Updated: January 17, 2024 (June 25, 2018)

  Analyst Report

AAD Is Not a Replacement for Active Directory

My Atlas / Analyst Reports

588 wordsTime to read: 3 min
Wes Miller by
Wes Miller

Wes Miller analyzes and writes about Microsoft’s security, identity management, and systems management technologies. Before joining Directions on Microsoft, Wes... more

  • The Azure Active Directory hosted service could evolve over the coming years to be a more comprehensive alternative to Active Directory Domain Services on-premises.
  • Retiring Active Directory in favor of any hosted directory service is not practical for most organizations today.

Active Directory Domain Services (AD DS) is the Windows Server role that delivers on-premises identity and access management. Azure Active Directory (AAD) is a similar hosted service. At a very high level, AAD and AD DS can deliver similar functionality, and small organizations or business units might consider replacing AD DS with AAD. However, due to the differences between the two technologies, this is not likely possible today.

Limitations Preventing AD DS Retirement

Several capabilities of AD DS, or services that depend on it, would need to be replaced before an organization’s on-premises directory servers could be retired. For example, AAD does not include AD domain join, group policy, or support for AD Federation Services. While Microsoft offers AAD- or Intune-based alternatives for these technologies, none is a complete replacement of its on-premises counterpart.

Atlas Members have full access

Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.

Membership Options

Already have an account? Login Now