Microsoft Entra ID is a cloud identity and access management platform from Microsoft for controlling access to cloud and on-premises applications, priced per user starting at £5.40 per user per month when billed annually, with a free edition for basic identity management.
Listing updated . Checked by MSP Software .
Microsoft Entra ID is a cloud identity and access management platform from Microsoft for controlling access to cloud and on-premises applications. It is the foundation of Microsoft 365 and can be deployed standalone for any organization using cloud applications, whether or not they use other Microsoft services. The service provides single sign-on across thousands of SaaS applications and hybrid identity support for on-premises systems, making it essential for organizations that need to manage user access across multiple environments.
Entra ID includes multi-factor authentication, risk-based conditional access policies, and privileged access management to enforce least-privilege principles. It supports passwordless authentication methods including Windows Hello and FIDO2 security keys, and integrates with hybrid environments through directory synchronization, allowing administrators to manage users in on-premises Active Directory and automatically sync them to the cloud. The service includes machine learning-powered threat detection and identity protection, session and risk monitoring capabilities, and support for legacy protocols including RADIUS and SAML.
Pricing is published on a per-user basis: the P1 plan costs £5.40 per user per month when billed annually, and the P2 plan costs £7.70 per user per month when billed annually (checked September 2026). Microsoft also offers a free edition with basic user management, directory sync, SSO for Microsoft services and popular SaaS applications, and reports, automatically included with most commercial Microsoft subscriptions. A 30-day free trial is available for paid plans. Entra ID is a cloud-only service with no on-premises deployment option, though it integrates with on-premises Active Directory and legacy applications through standards including Kerberos and SAML. The console runs through the web browser with no software installation required. Microsoft is based in the United States, and support options include phone, email and knowledge base resources.
Microsoft Entra ID is the cloud identity solution for Microsoft 365 shops and the standard choice for organizations using Exchange Online, SharePoint, or Teams. It suits any MSP managing cloud-first organizations, hybrid identity scenarios, and organizations requiring strong authentication and risk-based access control. MSPs managing on-premises-only clients should look elsewhere; Entra ID requires cloud identity infrastructure. Confirm that conditional access policies (P1 and above) and identity protection (P2 only) align with your clients' security requirements before recommending a plan tier. Okta and Duo offer comparable standalone cloud identity platforms for non-Microsoft environments.
| Feature | Supported | Note |
|---|---|---|
| Multi-factor authentication | yes | Multi-factor authentication including authenticator app, phone call, SMS and hardware token options |
| Single sign-on | yes | Single sign-on across thousands of SaaS applications and on-premises systems |
| Conditional access and device trust | yes | Risk-based conditional access policies to control access based on user and device risk |
| Privileged access management | yes | Privileged identity management (P2) for just-in-time access and least-privilege principles |
| Passwordless and passkey support | yes | Windows Hello, FIDO2 security keys and passwordless phone sign-in |
| Directory sync | yes | Azure AD Connect for synchronizing on-premises Active Directory to cloud |
| Session and risk monitoring | yes | Machine learning-powered threat detection, identity protection and risky sign-in alerts |
| Legacy VPN and app support | yes | Support for legacy VPN, Kerberos, SAML and legacy application proxy |
| Self-service password reset | yes | User self-service password reset and MFA registration |
| Breach monitoring | unknown | |
| RADIUS and SAML support | yes | Support for RADIUS, SAML, WS-Fed and other federation protocols |
| Admin audit log | yes | Comprehensive admin audit logs and sign-in activity reports |
| Feature | Supported |
|---|---|
| Tenant and user provisioning | unknown |
| Licence assignment | unknown |
| Security baseline templates | unknown |
| Conditional access management | unknown |
| Multi-tenant console | unknown |
| Shadow SaaS discovery | unknown |
| Automated offboarding | unknown |
| Reporting and QBR exports | unknown |
| Microsoft Graph API integration | unknown |
| PSA integration | unknown |
| Backup integration | unknown |
| Delegated admin (GDAP) support | unknown |
Microsoft Entra ID P1 costs £5.40 per user per month when billed annually and includes conditional access, hybrid identity, and self-service password reset. P2 costs £7.70 per user per month when billed annually and adds identity protection, privileged identity management, and risk-based conditional access policies. Organizations requiring advanced threat detection and privileged access controls should choose P2, while those needing basic conditional access and self-service capabilities can start with P1.
Yes, Microsoft Entra ID includes a free edition with basic user and group management, directory synchronization to on-premises Active Directory, single sign-on across Microsoft services and popular SaaS applications, and basic reporting. The free edition is automatically included with most commercial Microsoft subscriptions. Organizations requiring conditional access policies or identity protection must upgrade to P1 or P2 paid plans. A 30-day free trial is available for evaluating paid plan features.
Yes, Microsoft Entra ID is designed for hybrid identity scenarios. Azure AD Connect synchronizes users and groups from on-premises Active Directory to the cloud, allowing administrators to manage user lifecycle from a single location. Entra ID supports pass-through authentication, federated authentication using ADFS, and hybrid joined devices. Organizations can use legacy on-premises applications while managing cloud access policies centrally, though applications must support standards like SAML or RADIUS to integrate with cloud identity.
Yes, Microsoft Entra ID works with thousands of SaaS applications through pre-built integrations and supports SAML, WS-Fed and OpenID Connect federation protocols for custom applications. However, it is designed first for Microsoft 365 environments and integrates most directly with Exchange Online, SharePoint, Teams and other Azure services. Non-Microsoft applications require their application to support modern federation standards or custom integration. Organizations with primarily on-premises or non-Microsoft platforms may find competing solutions like Okta more flexible.
Microsoft Entra ID has extensive documentation, tutorial videos, and webinar resources available on Microsoft's website and in the Azure portal. Phone and email support are available through Microsoft Premier Support or Microsoft Support agreements, with response times depending on the support plan. A knowledge base and community forums provide peer support. MSPs should verify their support agreement with Microsoft before implementing Entra ID, as basic support may have limited response times for production issues.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review