No more typing reviews! Try our Samantha, our new voice AI agent.

Amazon Cognito vs Microsoft Entra ID comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 11, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Amazon Cognito
Ranking in Access Management
10th
Average Rating
7.6
Reviews Sentiment
6.5
Number of Reviews
17
Ranking in other categories
No ranking in other categories
Microsoft Entra ID
Ranking in Access Management
1st
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
276
Ranking in other categories
Single Sign-On (SSO) (1st), Authentication Systems (1st), Identity Management (IM) (3rd), Identity and Access Management as a Service (IDaaS) (IAMaaS) (1st), Microsoft Security Suite (2nd)
 

Mindshare comparison

As of June 2026, in the Access Management category, the mindshare of Amazon Cognito is 3.0%, down from 6.0% compared to the previous year. The mindshare of Microsoft Entra ID is 12.1%, down from 26.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Access Management Mindshare Distribution
ProductMindshare (%)
Microsoft Entra ID12.1%
Amazon Cognito3.0%
Other84.9%
Access Management
 

Featured Reviews

BM
Staff Software Engineer at Visa
Custom authentication has enabled secure multi-factor logins and unified access across apps
The features or capabilities of Amazon Cognito that I have found the most valuable so far include its seamless operation and the requirement of fewer integrations from the client side. All the features are there, enabling us to create the users, manage the groups, and manage access. Mostly, the access management is very good in Amazon Cognito, I would say. The benefits and positive impacts that Amazon Cognito has had in my experience include the fact that earlier we needed to implement so many things on behalf of the product itself. Now, the go-to-market strategy requires less than a week to complete integrations of the user flow, specifically mentioning that a basic authentication flow could be completed in a week itself. We don't have to care about how we manage the passwords, how we manage groups, and how we manage access management because all those things are there. It's handy, the documentation is very good, and it is easy to integrate. That's the reason I would say that the impact AWS is building on the product is great.
Stafin Jacob - PeerSpot reviewer
Microsoft 365 Security & Compliance Practice Lead at Invoke
Identity has become our central gatekeeper and has provided secure single sign-on for all users
Microsoft Entra ID can improve by focusing more on new passwordless methods and becoming a primary adopter. One feature we would like to see is the ability to have security questions for password resets. I know the current capability is phasing out, so we do not have an alternative method yet. Customers who already use security questions require a smoother transition for that capability to be available. My experience with the deployment has had some challenges, particularly around the Microsoft MFA campaigns. The hardest part is moving users from a different MFA provider to the Microsoft MFA provider, as it ultimately depends on user activity. In large enterprises with numerous users across various geographies, this transition takes time. If there are ways to exert more control around that process, it would improve the situation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the key benefits of this software is its ease of integration with a wide range of applications, including mobile apps and web applications. This simplifies the process of integration, and it can be seamlessly incorporated with Azure, Kubernetes, and other software systems."
"What I find most valuable about Amazon Cognito is the single sign-on feature that provides a token for accessing protected APIs."
"The multi-factor authentication setup has room for improvement."
"The features most valuable to us are the ability to integrate with various IDPs and the capability to sync with multiple applications."
"The most valuable feature of the solution is its swift authentication."
"I appreciate Amazon Cognito's ability to scale with demand and its seamless user verification features."
"This is a scalable solution. If our app or general usage increases, this solution can support it."
"What is quite valuable is that we can outsource storage of the credentials to AWS, and they manage it quite securely."
"Identity management with policies stands out as the most valuable feature. It offers a hands-off experience, providing full control over user access."
"The implementation of device-bound passkeys in Microsoft Authenticator helps with phishing-resistant authentication."
"I would rate the solution as 9. It is a very good solution for unified management."
"The way the laptops are joined is valuable. We can take advantage of that in terms of being able to log in and do things. It is easier to change passwords or set things up."
"Single sign-on is the reason we use AD."
"Microsoft Entra ID offers strong security levels, especially with two-step authentication, which confirms that I am the real user."
"Scalability has been the biggest benefit."
"Azure Active Directory provides access to resources in a very secure manner. We can detect which user is logging in to access resources on the cloud. It gives us a comprehensive audit trace in terms of from where a user signed in and whether a sign-in is a risky sign-in or a normal sign-in. So, there is a lot of security around the access to resources, which helps us in realizing that a particular sign-in is not a normal sign-in. If a sign-in is not normal, Azure Active Directory automatically blocks it for us and sends us an email, and unless we allow that user, he or she won't be able to log in. So, the User Identity Protection feature is the most liked feature for me in Azure Active Directory."
 

Cons

"I would rate its scalability as five out of ten. Moving users between different pools or accounts creates new identities, which means IDs stored in our database must also be changed."
"Amazon Cognito’s UI needs improvement while onboarding new users."
"The setup and configuration can be complex, especially for advanced use cases."
"Amazon Cognito could improve by simplifying the configuration."
"In a future release, we would like to have different methods to validate the characteristic of a user. For example, we would like to use biometric data to analyze the behavior of users."
"The MFA related to the solution's side is nonexistent."
"Cognito triggers can improve by providing more direct use cases rather than giving a white paper. A white paper is not at all interesting, it has too many details. It would be a benefit to provide a smaller document that is summarized. The smaller version would bring microdata, macro data is not helpful."
"You need to evaluate the export users. The multifactor authentication, much less this room for improving the configuration setup of that."
"Its integration with open-source applications can be improved. I know that they are working on open-source authentication methods for integration with open-source applications, but they can make it more open."
"The visibility in the GUI is not good for management. There are a lot of improvements that could make it better. It should be more user-friendly overall. It is not user-friendly because everything keeps changing on the platform. I can understand it because I know the platform, am familiar with it, and use it every day. However, for a lot of clients, they don't use it every day or are not familiar with it, so it should be more user friendly."
"Azure AD needs to be more in sync. The synchronization can be time-consuming."
"I would evaluate Microsoft support as three out of ten. Microsoft support does not engage right away."
"The conditional access rules are a little limiting. There's greater scope for the variety of rules and conditions you could put in that rules around a more factual authentication for other users. If you have an Azure AD setup, you can then connect to other people's Azure AD, but you don't have a huge amount of control in terms of what you can do. Greater control over guest users and guest access would be better. It's pretty good as it is but that could be improved."
"I think Microsoft Entra ID could be improved by assigning permissions to nested groups in the next release."
"Azure AD does not support legacy authentication protocols, such as NTLM or Kerberos."
"The Cloud Provisioning Agent cannot provision a lot of the information that AD Connect does. For starters, the lightweight version cannot synchronize device information. If you have computers on-premises, the information about them will not be synchronized by the Cloud Provisioning Agent. In addition, if you have a user on the cloud and he changes his password, that information should be written back to the on-premises instance. But that workflow cannot be done with the lightweight agent. It can only be done with the more robust version."
 

Pricing and Cost Advice

"The price of Amazon Cognito is expensive. We are on an annual subscription."
"We pay $600 monthly per user for licences and there are no other additional costs."
"The pricing is bad so I rate it a two out of ten."
"The pricing of this solution is good compared to other solutions on the market."
"The price of the solution depends on the number of users using it."
"The price of Amazon Cognito is low. The pricing model is based on the users."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a five out of ten."
"The product is relatively inexpensive compared to other tools."
"It is bundled with other services and the pricing is quite reasonable."
"Entra's pricing is somewhat higher compared to AWS."
"It is a really nice tool and we have a license for the more complex model."
"Pricing-wise, they offer a stepladder approach. You can start with the lowest level features, then start increasing based on new requirements."
"The subscription should be categorized by business size. For example, small companies should have a discounted price, this would help small companies and the organization to be automated."
"It is a packaged license. We have a Premium P1 subscription of Office 365, and it came with that."
"The price is fine. It's a good value for the money compared with other solutions."
"The solution can be cheaper."
report
Use our free recommendation engine to learn which Access Management solutions are best for your needs.
900,838 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
11%
Construction Company
9%
Financial Services Firm
8%
Manufacturing Company
7%
Financial Services Firm
12%
Manufacturing Company
8%
Government
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise5
By reviewers
Company SizeCount
Small Business89
Midsize Enterprise41
Large Enterprise161
 

Questions from the Community

What is your experience regarding pricing and costs for Amazon Cognito?
I am aware that the pricing of Amazon Cognito is not managed by me directly but is managed by some other teams, specifically the DevOps teams. As far as I know, it is based on how many users we hav...
What needs improvement with Amazon Cognito?
I think Amazon Cognito provides less flexibility to customize at the moment. It is very tightly coupled with its own services, so it does not provide customization according to what the client need...
What is your primary use case for Amazon Cognito?
The usual use cases for Amazon Cognito that I have been working with mostly involve working for TLG Apps for three and a half years, where TLG Apps is a FinTech company in the UK. We were working f...
How does Duo Security compare with Microsoft Authenticator?
We switched to Duo Security for identity verification. We’d been using a competitor but got the chance to evaluate Duo for 30 days, and we could not be happier. Duo Security is easy to configure a...
What is your experience regarding pricing and costs for Azure Active Directory?
My experience with pricing, setup cost, and licensing is that going through and being able to use these things is always part of delivering an M365 bundle, so I don't think the experience is great ...
What needs improvement with Azure Active Directory?
Microsoft Entra ID can be improved by open-sourcing it. You already have Windows Subsystem for Linux, which is open-source Linux in Microsoft. One major shift for Microsoft would be using the commo...
 

Also Known As

No data available
Azure AD, Azure Active Directory, Azure Active Directory, Microsoft Authenticator
 

Interactive Demo

 

Overview

 

Sample Customers

Expedia, Intuit, Royal Dutch Shell, Brooks Brothers
Microsoft Entre ID is trusted by companies of all sizes and industries including Walmart, Zscaler, Uniper, Amtrak, monday.com, and more.
Find out what your peers are saying about Amazon Cognito vs. Microsoft Entra ID and other solutions. Updated: June 2026.
900,838 professionals have used our research since 2012.