Skip to main content
AD Academy
Microsoft Entra ID (Azure AD)
Intermediate12 minLast updated: Topic 1 of 6

What Entra ID is and how it differs from AD DS

Cloud identity versus an on-prem domain controller — the core concepts.

Not read

What you will learn here

  • What Entra ID does — and what it does not
  • The key differences from on-prem AD DS
  • Core objects: Users, Groups, App Registrations

Microsoft Entra ID (formerly Azure ) is a cloud identity service. It manages users, groups and access to SaaS apps such as Microsoft 365. Important: Entra ID is not a cloud version of AD DS — it is a different service with different protocols.

Key differences

  • DS uses and ; Entra ID uses OAuth 2.0, OpenID Connect and SAML.
  • DS has OUs and GPOs; Entra ID has Administrative Units and Intune policies.
  • DS manages domain-joined computers; Entra ID manages access to cloud apps and devices through Intune.
  • Entra ID has no forest and no domain controllers — it is a managed service layer.

Main objects

  • Users — cloud-only accounts or accounts synced from DS.
  • Groups — Security and Microsoft 365, with static or dynamic membership.
  • App Registrations and Service Principals — identities for apps and scripts.
  • Roles — admin roles such as Global Administrator or User Administrator.

Two columns: on-prem AD DS on the left, cloud Entra ID on the right. Protocols — Kerberos, NTLM and LDAP versus OAuth 2.0, OpenID Connect and SAML. Structure — Forest, Domain, OU and GPO versus Tenant, Administrative Units and Intune policies. Manages — AD DS manages domain computers and domain controllers, Entra ID manages access to SaaS such as Microsoft 365 and devices through Intune. Objects — users, groups and computers in the NTDS.dit database versus users, groups, app registrations, service principals and roles.

Check yourself

Which protocol does Entra ID use to authenticate cloud apps?

What does Entra ID not have?

Was this page helpful?