Try our new research platform with insights from 80,000+ expert users

AWS Directory Service vs Microsoft Entra External ID comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 2, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS Directory Service
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
19th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
16
Ranking in other categories
No ranking in other categories
Microsoft Entra External ID
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
9th
Average Rating
7.8
Reviews Sentiment
5.7
Number of Reviews
17
Ranking in other categories
Customer Identity and Access Management (CIAM) (5th), Microsoft Security Suite (17th)
 

Mindshare comparison

As of March 2026, in the Identity and Access Management as a Service (IDaaS) (IAMaaS) category, the mindshare of AWS Directory Service is 1.1%, down from 1.9% compared to the previous year. The mindshare of Microsoft Entra External ID is 2.1%, up from 2.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Identity and Access Management as a Service (IDaaS) (IAMaaS) Mindshare Distribution
ProductMindshare (%)
Microsoft Entra External ID2.1%
AWS Directory Service1.1%
Other96.8%
Identity and Access Management as a Service (IDaaS) (IAMaaS)
 

Featured Reviews

Akram Zaki - PeerSpot reviewer
IT Specialist at FlairsTech
Hybrid directory service has streamlined global server access and supported reliable daily operations
Some features in AWS Directory Service are not automated and are not scriptable, so they require manual work. In today's world where everything is pretty much automated and scriptable using AI, this is a downside. The price is another concern. AWS is really expensive. They provide an awesome service in general, but it's still expensive, very expensive. AD Connector is an application which connects my own Active Directory to AWS Directory Service or AWS infrastructure. There is a bit of latency which is bound by the AD Connector availability. If the AD Connector is having issues, there is a bit of latency, but in general, it's way better than Microsoft Azure. Still, it could be better. The migration was a bit challenging and required intensive planning and migration time. That is always a hassle. No matter which cloud environment you're moving into, the migration is sensitive because you're generally moving from on-premise to a cloud environment, so there is downtime and there are unexpected issues and errors. It needs very careful planning before doing the migration itself. AWS Directory Service is lacking a few things which could be better. Single sign-on federation is missing. SCIM provisioning is not available. In my company, we use other services for SSO federation, SCIM provisioning, and authentication because of these gaps. I would like AWS Directory Service to enroll a multi-factor authentication method. I would like to have an SSO federation where users, if we're hosting applications in AWS, would not need to log in to each application. Single sign-on would log in the user to their account and from there they can open all their applications without requiring a login each time. One of the other cons in AWS is that directories cannot span multiple regions because it's a region-bound architecture. This requires several directories for multi-region deployment. This is the case on my end because my company has several branches all over the world, so it requires several deployments.
FS
Consultant at Artifield
Offers strong identity unification but needs better customization
Microsoft Entra External ID can be improved with additional features, specifically customizable flexibility and a customizable user interface for the login dialog. Currently, the login dialog has very limited customization options, which only include font styles, colors, text messages, or brand icons. Last month, Entra ID introduced some customizable features in their login dialog, but this does not apply to Microsoft Entra External ID, indicating a significant gap between the two. In theory, Entra External ID can support many external identity providers where custom login dialogs could be integrated, potentially via SSO feature coordination, although I have not yet confirmed this. Hence, enhanced customizable login options and the ability to use attribute password logins are critical features that are required for Microsoft Entra External ID to gain dominance in the authentication market.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"AWS Directory Service is secure."
"The pricing is very good because it is low and there is no management cost."
"AWS has eliminated the downtime we waste when our on-premises resources go down."
"I would rate AWS Directory Service nine out of ten."
"Two-step authentication is very useful and important."
"The AD Connector is very good and easy to implement."
"The most valuable feature is ease of use."
"We can provide specific access to people based on what they need from our accounts."
"For policy management in my organization, I would say it is perfect."
"The most beneficial feature for us is the ease of setup. With about five clicks, we can generate unique IDs and keys and set up in less than 30 minutes. We can also generate these for multiple years simultaneously, which is convenient."
"The fact that it is quite integrated into the entire Microsoft environment makes it quite easy to use."
"The single sign-on access is the most useful feature we use."
"Microsoft Entra External ID is more secure, offering a secure environment."
"The fact that it is quite integrated into the entire Microsoft environment makes it quite easy to use."
"The impact of having multiple authentication types available significantly helps with security practices using Microsoft Entra External ID."
"The most valuable feature for me is the firewall capabilities."
 

Cons

"AWS could improve the number of regions. Azure has passed them. The ned more consistency, as far as the Northeast is concerned."
"Some of the security protocols are difficult to understand."
"We had a problem with the schema uploading and setting up the directory when we are migrating our users from on-premises to cloud infrastructure."
"Our only complaint is that you cannot integrate your Exchange server. Or, if you are planning to install an Exchange server on your Amazon EC2 instance, then you need to configure Active Directory on EC2 instance. We would like for this limitation to be lifted."
"Currently, there is no option to integrate our on-premises Cisco AWS Directory Service, requiring some manual configuration. If AWS Active Directory Service provided additional domain controller functionalities, like other on-premises Active Directory, it would be very helpful."
"Accessing the data needs improvement."
"Can be improved by including on-premises access for services through Identity Access Management."
"To get CloudWatch to monitor your memory and storage, you have to do some configuration within your server, which sometimes results in errors."
"The only problem that you might face with Microsoft now is their complex licensing model."
"The training generally is complicated to understand, leading us to often go through a managed service provider."
"A common concern among the customers I visit is the unpredictability of Microsoft's costs at every renewal. This is really bothersome for the customer, and I would say it is the worst element I have seen in these years."
"The cost is very high."
"Microsoft Entra External ID isn't a complete cloud-based account solution, as it must handle internal employees and collaborate with internal Active Directory."
"The problem with Microsoft products is that they often cater to enterprise-level needs, which can be too costly for medium-sized businesses."
"There have been a couple of times when it was unavailable because of Microsoft issues, but other than that, I don't remember any problems."
"The authentication methods available are very limited, and this presents a weak point."
 

Pricing and Cost Advice

"The pricing is reasonable."
"The pricing depends because with AWS there are two types of directory objects: 30,000 and 500,000. It varies. AWS provides the pricing calculators so we can get an estimate from there as per the company requirement of how many users and objects that we need to create. So we can go to that portal, put in the data, and get the quotation. There are no extra licensing fees. It's all included."
"We pay an annual subscription fee."
"AWS' pricing is fair, and costs can be cut if you look carefully at when you're using it."
"We don't pay separately for Microsoft Entra External ID as it's part of our Microsoft Exchange subscription."
report
Use our free recommendation engine to learn which Identity and Access Management as a Service (IDaaS) (IAMaaS) solutions are best for your needs.
884,933 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Government
11%
Performing Arts
11%
Manufacturing Company
7%
Computer Software Company
13%
Financial Services Firm
11%
Manufacturing Company
10%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise3
Large Enterprise5
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for AWS Directory Service?
The pricing is very good because it is low and there is no management cost. You do not need to hire any system administrator to manage your Active Directory.
What needs improvement with AWS Directory Service?
Some features in AWS Directory Service are not automated and are not scriptable, so they require manual work. In today's world where everything is pretty much automated and scriptable using AI, thi...
What advice do you have for others considering AWS Directory Service?
I would like AWS Directory Service to enroll a multi-factor authentication method. I would like to have an SSO federation where users, if we're hosting applications in AWS, would not need to log in...
What is your experience regarding pricing and costs for Microsoft Entra External ID?
Microsoft is flexible in the pricing for the product, so I cannot say that it is expensive, but definitely they are flexible in the price lists and their ways of doing payments.
What needs improvement with Microsoft Entra External ID?
Not really at the moment, but perhaps when we go deeper into using Microsoft Entra External ID, we may experience some things we may not prefer. However, up to now, we have not encountered anything...
What is your primary use case for Microsoft Entra External ID?
When I say identity, I mean Microsoft Entra External ID. We have been using Microsoft Entra External ID since the beginning of 2022. I am using it as a client. The purposes for using Microsoft Entr...
 

Also Known As

AWS Managed Microsoft AD
Azure Active Directory External Identities
 

Overview

 

Sample Customers

Expedia, Intuit, Royal Dutch Shell, Brooks Brothers
Information Not Available
Find out what your peers are saying about AWS Directory Service vs. Microsoft Entra External ID and other solutions. Updated: March 2026.
884,933 professionals have used our research since 2012.