Microsoft Entra ID (formerly Microsoft Azure Active Directory or Azure AD) is a cloud-based identity and access management (IAM) solution supporting restricted access to applications with Azure Multi-Factor Authentication (MFA) built-in, single sign-on (SSO), B2B collaboration controls, self-service password, and integration with Microsoft productivity and cloud storage (Office 365, OneDrive, etc) as well as 3rd party services.
$6
per user/per month
Zscaler Internet Access
Score 8.8 out of 10
N/A
Zscaler Internet Access™ (ZIA) is a secure web gateway (SWG), delivering cloud native cyberthreat protection and zero trust access to the internet and SaaS apps.
Google Workspace is really pretty much the only other primary competitor. And again, Microsoft has just been the standard for so many years and it was in place at the organization when I was first brought on at the beginning of my tenure. And so it didn't seem logical to switch …
Yeah, so basically that product to be honest, was more of a getting comfortable with cloud identification management. So that was a product I used. It has all the policies for desktops and doing updates and all that central directory identity provisioning stuff for users. Users …
We use DUO as another IDP solution and we also evaluated Okta as a solution. We didn't have a choice to be honest, because Microsoft products, you can't get away with it, but it's built in and a bunch of other providers have it as authentication, so it's great.
We've used other Microsoft products and we've also used some standalone products, like each application you can have its own identity, so we've looked at some of those too, but we try to use the Entra ID as much as possible because it offers a wider range of reliability.
We actually did just the Microsoft Active directory, so we picked the actual. We did just pure active directory. I mean the open LDAP stuff, but it didn't quite work that well.
I think the closest one would be because we recently went through an implementation, but Salesforce has their own version of a signal sign-on product. It's not the same. I'd say that it works, but it doesn't give you as much functionality.
For us, it was a natural evolution of our use of active directory. As we went from on-premises to the cloud, this was an easy extension of our authentication infrastructure. We looked at other products from Oracle, so Oracle ID, Oracle Identity Management. We looked at pink …
We used Google before, but we tried to use it but it didn't. We didn't like it. I'll this is better. It integrates better with our environment that we have right now.
We're Microsoft dedicated. We do however, displace other products that do similar things, so a lot of third party products, so even like Okta. In my opinion, it's just equally as powerful or more powerful of a product and it has a way better price point for customers. I think …
I'd love to tell you about Amazon IM and Google's IM because they suck and they tell you to use Entra ID, factually. They're like, oh cool, set it up with Entra ID. They just know you're going to do it. I don't think you guys have a competitor, to be honest. You just don't.
We're a Microsoft Native shop, so we're looking at Okta's identity tool, SailPoint and a few other competitors of Venture id. And we decided to go with this one because we're already using Active Directory, so just using the native Microsoft Suites kind of just they integrate …
Well, it's natively integrated with all Microsoft Stack, so it comes very handy when you need to, for example, use it for Intune Association, et cetera, so it's very handy.
Previously we had worked with Okta, which was kind of using our replacement for active directory server, and I know that has integrations, but we ended up just going with Entra ID just for the ease of access and without having to stack on an additional third party application …
In our application use case, it's kind of unique and there isn't any like for if there's anything on the identity space, probably Okta. Yeah. But we do both use them and we have integration with Okta and Entra ID, so it works for us very well.
Microsoft Login ID was chosen for its ease of use and availability of access via any device. Unlike the old Active Directory, it has a low learning curve and is very intuitive for analysts who are using it for the first time.
Netskope was good however did not have all the features Zscaler had. Zscaler provides the same type of protection as Netskope but more. We also found the netskope agent used a lot of resoures on devices. ZCC was very light-weight and did not consume a lot of resources on laptops.
Palo support has been a large enough negative experience on multiple occasions that we have been looking to move away from the platform and Zscaler Internet Access looks to be a suitable replacement
Zscaler Internet Access is most akin to ZPA - we bought both at the same time to handle all traffic internally and externally. In terms of quality - I would make the statement that Zscaler Internet Access is a simpler product but that's also cause there are no App Connectors …
Zscaler Internet Access has significantly more configurability and capability in the platform, and can scale much better with large organizations. It is also much more affordable for our environment and gives us greater flexibility to grow into the Zscaler Platform.
For one, a significant factor for us is that it is integrated with HelloID, which gives us, as the IT department, a lot of time back because we don’t need to create user accounts manually. It is great for the roles we have defined, as they can be used repeatedly. A great feature is that guest accounts can be created for external users; we only need to be in a closed area of your domain.
Zscaler Internet Access has extremely powerful category selection and it is very easy to create your own destinations for inspection and policy exceptions (SSL exception specifically). It is also very affordable and just as powerful (if not more) than some of the other solutions I have used in the past to achieve internet security.
It addresses the issue of identity management very well with respect to putting in that multi authentication.
It can also support with respect to we can push these policies into another product that is not Microsoft, but it needs that SSO so we can have one account going into multi different accounts. I think that's the biggest pros and the easy use of Microsoft 365 also is one of those pros also in terms of administration.
The depth that Cloud App control policies can go into. Being able to control individual actions within an application, more than just all or nothing access.
The UX/UI design makes it really easy to navigate the portal.
Understanding how cloud app/url control policy gets evaluated and creating/editing existing policy is extremely straightforward.
Well, I'm an active ad admin, so there's a lot of features in active directory that Entra ID seems to be just adding now. We're kind of figuring out that the policies are different than Entra ID that they were in active directory and we're finding other products to do that, like Azure policy. Some things I'm used to seeing in identity products or like active directory aren't in Entra iID, but are doing good job of managing stuff that it does so far.
Entra ID is a vital part of our Identity management/administration. With the integrations it has to other Microsoft products, setup and configuration is a breeze. Additionally, Microsoft has been around a long time and have the resources to ensure this product is stable and secure for many years to come. We know it will evolve with time to provide us what we need as technology changes.
While Zscaler Internet Access (ZIA) delivers critical value in cloud security and RBI compliance, I rate renewal likelihood 7/10 due to evolving needs versus platform limitations. Below is my rationale:
Very easily usable. It could be easier to use. Implementation was kind of tricky. We do run a hybrid environment, so we're syncing a local active directory instance with Entra ID, so that could be a little tricky. But outside of that, if you're not running a hybrid deployment or a version of Entra ID usually, it's pretty straightforward.
The application is easy to install and configure on all Windows devices. To troubleshoot any internet issue, we can easily collect all the relevant logs from Zscaler and check the exact issue. The only problem is with the uninstall, as a dedicated crew needs to provide the password.
Microsoft has offered Azure Active Directory as a solution for a couple of decades now, so they have seen and anticipated almost any issue that an organization may face and can therefore help. The cloud offering of Azure Active Directory offers some additional "self healing" or monitoring services that can minimize the need for a service call. However, as with most large companies supporting a fast growing market, there may be some gaps in service knowledge (and particularly processing) from the front line / tier one staff as they follow a corporate script at first contact.
Zscaler's ZIA support is quick and knowledgable. They respond within 1-2 hours of you submitting your ticket. They are very thorough and are typically ready to jump on a live troubleshooting session. Our ZIA platform and how we use is it unique so at times tickets can be open for weeks but we alway get quality support compared to other unrelated product support in our enterprise
Make sure you use a good partner. Our implementation was a bit longer and more problematic than we expected. Our partner got it done, but, in my opinion, some of their inexperience and staffing issues were evident.
Microsoft Entra ID is not as stand-alone product as competitors like Okta. It may lack some of the features that competing products have but on the other hand it integrates both technically and license wise with other Microsoft cloud services and is easy to deploy. It is also the easiest way to extend identity management to the cloud if you already have Microsoft Active Directory in use.
Zscaler Internet Access is most akin to ZPA - we bought both at the same time to handle all traffic internally and externally. In terms of quality - I would make the statement that Zscaler Internet Access is a simpler product but that's also cause there are no App Connectors involved in that process.
I don't know if I can really quantify that. It's one of those products that just exists and so there's not a whole lot of changes that we need to make with the product. And so I guess in terms of value, what we get is we don't have to worry about the identity management piece. We know that that's taken care of.
Has allowed us to remove other products that were suboptimal
Saved us money overall by stacking it with other Zscaler products
Created a more secure work environment for our users through intelligent internet policies that are not needlessly restrictive while still maintaining security best practices