Comparison Table: Microsoft Identity Solutions Over Time
🔄 Comparison Table: Microsoft Identity Solutions Over Time
Feature / Aspect | Active Directory (AD) | AD Federation Services (AD FS) | Azure Active Directory (Azure AD) | Microsoft Entra ID |
---|---|---|---|---|
Launch Year | 1999 | 2003 (with Windows Server 2003) | 2013 | 2023 (rebrand) |
Deployment | On-premises | On-premises | Cloud-based | Cloud-based |
Primary Use Case | Internal network identity | Federated SSO for web apps | Cloud identity for SaaS, hybrid users | Unified cloud IAM |
User Authentication | Kerberos, NTLM | SAML, WS-Federation | OAuth 2.0, OpenID Connect, SAML | Same as Azure AD |
Supports Cloud Apps (e.g., M365, Salesforce) | ❌ No | ⚠️ Limited via federation | ✅ Yes | ✅ Yes |
SSO Capabilities | ❌ Basic (on-prem only) | ✅ Yes (with setup) | ✅ Native | ✅ Native |
Multi-Factor Authentication | ❌ No | ⚠️ Via 3rd-party | ✅ Built-in (with premium tiers) | ✅ Built-in |
Conditional Access | ❌ No | ❌ No | ✅ Yes (P1/P2 licenses) | ✅ Yes |
External/B2B User Support | ❌ No | ⚠️ Complex setup | ✅ Yes | ✅ Yes |
Hybrid Identity Support | ✅ Native | ⚠️ via AD FS | ✅ via Azure AD Connect | ✅ via Azure AD Connect |
Device Management | ✅ via GPO | ❌ No | ✅ via Intune integration | ✅ via Intune integration |
Governance Features (PIM, Access Reviews) | ❌ No | ❌ No | ✅ (P2 license) | ✅ (P2 license) |
Identity Standards Support | LDAP, Kerberos | SAML, WS-Fed | SAML, OAuth2, OIDC | Same as Azure AD |
Part of Microsoft 365? | ❌ No | ❌ No | ✅ Yes | ✅ Yes |
Branding | Windows Server AD | AD FS | Azure AD | Microsoft Entra ID |
✅ Key Takeaways:
-
Active Directory (AD) is best for on-premises infrastructure.
-
AD FS was a bridge for early web/cloud SSO but is now largely deprecated in favor of Azure AD.
-
Azure Active Directory introduced cloud-native identity and modern authentication.
-
Microsoft Entra ID is essentially Azure AD rebranded, now positioned under a broader Microsoft Entra identity and security platform.
Comments
Post a Comment