Microsoft Azure Active Directory (Azure AD) sits in the emerging category of Cloud IAM (Identity and Access Management), sometimes labeled IDaaS, though that term often omits the crucial “access management” dimension. In the KuppingerCole model, Cloud IAM combines cloud directory services, identity federation, access management for federated services, and modern authentication options such as social login, adaptive authentication, and step-up authentication. While not all vendors cover this full set—and many still depend on on-premises directories—Cloud IAM is positioned as a complement to traditional on-premises IAM, not a “rip and replace” alternative, especially where legacy IT must be supported.
The demand for Cloud IAM is driven by the “Computing Troika” of cloud, mobile, and social computing: organizations need rapid onboarding/offboarding, self-registration for customers, BYOD realities, and the ability to manage far more external identities (partners and potentially millions of customers) than classic employee-focused IAM models were built for. Azure AD is both Microsoft’s own IAM foundation for services like Azure and Office 365 and a customer-facing offering, demonstrating proven elasticity and massive daily scale.
Despite the name, Azure AD is not a direct cloud port of on-premises Active Directory; it is purpose-built for Cloud IAM. It includes a highly scalable directory with a fully flexible schema, multi-tenant isolation, and modern access via a REST-based Graph API rather than LDAP by default. Azure AD supports federation standards (SAML 2.0, OAuth 2.0, WS-Federation/WS-Trust), integrates with thousands of cloud services, and offers cloud provisioning when federation is unsuitable. Integration with on-premises environments is supported via synchronization (Azure AD Connect) or federation with AD FS. Azure AD is offered in Free, Basic, and Premium editions, with Premium adding features such as Multi-Factor Authentication, and is positioned as a leading-edge Cloud IAM choice for managing external users and extending on-premises Active Directory into the cloud.
See All Locations
See All Locations