
On-premises Active Directory from Microsoft has existed longer than Azure AD Identity. Companies have implemented Active Directory Domain Services (Azure AD DS) for authentication and authorisation on-premises globally.
Companies are also taking advantage of the capacity and capabilities, reducing costs and utilising cloud authentication and authorisation (with all its benefits, such as built-in SSO). MICROSOFT’S Azure AD (Active Directory) is a multi-tenant, cloud-based Identity as a Service (IDaaS).
Azure Active Directory (Azure AD) is an inclusive identity and access management cloud solution offered by Microsoft to help businesses transform how they work. We can help you learn and understand how to use this digital infrastructure to sign in, access external resources, and manage your internal IT systems and employees on the cloud. Microsoft combines core directory services, application access management, and advanced Azure AD protection to provide the best Azure AD services.
Features of Azure AD Identity
Azure Identity management gives you multiple features to manage your data. Some of the advanced functionalities of Azure AD are:
- Manage both cloud and on-premises apps efficiently with Single Sign-On
- Secure authentication with conditional access
- Governance and Identity protection
- Access your network via on-premises and external devices
In addition to Single Sign-On, Azure AD Identity has enhanced robust identity management and security capabilities, such as multi-factor authentication (MFA), self-service password reset, privileged identity management (PIM), role-based access control, and application usage monitoring, auditing and security monitoring, and alerting.
Azure AD is available in four editions with different features and functionality. Server Consultancy can help you pick the proper subscription to meet your requirements.
| Azure Active Directory | Microsoft Office 365 | Azure Active Directory Premium P1 | Azure Active Directory Premium P2 | |
| Azure AD Premium P1, included with Microsoft 365 E3, offers a free 30-day trial. Azure and Office 365 subscribers can buy it online. | Additional Azure AD features are included with Office 365 E1, E3, E5, F1, and F3 subscriptions.2 | Azure AD Premium P1, included with Microsoft 365 E3, offers a free 30-day trial. Azure and Office 365 subscribers can buy Azure AD Premium P1 online. | Azure AD Premium P2, included with Microsoft 365 E5, offers a free 30-day trial. Azure and Office 365 subscribers can buy Azure Active Directory Premium P2 online. | |
| End-user self-service | √ | |||
| Self-service sign-in activity search and reporting | √ | √ | √ | |
| User application collections in My Apps | √ | √ | √ | √ |
| Self-service password change for cloud users | √ | √ | √ | √ |
| Application launch portal (My Apps) | √ | √ | √ | √ |
| Self-service entitlement management (My Access) | √ | |||
| Self-service account management portal (My Account) | √ | √ | √ | √ |
| Self-service password reset/change/unlock with on-premises write-back | √ | √ | ||
| Self-service group management (My Groups) | √ | √ | ||
| Applications Access | √ | √ | ||
| Secure hybrid access partnerships8 (Kerberos, NTLM, LDAP, RDP, and SSH authentication) | √ | √ | √ | √ |
| Cloud app discovery (Microsoft Defender for Cloud Apps)7 | √ | √ | ||
| Group assignment to applications | √ | √ | ||
| SaaS apps with modern authentication (Azure AD application gallery apps, SAML, and OAuth 2.0) | √ | √ | √ | √ |
| Application Proxy for on-premises, header-based, and Integrated Windows Authentication | √ | √ | ||
| Event logging and reporting | √ | |||
| Advanced security and usage reports | √ | √ | ||
| Identity Protection: risk events investigation, SIEM connectivity | √ | |||
| Azure AD Identity Protection Portal: vulnerabilities and risky accounts | √ | |||
| Basic security and usage reports | √ | √ | √ | √ |
| Authentication, single sign-on and multi-factor authentication (MFA) | √ | √ | ||
| Passwordless (Windows Hello for Business, Microsoft Authenticator, FIDO2 security key integrations5) | √ | √ | √ | √ |
| Cloud authentication (Pass-through authentication, password hash synchronisation) | √ | √ | √ | √ |
| Single sign-on (SSO) unlimited3 | √ | √ | √ | √ |
| Service-level agreement6 | √ | √ | ||
| Multi-factor authentication (MFA)4 | √ | √ | √ | √ |
| Federated authentication (Active Directory Federation Services or federation with other identity providers) | √ | √ | √ | √ |
| Frontline workers | √ | √ | ||
| Delegated user management portal (My Staff) | √ | √ | ||
| SMS sign-in | √ | √ | ||
| Shared device sign-out | √ | √ | ||
| Administration and hybrid identity | √ | √ | ||
| Global password protection and management – cloud-only users | √ | √ | √ | √ |
| User and group management | √ | √ | √ | √ |
| Global password protection and management – custom banned passwords, users synchronised from on-premises Active Directory. | √ | √ | ||
| Directory synchronisation—Azure AD Connect (sync and cloud sync) | √ | √ | √ | √ |
| Microsoft Identity Manager user client access license (CAL)10 | √ | √ | ||
| Delegated administration—built-in roles | √ | √ | √ | √ |
| Advanced group management (Dynamic groups, naming policies, expiration, default classification) | √ | √ | ||
| Azure AD Connect Health reporting9 | √ | √ | ||
| Azure AD Identity Governance | √ | |||
| Terms of use attestation | √ | √ | ||
| Privileged Identity Management (PIM), just-in-time access | √ | |||
| Automated user provisioning to apps | √ | √ | √ | √ |
| HR-driven provisioning | √ | √ | ||
| Entitlements management | √ | |||
| Automated group provisioning to apps | √ | √ | ||
| Access certifications and reviews | √ | |||
| Authorisation and Conditional Access | √ | |||
| SharePoint limited access | √ | √ | ||
| Role-based access control (RBAC) | √ | √ | √ | √ |
| Identity Protection (Risky sign-ins, risky users, risk-based conditional access) | √ | |||
| Session lifetime management | √ | √ | ||
| Conditional Access | √ | √ |
- The free edition of Azure AD identity is included with a subscription to a commercial online service such as Azure, Dynamics 365, Intune, Power Platform, and others in countries where they are available for sale.
- Additional Azure AD identity features are included with Office 365 E1, E3, E5, F1, and F3 subscriptions in countries that are available for sale.
- With the free edition of Azure AD identity, end-users are assigned access to the software as a service (SaaS) apps and can get single sign-on access to an unlimited number of cloud apps. On-premises apps require Azure AD Identity Application Proxy or secure hybrid partnerships integrations with Azure AD Identity Premium P1 and Premium P2.
- Authentication methods and configuration capabilities may vary by subscription. Learn more.
- FIDO2 security key partners.
- Terms and conditions for service-level agreements.
- To access the cloud app discovery features, go to the cloud app security portal and log in with your Azure AD Premium P1 credentials. Azure AD Identity Premium P2 customers won’t need to enter credentials and will be automatically redirected.
- Secure hybrid access partnerships: The conditional access API requires Premium P1, and the Risky User API requires Premium P2 for Secure Hybrid Access.
- The first monitoring agent requires at least one license, and each additional agent requires 25 additional incremental permissions. Agents monitoring Azure AD Federation Services, Azure AD Connect, and Azure AD Domain Services are separate agents.
- Microsoft Identity Manager Server software rights are granted with Windows Server licenses (any edition). Since Microsoft Identity Manager runs on Windows Server OS, as long as the server is running a valid, licensed copy of Windows Server, Microsoft Identity Manager can be installed and used on that server. No separate license is required for the Microsoft Azure AD Identity Manager Server.





