

ForgeRock and Microsoft Entra External ID compete in identity and access management, each offering unique benefits. Microsoft Entra External ID has the upper hand with seamless Azure integration and potentially quicker ROI through bundled services.
Features: ForgeRock offers dynamic authorization, identity orchestration, and rich API capabilities for customization. Microsoft Entra External ID features strong Azure service integration, allowing streamlined processes and substantial scalability. The key difference is ForgeRock's focus on a customizable experience, while Entra emphasizes integration within Microsoft systems.
Ease of Deployment and Customer Service: Microsoft Entra External ID has an intuitive setup process, benefiting from native Azure integration and strong support channels for quick resource access and assistance. ForgeRock requires more complex initial deployment but offers robust customization. Microsoft stands out in deployment due to a streamlined process leveraging existing infrastructures.
Pricing and ROI: ForgeRock has a higher initial setup cost but justifies it with long-term ROI through customization and scalability. Microsoft Entra External ID offers competitive pricing beneficial for those integrated into Azure, providing potentially quicker ROI through reduced infrastructure changes. The distinction lies in ForgeRock's long-term customization benefits versus Entra's cost-effective integration.
On a B2B level, it opened up the market for TomTom to sell its services in a more efficient way to car companies.
We can use a Linux image from ForgeRock with different systems, applications, websites, and mobile apps to create various types of access for users.
I can definitely see that fewer employees are needed compared to using different SaaS applications.
It has led to cost savings as well as time savings because I can use a single solution for all applications.
Companies can leverage it for setting up external identities without needing to develop their own solutions.
In terms of return on investment, prior to using this product, our company managed our own mail server with all internal authentication happening on premises, resulting in a ROI in the thousands every year.
The support portals offer comprehensive documentation, troubleshooting guides, and community forums that have been helpful for resolving common issues independently.
For standard support tickets, response times were very decent, and the support team was helpful in identifying configuration issues, especially with authentication trees, token settings, and directory replications.
The customer support is very flexible and supportive, particularly in the area of automation and customer deployments.
Companies without a Microsoft license for Entra ID or Azure portal cannot add Azure AD B2C, creating logistical issues for some of my clients who are unable to evaluate the platform.
The support for business applications, infrastructure support, and Entra has been mostly positive with highly skilled technicians.
The documentation is very thorough, reducing the need for support.
The access management layer is stateless, so I can scale horizontally by adding more nodes behind a load balancer as traffic increases.
The platform provides flexible authentication trees, enabling us to design custom MFA flows tailored for different user groups and risk profiles.
We scaled up with ForgeRock. My team received an award for implementing it for a 60 million customer base, which was the largest implementation at that time.
This is one of EID's weak points compared to Azure AD B2C, which offers customizable authentication options, including attribute and password combinations.
End-user workloads experience increased latency in a cloud environment compared to on-premises resources.
Microsoft Entra External ID is quite scalable, and I would rate its scalability between eight and nine out of ten.
ForgeRock supports integration with legacy systems in our organization by offering a wide range of connectors and APIs.
ForgeRock is very stable because it manages access, authentication, and authorization effectively.
I'd rate the stability of the Microsoft Entra External ID as a 10.
The stability of this solution is very good.
I have not encountered any stability issues with Microsoft Entra External ID.
ForgeRock needs to focus on low-code, no-code solutions that allow for drag-and-drop functionality with good orchestration.
It would be better if they were available for support whenever the customer needs it, especially during migration or go-live time periods.
The main area is complexity. ForgeRock is extremely flexible, but the learning curve can be steep.
This is particularly challenging during enterprise agreement renewals, as it's difficult for customers to review costs leading to lengthy negotiations.
Enhanced customizable login options and the ability to use attribute password logins are critical features that are required for Microsoft Entra External ID to gain dominance in the authentication market.
I would like to see a more detailed alert system that provides a summary of why alerts are generated, who is generating them, and the reasons behind it.
The pricing, setup cost, and licensing are very straightforward, which is a good success.
One has to spend considerable time trying to understand the different modules and different needs for those modules on the licensing front.
Regarding pricing, the cost seems high for single sign-on, especially for external applications like Oracle.
Microsoft's pricing is complex and difficult to fathom due to a range of different licensing options.
The cost can be a factor for Microsoft Entra External ID, but in general, it offers a scalable and efficient solution compared to deploying individual solutions.
Centralized management makes the biggest difference because it allows us to define, update, and enforce security and compliance rules from a single location.
ForgeRock positively impacts our organization as we manage a large number of users with ease, providing a standard IAM solution that simplifies our processes.
ForgeRock has positively impacted my organization by allowing us to migrate from the older system to the newer ForgeRock component, enabling us to go live with many products across geographies, enhancing security as it is all cloud-based, and with the company taking care of availability, it has reduced costs for the company.
It is crucial for hybrid environments, especially for integrating existing on-site infrastructures with cloud-based Active Directory, such as in Office 365 implementations.
EID unifies workforce users with external business partners, which is a very strong feature.
The detailed monitoring and reporting in Microsoft Entra External ID support compliance efforts effectively.
| Product | Mindshare (%) |
|---|---|
| ForgeRock | 8.1% |
| Microsoft Entra External ID | 5.0% |
| Other | 86.9% |
| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 5 |
| Large Enterprise | 18 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 2 |
| Large Enterprise | 6 |
ForgeRock is a comprehensive open-source identity and access management solution designed to meet the unique needs of your users and workforce. With ForgeRock you can orchestrate, manage, and secure the complete lifecycle of identities in any cloud or hybrid environment. ForgeRock allows you to set up bot detection, identity proofing, and risk-based authentication.
With ForgeRock, you can define access policies and automate the management of the identity lifecycle all from a central, easy to use, and graphical dashboard. ForgeRock Access Management allows you to build safe authentication using options like passwordless and usernameless logins, single sign-on, biometrics, contextual analytics, and behavioral authentication. When threats appear, you can swiftly change how your users access your most sensitive applications and provide users with secure access to the applications, systems, and resources they need on demand.
ForgeRock Benefits and Key Features
Reviews from Real Users
ForgeRock stands out among its competitors for a number of reasons. Two major ones are its robust identity and access tools and its being easy to manage and scale with one central dashboard.
PeerSpot users note the effectiveness of these features. A technology solutions leader at an outsourcing company writes, “We need it for multiple clients, multiple implementations. Not all of them are necessarily a multi-tenant solution. We need a very versatile solution that can do a lot of work, but from a single instance that we can centralize authentications and we don't duplicate the efforts and that's where ForgeRock seems to do better.”
Mohamed B., a cyber security consultant at a tech company, writes, "Their access management solution, OpenAM, is most valuable because it meets the needs of a lot of users. ForgeRock secured our system so that it is accessed only by authorized people, and it implemented the SSO."
Microsoft Entra External ID, part of Microsoft Entra, provides highly secure digital experiences for partners, customers, citizens, patients, or any users outside your organization with customization controls. Combine external identities and user directories in one portal to seamlessly manage access across the organization.
Microsoft Entra External ID refers to all the ways you can securely interact with users outside of your organization. If you want to collaborate with partners, distributors, suppliers, or vendors, you can share your resources and define how your internal users can access external organizations. If you're a developer creating consumer-facing apps, you can manage your customers' identity experiences.
With External ID, external users can "bring their own identities." Whether they have a corporate or government-issued digital identity, or an unmanaged social identity like Google or Facebook, they can use their own credentials to sign in. The external user’s identity provider manages their identity, and you manage access to your apps with Entra ID or Entra External ID to keep your resources protected.
The following capabilities make up External ID:
We monitor all Customer Identity and Access Management (CIAM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.