Dimitri Cabete Jorge, Co-Founder & CTO · Last updated: August 2026 · Facts verified: August 2026
TL;DR verdict: Microsoft Entra ID (formerly Azure AD) is Microsoft's cloud identity platform, and for most Microsoft 365 or Azure customers it is already paid for. The catch is licensing: risk-based Conditional Access and full governance sit behind P2 and a paid add-on, so the bundling advantage and the paywall are one fact seen from two sides. It is the default for Microsoft-anchored organizations; SaaS-diverse stacks will find Okta a more natural fit.
Ratings: G2: 4.5/5 · Gartner: 4.5/5 , verified August 2026
What Is Microsoft Entra ID?
Microsoft Entra ID is Microsoft's cloud-based identity management service and the foundation of the Microsoft Entra family. Microsoft announced the rename from Azure Active Directory on July 11, 2023 and completed it over the rest of that year; login URLs, APIs, PowerShell cmdlets, and auth libraries were unchanged. Entra ID itself handles authentication and access-policy enforcement for users, devices, apps, and resources. The family now reaches past people. Entra Workload ID governs workload identities and Entra Agent ID governs AI-agent identities, which sit alongside Entra ID rather than inside it. Gartner Peer Insights reviewers gave it a 2026 Customers' Choice badge for user authentication.
What Is Microsoft Entra ID Used For?
In Microsoft-heavy organizations, Entra ID is the login for Microsoft 365, Azure, and the SaaS apps around them, and the place where access decisions are made.
- Onboard a new hire's access on day one: Accounts, group memberships, and licenses follow from the directory record, and inbound feeds from HCM systems like Workday can start the process before the first Monday.
- Retire access at exit: The same path runs in reverse, so a leaver loses app access when the account is disabled rather than weeks later.
- Satisfy an access-recertification requirement: Reviewers confirm on a schedule that access still matches policy, which is what SOC 2 and ISO 27001 auditors ask for.
- Let a contractor reach one app without a tenant account: Microsoft Entra External ID gives external identities their own way in, under the same policy conditions applied to employees.
- Cut the password and MFA-reset queue: Employees reset their own credentials instead of opening a ticket for it.
- Keep on-premises apps under the same rules: Microsoft Entra Connect extends cloud access policies to legacy applications that never moved.
Key Features of Microsoft Entra ID
Entra ID's 2026 surface is a set of named components, several of them new enough that an evaluation from last year no longer describes the product.
- SSO and MFA. Covers the full Microsoft suite plus the third-party SaaS apps in Microsoft's application gallery via SAML, OAuth, and SCIM, with phishing-resistant methods (FIDO2, Windows Hello, passkeys).
- Conditional Access. The policy engine that combines user risk, sign-in risk, device platform, network location, and client app to enforce Zero Trust access under Microsoft's own guidance.
- Identity Protection. Microsoft's risk engine applies AI and ML across Microsoft security signals to block or challenge anomalous token use, impossible travel, and unfamiliar sign-ins.
- ID Governance and Access Reviews. Access certifications with ML assistance, entitlement management with separation-of-duties checks, lifecycle workflows, and full Privileged Identity Management.
- Global Secure Access. Internet Access, an identity-centric secure web gateway, went GA in September 2024. Private Access replaces the VPN with Zero Trust Network Access, and both sit inside Entra Suite, Microsoft's paid add-on bundle.
- AI-era identity (2026). Microsoft Entra Agent ID gives every AI agent a directory identity of its own, so Conditional Access policies, role assignments, and activity logging apply to agents the way they apply to people.
- Agent governance. Agent 365 shipped in May 2026 and extends Entra network controls to Copilot Studio agents. Security Copilot handles lifecycle-workflow management inside Entra ID Governance.
Microsoft Entra ID Pros & Cons
For Microsoft-first estates the identity layer is largely pre-paid; the cost is licensing gates on the best controls and real operational complexity.
What Users Say
What users consistently praise:
- SSO breadth and third-party coverage. Single sign-on is the headline strength, praised for the range of supported apps and the ease of bringing third-party SaaS into the identity perimeter.
- MFA implementation. Phishing-resistant methods, FIDO2 keys and Windows Hello among them, come with the platform, so there is no separate MFA vendor to buy, license, and support.
- Microsoft 365 and Azure fit. The value compounds when the org already runs Microsoft 365 or Azure, since the identity layer is bundled with licenses teams already pay for.
- Conditional Access policy engine. Enforcing device compliance, MFA strength, and location rules from a single policy framework is the most-praised capability on the platform.
- Centralized management and self-service password reset (SSPR). One administrative surface covers governance, authentication, and security, and SSPR removes a recurring category of password tickets from the helpdesk queue.
What users consistently complain about:
- Licensing paywalls for advanced controls. Advanced security and governance require paid upgrades that add real per-user cost, and this is the complaint that turns up on every platform.
- Fragmented, slow admin experience. Administration spans PowerShell, Azure CLI, Graph API, and the Entra portal; sign-in log queries are slow, and the Azure AD rename left lingering documentation drift.
- Non-Microsoft integration takes real work. Connecting tools outside the Microsoft estate takes extra effort, and initial configuration is dense for teams not already operating in a Microsoft-centric environment.
- Entra Suite paywall for B2B guest lifecycle. A proper guest-account lifecycle workflow for vendor accounts requires the Entra Suite, which is a separate purchase on top of P1.
- Opaque risk engine, short log retention. Entra ID Protection misclassifies legitimate users as risky with logic too opaque to tune. Sign-in and audit logs are retained seven days on the Free tier and 30 days on P1 or P2. Keeping them longer means routing them to Azure Monitor or a storage account, which is another bill and another system to run.
- Support is circular when things break badly. Tenant-wide lockouts can prevent opening a support ticket, and tickets routed through a cloud solution provider bounce between queues.
Where reviewers diverge:
- Bundling framing. To the people signing the invoice, Microsoft 365 inclusion is a cost advantage because the licence is already bought. To the people configuring it, security is a paid feature with the critical controls two tiers up.
- Conditional Access reliability. On the buying side it rates as a headline strength; in daily operation it is brittle at the edges. Report-only mode does not predict what breaks in production, and an authentication-strength mismatch can lock a team out of its own tenant.
Microsoft Entra ID Pricing
Paid plans are annual-commitment only; no month-to-month option is published.
Rates come from Microsoft's pricing and the 2026 packaging update. All pricing information verified August 2026.
Gotchas:
- Prices reflect Microsoft's July 1, 2026 increase, which took P1 from $6 to $7 and P2 from $9 to $10.
- Entra ID Free covers unlimited SSO and basic MFA, and every risk-based and governance control sits in a paid tier.
- Risk-based Conditional Access and full Entra ID Protection require P2.
- Access reviews require an Entra ID Governance or Entra Suite license, and Microsoft does not enumerate which capabilities work on P2 alone.
- Entra Suite requires an existing P1 subscription, so its $12 sits on top of P1's $7 rather than replacing it. Microsoft also notes special pricing for P2 and Microsoft 365 E5 customers.
- External ID core features are free for the first 50,000 monthly active users, and rates above that are published on Microsoft's External ID pricing page.
Is Microsoft Entra ID Worth It?
Yes, if your organization runs primarily on Microsoft 365, Azure, or both. P1 is included in Microsoft 365 E3 and Business Premium and P2 in E5, so the license is often already bought. Native integration with Intune, Defender, Teams, SharePoint, and Exchange means access controls that talk to the rest of your stack. For Microsoft-heavy shops it is the path of least resistance to Zero Trust, and the 2026 AI-era additions (Security Copilot, Agent ID, Agent 365) matter if you are managing Copilot Studio agents.
Look elsewhere if your stack is SaaS-diverse and non-Microsoft-first. Orgs running Google Workspace, Salesforce, Slack, AWS, and Workday as primary systems will find Entra ID adds friction, and vendor-neutral platforms price and integrate on different assumptions, with Okta the closest like-for-like. Smaller orgs replacing on-premises Active Directory may prefer JumpCloud's lighter footprint. If you only need SSO and basic MFA, Free or P1 is competitive. Full governance means P2 at $10 plus the Governance add-on at $7, which is $17 per user per month before the Suite enters the conversation.
Microsoft Entra ID vs Okta
Entra ID wins for Microsoft-anchored organizations, Okta for SaaS-diverse ones. In Gartner's access management market specifically, Entra ID scores 4.4 out of 5 across 836 reviews with 92% of reviewers willing to recommend it, against 4.6 across 1,145 reviews for Okta.
- Entra ID wins for Microsoft-anchored estates. If you already run Microsoft 365, Windows, and Azure, the identity layer is bundled with licenses you already pay for and integrates natively with Conditional Access and Intune, often at zero marginal cost.
- Okta wins for SaaS-diverse environments. It is a vendor-neutral platform that connects non-Microsoft tools such as Google Workspace, Salesforce, Slack, AWS, and Workday from one place, and it has been a Gartner Access Management Leader for nine consecutive years.
See the full comparison.
Microsoft Entra ID Alternatives
Teams leave Entra ID for two reasons: a stack too SaaS-diverse for a Microsoft-first identity layer, or an on-premises Active Directory a smaller team wants to retire.
- Okta: Pick this if your stack is SaaS-diverse and non-Microsoft-first and you want a vendor-neutral workforce IAM platform.
- JumpCloud: Pick this if you are an SMB replacing on-premises Active Directory with a lighter-weight identity and device management console, especially for distributed teams.
How Microsoft Entra ID Works With Siit
Microsoft Entra ID is a native Siit integration. An employee asks for app access or an account change in Slack or Microsoft Teams, and Siit's AI triages the request and routes it to the right approver.
Once the approval lands, Siit executes the Entra ID actions it documents. It adds or removes users from groups and updates memberships when someone changes role, and it syncs directory data to keep those records current. The request layer sits on top of your identity stack rather than replacing it.
The practical effect is that the requester stops waiting for an admin to open the Entra console, and the admin stops opening it. Automated access approvals hand that time back, and they cover the part of the job directory data alone never reaches.