Skip to main content

Comparison

Entra ID vs Active Directory

They share a vendor and half a name, and that is where the similarity ends. Active Directory governs domain-joined machines on a network you control. Entra ID governs identity for cloud applications and devices anywhere. Most companies still run both, and the interesting question is how to stop.

Microsoft Entra ID · Active Directory Domain Services · Entra Connect

Cloud

Entra ID scope

Domain

Active Directory scope

P1/P2

Entra licence tiers

3-9 months

Typical AD retirement

Quick Verdict

Entra ID is not a hosted version of Active Directory. It is a different model: identity for cloud applications and internet-facing devices, governed by conditional access rather than by network location. Active Directory still does things Entra cannot, chiefly Group Policy, Kerberos and LDAP for on-premise servers. If those dependencies are gone, keeping a domain controller alive is cost and risk with no return.

Entra IDBest for cloud-first companies, remote and hybrid teams, and anyone whose applications are SaaS rather than on-premise.
Active DirectoryStill required for Group Policy, Kerberos, LDAP-dependent applications, file and print servers, and legacy line-of-business systems.

Side-by-Side Comparison

FeatureMicrosoft Entra IDActive Directory (AD DS)
ProtocolsSAML, OIDC, OAuth 2.0, SCIMKerberos, NTLM, LDAP
Where it livesMicrosoft cloud, no servers to runDomain controllers you patch and back up
Device modelEntra joined or registered, anywhereDomain joined, on the corporate network or VPN
Policy engineConditional Access and Intune configurationGroup Policy
SaaS single sign-onNativeOnly via a federation layer
Works off the networkRequires VPN or line of sight to a DC
MFANativeThird-party add-on required
File and print services
Legacy LDAP applicationsEntra Domain Services (separate paid service)Native
Identity governanceAccess reviews and PIM with P2Manual, or third-party tooling
LicensingFree tier, P1 with E3, P2 with E5Windows Server licences plus the hardware
Best forCloud applications and mobile workforcesOn-premise servers and legacy dependencies

Not sure which one fits?

Book a free 20-minute call. We will map what still depends on your domain and what it would take to remove it.

Book a scoping call →

What only Entra ID does

Identity that travels

A laptop in a coffee shop is governed exactly like one in the office. No VPN required for policy to apply.

Conditional access

Access decisions consider user risk, device compliance, location and application sensitivity, rather than assuming the network is trusted.

SaaS provisioning

SCIM provisioning and deprovisioning across cloud applications, so leavers actually lose access everywhere.

No servers to run

No domain controllers to patch, back up, or discover have quietly failed six months ago.

What still needs Active Directory

Group Policy

Thousands of Windows settings have no exact Intune equivalent. Most have a close one, but the mapping exercise is real work.

Kerberos and LDAP apps

Older line-of-business software that authenticates against a domain controller cannot simply be pointed at Entra ID.

File and print servers

On-premise file shares and print servers still expect domain-joined machines and domain accounts.

Certificate services

Internal PKI issued from AD Certificate Services usually needs a migration plan of its own before the domain can go.

Hybrid is the normal state, not the destination

Most organisations run Entra Connect to synchronise accounts from Active Directory into Entra ID. That is a sensible interim architecture, but it is often treated as permanent by default rather than by decision.

The cost of leaving it in place is real: two directories to keep consistent, synchronisation failures that surface as mysterious login problems, and an on-premise attack surface that has to be patched and monitored.

Retiring Active Directory is a dependency exercise, not a migration. List every application and service that authenticates against the domain, find the cloud-native path for each, and the domain controllers eventually become removable.

What we see in practice

Companies founded in the last decade generally never had Active Directory and should not acquire one. Cloud-only Entra ID with Intune or Jamf handles devices and identity without a server in the building.

For companies that do have it, the remaining dependencies are usually a file server, a print server and one or two legacy applications. Each has a modern replacement, and none of them are dramatic on their own.

A realistic Active Directory retirement runs three to nine months depending on application count. The technical work is rarely the hard part. Finding every dependency is.

Entra ID vs Active Directory FAQs

Is Entra ID just Active Directory in the cloud?

No. Active Directory uses Kerberos and LDAP to manage domain-joined machines on a controlled network. Entra ID uses SAML, OIDC and SCIM to manage identity for cloud applications and devices anywhere. Different protocols, different device model, different policy engine.

Can Entra ID fully replace Active Directory?

For cloud-first organisations, yes. It cannot replace Group Policy, Kerberos or LDAP for on-premise servers and legacy applications. Once those dependencies are gone, the domain controllers can be retired.

Do I still need domain controllers?

Only if something still authenticates against them: file and print servers, legacy line-of-business applications, internal PKI, or Group Policy that has not been reproduced in Intune. Otherwise they are cost and risk without benefit.

What is Entra Connect for?

It synchronises accounts from Active Directory into Entra ID so users have one identity across both. It is a bridge for hybrid environments, not a replacement for either directory.

How long does it take to retire Active Directory?

Typically three to nine months, driven by how many applications depend on the domain. Discovery and application remediation take most of that time; decommissioning the controllers is the short part.

Is Entra ID free?

A basic tier is included with Microsoft 365. The controls most companies actually need, including Conditional Access, are in P1, which comes with E3. Access reviews, PIM and Identity Protection are in P2, which comes with E5.

Still running domain controllers?

Tell us what authenticates against them and we will tell you honestly whether they can go, and what it would take.