Quick Verdict
Entra ID is not a hosted version of Active Directory. It is a different model: identity for cloud applications and internet-facing devices, governed by conditional access rather than by network location. Active Directory still does things Entra cannot, chiefly Group Policy, Kerberos and LDAP for on-premise servers. If those dependencies are gone, keeping a domain controller alive is cost and risk with no return.
Side-by-Side Comparison
| Feature | Microsoft Entra ID | Active Directory (AD DS) |
|---|---|---|
| Protocols | SAML, OIDC, OAuth 2.0, SCIM | Kerberos, NTLM, LDAP |
| Where it lives | Microsoft cloud, no servers to run | Domain controllers you patch and back up |
| Device model | Entra joined or registered, anywhere | Domain joined, on the corporate network or VPN |
| Policy engine | Conditional Access and Intune configuration | Group Policy |
| SaaS single sign-on | Native | Only via a federation layer |
| Works off the network | Requires VPN or line of sight to a DC | |
| MFA | Native | Third-party add-on required |
| File and print services | ||
| Legacy LDAP applications | Entra Domain Services (separate paid service) | Native |
| Identity governance | Access reviews and PIM with P2 | Manual, or third-party tooling |
| Licensing | Free tier, P1 with E3, P2 with E5 | Windows Server licences plus the hardware |
| Best for | Cloud applications and mobile workforces | On-premise servers and legacy dependencies |
Not sure which one fits?
Book a free 20-minute call. We will map what still depends on your domain and what it would take to remove it.
Book a scoping call →What only Entra ID does
Identity that travels
A laptop in a coffee shop is governed exactly like one in the office. No VPN required for policy to apply.
Conditional access
Access decisions consider user risk, device compliance, location and application sensitivity, rather than assuming the network is trusted.
SaaS provisioning
SCIM provisioning and deprovisioning across cloud applications, so leavers actually lose access everywhere.
No servers to run
No domain controllers to patch, back up, or discover have quietly failed six months ago.
What still needs Active Directory
Group Policy
Thousands of Windows settings have no exact Intune equivalent. Most have a close one, but the mapping exercise is real work.
Kerberos and LDAP apps
Older line-of-business software that authenticates against a domain controller cannot simply be pointed at Entra ID.
File and print servers
On-premise file shares and print servers still expect domain-joined machines and domain accounts.
Certificate services
Internal PKI issued from AD Certificate Services usually needs a migration plan of its own before the domain can go.
Hybrid is the normal state, not the destination
Most organisations run Entra Connect to synchronise accounts from Active Directory into Entra ID. That is a sensible interim architecture, but it is often treated as permanent by default rather than by decision.
The cost of leaving it in place is real: two directories to keep consistent, synchronisation failures that surface as mysterious login problems, and an on-premise attack surface that has to be patched and monitored.
Retiring Active Directory is a dependency exercise, not a migration. List every application and service that authenticates against the domain, find the cloud-native path for each, and the domain controllers eventually become removable.
What we see in practice
Companies founded in the last decade generally never had Active Directory and should not acquire one. Cloud-only Entra ID with Intune or Jamf handles devices and identity without a server in the building.
For companies that do have it, the remaining dependencies are usually a file server, a print server and one or two legacy applications. Each has a modern replacement, and none of them are dramatic on their own.
A realistic Active Directory retirement runs three to nine months depending on application count. The technical work is rarely the hard part. Finding every dependency is.
Entra ID vs Active Directory FAQs
Is Entra ID just Active Directory in the cloud?
Can Entra ID fully replace Active Directory?
Do I still need domain controllers?
What is Entra Connect for?
How long does it take to retire Active Directory?
Is Entra ID free?
Still running domain controllers?
Tell us what authenticates against them and we will tell you honestly whether they can go, and what it would take.