No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Entra ID vs Microsoft Entra ID Governance comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 2, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Entra ID
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
1st
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
276
Ranking in other categories
Single Sign-On (SSO) (1st), Authentication Systems (1st), Identity Management (IM) (3rd), Access Management (1st), Microsoft Security Suite (2nd)
Microsoft Entra ID Governance
Ranking in Identity and Access Management as a Service (IDaaS) (IAMaaS)
12th
Average Rating
7.8
Reviews Sentiment
6.3
Number of Reviews
14
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Identity and Access Management as a Service (IDaaS) (IAMaaS) category, the mindshare of Microsoft Entra ID is 15.0%, down from 28.1% compared to the previous year. The mindshare of Microsoft Entra ID Governance is 3.0%, up from 1.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Identity and Access Management as a Service (IDaaS) (IAMaaS) Mindshare Distribution
ProductMindshare (%)
Microsoft Entra ID15.0%
Microsoft Entra ID Governance3.0%
Other82.0%
Identity and Access Management as a Service (IDaaS) (IAMaaS)
 

Featured Reviews

Stafin Jacob - PeerSpot reviewer
Microsoft 365 Security & Compliance Practice Lead at Invoke
Identity has become our central gatekeeper and has provided secure single sign-on for all users
Microsoft Entra ID can improve by focusing more on new passwordless methods and becoming a primary adopter. One feature we would like to see is the ability to have security questions for password resets. I know the current capability is phasing out, so we do not have an alternative method yet. Customers who already use security questions require a smoother transition for that capability to be available. My experience with the deployment has had some challenges, particularly around the Microsoft MFA campaigns. The hardest part is moving users from a different MFA provider to the Microsoft MFA provider, as it ultimately depends on user activity. In large enterprises with numerous users across various geographies, this transition takes time. If there are ways to exert more control around that process, it would improve the situation.
AmitRathod - PeerSpot reviewer
Senior Analyst at Toll Holdings Limited
Automated access governance has strengthened security and supports user-centric approvals
The workflows such as joiner, mover, and leaver work in Microsoft Entra ID Governance. Entitlement Management is a bundle of resources where Microsoft Entra ID applications, groups, and SharePoint sites are packaged into a single package so that users can request it. This is one of the great features for Microsoft Entra ID Governance. Another feature is Access Review, which allows an automated schedule to be managed for the manager or resource owner so that they can verify whether people still need access. Privileged Identity Management is another feature for governance that provides just-in-time (JIT) access for administrative roles. For example, instead of being a permanent or global admin, which is a major security risk, an IT professional is eligible for the role and must request four hours of access only when they need to perform a specific task. There is a feature called access package. If any user wants particular application access, they can request this application via Microsoft Entra ID Governance access package. Whenever an end user makes a request, the access goes to one application manager and their current line manager. If they approve it, then they get the application access. This is a very good feature for user-centric purposes. Microsoft Entra ID Governance includes securing AI agent identity. As a company uses more AI generation such as Copilots or custom bots, those bots need their own identity just as employees do. Microsoft Entra now provides a way to assign unique identities to AI agents so you can control what data they can access. Microsoft Entra ID Governance protection now looks for risky behavior in AI agents. If a bot suddenly tries to download an unusual amount of data or unconscious data, it can detect this as a risk detection factor. Security Copilot allows Entra administrators to manage identity with natural language. Microsoft Entra ID Governance has protection and authentication features. Smart risk detection protects and analyzes to detect threats such as impossible travel. If a person is logging in from many different locations, it detects this as a risk factor. A user cannot use an unauthenticated password or log in from an incompatible device. These AI features are used in conditional access management in Microsoft Entra ID Governance. Automation is used for user onboarding, user offboarding, and user update processes through user lifecycle management. If an organization uses Workday as an HR application where new users join and fill in their details, all these details get reflected into Workday and then reflected into Active Directory as well as Microsoft Entra ID Governance. This automation helps to manage the day-to-day user onboarding process, user offboarding process, and user update process. Microsoft Entra ID Governance automation also helps with password-related tasks, access recertification, and reporting.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We haven't had any problems with stability. Everything works fine."
"The most valuable feature of Microsoft Entra ID is its security options, where we can provide highly effective security for user accounts during authentication."
"Having access to Azure Active Directory on the cloud gives us speed and use of the latest technology. The application services are very good, such as GitHub."
"It offers good Microsoft integration capabilities."
"It enhanced our end user experience quite a bit. Instead of the days of having to contact the service desk with challenges for choosing their password, users can go in and do it themselves locally, regardless of where they are in the world. This has certainly made it a better experience accessing their applications. Previously, a lot of times, they had to remember multiple usernames and passwords for different systems. This solution brings it all together, using a single sign-on experience."
"Application integration is easy. MFA and password self-service have reduced most of the supportive work of IT. We use multi-factor authentication. Every access from a user is through multi-factor authentication. There is no legacy authentication. We have blocked legacy authentication methods. For people who use the MDM on mobile, we push our application through Intune. In a hybrid environment, users can work from anywhere. With Intune, we can push policies and secure the data."
"Microsoft Entra ID has also massively improved secure access to apps or resources compared to our previous setup."
"Azure Active Directory provides access to resources in a very secure manner. We can detect which user is logging in to access resources on the cloud. It gives us a comprehensive audit trace in terms of from where a user signed in and whether a sign-in is a risky sign-in or a normal sign-in. So, there is a lot of security around the access to resources, which helps us in realizing that a particular sign-in is not a normal sign-in. If a sign-in is not normal, Azure Active Directory automatically blocks it for us and sends us an email, and unless we allow that user, he or she won't be able to log in. So, the User Identity Protection feature is the most liked feature for me in Azure Active Directory."
"Access reviews are an essential feature of Entra Governance. Additionally, privileged identity management is one of its most valuable features. Just-in-time access, or Jet GIT, is integral to this system. Moreover, user behavior analytics stands out as one of its top features."
"The most valuable feature of Microsoft Entra ID Governance is access reviews."
"I am very happy with the solution."
"The platform's most valuable feature is the single sign-on service."
"The solution gives me the capability to automatically move guest accounts from the tenant without any manual intervention."
"The most valuable feature of Microsoft Entra ID Governance for identity management is multi-factor authentication."
"The features of Microsoft Entra ID Governance have benefited our organization because we have ServiceNow in our organization and we have been able to create integrations through Lifecycle Management to do onboarding and offboarding easier."
"The most valuable functions in Microsoft Entra ID Governance are ease of use, conducting access reviews, and tighter platform coupling."
 

Cons

"The permission management is a mess."
"Sometimes, level-one support lacks the immediate information needed, causing delays in receiving appropriate support."
"Our organization's approach to defending against token theft and nation-state attacks has not changed significantly since implementing Microsoft Entra ID, as we have a big concern about token theft yet know we cannot do anything."
"The ease of use regarding finding audit information for users could also be improved."
"I would like to be able to authenticate Wi-Fi users using the Azure ID"
"Microsoft Entra ID could benefit from more fine-tuned rights. It is necessary to prevent granting an application or user broad access rights."
"Microsoft should work on enhancing its machine-learning algorithm to prevent unnecessary lockouts of users."
"Licenses are very expensive."
"One area for improvement in Microsoft Entra ID Governance could be providing more granular control over security policies."
"Microsoft has done a commendable job with RPAX. However, Microsoft should prioritize enhancing its ABAC (Attribute-Based Access Control) capabilities. Currently, Microsoft's ABAC offering falls behind AWS in comparison."
"Sometimes, the solution is not super reliable."
"Microsoft Entra ID Governance is relatively new, and some features require more development. For example, when creating user access review campaigns, we can't specify the time to send emails to reviewers—only the date."
"There is a slight delay from creation of the actual access review to how long it takes to complete the actual review. For us, we are a large organization with over ten thousand employees... it takes a while to actually complete, and then it becomes a headache for managers."
"There are some areas where improvements are necessary. Even though we have almost the full package, there are some bugs."
"The product's workflow approval process needs improvement."
"I would rate customer service at three out of ten."
 

Pricing and Cost Advice

"Expensive solution, but if you look at the technical benefits it provides, the price for it is decent."
"The pricing depends on the use case and can be negotiated based on volume."
"It is not too expensive."
"For you to make use of some of the security features, you need to upgrade your licenses. If it is possible, could they just make some features free? For instance, for the Condition Access policy, you need to set that up and be on Azure AD P2 licensing. So if they could make it free or reduce the licensing for small businesses, that would be cool, as I believe security is for everyone."
"Everything needs to be considered for the requirements and if it is within the budget, then you can come up with a solution, whether it is SaaS, PaaS, or IaaS."
"We got a good deal. If you get rid of all the products providing features that Azure Suite can provide, then it makes sense cost-wise."
"If you have a different IDP today, I would take a close look at what your licensing looks like, then reevaluate the licensing that you have with Microsoft 365, and see if you're covered for some of this other stuff. Folks sometimes don't realize that, "Oh, I'm licensed for that service in Azure." This becomes one of those situations where you have the "aha" moment, "Oh, I didn't know we can do that. Alright, let's go down this road." Then, they start to have conversations with Microsoft to see what they can gain. I would recommend that they work closely with their TAM, just to make sure that they are getting the right level of service. They may just not be aware of what is available to them."
"We have various levels of their licensing, which includes users on different levels of their enterprise offering."
"There are no additional costs besides the standard licensing fees."
"The solution's pricing is not low but reasonable."
"In the education sector where I work, the annual cost for my Google and Microsoft environments is approximately $35,000. This covers the needs of 3,400 students and 800 faculty and staff members."
"While other products give the pricing for their application, Microsoft Entra ID Governance has a per-user-based license model."
report
Use our free recommendation engine to learn which Identity and Access Management as a Service (IDaaS) (IAMaaS) solutions are best for your needs.
900,838 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Manufacturing Company
8%
Government
8%
Computer Software Company
7%
Computer Software Company
11%
Financial Services Firm
10%
Government
9%
Healthcare Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business89
Midsize Enterprise41
Large Enterprise161
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise3
Large Enterprise10
 

Questions from the Community

How does Duo Security compare with Microsoft Authenticator?
We switched to Duo Security for identity verification. We’d been using a competitor but got the chance to evaluate Duo for 30 days, and we could not be happier. Duo Security is easy to configure a...
What is your experience regarding pricing and costs for Azure Active Directory?
My experience with pricing, setup cost, and licensing is that going through and being able to use these things is always part of delivering an M365 bundle, so I don't think the experience is great ...
What needs improvement with Azure Active Directory?
Microsoft Entra ID can be improved by open-sourcing it. You already have Windows Subsystem for Linux, which is open-source Linux in Microsoft. One major shift for Microsoft would be using the commo...
What needs improvement with Microsoft Entra ID Governance?
There is one feature that I do not prefer. If a manager approves access for a particular user and wants to change their decision about whether the user should retain access or not, once they approv...
What is your primary use case for Microsoft Entra ID Governance?
I use Microsoft Entra ID Governance for identity and access management as well as access recertification. The workflows such as joiner, mover, and leaver work in Microsoft Entra ID Governance. Enti...
What advice do you have for others considering Microsoft Entra ID Governance?
The best features are Access Review and Entitlement Management. Recertification can be run on-demand as and when any recertification slip occurs. There is also time-based recertification, which we ...
 

Also Known As

Azure AD, Azure Active Directory, Azure Active Directory, Microsoft Authenticator
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Microsoft Entre ID is trusted by companies of all sizes and industries including Walmart, Zscaler, Uniper, Amtrak, monday.com, and more.
Information Not Available
Find out what your peers are saying about Microsoft Entra ID vs. Microsoft Entra ID Governance and other solutions. Updated: June 2026.
900,838 professionals have used our research since 2012.