{"id":43669,"date":"2023-01-03T09:32:11","date_gmt":"2023-01-03T14:32:11","guid":{"rendered":"https:\/\/jumpcloud.com\/?p=43669"},"modified":"2024-11-08T17:53:22","modified_gmt":"2024-11-08T22:53:22","slug":"azure-ad-total-cost-ownership","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership","title":{"rendered":"Total Cost of Ownership of Azure AD"},"content":{"rendered":"\n

Editor\u2019s Note: Given the fast-paced nature of technology, it is possible that some of the information presented in this article is out-of-date, or incomplete, in some fashion. The author periodically reviews and revises this article to ensure information contained within is as accurate as possible.<\/em><\/p>\n\n\n


\n\n\n\n

Microsoft\u00ae<\/sup> Azure\u00ae<\/sup> is an umbrella for a variety of cloud services, including Azure Active Directory (AAD). On its face, Azure AD might seem like a replacement<\/a> for on-prem Active Directory (AD)<\/a> or a cloud-based solution for organizations in need of a directory service, but more factors come into play for IT admins making purchasing decisions, including complicated SKUs and licensing. This article examines the total cost of ownership (TCO) of AAD for the type of configuration that a small and medium-sized enterprise (SME) would require for its identity management lifecycle.

AAD was created to extend on-prem AD identities to Azure in order to provide user management for Microsoft Office applications, and now single sign-on (SSO) for service providers (SP). It\u2019s available as a standalone product, but is also bundled with Microsoft 365 (M365) subscriptions. Microsoft has positioned AAD as the connective tissue within a broader identity and access management (IAM) ecosystem. That extends from users and devices to its security portfolio. Add-ons and integrations are almost inescapable, because AAD is very interwoven with those products. It\u2019s not even possible to implement Microsoft\u2019s
best practices for AAD<\/a> without paying more.<\/p>\n\n\n\n

A Codependent Approach<\/h2>\n\n\n\n

Significantly, Microsoft manages endpoints separately from identities even though experts recommend making identity the new perimeter<\/a> in cybersecurity. Device management (outside of AD) is only bundled with some of its premium M365 SKUs, but not AAD. Organizations that aren\u2019t using M365 will have to purchase a separate subscription to manage their devices.<\/p>\n\n\n\n

Microsoft\u2019s reference architecture suggests an array of Microsoft-based tools to fully leverage AAD, so even Microsoft-heavy IT shops will encounter more IT infrastructure and maintenance costs. You\u2019ll have limited administrative capabilities if you use AAD without on-prem AD, or aren\u2019t subscribed to premium tiers and add-on services. For example, you won\u2019t be able to employ the suite of group policy objects (GPOs) to on-prem Windows devices, and you\u2019ll struggle with authenticating local IT resources such as applications and file servers. <\/p>\n\n\n\n

AAD is also not an open directory, so working with external identities from other identity providers (IP) and connecting users to IT resources (RADIUS, LDAP) requires even more solutions. Some are cloud-based, but others expand its footprint on-premise, and are reliant on AD.<\/p>\n\n\n\n

\n
\n \"JumpCloud\"\n <\/div>\n
\n

\n Breaking Up with Active Directory <\/p>\n

\n Don\u2019t let your directory hold you back. Learn why it\u2019s time to break up with AD. <\/p>\n <\/div>\n

\n Read Now<\/a>\n <\/div>\n<\/div>\n\n\n\n\n

Costs of Azure Active Directory<\/h2>\n\n\n\n

To fully assess the TCO of Azure AD, it\u2019s necessary to account for tangential, but necessary, costs. Fortunately, we\u2019ve developed an equation to help you understand the TCO of AAD:<\/p>\n\n\n\n

\n

Costs of Azure Active Directory = Azure AD Premium Package + Add-Ons for device management + External Identities + Azure AD DS + Active Directory + LDAP Server + RADIUS Server + Integration\/Management Time for your implements<\/p>\n<\/blockquote>\n\n\n\n

Let\u2019s begin by assessing AAD\u2019s pricing and then branch outward to the other components.<\/p>\n\n\n\n

Standalone Azure AD and M365<\/h3>\n\n\n\n

Standalone AAD has three SKUs:<\/p>\n\n\n\n