Skip to main content
14/09/2026

Guide from AD to Entra Suite: Embracing Cloud-Only Identity and Access Management

Cloud & Infrastructure
Two women and one man having a casual meeting

Introduction

Identity and Access Management (IAM) is evolving rapidly as organizations replace on-premises Active Directory (AD) environments with cloud-based identity services. Increasingly, identity management is centralized in platforms such as Microsoft Entra to improve agility, security, and operational clarity. Microsoft Entra ID, formerly Azure AD, is Microsoft’s cloud-based identity and access management service and part of the broader Entra product family.

This guide outlines the benefits of moving to cloud-based identity and access management and introduces the key Microsoft Entra offerings: Entra ID P1, Entra ID P2, and Microsoft Entra Suite. It also compares Entra with dedicated IAM solutions and considers both its strengths and limitations.

Moving to cloud-based identity and access management

Organizations are moving from on-premises Active Directory to cloud identity platforms to meet the requirements of hybrid and remote work. Traditional Windows Active Directory was designed for on-premises environments and therefore requires network and server infrastructure as well as continuous maintenance.

Microsoft Entra ID, by contrast, is a cloud-based identity service that supports modern protocols such as SAML, OAuth, and OpenID Connect without requiring on-premises directory servers.

This shift offers several key benefits:

  • No on-premises infrastructure: Entra ID is delivered as SaaS, so separate directory servers are not required. Microsoft operates the service infrastructure and high availability, allowing IT to focus less on maintaining physical AD servers and more on strategic work.

  • Access regardless of location: In a cloud model, access control is based on verifying the user and device rather than trusting the internal network. Employees and partners can sign in securely from different locations and devices, supporting remote and mobile work.

  • Modern security capabilities: Cloud IAM includes multi-factor authentication, risk-based Conditional Access, and single sign-on to thousands of SaaS applications. Entra ID supports Zero Trust by evaluating the user, device, and sign-in context before access is granted. Together with Microsoft Defender and Intune, it helps protect identities, devices, applications, and data.

  • Seamless cloud integration: Entra ID provides a common identity for Microsoft 365 and Azure and integrates with other SaaS applications through OIDC and SAML. Centralizing identities in one directory reduces silos and simplifies user management.

  • Less dependence on legacy systems: A cloud model supports application modernization and the replacement of legacy solutions with SaaS services. It also reduces the need to maintain identity infrastructure solely for individual dependencies. As Microsoft Identity Manager use approaches its end by 2029, organizations should plan to replace MIM processes with cloud-based solutions.

In summary, a cloud-based IAM model improves agility, strengthens security, and simplifies administration. Self-service and automation accelerate onboarding and access management while reducing support requests such as password resets.

The transition should still be phased and carefully planned, because critical on-premises applications may need to be updated or replaced. When implemented well, centralizing IAM in Microsoft Entra delivers substantially more benefits than challenges.

Overview of Microsoft Entra

Microsoft Entra is Microsoft’s integrated identity and access management portfolio, with Microsoft Entra ID at its core. Its capabilities are available through Entra ID P1 and P2 and the Microsoft Entra Suite add-on. The sections below summarize the key features of each. Microsoft Entra Suite is also included in the Microsoft 365 E7 license package.

Foundational IAM Features

Microsoft Entra ID Premium P1 includes essential IAM capabilities needed to manage and secure identities in the cloud:

  • Single sign-on and centralized identity management: Entra ID P1 consolidates user and group information in one directory and enables SSO to Microsoft 365 and thousands of integrated applications. Dynamic groups and delegated administration simplify maintenance, while centralized access management reduces the need for separate accounts in each application.

  • Self-service password management: Users can reset their passwords through SSPR. In hybrid environments, the new password can be written back to on-premises AD. Password protection helps prevent common and compromised passwords across cloud and on-premises accounts.

  • Conditional Access and multi-factor authentication: Policies based on sign-in context can require MFA, restrict usage, or block access. Sign-ins from unfamiliar locations or unmanaged devices can be challenged or denied. Each request is evaluated individually in line with Zero Trust principles.

  • Hybrid environment support: Entra ID P1 synchronizes on-premises AD identities to the cloud with Entra Connect or Entra Cloud Sync. Entra Application Proxy publishes on-premises web applications for secure remote access with Entra ID SSO.

  • Microsoft Entra Verified ID: This decentralized identity solution enables organizations to issue and verify digital credentials, such as employee IDs or certificates. HR processes can use it, for example, with background or education credentials.

  • Foundational identity governance: P1 provides group-based licensing, application access, and delegated group management. Users and managers can handle straightforward access changes without continuous IT involvement.

In summary, Entra ID P1 provides the foundation for cloud identity: directory services, single sign-on, strong authentication, and essential security capabilities. It meets the everyday IAM needs of most organizations.

Self-service and single sign-on reduce administrative work for HR and IT. Entra ID P1 is included in many Microsoft base packages, including Microsoft 365 F1/F3/E1/E3. More advanced security and lifecycle management needs require Entra ID P2 and Entra ID Governance capabilities.

Advanced security and identity governance

Entra ID Premium P2 includes all P1 features and adds critical Identity Governance and enhanced security capabilities for organizations that need tighter control over identities and access lifecycle.

Key Entra ID P2 features include:

Entra Identity Protection

This feature uses Microsoft’s machine learning and threat intelligence to assess risk in real time during sign-ins. It can detect risky sign-in behavior (signs of compromised accounts like leaked passwords, atypical travel, malware-linked IPs) and automate responses.

For example, if a login is flagged as high-risk, risk-based conditional access policy can require a password change or MFA verification automatically. This helps organizations proactively respond to identity threats without waiting for manual admin action.

Privileged Identity Management (PIM)

Entra P2 provides just-in-time admin access for Entra ID and Azure roles. Rather than giving admins permanent standing permissions, PIM allows elevation to a role only when needed (and for a limited time).

Admins must activate roles (with MFA and approval if required) to perform privileged tasks, drastically reducing the window in which high-level permissions exist. PIM also logs and audits all privileged access and can enforce approval workflows, ensuring better control over who has admin access and when.

Access Reviews

To maintain least privilege, Access Reviews enable periodic review of users’ access rights. For any group, application, or role, managers or resource owners can be tasked to regularly certify who should continue to have access.

If a user no longer needs it (e.g. an employee changed departments), the reviewer can revoke that access during the review cycle. This is especially useful for sensitive resources and for managing guest users’ access.

Entitlement Management (Access Packages)

A standout Entra P2 feature is Entitlement Management, which includes Access Packages for self-service access requests. This allows IT to create bundles of resources (groups, applications, SharePoint sites, Teams, etc.) that users can request access to through a portal.

Access Packages come with built-in policies for approval workflow, duration of access, and automatic expiration. For example, you might publish an “Finance Apps Access” package that includes an expense system and finance SharePoint site; an employee in another department can request it, the request goes to the finance manager for approval, and the system will automatically revoke access after a defined period or trigger a review. This reduces IT and manager workload by automating access grant and removal.

Comprehensive Identity Governance Solution

Collectively, the above features (often grouped under Entra ID Governance) ensure that “the right people have the right access to the right resources at the right time,” in Microsoft’s words.

Entra P2’s tools help automate and enforce lifecycle practices that were traditionally manual. For organizations with strict compliance requirements (financial, healthcare, etc.), these features are often necessary.

Entra ID P2 is suitable for organizations that need stronger security, auditability, and access lifecycle management than P1 provides. It offers native access reviews and governed self-service processes.

The features require appropriate licensing for users who use or benefit from them. Entra ID P2 is included, for example, in Microsoft 365 E7, E5, and Microsoft 365 F5/E5 Security packages, and is also available as a standalone license

Microsoft Entra Suite – extending Entra ID P1/P2

Microsoft Entra Suite extends Entra ID with identity and network access solutions. P1 and P2 address core IAM needs, while the Suite adds capabilities that support a cloud-focused strategy. Its main components include:

  • Microsoft Entra ID Governance: This offering automates identity and access lifecycles and simplifies governance across cloud and on-premises applications. It brings together and extends capabilities such as access packages, access reviews, PIM, and Lifecycle Workflows.

  • Global Secure Access (GSA): Entra Internet Access and Entra Private Access protect access to internet and private resources through cloud-based network access controls. They extend identity-aware security to the network and implement a Zero Trust Network Access model.

  • Microsoft Entra Verified ID: Entra Suite supports high-assurance access processes in which Verified ID can be used, for example, to validate access requests. Face Check complements the solution with facial matching verification.

Entra Suite reflects Microsoft’s vision of a unified identity and network access platform. For IAM professionals, the most relevant parts are the P1 and P2 capabilities and Entra ID Governance, because they directly affect workforce identity management. Verified ID and network access services complement the solution according to organizational needs.

Microsoft’s leadership in cloud identity is evidenced by industry recognition: for eight consecutive years, Microsoft has been named a Leader in Gartner’s Magic Quadrant for Access Management, reflecting the strength of Entra ID in enabling secure access for millions of organizations. With the Entra Suite, Microsoft is expanding into adjacent IAM areas, though some are emerging offerings.

Microsoft Entra Workload ID

Microsoft Entra Workload ID: This Entra add-on includes features to manage non-human identities (service accounts, app registrations, workload credentials). This ensures applications and services follow the same identity security practices – e.g., Workload ID extends Access Reviews and Entra Identity Protection to workload identities, and enables Conditional Access for non-human service principals.

Microsoft Entra Permissions Management (retired)

Microsoft Entra Permissions Management (Retired): Previously, Entra included a Cloud Infrastructure Entitlement Management tool (from the CloudKnox acquisition) called Permissions Management, aimed at controlling excessive permissions in Azure/AWS/GCP.

However, this product has been retired and is no longer part of Entra’s offerings, so we will not cover it as per the latest guidance.

Entra vs. dedicated IAM solutions: How does it compare?

Microsoft Entra offers strong IAM and governance capabilities, but how does it compare with specialized platforms such as SailPoint, Okta, CyberArk, or Ping Identity? Large organizations have traditionally used dedicated IAM and IGA platforms for complex lifecycle and compliance requirements. The following sections summarize Entra’s main strengths and limitations.

Strengths

  • Highly scalable, globally distributed service with AI-driven security. Recognized by Gartner as a leader in Access Management for its comprehensive approach.

  • Entra ID provides a single control plane for authentication, MFA, SSO, and user/group management across Microsoft and many third-party apps.

  • Natively integrated with Microsoft 365 and Azure, offering seamless SSO and user provisioning. End-users benefit from self-service features in one portal, and admins get rich security tools (Conditional Access, Identity Protection) out-of-the-box.

  • Entra includes access request workflows, access reviews, and role management (PIM) features, covering many governance requirements without a separate product.

  • Entra has comprehensive API for creating customized automations and reporting and supports SCIM protocol for provisioning users and groups to scim-enabled SaaS applications. Organizations have successfully integrated on-premises catalogs using Entra’s provisioning services, though complex legacy environments might still find third-party tools useful.

  • Logic App Extendability: Microsoft Entra’s platform can be further enhanced through the integration of Azure Logic Apps, allowing organizations to automate complex identity workflows and tailor processes to their unique requirements. This extendability enables users to build custom connectors, trigger automated actions in response to identity events, and create advanced approval chains or notifications across systems, offering flexibility well beyond basic out-of-the-box capabilities.

Limitations

  • Entra focuses primarily on access within Entra ID and connected cloud apps, lacking the extensive connectors to every on-prem app or database that some enterprise IAM products offer out-of-the-box. For example, Entra does not have a separate "identity database" that you could connect with multiple identity sources for enriching the data and making for example provisioning decisions.

  • Despite Entra's ongoing improvements, its identity governance is not yet as advanced as that of dedicated IGA tools. Organizations may find that features such as conditional user provisioning, managers' reports and management of direct reports' permissions, complex role-based access controls, and fine-grained separation-of-duties policies are somewhat limited in Entra.

  • Dedicated solutions often allow custom workflows and UI tailored to business processes. Entra’s built-in processes are configurable but not fully customizable. If your process doesn’t fit interfaces provided by Entra, you might find it less flexible than an IGA platform where you can for example customize UI or define custom forms for different IAM scenarios.

Bottom Line: Microsoft Entra covers the identity basics and many advanced features for many use cases, especially in Microsoft-centric and cloud-forward environments. Its strengths lie in seamless user experiences, strong security integration, and progressively richer governance capabilities built right into the platform.

Dedicated IAM and IGA products offer more connectors, deeper governance, and broader customization. They may be necessary in complex environments, but they also add cost and architectural complexity. Organizations should therefore evaluate Entra ID P2 and Entra Suite capabilities first.

If clear gaps remain, such as managing accounts in a legacy on-premises system or supporting unusually detailed access reviews, Entra ID can be combined with a dedicated IGA solution. Missing capabilities may also be implemented with ITSM tools or, for example, Microsoft Power Platform.

Microsoft is quickly catching up in governance capabilities, and many organizations have begun to rely on Entra as their one-stop IAM solution. The trend in the industry suggests that cloud platforms like Entra will continue to integrate more governance functions, potentially reducing the need for separate IAM products in the future for all but the most complex scenarios.

What next?

Identity management is at the heart of digital transformation. An IAM solution based on Microsoft Entra can improve security and efficiency by reducing on-premises infrastructure, standardizing integrations, and introducing continuously evolving protection capabilities. When IAM is centralized in Entra, HR and IT can manage each user’s identity consistently throughout its lifecycle.

For HR, Entra enables better alignment between identity processes and workforce processes: new employees receive the required access on their first day, role changes trigger the correct updates, and departures are handled promptly. Self-service and automation, including access packages and Lifecycle Workflows, reduce forms and email. IAM specialists gain native tools for implementing Zero Trust principles and governance controls.

When planning IAM modernization, consider the following steps:

  • Start with Entra ID P1: Deploy application SSO, MFA, passwordless authentication such as passkeys, Conditional Access, and self-service password reset comprehensively. These capabilities deliver security and productivity benefits quickly without substantial additional complexity.

  • Introduce P2 governance features gradually: If you have the licensing, start with a pilot of one or two P2 features. For example, enable Privileged Identity Management for your Administrators to protect those high-impact accounts, or set up Access Reviews for a critical application group to clean up any excess access. This will let your organization feel out the processes and tweak as needed. Over time, expand these governance practices to more areas (e.g. quarterly reviews of all guest users, entitlement management for one department’s access needs, etc.).

  • Use Access Packages for common scenarios: Identify frequent access request scenarios (joining a project, requesting admin access to an application, partner access, etc.) and deploy Access Packages for them. Communicate the availability of the “My Access” self-service portal to your users and partners. This not only reduces the IT burden but also provides a better user experience. People will get access faster and with proper approvals in place, and the organization retains control and visibility.

  • Partnership between IT and HR on Lifecycle Workflows: HR and IT responsible of IAM should work closely to integrate Entra’s lifecycle automation with HR’s processes. For instance, HR can agree to provide accurate start dates, transfer dates, and end dates in the system, and IAM will configure workflows to act on those. This partnership will ensure that both teams are in sync – HR triggers and IT actions will be coordinated. As a result, the joiner/mover/leaver process can become nearly hands-free, with audit trails to satisfy compliance.

  • Monitor and tidy up external identities: External collaboration is essential, but so is security. Put policies in place using Entra to manage guest accounts: require that each guest has an internal sponsor, use access reviews to periodically reconfirm guest access, and consider setting up automated removal for inactive guests. This governance will prevent an accumulation of “forgotten” accounts in your directory. Many breaches originate from old accounts that were never deprovisioned – don’t let that happen in your Entra ID.

  • Assess additional tools based on need: Compare requirements with Entra’s capabilities and distinguish temporary gaps from permanent needs. Short-term gaps can often be addressed with scripts or a limited complementary tool. Consider a dedicated IGA solution only for long-term, complex requirements and integrate it closely with Entra.

Follow Microsoft’s roadmap and industry best practices. IAM is developing rapidly, and a limitation today may be addressed in a future Entra update. Microsoft community resources, blogs, research, and peer assessments can help organizations evaluate the platform’s direction and others’ experiences.

At Context&, we can help you build a roadmap and deploy these services in your organization. Contact us to continue the discussion.

Read more

icon
Blog

Guide from AD to Entra Suite: Embracing Cloud-Only Identity and Access Management

icon
Blog

Advanced Intune Capabilities Now Included in Microsoft 365 E3 and E5 – What It Means for Your Organization

icon
Blog

From Configuration Manager to Intune: Why Modern Endpoint Management Is Essential for AI Readiness

icon
Blog

How do you transition to modern device management in practice?