No more typing reviews! Try our Samantha, our new voice AI agent.

AWS Directory Service vs Microsoft Entra ID comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 2, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS Directory Service
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
17th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
16
Ranking in other categories
No ranking in other categories
Microsoft Entra ID
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
1st
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
278
Ranking in other categories
Single Sign-On (SSO) (2nd), Authentication Systems (1st), Identity Management (IM) (2nd), Access Management (1st), Microsoft Security Suite (2nd)
 

Mindshare comparison

As of September 2026, in the Identity and Access Management as a Service (IDaaS) (IAMaaS) category, the mindshare of AWS Directory Service is 1.0%, down from 1.7% compared to the previous year. The mindshare of Microsoft Entra ID is 16.6%, down from 24.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Identity and Access Management as a Service (IDaaS) (IAMaaS) Mindshare Distribution
ProductMindshare (%)
Microsoft Entra ID16.6%
AWS Directory Service1.0%
Other82.4%
Identity and Access Management as a Service (IDaaS) (IAMaaS)
 

Featured Reviews

Akram Zaki - PeerSpot reviewer
IT Specialist at FlairsTech
Hybrid directory service has streamlined global server access and supported reliable daily operations
Some features in AWS Directory Service are not automated and are not scriptable, so they require manual work. In today's world where everything is pretty much automated and scriptable using AI, this is a downside. The price is another concern. AWS is really expensive. They provide an awesome service in general, but it's still expensive, very expensive. AD Connector is an application which connects my own Active Directory to AWS Directory Service or AWS infrastructure. There is a bit of latency which is bound by the AD Connector availability. If the AD Connector is having issues, there is a bit of latency, but in general, it's way better than Microsoft Azure. Still, it could be better. The migration was a bit challenging and required intensive planning and migration time. That is always a hassle. No matter which cloud environment you're moving into, the migration is sensitive because you're generally moving from on-premise to a cloud environment, so there is downtime and there are unexpected issues and errors. It needs very careful planning before doing the migration itself. AWS Directory Service is lacking a few things which could be better. Single sign-on federation is missing. SCIM provisioning is not available. In my company, we use other services for SSO federation, SCIM provisioning, and authentication because of these gaps. I would like AWS Directory Service to enroll a multi-factor authentication method. I would like to have an SSO federation where users, if we're hosting applications in AWS, would not need to log in to each application. Single sign-on would log in the user to their account and from there they can open all their applications without requiring a login each time. One of the other cons in AWS is that directories cannot span multiple regions because it's a region-bound architecture. This requires several directories for multi-region deployment. This is the case on my end because my company has several branches all over the world, so it requires several deployments.
Stafin Jacob - PeerSpot reviewer
Microsoft 365 Security & Compliance Practice Lead at Invoke
Identity has become our central gatekeeper and has provided secure single sign-on for all users
Microsoft Entra ID can improve by focusing more on new passwordless methods and becoming a primary adopter. One feature we would like to see is the ability to have security questions for password resets. I know the current capability is phasing out, so we do not have an alternative method yet. Customers who already use security questions require a smoother transition for that capability to be available. My experience with the deployment has had some challenges, particularly around the Microsoft MFA campaigns. The hardest part is moving users from a different MFA provider to the Microsoft MFA provider, as it ultimately depends on user activity. In large enterprises with numerous users across various geographies, this transition takes time. If there are ways to exert more control around that process, it would improve the situation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of this solution is the security of my customers and my customers' customers."
"It's a pretty good solution in terms of performance with good availability and minimal downtime."
"AWS Directory Service is very useful; it is a role-based mechanism, similar to identity management, and it is one of the most useful AWS features."
"AWS is cost-friendly, support-friendly, and its system is 99.99% reliable."
"This solution does what we want to achieve."
"The most valuable feature of AWS Directory Service is cost-cutting features."
"The most valuable feature is ease of use."
"The most valuable feature is that because it's all in the cloud, you don't need to manage the infrastructure."
"This is the kind of solution that I feel you cannot run an organization without using."
"We are satisfied with this solution because we use all of its features."
"The user-friendliness of Microsoft Entra ID is what I appreciate the most; everything is organized, simple, and straightforward, and even new technicians can come into it and know what they're looking for, making it the main housing unit for everything that I do in my role."
"The most valuable feature is Identity and Access Management. As an IT administrator, this feature allows me to manage access for users and groups."
"The features I find most valuable are conditional access, privilege management, and dynamic groups."
"We like the ease of app registrations and single sign-on with Entra ID. It offers an easy way to add multi-factor authentication to nearly any application and system."
"Privileged Identity Management (PIM), managed identities, dynamic groups, and extension and security attributes are all great features."
"Active Directory itself is the best feature it has. It also gives us a single pane of glass for managing user access."
 

Cons

"The AWS Directory Service should be easier to integrate."
"I would like to see better integration with other business solutions."
"AWS could improve the number of regions. Azure has passed them. The ned more consistency, as far as the Northeast is concerned."
"AWS is really expensive. They provide an awesome service in general, but it's still expensive, very expensive."
"The group policy can be improved."
"AWS Directory Service needs to improve processing."
"Our only complaint is that you cannot integrate your Exchange server. Or, if you are planning to install an Exchange server on your Amazon EC2 instance, then you need to configure Active Directory on EC2 instance. We would like for this limitation to be lifted."
"I would like to grant partial access to a table contained in a database without having to provide full access to the whole database."
"The pricing is okay, however, it could always be better in the future."
"There is a feature that we have been waiting for regarding Bicep templates. The option to use Bicep templates to deploy Microsoft Entra ID objects from the Azure Portal is needed."
"The automation aspects of Entra ID could be improved, particularly when automating through different providers and SDKs. It's somewhat clunky to automate ID management, but it's great once it's set up. I would also like to see better Terraform support."
"The only issue with Azure AD is that it doesn't have control over the wifi network. You have to do something more to have a secure wifi network. To have it working, you need an active directory server on-premises to take care of the networks."
"The robustness of the conditional access feature of the zero trust strategy to verify users is adequate but not comprehensive."
"If somebody is using an IdP or an identity solution other than Active Directory, that's where you have to start jumping through some hoops... I don't think the solution is quite as third-party-centric as Okta or Auth0."
"The role-based access control can be improved. Normally, the role-based access control has different privileges. Each role, such as administrator or user, has different privileges, and the setup rules for them should be defined automatically rather than doing it manually."
"The variety of different group types has caused challenges in areas where we have Microsoft 365 groups, distribution groups, and security groups, and the different types do not always make programmatic management clear."
 

Pricing and Cost Advice

"The pricing is reasonable."
"The pricing depends because with AWS there are two types of directory objects: 30,000 and 500,000. It varies. AWS provides the pricing calculators so we can get an estimate from there as per the company requirement of how many users and objects that we need to create. So we can go to that portal, put in the data, and get the quotation. There are no extra licensing fees. It's all included."
"We pay an annual subscription fee."
"AWS' pricing is fair, and costs can be cut if you look carefully at when you're using it."
"Licensing costs for Microsoft Entra ID remain a concern, especially with the price increases in 2023."
"The licensing model is straightforward. I don't think there are any issues with the E3 license or E5 license."
"I do not have experience with pricing."
"The subscription should be categorized by business size. For example, small companies should have a discounted price, this would help small companies and the organization to be automated."
"The cost is billed on a per-user licensing basis."
"Azure Active Directory has a very extensive licensing model. Most of the features are available in the free and basic version, and then there are premium P1 and P2 editions. The licensing model is based on how many users you have per month. In Australia, for a P1 license, the cost is 8 dollars. With P1 and P2 licenses, you get a lot of goodies around the security side of things. For example, User Identity Protection is available only in P2. These are extra features that allow you to have a pretty good security posture, but most of the required things are available in the free and basic version."
"It's really affordable."
"Previously, only building and global administrators could purchase subscriptions or licenses. Mid-last year, Microsoft made it so users can purchase the license online. Microsoft business subscription is for 200 to 300 users. If you have more than 300 users, you can't purchase the business plan. You have to purchase the enterprise plan. The enterprise plan is for 301 users and above. Pay as you go is also available. If you pay as you go in Azure, you will be billed for whatever you use."
report
Use our free recommendation engine to learn which Identity and Access Management as a Service (IDaaS) (IAMaaS) solutions are best for your needs.
914,322 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Manufacturing Company
11%
Performing Arts
9%
Construction Company
8%
Outsourcing Company
13%
Financial Services Firm
10%
Manufacturing Company
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise3
Large Enterprise5
By reviewers
Company SizeCount
Small Business90
Midsize Enterprise42
Large Enterprise162
 

Questions from the Community

What is your experience regarding pricing and costs for AWS Directory Service?
The pricing is very good because it is low and there is no management cost. You do not need to hire any system administrator to manage your Active Directory.
What needs improvement with AWS Directory Service?
Some features in AWS Directory Service are not automated and are not scriptable, so they require manual work. In today's world where everything is pretty much automated and scriptable using AI, thi...
What advice do you have for others considering AWS Directory Service?
I would like AWS Directory Service to enroll a multi-factor authentication method. I would like to have an SSO federation where users, if we're hosting applications in AWS, would not need to log in...
How does Duo Security compare with Microsoft Authenticator?
We switched to Duo Security for identity verification. We’d been using a competitor but got the chance to evaluate Duo for 30 days, and we could not be happier. Duo Security is easy to configure a...
What is your experience regarding pricing and costs for Azure Active Directory?
I would rate the pricing of the product as four out of five. The product is definitely good, and I see it as part of the future roadmap for managing all endpoints.
What needs improvement with Azure Active Directory?
I believe instead of putting everything in a single form under Microsoft Entra ID, it would be best for Microsoft to segregate these features. For example, if someone wants to design the Conditiona...
 

Also Known As

AWS Managed Microsoft AD
Azure AD, Azure Active Directory, Azure Active Directory, Microsoft Authenticator
 

Interactive Demo

 

Overview

 

Sample Customers

Expedia, Intuit, Royal Dutch Shell, Brooks Brothers
Microsoft Entre ID is trusted by companies of all sizes and industries including Walmart, Zscaler, Uniper, Amtrak, monday.com, and more.
Find out what your peers are saying about AWS Directory Service vs. Microsoft Entra ID and other solutions. Updated: September 2026.
914,322 professionals have used our research since 2012.