No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Entra ID vs Microsoft Entra ID Governance comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 2, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Entra ID
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
1st
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
276
Ranking in other categories
Single Sign-On (SSO) (1st), Authentication Systems (1st), Identity Management (IM) (2nd), Access Management (1st), Microsoft Security Suite (2nd)
Microsoft Entra ID Governance
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
9th
Average Rating
7.8
Reviews Sentiment
6.3
Number of Reviews
14
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Identity and Access Management as a Service (IDaaS) (IAMaaS) category, the mindshare of Microsoft Entra ID is 16.1%, down from 28.4% compared to the previous year. The mindshare of Microsoft Entra ID Governance is 3.2%, up from 1.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Identity and Access Management as a Service (IDaaS) (IAMaaS) Mindshare Distribution
ProductMindshare (%)
Microsoft Entra ID16.1%
Microsoft Entra ID Governance3.2%
Other80.7%
Identity and Access Management as a Service (IDaaS) (IAMaaS)
 

Featured Reviews

Stafin Jacob - PeerSpot reviewer
Microsoft 365 Security & Compliance Practice Lead at Invoke
Identity has become our central gatekeeper and has provided secure single sign-on for all users
Microsoft Entra ID can improve by focusing more on new passwordless methods and becoming a primary adopter. One feature we would like to see is the ability to have security questions for password resets. I know the current capability is phasing out, so we do not have an alternative method yet. Customers who already use security questions require a smoother transition for that capability to be available. My experience with the deployment has had some challenges, particularly around the Microsoft MFA campaigns. The hardest part is moving users from a different MFA provider to the Microsoft MFA provider, as it ultimately depends on user activity. In large enterprises with numerous users across various geographies, this transition takes time. If there are ways to exert more control around that process, it would improve the situation.
AmitRathod - PeerSpot reviewer
Senior Analyst at Toll Holdings Limited
Automated access governance has strengthened security and supports user-centric approvals
The workflows such as joiner, mover, and leaver work in Microsoft Entra ID Governance. Entitlement Management is a bundle of resources where Microsoft Entra ID applications, groups, and SharePoint sites are packaged into a single package so that users can request it. This is one of the great features for Microsoft Entra ID Governance. Another feature is Access Review, which allows an automated schedule to be managed for the manager or resource owner so that they can verify whether people still need access. Privileged Identity Management is another feature for governance that provides just-in-time (JIT) access for administrative roles. For example, instead of being a permanent or global admin, which is a major security risk, an IT professional is eligible for the role and must request four hours of access only when they need to perform a specific task. There is a feature called access package. If any user wants particular application access, they can request this application via Microsoft Entra ID Governance access package. Whenever an end user makes a request, the access goes to one application manager and their current line manager. If they approve it, then they get the application access. This is a very good feature for user-centric purposes. Microsoft Entra ID Governance includes securing AI agent identity. As a company uses more AI generation such as Copilots or custom bots, those bots need their own identity just as employees do. Microsoft Entra now provides a way to assign unique identities to AI agents so you can control what data they can access. Microsoft Entra ID Governance protection now looks for risky behavior in AI agents. If a bot suddenly tries to download an unusual amount of data or unconscious data, it can detect this as a risk detection factor. Security Copilot allows Entra administrators to manage identity with natural language. Microsoft Entra ID Governance has protection and authentication features. Smart risk detection protects and analyzes to detect threats such as impossible travel. If a person is logging in from many different locations, it detects this as a risk factor. A user cannot use an unauthenticated password or log in from an incompatible device. These AI features are used in conditional access management in Microsoft Entra ID Governance. Automation is used for user onboarding, user offboarding, and user update processes through user lifecycle management. If an organization uses Workday as an HR application where new users join and fill in their details, all these details get reflected into Workday and then reflected into Active Directory as well as Microsoft Entra ID Governance. This automation helps to manage the day-to-day user onboarding process, user offboarding process, and user update process. Microsoft Entra ID Governance automation also helps with password-related tasks, access recertification, and reporting.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The passwordless feature of Microsoft Entra ID is the most valued feature, and its implementation has had an impact on secure app access to resources in the environment, particularly in security and compliance."
"Microsoft Entra ID scales effectively with the growing needs of our organization, as we have never faced any challenges with its scalability."
"Whether you are a small business or large business, you can always enjoy a very secure cloud platform."
"Syncing with our on-prem Active Directory is valuable because we do not have to keep multiple identities for each of our staff members. We can easily evaluate login risks and provide access for SSO via 365 into applications, such as Salesforce, and other things that we run our business on."
"Being able to use Azure AD means that you can use some of the Azure AD security features like Advanced Password Protection. As well as querying your normal password requirements like lengths and complexity, Azure AD has a feature in which you can put specific words. It can be words to do with your company, words to do with your company location, or words that a lot of your employees would otherwise use. You can disallow them. It's very good at making more obvious passwords, ones they're not allowed to use anymore. That's a good feature."
"Federated identity management is a great feature for the zero-trust model."
"I like that you can run it on-premises. I also like that I can use Azure at any time as the main one."
"I like Azure AD's conditional access policies. Microsoft Entra provides a single pane of glass for managing user access, improving the overall user experience."
"The best features are Access Review and Entitlement Management, where recertification can be run on-demand or on a time-based schedule so that all privileged users get certified by their managers regarding whether they still need access, making it a very good feature for user-centric purposes."
"Access reviews are an essential feature of Entra Governance. Additionally, privileged identity management is one of its most valuable features. Just-in-time access, or Jet GIT, is integral to this system. Moreover, user behavior analytics stands out as one of its top features."
"The features of Microsoft Entra ID Governance have benefited our organization because we have ServiceNow in our organization and we have been able to create integrations through Lifecycle Management to do onboarding and offboarding easier."
"The most valuable feature of Microsoft Entra ID Governance for identity management is multi-factor authentication."
"The product's most valuable features are the robust audit trail capabilities."
"Regarding Microsoft Entra ID Governance integration with Microsoft services, there is automated identity lifecycle management in the product."
"The solution is fully scalable, supporting everything from small companies to large enterprises."
"The platform's most valuable feature is the single sign-on service."
 

Cons

"My problem with Azure AD is that it's designed for medium to large systems, and we're not that large."
"We'd like to be able to link to non-Mircosft products, like Linux."
"Technical support is a thing they need to improve a lot from their side."
"I want better integration between Azure AD and the on-prem environment because there are currently limitations that can hamper employee experience. We use a feature called password writeback, that can be challenging to implement in a hybrid environment. Employees can change their passwords using a self-service password reset (SSPR) feature, which reflects from the cloud to the on-prem identity, but not the other way around. Currently, there is no way to reflect passwords from on-prem identities to the cloud."
"The pricing is okay, however, it could always be better in the future."
"One thing that bothers me about Azure AD is that I can't specify login hours."
"For the end users, it can be confusing if they have worked for another company that had the Authenticator app."
"Its area of improvement is more about the synchronization of accounts and the intervals for that. Sometimes, there are customers with other network challenges, and it takes a while for synchronization to happen to the cloud."
"Microsoft Entra ID Governance is relatively new, and some features require more development. For example, when creating user access review campaigns, we can't specify the time to send emails to reviewers—only the date."
"One area for improvement in Microsoft Entra ID Governance could be providing more granular control over security policies."
"There are some areas where improvements are necessary. Even though we have almost the full package, there are some bugs."
"Sometimes, the solution is not super reliable."
"Bridging between on-premises and cloud services has the potential for improvement. For instance, it would be beneficial to be able to synchronize traditional directory schemas with Azure. I need to maintain an on-premises Active Directory server for certain required services."
"The platform's configuration process needs improvement."
"The product's workflow approval process needs improvement."
"I would rate customer service at three out of ten."
 

Pricing and Cost Advice

"We don't really have a choice. It's the one shop in town. If you want this, you have to pay for it."
"Entra ID is not too bad, but Microsoft licensing generally is insane. Most customers normally buy a bundle license with Microsoft 365, E3, or E5. Out of our 2,000 customers, for 99.9% of our customers, the Entra ID license that they are getting through the part of that would be sufficient. There are some more advanced ones that give you a bit more functionality, but we probably have not had a customer for that. We do not even internally use that ourselves. When you buy the Entra ID license on its own, it is probably three or four pounds. You just get it included in the license."
"This product is sold as part of the enterprise package and our licensing fees are paid on a yearly basis."
"Active Directory is bundled with a package of Microsoft services, so it doesn't cost much. I don't know about the individual license of Active Directory."
"MFA and P2 licenses for two Azures for fully-enabled scenarios and features cost a lot of money. This is where Okta is trying to get the prices down."
"It is a packaged license. We have a Premium P1 subscription of Office 365, and it came with that."
"I work for an academic medical center, where there is a watch kept over every dollar spent. I do have concerns about the micro charges for different levels or features of the product."
"The licensing model is straightforward. I don't think there are any issues with the E3 license or E5 license."
"While other products give the pricing for their application, Microsoft Entra ID Governance has a per-user-based license model."
"In the education sector where I work, the annual cost for my Google and Microsoft environments is approximately $35,000. This covers the needs of 3,400 students and 800 faculty and staff members."
"The solution's pricing is not low but reasonable."
"There are no additional costs besides the standard licensing fees."
report
Use our free recommendation engine to learn which Identity and Access Management as a Service (IDaaS) (IAMaaS) solutions are best for your needs.
893,311 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Manufacturing Company
8%
Government
8%
Computer Software Company
8%
Computer Software Company
11%
Government
9%
Financial Services Firm
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business90
Midsize Enterprise40
Large Enterprise161
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise3
Large Enterprise10
 

Questions from the Community

How does Duo Security compare with Microsoft Authenticator?
We switched to Duo Security for identity verification. We’d been using a competitor but got the chance to evaluate Duo for 30 days, and we could not be happier. Duo Security is easy to configure a...
What is your experience regarding pricing and costs for Azure Active Directory?
My experience with pricing, setup cost, and licensing is that going through and being able to use these things is always part of delivering an M365 bundle, so I don't think the experience is great ...
What needs improvement with Azure Active Directory?
Microsoft Entra ID can be improved by open-sourcing it. You already have Windows Subsystem for Linux, which is open-source Linux in Microsoft. One major shift for Microsoft would be using the commo...
What needs improvement with Microsoft Entra ID Governance?
There is one feature that I do not prefer. If a manager approves access for a particular user and wants to change their decision about whether the user should retain access or not, once they approv...
What is your primary use case for Microsoft Entra ID Governance?
I use Microsoft Entra ID Governance for identity and access management as well as access recertification. The workflows such as joiner, mover, and leaver work in Microsoft Entra ID Governance. Enti...
What advice do you have for others considering Microsoft Entra ID Governance?
The best features are Access Review and Entitlement Management. Recertification can be run on-demand as and when any recertification slip occurs. There is also time-based recertification, which we ...
 

Also Known As

Azure AD, Azure Active Directory, Azure Active Directory, Microsoft Authenticator
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Microsoft Entre ID is trusted by companies of all sizes and industries including Walmart, Zscaler, Uniper, Amtrak, monday.com, and more.
Information Not Available
Find out what your peers are saying about Microsoft Entra ID vs. Microsoft Entra ID Governance and other solutions. Updated: April 2026.
893,311 professionals have used our research since 2012.