Try our new research platform with insights from 80,000+ expert users

Microsoft Entra ID vs Microsoft Entra ID Governance comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 2, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Entra ID
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
1st
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
266
Ranking in other categories
Single Sign-On (SSO) (1st), Authentication Systems (1st), Identity Management (IM) (2nd), Access Management (1st), Microsoft Security Suite (2nd)
Microsoft Entra ID Governance
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
10th
Average Rating
7.6
Reviews Sentiment
6.3
Number of Reviews
13
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of December 2025, in the Identity and Access Management as a Service (IDaaS) (IAMaaS) category, the mindshare of Microsoft Entra ID is 22.9%, down from 29.8% compared to the previous year. The mindshare of Microsoft Entra ID Governance is 2.2%, up from 0.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Identity and Access Management as a Service (IDaaS) (IAMaaS) Market Share Distribution
ProductMarket Share (%)
Microsoft Entra ID22.9%
Microsoft Entra ID Governance2.2%
Other74.9%
Identity and Access Management as a Service (IDaaS) (IAMaaS)
 

Featured Reviews

JP
Senior Information Security Engineer at a financial services firm with 1,001-5,000 employees
Implementing seamless integration boosts secure access and supports Zero Trust
What I appreciate the most about Microsoft Entra ID is that it integrates seamlessly with all the Defender products and is easy to use. Microsoft Entra ID's integration capabilities influence our Zero Trust model by allowing us to enforce our Zero Trust model. Conditional access policies allow us to leverage Microsoft Entra ID to verify that devices signing in to our cloud services are coming from registered devices, and that people are passing all the other requirements we have in order to complete sign-on or conditional access policies. Since implementing Microsoft Entra ID, I've observed changes in the frequency and nature of identity-related security incidents. The organization already had it implemented when I arrived, and I've been working to enhance it. Better configuration of Microsoft Entra ID has allowed us to better protect our organization from threats. Having it alone isn't a solution, but ensuring proper configuration goes a long way in preventing future compromises. My company's approach to defending against token theft and nation-state attacks has evolved since implementing Microsoft Entra ID. We haven't experienced any known compromises from nation-state attacks, and implementing newer features gives me more confidence in our protection. Regarding device-bound passkeys in Microsoft Authenticator and our approach to phishing-resistant authentication, we are currently implementing Microsoft Entra ID certificate-based authentication. Adding a strong form of MFA is important as we found it to be the most cost-effective way. While other solutions might be equally or more secure, they are significantly more expensive. Having worked as an IT consultant mainly with the Microsoft stack across various industries, I have experience with different identity management solutions. Microsoft Entra ID remains the best option. The major advantages when comparing it to Okta include integration with Defender products, Defender for Identities' integration with conditional access policies, and insider threat management integration for blocking sign-ins based on risk factors. The enhancement of Microsoft Entra ID's implementation is relatively straightforward. My main concern is the occasional lack of documentation and the frequency of changes, which can make feature location challenging.
JG
Lead Cloud Systems Architect at a computer software company with 5,001-10,000 employees
Access reviews and lifecycle policies have streamlined privileged account oversight and onboarding automation
I am not using the access review agent feature in Microsoft Entra ID Governance because that is in preview right now, and I do not know if that is available. My perception of Microsoft Entra ID Governance's ability to handle large volumes of users access and management tasks is good. There is a slight delay from creation of the actual access review to how long it takes to complete the actual review. For us, we are a large organization with over ten thousand employees. If we are doing a review on a larger group that has thousands of employees inside of it, it takes a while to actually complete, and then it becomes a headache for managers. If there were a way to condense that or decrease the amount of time it takes to do it, that would be better. We inspect thousands of people. Microsoft Entra ID Governance can be improved, and I actually have two tickets in with you now about improvements. I would have to dig it up because I do not know off the top of my head, but you can find it. We have two tickets that have been put in by the FastTrack team that I work with for identity governance. I think it was something about the ability to stop reviews early. When you create an access review now, and you put a time gate on it, say it is the end of this week, once the access review is finished, the managers went in there and finished the access review, you cannot finish it until the end of the week. That is a slight problem because we do not get a notification for people that are on the identity side that they have actually finished that, and I think there are two tickets in for that right now.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"User and device management is the most valuable feature."
"The best feature is the single sign-on provision for the various type of users."
"Entra ID provides an excellent overview of the applications and the options applied to them."
"The most valuable feature is the ease of scalability."
"The write-back caching of Microsoft Entra ID allows us to keep our existing Active Directory environment while also using Azure services, which helped tremendously because we didn't have to do a full conversion from one to the other."
"The centralized management with the single sign-on feature of Microsoft Entra ID has been huge, and that aspect has been nice as a data point demonstrating the ROI."
"The initial setup was very straightforward."
"The centralized management feature is very valuable."
"The most valuable features are multifactor authentication and account creation for the Exchange environment in Office 365."
"The platform's most valuable feature is the single sign-on service."
"The most valuable feature of Microsoft Entra ID Governance is access reviews."
"I am very happy with the solution."
"The solution is fully scalable, supporting everything from small companies to large enterprises."
"The most valuable feature of Microsoft Entra ID Governance for identity management is multi-factor authentication."
"Access reviews are an essential feature of Entra Governance. Additionally, privileged identity management is one of its most valuable features. Just-in-time access, or Jet GIT, is integral to this system. Moreover, user behavior analytics stands out as one of its top features."
"Regarding Microsoft Entra ID Governance integration with Microsoft services, there is automated identity lifecycle management in the product."
 

Cons

"Anytime that we have tried to allow Microsoft Entra ID to authenticate our users to come back on-premises, we have run into some issues, usually with latency or delay."
"Over the past year, syncs have occasionally taken longer than expected to complete between on-premises and cloud environments."
"My understanding is, in the future, they will be able to bring everything into one single platform and they are not there yet."
"I want better integration between Azure AD and the on-prem environment because there are currently limitations that can hamper employee experience. We use a feature called password writeback, that can be challenging to implement in a hybrid environment. Employees can change their passwords using a self-service password reset (SSPR) feature, which reflects from the cloud to the on-prem identity, but not the other way around. Currently, there is no way to reflect passwords from on-prem identities to the cloud."
"The product needs to improve its support."
"Microsoft Entra ID's impact on access and identity management is relatively limited."
"The Cloud Provisioning Agent cannot provision a lot of the information that AD Connect does. For starters, the lightweight version cannot synchronize device information. If you have computers on-premises, the information about them will not be synchronized by the Cloud Provisioning Agent. In addition, if you have a user on the cloud and he changes his password, that information should be written back to the on-premises instance. But that workflow cannot be done with the lightweight agent. It can only be done with the more robust version."
"I would rate my customer service and technical support as six out of ten, noting that level two support is really poor while everything else above that is good."
"If you want to conduct access review of database-based applications, then you cannot do that."
"If you want to conduct access review of database-based applications, then you cannot do that."
"Microsoft Entra ID Governance should improve its capability to manage identities and access from a single console."
"Microsoft Entra ID Governance is relatively new, and some features require more development. For example, when creating user access review campaigns, we can't specify the time to send emails to reviewers—only the date."
"The product's workflow approval process needs improvement."
"One area for improvement in Microsoft Entra ID Governance could be providing more granular control over security policies."
"Bridging between on-premises and cloud services has the potential for improvement. For instance, it would be beneficial to be able to synchronize traditional directory schemas with Azure. I need to maintain an on-premises Active Directory server for certain required services."
"There are some areas where improvements are necessary. Even though we have almost the full package, there are some bugs."
 

Pricing and Cost Advice

"There are four different levels of subscription including the free level, one that includes the Office 365 applications, the Premium 1 (P1) level, and the Premium 2 (P2) level."
"Active Directory is bundled with a package of Microsoft services, so it doesn't cost much. I don't know about the individual license of Active Directory."
"I feel Microsoft is very costly compared to other products. That is also what management is thinking. But when we consider security and support, Microsoft is better than any other product."
"For a small business buying individual licenses, it is an affordable solution."
"Microsoft has a free version of Azure AD. So, if you don't do a lot of advanced features, then you can use the free version, which is no cost at all because it is underpinning Office 365. Because Microsoft gives it to you as a SaaS, so there are no infrastructure costs whatsoever that you need to incur. If you use the free version, then it is free. If you use the advanced features (that we use), it is a license fee per user."
"Expensive solution, but if you look at the technical benefits it provides, the price for it is decent."
"The product's price is in the midrange."
"Previously, only building and global administrators could purchase subscriptions or licenses. Mid-last year, Microsoft made it so users can purchase the license online. Microsoft business subscription is for 200 to 300 users. If you have more than 300 users, you can't purchase the business plan. You have to purchase the enterprise plan. The enterprise plan is for 301 users and above. Pay as you go is also available. If you pay as you go in Azure, you will be billed for whatever you use."
"While other products give the pricing for their application, Microsoft Entra ID Governance has a per-user-based license model."
"In the education sector where I work, the annual cost for my Google and Microsoft environments is approximately $35,000. This covers the needs of 3,400 students and 800 faculty and staff members."
"The solution's pricing is not low but reasonable."
"There are no additional costs besides the standard licensing fees."
report
Use our free recommendation engine to learn which Identity and Access Management as a Service (IDaaS) (IAMaaS) solutions are best for your needs.
879,310 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Computer Software Company
11%
Manufacturing Company
9%
Government
8%
Computer Software Company
16%
Energy/Utilities Company
8%
Healthcare Company
8%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business85
Midsize Enterprise38
Large Enterprise155
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise2
Large Enterprise9
 

Questions from the Community

How does Duo Security compare with Microsoft Authenticator?
We switched to Duo Security for identity verification. We’d been using a competitor but got the chance to evaluate Duo for 30 days, and we could not be happier. Duo Security is easy to configure a...
What do you like most about Azure Active Directory?
It is very simple. The Active Directory functions are very easy for us. Its integration with anything is very easy. We can easily do third-party multifactor authentication.
What is your experience regarding pricing and costs for Azure Active Directory?
My experience with the pricing, setup costs, and licensing of Microsoft Entra ID is that it is decent.
What do you like most about Microsoft Entra ID Governance?
The most valuable feature of Microsoft Entra ID Governance is access reviews.
What needs improvement with Microsoft Entra ID Governance?
I am not using the access review agent feature in Microsoft Entra ID Governance because that is in preview right now, and I do not know if that is available. My perception of Microsoft Entra ID Gov...
What is your primary use case for Microsoft Entra ID Governance?
My main use cases for Microsoft Entra ID Governance are access reviews, but specifically Privileged Identity Management access reviews. I am utilizing the user-centric access reviews in Microsoft E...
 

Also Known As

Azure AD, Azure Active Directory, Azure Active Directory, Microsoft Authenticator
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Microsoft Entre ID is trusted by companies of all sizes and industries including Walmart, Zscaler, Uniper, Amtrak, monday.com, and more.
Information Not Available
Find out what your peers are saying about Microsoft Entra ID vs. Microsoft Entra ID Governance and other solutions. Updated: December 2025.
879,310 professionals have used our research since 2012.