Microsoft Entra ID (formerly Azure ) is a cloud identity service. It manages users, groups and access to SaaS apps such as Microsoft 365. Important: Entra ID is not a cloud version of AD DS — it is a different service with different protocols.
Key differences
- DS uses and ; Entra ID uses OAuth 2.0, OpenID Connect and SAML.
- DS has OUs and GPOs; Entra ID has Administrative Units and Intune policies.
- DS manages domain-joined computers; Entra ID manages access to cloud apps and devices through Intune.
- Entra ID has no forest and no domain controllers — it is a managed service layer.
Main objects
- Users — cloud-only accounts or accounts synced from DS.
- Groups — Security and Microsoft 365, with static or dynamic membership.
- App Registrations and Service Principals — identities for apps and scripts.
- Roles — admin roles such as Global Administrator or User Administrator.
Two columns: on-prem AD DS on the left, cloud Entra ID on the right. Protocols — Kerberos, NTLM and LDAP versus OAuth 2.0, OpenID Connect and SAML. Structure — Forest, Domain, OU and GPO versus Tenant, Administrative Units and Intune policies. Manages — AD DS manages domain computers and domain controllers, Entra ID manages access to SaaS such as Microsoft 365 and devices through Intune. Objects — users, groups and computers in the NTDS.dit database versus users, groups, app registrations, service principals and roles.