup but I assume that it was not complex because we have Microsoft consultants assisting us.
What about the implementation team?
We specifically work with Microsoft directly. We don't use a reseller or service provider. All of the assistance that we get is directly from the vendor.
Our technical team is responsible for deployment and maintenance. I'm not sure how many people are in that team. Somebody from security is involved, but I'm not sure what other roles are required for maintenance tasks.
What was our ROI?
We have definitenly seen a return on investment from using this product. We have seamless authentication, quicker response times, more robust security, access from anywhere without having to set up VPN links, and federated models.
If we had similar services on-premises, I assume that it would be expensive, especially given that we used to have a perpetual licensing model. Now that we are able to have a subscription-based service, it has not only improved our security posture but also cut down on costs.
What's my experience with pricing, setup cost, and licensing?
My advice concerning the pricing and licensing would vary depending upon the stage of maturity of the organization. I've been with companies that are using the Office 365 license for Active Directory, whereas others are able to use the free version of it.
For organizations such as the one that I'm at now, where we require more security and have services like the Conditional Access Policies or Privileged Identity management, you have to upgrade to a higher level of the solution.
I'm not sure about the specific costs or how they're calculated, but essentially, the costs go up based on the level of security that is required by the organization.
What other advice do I have?
I can't say for certain what our future plans are for Azure AD but I see it being used long-term. It has helped our organization to grow because of what we are able to do. Also, it has greatly improved our security posture because of the services that are available.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Entra ID Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Single Sign-On (SSO) Authentication Systems Identity Management (IM) Identity and Access Management as a Service (IDaaS) (IAMaaS) Access Management Microsoft Security SuitePopular Comparisons
Microsoft Intune
Microsoft Defender for Endpoint
Cloudflare One
Microsoft Defender for Cloud
Okta Platform
SailPoint Identity Security Cloud
Microsoft Sentinel
Microsoft Defender for Office 365
Microsoft Purview Data Governance
Microsoft Defender XDR
Workspace ONE UEM
Azure Key Vault
Ping Identity Platform
Microsoft Purview Data Loss Prevention
Google Cloud Identity
Buyer's Guide
Download our free Microsoft Entra ID Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- What are the biggest differences between Google Cloud Identity and Microsoft Azure Active Directory?
- How does Duo Security compare with Microsoft Authenticator?
- How does Microsoft Authenticator compare with Forinet FortiToken?
- When evaluating Single Sign-On, what aspect do you think is the most important to look for?
- CA SiteMinder vs IBM Tivoli Access Manager
- What single sign-on platform do you recommend?
- How much time does SSO save?
- Why is SSO needed?
- Why is Single Sign-On (SSO) important for companies?













