Azure AD is primarily used as the backend for all Microsoft Office 365 user accounts and licensing, as well as for securing those accounts. Endpoint Manager is also utilized, which is part of domain control in the cloud, even though it is not Azure AD.
Network specialist at a wellness & fitness company with 501-1,000 employees
Provides secure access to resources, and consolidates user accounts and authentication
Pros and Cons
- "The security features, such as attack surface rules and conditional access rules, are the most valuable aspects of Azure AD."
- "The only improvement would be for everything to be instant in terms of applying changes and propagating them to systems."
What is our primary use case?
How has it helped my organization?
Azure AD has enabled the organization to set up single sign-on to all applications and has consolidated everything to a single cloud authentication for users. This saved a lot of time by not having to administer accounts in multiple systems, and it has also made it easy to control user identity for all cloud and internal applications. Security features such as attack surface rules and conditional access rules are also highly valuable and help the organization feel safe with all its user accounts. The Entra conditional access feature is used to enforce fine-tuned and adaptive access controls, and it is perfect for verifying users in line with the Zero Trust strategy. Overall, Azure AD enabled the organization to control one set of accounts and policies for everything, providing a huge benefit.
What is most valuable?
The security features, such as attack surface rules and conditional access rules, are the most valuable aspects of Azure AD.
What needs improvement?
The only improvement would be for everything to be instant in terms of applying changes and propagating them to systems.
Buyer's Guide
Microsoft Entra ID
September 2026
Learn what your peers think about Microsoft Entra ID. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,889 professionals have used our research since 2012.
For how long have I used the solution?
I've been using this solution since 2017.
What do I think about the stability of the solution?
The stability of Azure AD is perfect.
What do I think about the scalability of the solution?
Azure AD is highly scalable and enables the organization to control everything from one office.
How are customer service and support?
The support channel for Azure AD is probably pretty good, although there was a strange experience with technical support once. Overall, the customer service and support would be rated as positive, with an eight out of ten rating.
Which solution did I use previously and why did I switch?
I have never used any other products except Google Workspace, which is very intuitive but not comparable to an identity system.
How was the initial setup?
The initial setup of Azure AD was quick and took just a workday or two, although tweaking it took about a week. The implementation of Azure AD probably took about 48 hours. In terms of maintenance, Azure AD doesn't require any maintenance as it is a cloud service that is always up to date.
What about the implementation team?
At the time, we used contractors to set it up because it was new to us. If I was going to do it today, it wouldn't be that complex for me because I now know the ins and outs of it, but at that time, we contracted people to help us set it up so that we could do it with the best practice. We probably had just one contractor and then we just helped out.
What other advice do I have?
For those looking to implement Azure AD in their organization for the first time, it would be recommended to get rid of the legacy Active Directory right away and go straight to Azure AD instead of starting out hybrid and having to wind that down. If local Active Directory isn't needed, it's best to move all authentication over to the cloud and scrap the Active Directory domain controllers. The Entra portal is a huge benefit as it provides a consolidated view of everything and makes it easier to navigate security, users, conditional access, and identity protection.
Microsoft has been consolidating the view to provide a single pane of glass. It has been more and more down to that. They're now out with something called Entra. It's the Entra portal, and it has a very consolidated view of everything I need to do. Microsoft Entra is basically Endpoint Manager, Microsoft Defender, and Azure Active Directory pulled together for an easy view and ease of navigation. I've started to use Entra a little bit. It has only been out for a little while, but it was created to simplify finding everything. So, instead of navigating through the portal at Azure, I've started using Entra. I like it a lot. At first glance, it looks very intuitive, especially based on how I've been navigating until now.
What Entra is doing is a huge benefit. If you're starting up today, it's much easier to get into security, users and conditional access, and identity protection. They've consolidated most of the important things there. You can navigate to everything from there, but they draw forth the most important ones in a more intuitive way. They've done that, and what they've done with Entra is what was missing.
Overall, I'd rate Azure Active Directory an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Information Officer at a construction company with 10,001+ employees
Gives us security and centralized database when integrating together all Active Directories of our branches
Pros and Cons
- "Active Directory itself is the best feature it has. It also gives us a single pane of glass for managing user access."
What is our primary use case?
It gives us security when integrating all the Active Directories of all our branches together, giving us a centralized database and authentication.
How has it helped my organization?
It has helped save time for our IT administrators. It's seamless for the users because they simply log into the stations, but it's affecting the response time and efficiency of the IT team.
What is most valuable?
Active Directory itself is the best feature it has. It also gives us a single pane of glass for managing user access.
For how long have I used the solution?
I have been working with Azure Active Directory for almost a year.
What do I think about the stability of the solution?
So far, it has been a stable solution.
What do I think about the scalability of the solution?
It is scalable.
Which solution did I use previously and why did I switch?
We did not have a previous solution.
What was our ROI?
I am working right now on whether we have seen ROI from the solution.
What's my experience with pricing, setup cost, and licensing?
We are always looking for better pricing. Our agreement is on a monthly basis.
What other advice do I have?
We're planning to use conditional access to access controls, but we have not done so in the meantime.
The solution doesn't require much maintenance; we're talking about two or three people.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Entra ID
September 2026
Learn what your peers think about Microsoft Entra ID. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,889 professionals have used our research since 2012.
Information Security Officer at a computer software company with 11-50 employees
Saves our clients significant time through automation and provides a good level of security
Pros and Cons
- "One of the most important is the Conditional Access. It helps affect a Zero Trust strategy positively."
- "I would like them to improve the dashboard by presenting the raw data in a more visual way for the logs and events. That would help us understand the reports better."
What is our primary use case?
I set up Azure Active Directory for many customers of the company I work for. I'm an implementer. It is the basis of identity and access for all the tenants we are using for our customers.
How has it helped my organization?
Microsoft Entra helps our clients save a lot of time, especially with the many automation processes that we can leverage to facilitate our work. The amount of time saved depends on the customer's needs. In general, on average I would estimate it saves them 40 percent in terms of time. But in some cases, it could be up to 70 percent.
It also helps them save money because they can work with fewer employees, or they don't have to hire more employees to do tasks that can be automated.
Another benefit is that it provides satisfaction at the administration level. On the user level, the ease of use makes it easy to understand without any limitations.
And it provides quite a good level of security for all users.
What is most valuable?
All the features of the solution are helpful. Among them, one of the most important is the Conditional Access. It helps affect a Zero Trust strategy positively.
Also, I use Entra Permission Management to distribute the roles among all users according to management requests. Microsoft provides reports for visibility and all kinds of controls where you can see the users and their access. Permission Management helps reduce the risk surface when it comes to identity permissions. It supports adaptive controls and that helps me in defining the right controls for users.
What needs improvement?
I would like them to improve the dashboard by presenting the raw data in a more visual way for the logs and events. That would help us understand the reports better.
For how long have I used the solution?
I have been using Azure Active Directory for about three years.
What do I think about the stability of the solution?
It's stable. I haven't experienced any downtime or breakdowns with the product.
What do I think about the scalability of the solution?
It's scalable.
How are customer service and support?
I'm satisfied with their support.
How would you rate customer service and support?
Neutral
How was the initial setup?
It's easy to set up.
The amount of time needed to set up Azure Active Directory depends on each customer's use case. It will take at least three to four hours for a small organization, and in that scenario you wouldn't need more than one person to set it up. For larger organizations, it may take a week and we would need two to three persons.
What's my experience with pricing, setup cost, and licensing?
Our customers are looking for advanced features and processes for it to be cost-effective for their organizations. They see it as an overpriced product. They are enjoying using Azure Active Directory, but they are looking for better prices.
What other advice do I have?
Just follow the book.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
General Manager at a tech services company with 11-50 employees
MFA is key, keeping threat actors from being able to steal identities
Pros and Cons
- "A couple of features are valuable, but the one that comes across the most to me is multi-factor authentication."
- "When it comes to identity and access life cycle management for applications that are run on-premises, as well as access governance, if those kinds of capabilities could be built into Azure Active Directory, that would be good."
What is our primary use case?
We use it for identity and access management for cloud-based applications.
What is most valuable?
A couple of features are valuable, but the one that comes across the most to me is multi-factor authentication. That is huge because, with the promise of cloud—the ease and flexibility—comes a challenge of security. That means organizations are quite susceptible to cyber security threats and attacks. Nowadays, because assets have moved from the on-premises environment to the cloud, identity has become a new parameter.
MFA is the most valuable feature because it only takes threat actors who keep guessing the password—even a password with a high degree of complexity, given all the tools available to crack them—to gain access. Then they are able to steal identity information and all the digital assets of an organization.
We, ourselves, experienced a "near miss" but we were able to detect it at a very early stage and then immediately implement multi-factor authentication, which of course means that in addition to the regular user ID and password, there's another key requirement for validating and verifying the true identity. That's been very valuable to us and to our clients.
We also use Entra’s Conditional Access feature to enforce fine-tuned and adaptive access controls. It's all about taking a further step and layering additional controls to prevent unwanted access. It helps with Zero Trust, ensuring that we can protect assets. The entire paradigm is to make sure that you do not grant access to any potential user without verifying and properly validating who that entity is. That's most invaluable because you can identify a set of conditions that are unique to the organization. They can be related or linked to the profile of the organization and, based on that, you can grant access. Microsoft, from what we've seen, is at the forefront. They're actually spot-on with that.
What needs improvement?
Using wild imagination, I am thinking about to what extent AAD can integrate with products in a seamless way, such as applications that are running on-premises and making use of on-premises directory services. The most common, of course, is Azure Active Directory Domain Services. To what extent can it be used to replace the on-premises Active Directory Domain Services? Even though they are similar in concept, they are totally separate products.
I would like to see applications that make use of on-premises Active Directory Domain Services have the ability to also seamlessly make use of Azure Active Directory.
And when it comes to identity and access life cycle management for applications that are run on-premises, as well as access governance, if those kinds of capabilities could be built into Azure Active Directory, that would be good.
For how long have I used the solution?
I have been using Azure Active Directory since 2015.
What do I think about the stability of the solution?
It's very stable. I don't think I can recall a major outage of Microsoft's products or services.
There could be outages impacting other services, and over time, you do experience degradation. But what makes it work is that Microsoft has a lot of resilience built into its cloud architecture.
What do I think about the scalability of the solution?
It's highly scalable. I've worked on projects where we have to deploy Active Directory for in excess of 12,000 users.
More than 90 percent of the people in our organization are using Azure Active Directory.
How are customer service and support?
Overall, I'm satisfied. In some cases, there are incidents that take some time to resolve, but those are more exceptions than they are the rule. We seem to find such cases when we have situations with on-premises workloads, technologies that are not yet in the cloud.
But for the most part, in recent times, on average we tend to have quicker resolutions, relatively speaking, for issues that have to do with the cloud product.
What I consider to be the aspect that makes the experience good for us is that we get support for all the products. We have access to Premier Support and that enhances the quality of our experience.
How would you rate customer service and support?
Neutral
How was the initial setup?
It's quite easy to set up.
The time needed to set up Azure Active Directory is a function of the environment. For simple deployments, it can be done within hours or within a day. But for complex environments, it might take anywhere from two weeks and up. You need to go through an environment assessment and make use of a project delivery framework.
For example, suppose a customer already has on-premises Active Directory services, and the requirement is to deploy or implement a hybrid identity architecture. That means there are workloads on-premises and in the cloud, and the customer wants to use the same identity scheme or single sign-on. Those are the type of requirements that determine how long it will take to get Azure Active Directory set up.
Deployment generally requires a project manager, an engagement manager, and an architect; a minimum of three people. And if there are other specific solution domains that require specialist skills, it could be four.
There is zero maintenance. The focus, in my own experience, is typically around security: how you're monitoring the environment to ensure that it's still secure. And when there are incidents, to what extent, and how quickly, you can triage and pinpoint and remediate to keep the infrastructure secure? But the actual is maintenance is zero.
What was our ROI?
It will save us money eventually, even though that's not the case now. For example, for HR, with onboarding and exits, we're beginning to see that this is an area where Entra can help us manage the life cycle of identities. The convenience that comes with that, and how that also helps ensure security and compliance, are areas that Entra can help us with.
What's my experience with pricing, setup cost, and licensing?
The pricing of Azure Active Directory is competitive. By default, the product exists in almost every Microsoft cloud product. But it then depends on the features that a customer really wants to make use of. The extent of the security requirements will inform what kind of plan will be suitable for the customer's situation.
Which other solutions did I evaluate?
As a business, we have always been cloud-native, so we've always been making use of Azure Active Directory. The very fact that that's what drives our productivity platform, both for ensuring that employees are well engaged and they can deliver on productivity, and meet customer requirements and demands, means we haven't looked at alternatives.
What other advice do I have?
Regarding Entra, the expectation is that when it is deployed, the employee experience should be better. We haven't started exploiting all the features of Entra. It makes use of the core Active Directory: identity and access management, conditional access, et cetera. But we're not making use of all its features at the moment. We hope to implement them in the near future.
Overall, I'm satisfied.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT Manager at a tech services company with 10,001+ employees
Responsive and knowledgeable support, good documentation available online, and single sign-on integrates seamlessly
Pros and Cons
- "The most valuable feature is the single sign-on, which allows any application that is SAML or OAuth compatible to use Azure as an identity provider for seamless sign-in."
- "In a hybrid deployment, when we update a license by changing the UPN or email address of a user, it does not get updated automatically during normal sync. This means that we have to update it manually from Azure, which is something that needs to be corrected."
What is our primary use case?
My primary use case is Azure SSO. Then, it is a hybrid synchronization of users and computers, and also for SCIM provisioning.
How has it helped my organization?
Using this product has helped improve our security posture. I don't handle security directly, but I know that our security team was able to identify logs containing erratic behavior, such as logins that were not authentic. They were able to identify and solve those problems.
This solution has improved our end-user experience a lot because previously, users had to remember different passwords for different applications. Sometimes, the integration with on-premises AD was a little bit difficult over the firewall. However, with Azure, that integration has become seamless. The users are also happy with the additional security afforded by multifactor authentication.
One of the benefits that we get from this solution is the Azure hybrid join, where my presence of the domains is both on-premises and on the cloud. It has allowed us to manage the client machines from the cloud, as well as from the on-premises solution. We are currently building upon our cloud usage so that we can manage more from the Azure instance directly.
Our cloud presence is growing because most people are working from home, so the management of end-users and workstations is becoming a little challenging with the current on-premises system. Having cloud-based management helps us to manage end-users and workstations better. This is because, with an on-premises solution, you need a VPN connection to manage it. Not all users have a VPN but for a cloud-based solution, you just need the internet and almost everyone now has an internet connection.
What is most valuable?
The most valuable feature is the single sign-on, which allows any application that is SAML or OAuth compatible to use Azure as an identity provider for seamless sign-in.
I like the SCIM provisioning, where Azure is the single database and it can push to Google cloud, as well as Oracle cloud. This means that the user directory is synchronized across platforms, so if I am managing Azure AD then my other platforms are also managed.
What needs improvement?
In a hybrid deployment, when we update the UPN or email address of a user who has license assigned, it does not get updated automatically during normal sync. This means that we have to update it manually from Azure, which is something that needs to be corrected. Essentially, if it's a hybrid sync then it should happen automatically and we shouldn't have to do anything manually.
Azure AD DS allows only one instance in a particular tenant, which is something that could be improved. There are people that want to have AD DS on a per-subscription basis.
For how long have I used the solution?
I have been using Azure Active Directory for more than three years.
What do I think about the stability of the solution?
Other than a few global outages, I have not seen any specific outages to the tenant that we use. In the typical case, we haven't faced any issues.
What do I think about the scalability of the solution?
The scalability has been good. For the infrastructure that we have developed, there were no issues. We have nothing in terms of abnormal outages or any abnormal spikes that we have observed. Overall, scalability-wise, we are happy with it.
We have thousands of users on the Azure platform. The entire organization is on Azure AD, and everyone has a different, specific role assigned to them. Some people are using the database, whereas somebody else is using other infrastructure service, and the same is true for all of the different features. We have different teams using different features and I am part of managing identities, which involves using Azure AD and its associated features.
How are customer service and support?
The support from Microsoft is very good. I would rate them a nine out of ten. They are responsive and very knowledgeable.
Which solution did I use previously and why did I switch?
Prior to Azure AD, we used on-premises Active Directory.
How was the initial setup?
The initial setup was not very complicated because there are very good articles online, published by Microsoft. They give detailed steps on the process and including what challenges you may face. In our setup, the articles online were sufficient but suppose you run into any issues, you simply reach out to Microsoft for support.
Taking the purchases, planning, and everything else into account, it took between three and four months to complete the deployment.
What about the implementation team?
Our in-house team was responsible for deployment. In a few cases, we reached out to Microsoft for support.
Which other solutions did I evaluate?
We have not evaluated other options. The reason is that the integration between Azure AD and on-premises Active Directory is seamless and easy. Both solutions are by Microsoft.
What other advice do I have?
My advice for anybody who is implementing Azure AD is to consider the size of their environment. If it's a large on-premises environment then you should consider a hybrid model, but if it's a small environment then it's easy to move to the Azure cloud model directly. If it's a small environment then Azure AD is also available on a free license. This is how I would suggest you start looking at having a cloud presence.
Azure AD is easy to integrate and manage, and it will reduce your capital cost a lot.
In summary, this is a good product but there is always scope for improvement.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Administrative Assistant at Tecapro
Great for SSO, works across deployments, and increases efficiencies
Pros and Cons
- "It has given us the ability to be able to establish single sign-on identities in which we can establish credentials no matter where we are, whether it is on-premises or in the cloud, in a hybrid cloud, or in an additional connection from another cloud where we share equipment or host."
- "It is one of the hybrid solutions that can be used the most to establish an entity configuration in multiple environments."
- "I want to see new functionalities for the active directory."
What is our primary use case?
We had the need to integrate the solution that we had on-premise and the email-based identities, so we looked for a solution from the same provider that could establish us and provide a synchronized identity (what we know today as SSO) in our resources and thus be able to log in with the same identities we had on-premise and in the cloud.
We wanted to take advantage of that synchronized identity quickly, simply, and safely. It was important to understand that users today want to have a single password for all resources, be they applications, or devices, in order to help them so that they are not constantly learning different credentials and can thus be faster and more efficient when establishing a single login.
How has it helped my organization?
It has given us the ability to be able to establish single sign-on identities in which we can establish credentials no matter where we are, whether it is on-premises or in the cloud, in a hybrid cloud, or in an additional connection from another cloud where we share equipment or host.
Additionally, we enabled more protection functions so that it is well protected even though it is a single credential for each environment and established for any environment it could be safely protected.
What is most valuable?
Its most outstanding feature is the ability to integrate, segment, establish, add and configure an identity for multiple domains in different regions, locations, or types of clouds. It is one of the hybrid solutions that can be used the most to establish an entity configuration in multiple environments. It is a tool that has given us the ability to establish identity security issues to share and perimeter segment the security of an organization, a domain, and multiple clouds in a fast, simple, and well-established way, which has allowed us to be more efficient.
What needs improvement?
I want to see new functionalities for the active directory. I would like to be able to establish that when you log into computers locally, it is installed on a laptop and you can enable the MFA feature that is currently not available for local computers or Windows on-or off-premise - thus being one of the characteristics that can give greater added value to information security issues.
If this feature was available on computers, it would help us in the future to avoid security breaches, information loss, or data backup vulnerabilities. In many cases, this could generate a complication. However, we always want to innovate, and the Innovation part is always to ensure that any place, device, or management that we are going to establish at the computational level is 100% secure.
For how long have I used the solution?
We've used the solution for one year and two months.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Jr. System Admin at a tech services company with 5,001-10,000 employees
Offers an additional layer of security with MFA, multiple authentication methods, and excellent technical support
Pros and Cons
- "The two-factor authentication provides an additional layer of security for our organizational data, so Microsoft Authenticator plays a crucial role in making our confidential data more secure."
- "Our users sometimes experience issues from having multiple Microsoft accounts, which can cause some confusion and hassle."
What is our primary use case?
We primarily use the solution for MFA; to access apps such as Teams or Outlook, two-factor authentication with our mobile phones is required.
We also use Authenticator to assist our clients with re-enrolling, moving, and adding new devices.
How has it helped my organization?
The solution helps us keep our data secure and prevents security breaches, malware, etc. The app also provides us with options regarding our authentication preferences.
What is most valuable?
The two-factor authentication provides an additional layer of security for our organizational data, so Microsoft Authenticator plays a crucial role in making our confidential data more secure.
The solution offers multiple authentication methods via text, call, or the app. This gives us many options and flexibility when it comes to MFA.
What needs improvement?
Our users sometimes experience issues from having multiple Microsoft accounts, which can cause some confusion and hassle.
It would be good to see the incorporation of fingerprints and Face IDs as authentication options. This would simplify the authentication process for end users, especially those who aren't as tech-savvy. It is also a consideration for visually impaired people, for example.
For how long have I used the solution?
We have been using the solution for about one and a half years.
What do I think about the stability of the solution?
Microsoft Authenticator is a very stable application; our only issue is that we run into the occasional bug.
What do I think about the scalability of the solution?
The solution is highly scalable. Many organizations use it around the world.
How are customer service and support?
The technical support is very good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I used PingID when working for another organization, which is slightly different from Microsoft Authenticator.
How was the initial setup?
I wasn't involved in the initial setup, but the solution is straightforward to use once installed.
The solution requires a little maintenance, as we sometimes encounter bugs where the app doesn't recognize a user account, for example.
What's my experience with pricing, setup cost, and licensing?
I am not involved in the pricing or licensing, so I can't speak to that.
What other advice do I have?
I would rate the solution a 10 out of 10.
I would advise potential users to familiarize themselves with the basics of the solution; how to set up an account, how to use the app etc. It's always a good idea to have a clear reason for using a particular solution, how it functions, and what role it fulfills.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Microsoft Teams Senior Engineer at a financial services firm with 10,001+ employees
Enhances security, especially for unregistered devices, and is straightforward to set up for the admins
Pros and Cons
- "It enhances security, especially for unregistered devices. It 1000% has security features that help to improve our security posture. It could be irritating at times, but improving the security posture is exactly what the Authenticator app does."
- "For the end users, it can be confusing if they have worked for another company that had the Authenticator app. It is tricky if they have already had the Authenticator app and then work somewhere else. If they have to download it again and use it again on their phone, it is something that gets complicated. I know how to get through it. They just need to uninstall and reinstall the application, but for them, sometimes, it is confusing."
- "For the end users, it can be confusing if they have worked for another company that had the Authenticator app."
What is our primary use case?
Identity verification would be the number one use case. It also factors into mobile device management for devices that aren't registered to the company. We use MFA, and the Authenticator app is a component for multifactor authentication. So, that's why we use it.
How has it helped my organization?
You can set policies to specify where users will have to use the Authenticator app to log into particular applications.
It makes all junior users accountable. There is no excuse for someone else logging into anything because of the multifactor authentication and Authenticator app. You have to verify your identity to log in to specific applications that contain confidential information, especially in a HIPAA-compliant environment.
What is most valuable?
It enhances security, especially for unregistered devices. It 1000% has security features that help to improve our security posture. It could be irritating at times, but improving the security posture is exactly what the Authenticator app does.
What needs improvement?
For the end users, it can be confusing if they have worked for another company that had the Authenticator app. It is tricky if they have already had the Authenticator app and then work somewhere else. If they have to download it again and use it again on their phone, it is something that gets complicated. I know how to get through it. They just need to uninstall and reinstall the application, but for them, sometimes, it is confusing. You can have the Authenticator app for multiple services on your phone, and that's what drives them crazy. They get a code and say "I'm using the code for the Authenticator app, but I can't get in." I tell them that it is because they already had it in, but it is for something else. They now have to add. They don't like that at all. You could be on the phone for 45 minutes trying to figure out what their problem is because they don't.
Instead of authenticating by getting a passcode or answering the phone, fingerprint identification should be added to the Authenticator app. Currently, with the Authenticator app, you have to reply to the email, enter a code, or answer the phone. It can just call my phone and then I just press the button to verify that this is me.
For how long have I used the solution?
I have been using this solution for at least six years.
What do I think about the stability of the solution?
It is very stable. If the Authenticator app is set up, you're not going to get into anything without it. It definitely works.
I'm not aware of any bugs or glitches. We usually run updates for the whole environment at a time. I'm not familiar with having run into specific bugs with the Authenticator app. I haven't had any problems over the years.
What do I think about the scalability of the solution?
I've managed over a hundred thousand users in total, but right now, there are about 10,000 users. We are HIPAA compliant. So, everybody has to use it for everything. They have to use it to log into everything under the Office 365 environment, but in other companies or other places where I worked, it was only for specific applications. So, that's based on company needs.
How are customer service and support?
I never had to call technical support for this.
Which solution did I use previously and why did I switch?
We were using normal MFA, which is similar. The Authenticator app is for mobile devices per se, but normal multifactor authentication doesn't have to focus on mobile devices. You can try and log in to, for example, SharePoint Online, and if MFA is activated, you would have to just scroll to your email and click, "Hey. Yeah, this is me." The Authenticator app is just for mobile devices in my eyes.
How was the initial setup?
It is straightforward for the admins, but end users hate it. On the admin side, it takes 20 minutes at the most.
The Authenticator app wants you to have all your prerequisites designed for whatever environment you want. If you're going through Azure, you can pick the particular applications on which you want this. You can also pick the users for whom you want it to be effective. You can pick the type of ways they authenticate through the Authenticator app. Those are the simple steps.
One person is enough for its deployment and maintenance. I do that. That's not even a role. It depends on who you are, but that's not a role. That's not something for which I would employ a person. I wouldn't employ an IT person or an administrator just to focus on this.
What's my experience with pricing, setup cost, and licensing?
I don't pay for it. Going by how I feel, I see the prices for any MFA solution going down because the more different alternatives there are, the cheaper things should be. Microsoft Authenticator app would be the preferred application, but there are too many ways to implement MFA. I don't know how much it cost, but the price should go down.
What other advice do I have?
It is pretty seamless for the end users, besides the end users having an issue setting up at times.
It is a seamless transition. It is straightforward on the admin side to set up. As a consultant, my advice to any company is that when it comes to big changes, manage end-user pain or frustration. Communicate with the end users and let them know what's going to happen. Explain to them that they're going to be frustrated, but explain why this exists.
I understand why it exists. So, it doesn't bother me, but our end users just hate it. I understand that they don't like it. Nobody likes it, but it is needed. You are never going to meet an end user who likes any type of MFA, but you need to be more clear about its purpose.
I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Technical Architect at a tech vendor with 10,001+ employees
Connects with other SaaS solutions, and SSOs with MFA make authentication much easier
Pros and Cons
- "It's multi-tenant, residing in multiple locations. The authentication happens quickly. Irrespective of whether I'm in Australia, the US, India, or Africa, I don't see any latency. Those are the good features that I rely on."
- "I would definitely recommend using Azure AD."
- "One area where it can improve is connectivity with other systems. Not all systems are connected and you have to do coding to establish a point of connectivity. It supports certain vendors and it supports certain protocols. It is limited in many other aspects at the attribute level."
- "One area where it can improve is connectivity with other systems."
What is most valuable?
The most valuable features are
- authentication
- authorization
- two-factor authentication
- I have never had a failure.
It's multi-tenant, residing in multiple locations. Authentication happens quickly. Irrespective of whether I'm in Australia, the US, India, or Africa, I don't see any latency. Those are the good features that I rely on.
It also has a variable extension, which is an added value because in Active Directory, if you have to do a schema, you have to make changes on multiple Active Directory instances. But here, as the extension attribute can be done from the application level, it helps you provide the provisioning.
Another good reason for using Azure AD is that it can connect with other SaaS services. It also has SSOs, which, along with the MFA, makes authentication much easier.
What needs improvement?
One area where it can improve is connectivity with other systems. Not all systems are connected and you have to do coding to establish a point of connectivity. It supports certain vendors and it supports certain protocols. It is limited in many other aspects at the attribute level.
Also, some of the provisioning filters are not capable enough. You cannot do a date filter on the provisioning.
Perhaps they could also have easy protocols to create the accounts. Instead of just a file upload, they should have an easy connector to do the provisioning part.
For how long have I used the solution?
I work in a service-based company and I've been using Azure Active Directory for my customers for around 10 years now.
What do I think about the stability of the solution?
From 2020 to 2022, there have not been more than two or three outages, and none was more than three to four hours long. And those outages may not have occurred the whole time in the entire environment, they may only have been in certain places.
When there is an outage, the end-user experience is affected, but that happens in AWS and in Azure. It happens with any SaaS product. Overall, it has not affected the end-user experience, but when there is an outage in Azure, it will have an impact on our environment.
What do I think about the scalability of the solution?
It's scalable, but if you need more than one region, you have to pay for it. You have to think about how you want the service to be available.
How are customer service and support?
The technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy and straightforward. Setting up Azure AD doesn't require you to do anything. You buy the product from Microsoft and Microsoft sets it up for you. You just establish the connectivity to it. It does not take more than a week or two to complete the setup.
The number of employees you require for deployment and maintenance of the solution depends on how you have set up your provisioning platform. If it is automated, you can have one resource. If you're still in manual, then it depends on the volume of the workload.
What's my experience with pricing, setup cost, and licensing?
Licenses are based on the usage. There is no cap. It's based on the number of users we provision.
A SaaS solution is the best product. You get it at a better price and you have many Windows-based services that are included for free.
What other advice do I have?
I would definitely recommend using Azure AD. Many companies are moving from other vendors to Azure because every company uses Office 365 anyway for Word, Excel, and PowerPoint. As soon as you use that, by default, you get an Azure AD account. If you have an Azure AD account, you definitely have features to use. Why would you want to go for another product?
Overall, I haven't seen any major issues with the product.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
CEO at Intelliway
Robust security, excellent integration with other Microsoft products, in an affordable, scalable, and stable solution
Pros and Cons
- "We have a history of all our authentications and excellent integration with the Microsoft solutions we use at our company. It runs smoothly in Windows and macOS."
- "The solution improved our and our clients' security; end users are more confident knowing that their information is confidential."
- "I want to see more features to improve security, such as integrated user behavior analysis."
What is our primary use case?
We use the Authenticator app on our mobile phones and to authenticate for Office 365. We also provide consulting services and recommend Microsoft Authenticator to clients looking for an MFA solution.
How has it helped my organization?
The solution improved our and our clients' security; end users are more confident knowing that their information is confidential. Strategic users, VIPs, and admins are protected from potential attacks because their authentication goes through Microsoft Authenticator.
The product has significantly increased our security maturity and gives us comfort knowing we have security in a good, affordable solution.
What is most valuable?
We have a history of all our authentications and excellent integration with the Microsoft solutions we use at our company. It runs smoothly in Windows and macOS.
What needs improvement?
I want to see more features to improve security, such as integrated user behavior analysis.
For how long have I used the solution?
We have been using the solution for two years.
What do I think about the stability of the solution?
The tool is stable, we haven't had any issues regarding stability.
What do I think about the scalability of the solution?
Scaling is easy as the product is hosted in the cloud; it's a robust and trustworthy solution.
Currently, we have 100 end users in our company, and we have some clients with around 1000 end users of Microsoft Authenticator.
How are customer service and support?
We never needed to contact technical support as we have never had any problems, so I can't comment on that.
Which solution did I use previously and why did I switch?
We previously used JumpCloud before migrating to Microsoft Authenticator, and we did that because it's more affordable and has better integration with Office 365 and the other Microsoft products we implement.
How was the initial setup?
The setup was straightforward. We made an implementation plan and transitioned from using MFA via email and SMS messages to using Microsoft Authenticator.
Our security team is responsible for all our security solutions, and they take care of the maintenance, which I understand to be relatively light.
We have a Security Operation Center in our company. Another company using the same solution without a team like ours may require several hours a month to manage the solution.
What about the implementation team?
We implemented it in-house since we are a consulting services company.
What was our ROI?
We think the solution is excellent and provides a return on our investment.
What's my experience with pricing, setup cost, and licensing?
I would advise implementing the solution to VIPs and admins; it's affordable, effective, and efficient. I would say training staff on properly using the tool is also essential.
Which other solutions did I evaluate?
We decided to go straight for the Microsoft offering since we use Office 365.
What other advice do I have?
I would rate this solution a nine out of ten.
When we deployed Microsoft Authenticator for our clients, we initially had some requests for training. We delivered the training, and the end users could adapt to it; the transition was smooth.
The solution is extensively used within our organization.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. MSSP
Buyer's Guide
Download our free Microsoft Entra ID Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Single Sign-On (SSO) Authentication Systems Identity Management (IM) Identity and Access Management as a Service (IDaaS) (IAMaaS) Access Management Microsoft Security SuitePopular Comparisons
Microsoft Intune
Microsoft Defender for Endpoint
Cloudflare One
Microsoft Defender for Cloud
Okta Platform
SailPoint Identity Security Cloud
Microsoft Sentinel
Microsoft Defender for Office 365
Microsoft Purview Data Governance
Microsoft Defender XDR
Workspace ONE UEM
Azure Key Vault
Ping Identity Platform
Google Cloud Identity
Microsoft Purview Data Loss Prevention
Buyer's Guide
Download our free Microsoft Entra ID Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- What are the biggest differences between Google Cloud Identity and Microsoft Azure Active Directory?
- How does Duo Security compare with Microsoft Authenticator?
- How does Microsoft Authenticator compare with Forinet FortiToken?
- When evaluating Single Sign-On, what aspect do you think is the most important to look for?
- CA SiteMinder vs IBM Tivoli Access Manager
- What single sign-on platform do you recommend?
- How much time does SSO save?
- Why is SSO needed?
- Why is Single Sign-On (SSO) important for companies?













