CyberArk Privileged Access Manager vs Microsoft Entra ID comparison

You must select at least 2 products to compare!
Comparison Buyer's Guide
Executive Summary
Updated on Sep 6, 2022

We performed a comparison between Azure Active Directory and CyberArk Privileged Access Manager based on our users’ reviews in five categories. After reading all of the collected data, you can find our conclusion below.

  • Ease of Deployment: Azure Active Directory users say deployment is simple and easy. Users of CyberArk Privileged Access Manager say the initial setup is complex and requires technical expertise.
  • Features: Users say both products have good stability, scalability, and security.

    Azure users like the solution’s ease of use, single sign on, identity-based authentication, and its privileged access management. Users say the conditional access rules are a little limiting and that provisioning is not intuitive

    CyberArk users like the solution’s performance, password protection, and monitoring tools. Reviewers mention that it lacks flexibility.
  • Pricing: Azure users mention that the solution has various levels of licenses, with a free basic tier. CyberArk users consider the solution to be expensive.
  • Service and Support: Most users of both solutions are satisfied with the level of support they receive.
  • ROI: Users of both solutions report a positive ROI.

Comparison Results: Based on the parameters we compared, Azure Active Directory is the more popular solution because its deployment is easier and it has a free version.

To learn more, read our detailed CyberArk Privileged Access Manager vs. Microsoft Entra ID Report (Updated: September 2023).
746,670 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
"Performance-wise, it is excellent.""The implementation of the PSM proxy has reduced the specific risk of "insider attacks" on our domain controllers and SLDAP servers by eliminating direct user login by an open secure connection on the user's behalf without ever revealing the privileged credentials.""It is a scalable product.""The product has allowed us to improve both the management and access to privileged credentials, while also creating a full audit trail of all activities happening within isolated sessions of all tasks and activities taking place within the solution.""It is one of the best solutions in the market. Ever since I started using this solution, there has not been any compromise when it comes to our lab.""The most valuable aspects of the solution include password management and Rest API retrieval of vaulted credentials.""The solution is scalable.""The most valuable feature of CyberArk Privileged Access Manager is the vault. I am satisfied with the interface and the documentation."

More CyberArk Privileged Access Manager Pros →

"It enhances security, especially for unregistered devices. It 1000% has security features that help to improve our security posture. It could be irritating at times, but improving the security posture is exactly what the Authenticator app does.""The most valuable feature of this solution is that is easy to use.""It's a very intuitive platform. It's easy to create groups and add people.""I like Intune's MDM and MI.""It's a very scalable solution.""We have a history of all our authentications and excellent integration with the Microsoft solutions we use at our company. It runs smoothly in Windows and macOS.""What I like is that I can go anywhere, at any time, and to any client premise, and I can simply log in to the admin panel and can serve any of my clients.""It's an easy product to maintain."

More Microsoft Entra ID Pros →

"PAM could be more user-friendly and CyberArk could update the documentation to include more real-world examples. You have to learn it yourself through trial and error. In particular, the online documentation should have more information about troubleshooting.""CyberArk PAM is a very broad product as everyone's requirements for implementation are different. In our particular case, the initial implementation was planned and developed by people who didn't know our specific network requirements, so the initial implementation needed to be tweaked over time. While this is normal, at the time all these "major" changes required CyberArk professional services to come in-plant and "assist" with the changes.""Currently, in Secure Connect, an end user is required to enter account information manually, and cannot save any of this information for future use.""The initial setup was a bit complex.""The greatest area of improvement is with the user interface of the Password Vault Web Access component.""In the beginning, CyberArk Privileged Access Manager didn't have a multifactor authentication feature, so that was an area for improvement, but now it's part of the solution. Having just one console for two CyberArk products would be good, particularly for the CyberArk Privileged Access Manager and the CyberArk Endpoint Privilege Manager, with the latter being a product for endpoint management that supports the workstations and allows you to manage workstations. In the next update of CyberArk Privileged Access Manager, it would be good to have a local agent where you can manage all users and processes, and have an agent on the servers such as Linux and Windows.""The initial setup has room for improvement to be more straightforward.""They are sometimes not flexible with things. For instance, from one day to another, there might be something that had been done years ago by CyberArk, then they say, "We do not support that." You then have to initiate a complaint and start working with them. Things might become complicated and months pass while you are working with them. Usually, they are good and fast, but sometimes they seem to be blocked with problems, e.g., you will suddenly be working with another team instead of the team that you were working with the day before."

More CyberArk Privileged Access Manager Cons →

"You can manage the users from the Office 365 administration center, and you can manage them from Azure Active Directory. Those are two different environments, but they do the same things. They can gather the features in one place, and it might be better if that place were Azure.""The only improvement would be for everything to be instant in terms of applying changes and propagating them to systems.""The pricing is okay, however, it could always be better in the future.""The technical support can be confusing - if you're looking for something very specific, it can be hard to get the right answer or a solution.""Maybe there could be a dashboard view for Active Directory with some pie or bar charts on who is logged in, who is not logged in, and on the activity of each user for the past few days: whether they're active or not active.""There is a lot of room for improvement in terms of its integration with the local Active Directory. There are some gaps in terms of the local Active Directory through which Microsoft is syncing our environment from our data center. There should be the availability of custom attributes on Azure Active Directory. In addition, there should be the availability of security groups and distribution groups that are residing on the local Active Directory. Currently, they are not replicated on Azure Active Directory by default.""I think the solution can improve by making the consumption of that data easier for our customers.""The downside of using a single password to access the entire system is that if those credentials are compromised, the hacker will have full access."

More Microsoft Entra ID Cons →

Pricing and Cost Advice
  • "It is in line with its competitors, but all such solutions cost too much money."
  • "CyberArk DNA is free if you purchase the CyberArk solution. There is no additional charge for CyberArk DNA, which is great."
  • "The main problem for the tool is its licensing. I work for a really big company. When you try to develop this as a service, usually you work with leverage teams who are formed with dozens of members. You might dedicate one FTE, or less, for something, e.g., an antivirus administrator. You might have half an FTE's effort dedicated to administering the antivirus, but then you have a team of about 30 users who might access that ticket. The problem is that CyberArk eliminated the possibility of concurrent users years ago. This is a big problem for companies who work with leverage teams. You need to pay for everyone. 40 licenses are used by 20 or 30 people. This is a big problem because licenses are not precisely cheap."
  • "It's expensive, certainly. But CyberArk is the leader in the market with regards to privileged access management. You pay a lot, but you are paying for the value that is being delivered."
  • "Previously, the pricing was very meager. They started publicizing and advertising the solution, growing CyberArk, as an organization. They also changed their pricing with that growth, e.g., the pricier the product, the more people who will purchase it."
  • "Generally, I don't get involved in the licensing or the purchasing side of it, but I do know that the licenses are expensive."
  • "CyberArk is one of the best PAM solutions and one of the most expensive, but it works better than the others, so the pricing is fair."
  • "The price of CyberArk Privileged Access Manager is expensive. There are no other fees other than the standard licensing fees."
  • More CyberArk Privileged Access Manager Pricing and Cost Advice →

  • "It is a packaged license. We have a Premium P1 subscription of Office 365, and it came with that."
  • "It's relatively inexpensive in comparison with third-party solutions. It's highly available and supported by Microsoft Azure in our enterprise agreements. With the addition of their B2C tenants, it's hard to beat from a cost perspective now."
  • "The solution has three types of tiers: E1 has very basic features. You get limited stuff in E2 and cannot have Office 360 associated with it. E3 is on the costly side and has all the features."
  • "We don't really have a choice. It's the one shop in town. If you want this, you have to pay for it."
  • "The price of the solution's license is good."
  • "The price is fine. It's a good value for the money compared with other solutions."
  • "We have a yearly license."
  • "The subscription should be categorized by business size. For example, small companies should have a discounted price, this would help small companies and the organization to be automated."
  • More Microsoft Entra ID Pricing and Cost Advice →

    Use our free recommendation engine to learn which Access Management solutions are best for your needs.
    746,670 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the… more »
    Top Answer:Licensing may sometimes seem a little complicated. A good partner from CyberArk can work it out.
    Top Answer:We switched to Duo Security for identity verification. We’d been using a competitor but got the chance to evaluate Duo for 30 days, and we could not be happier Duo Security is easy to configure and… more »
    Top Answer:Microsoft Entra ID Protection and Microsoft Sentinel are both excellent monitoring features for Microsoft Entra ID.
    Top Answer:Entra ID's pricing is comprehensive and affordable. The prices are easy to understand, and the licenses include a variety of security monitoring and additional features.
    Average Words per Review
    out of 36 in Access Management
    Average Words per Review
    Also Known As
    CyberArk Privileged Access Security
    Azure Active Directory (Azure AD), Azure Active Directory, Microsoft Authenticator
    Learn More

    CyberArk Privileged Access Manager is a next-generation solution that allows users to secure both their applications and their confidential corporate information. It is extremely flexible and can be implemented across a variety of environments. This program runs with equal efficiency in a fully cloud-based, hybrid, or on-premises environment. Users can now protect their critical infrastructure and access it in any way that best meets their needs.

    CyberArk Privileged Access Manager possesses a simplified and unified user interface. Users are able to manage the solution from one place. The UI allows users to view and manage all of the information and controls that administrators need to be able to easily access. Very often, management UIs do not have all of the controls and information streamlined in a single location. This platform provides a level of visibility that ensures users will be able to view all of their system’s most critical information at any time that they wish.

    Benefits of CyberArk Privileged Access Manager

    Some of CyberArk Privileged Access Manager’s benefits include:

    • The ability to manage IDs and permissions across a cloud environment. In a world where being able to work remotely is becoming increasingly important, CyberArk Privileged Access Manager is a very valuable tool. Administrators do not need to worry about infrastructure security when they are away from the office. They can assign and manage security credentials from anywhere in the world.
    • The ability to manage the program from a single centralized UI. CyberArk Privileged Access Manager’s UI contains all of the system controls and information. Users now have the ability to view and use all of their system’s most critical information and controls from one place.
    • The ability to automate user management tasks. Administrators can save valuable time by assigning certain management tasks to be fulfilled by the system itself. Users can now reserve their time for tasks that are most pressing. It can also allow for the system to simplify the management process by having the platform perform the most complex functions.

    Reviews from Real Users

    CyberArk Privileged Access Manager’s software stands out among its competitors for one very fundamental reason. CyberArk Privileged Access Manager is an all-in-one solution. Users are given the ability to accomplish with a single platform what might usually only be accomplished with multiple solutions.

    PeerSpot users note the truly all-in-one nature of this solution. Mateusz K., IT Manager at a financial services firm, wrote, "It improves security in our company. We have more than 10,000 accounts that we manage in CyberArk. We use these accounts for SQLs, Windows Server, and Unix. Therefore, keeping these passwords up-to-date in another solution or software would be impossible. Now, we have some sort of a platform to manage passwords, distribute the inflow, and manage IT teams as well as making regular changes to it according to the internal security policies in our bank."

    Hichem T.-B., CDO & Co-Founder at ELYTIK, noted that “This is a complete solution that can detect cyber attacks well. I have found the proxy features most valuable for fast password web access.”

    Secure access to any app or resource from anywhere

    Take advantage of adaptive identity and network access controls to secure access to any app or resource for every user or digital workload across your entire environment.

    Protect and verify every identity

    Implement consistent security policies for every user—employees, frontline workers, customers, partners—as well as apps, devices, and workloads across multicloud and hybrid.

    Provide only the access necessary

    Discover and right-size permissions, manage access lifecycles, and ensure least privilege access for any identity.

    Simplify the user experience

    Reduce IT friction and improve the hybrid workforce experience with seamless access to any resource, single sign-on, user self-service management, and automated lifecycle workflows.

    Learn more about CyberArk Privileged Access Manager
    Learn more about Microsoft Entra ID
    Sample Customers
    Rockwell Automation
    Microsoft Entre ID is trusted by companies of all sizes and industries including Walmart, Zscaler, Uniper, Amtrak,, and more.
    Top Industries
    Financial Services Firm24%
    Computer Software Company13%
    Insurance Company12%
    Healthcare Company9%
    Educational Organization28%
    Computer Software Company12%
    Financial Services Firm11%
    Financial Services Firm14%
    Computer Software Company14%
    Non Profit6%
    Educational Organization5%
    Educational Organization24%
    Computer Software Company12%
    Financial Services Firm10%
    Company Size
    Small Business21%
    Midsize Enterprise13%
    Large Enterprise66%
    Small Business15%
    Midsize Enterprise37%
    Large Enterprise49%
    Small Business33%
    Midsize Enterprise14%
    Large Enterprise54%
    Small Business19%
    Midsize Enterprise32%
    Large Enterprise50%
    Buyer's Guide
    CyberArk Privileged Access Manager vs. Microsoft Entra ID
    September 2023
    Find out what your peers are saying about CyberArk Privileged Access Manager vs. Microsoft Entra ID and other solutions. Updated: September 2023.
    746,670 professionals have used our research since 2012.

    CyberArk Privileged Access Manager is ranked 1st in Privileged Access Management (PAM) with 49 reviews while Microsoft Entra ID is ranked 1st in Access Management with 96 reviews. CyberArk Privileged Access Manager is rated 8.8, while Microsoft Entra ID is rated 8.8. The top reviewer of CyberArk Privileged Access Manager writes "Lets you ensure relevant, compliant access in good time and with an audit trail, yet lacks clarity on MITRE ATT&CK". On the other hand, the top reviewer of Microsoft Entra ID writes "Saves time, creates a single pane of glass, and offers good conditional access features". CyberArk Privileged Access Manager is most compared with Cisco ISE (Identity Services Engine), Delinea Secret Server, WALLIX Bastion, Zscaler Internet Access and SailPoint IdentityIQ, whereas Microsoft Entra ID is most compared with Google Cloud Identity, Yubico YubiKey, Auth0, Microsoft Intune and Fortinet FortiToken. See our CyberArk Privileged Access Manager vs. Microsoft Entra ID report.

    See our list of best Access Management vendors.

    We monitor all Access Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.