Try our new research platform with insights from 80,000+ expert users

Azure Firewall vs Microsoft Entra ID Protection comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Azure Firewall
Ranking in Microsoft Security Suite
10th
Average Rating
7.4
Reviews Sentiment
7.1
Number of Reviews
40
Ranking in other categories
Firewalls (13th)
Microsoft Entra ID Protection
Ranking in Microsoft Security Suite
9th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
16
Ranking in other categories
Identity Management (IM) (8th), Identity Threat Detection and Response (ITDR) (2nd)
 

Mindshare comparison

As of May 2025, in the Microsoft Security Suite category, the mindshare of Azure Firewall is 4.2%, down from 5.1% compared to the previous year. The mindshare of Microsoft Entra ID Protection is 4.6%, up from 3.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Microsoft Security Suite
 

Featured Reviews

AnvarSadique - PeerSpot reviewer
Easy setup and effective traffic routing enhance security
In terms of improvements, I think the price could be a concern as Azure ( /products/microsoft-azure-reviews ) services are often more expensive compared to other firewalls. However, the functional aspects of Azure Firewall met our needs. While I found the interface not particularly user-friendly, this is a common issue across vendors.
Mahender Nirwan - PeerSpot reviewer
Access to other software is just one click away and suitable for big organizations
Currently, we have limited use of Microsoft AD. We only use it to see if user blocks are available. If they are, we unblock the account and get access accordingly. AD has paid access control features. We can add access control over AD. For example, for documentation, we use an Outline tool. It's open source, and we add our company's knowledge base to it. It's an alternative to Confluence. We don't want everyone to have access to all documentation. If I create documentation for my team, only my team should have access, not support or sales. We can add these scopes or access controls over AD. Once integrated, the person will get the appropriate access control features upon logging in. Role-based access control is a great feature of Active Directory.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Microsoft's technical support is very good. They're quite knowledgable and responsive."
"Among the most valuable features are the DDoS protection that protects your virtual machines, the threat intelligence, and traffic filtering."
"I can easily configure it."
"Great security and connectivity."
"In terms of the reporting, it's beautiful. It integrates with Azure monitoring and with Azure policies. That piece is a big help. You can set governing policies and you can use the application firewall, as well as the Azure Firewall, to enforce those policies."
"The most valuable feature is the integration into the overall cloud platform."
"The SIEM that Azure Firewall provides us is very robust."
"Azure Firewall is a cloud-native solution that removes the pain of load balancers."
"The deployment process is straightforward. It takes a few hours to complete."
"For me, automatization is most valuable."
"The valuable features of Entra ID Protection include providing me visibility of my entire estate, managing access, and having a level of control."
"The valuable features include multifactor authentication, accessory capabilities, and conditional access for specific applications."
"The tool is simple and you can find a lot of tutorials, and videos on YouTube that can help you."
"As an end-user, I find the experience to be quite seamless. My main advantage is that I only need to manage one login and one two-factor authentication method to access all the necessary tools. I don't have to set up separate logins and authentication for each application."
"I find the most valuable feature to be conditional access."
"I find the most valuable feature to be conditional access. It allows for comprehensive security controls, network security, and application label security."
 

Cons

"It's a little heavy compared to a FortiGate or other firewalls."
"Azure Firewall has limited visibility for IDPS, no TLS inspection, no app ID, no user ID, no content ID, no device ID. There is no antivirus or anti-spyware. Azure Firewall doesn't scan traffic for malware unless it triggers an IDPS signature. There is no sandbox or machine learning functionality, meaning we are not protected from Zero-day threats. There is no DNS security and limited web categories."
"Azure has new versions including a premium firewall. But I would like to see them not put the premium features on Azure Firewall Premium alone because it is quite expensive."
"The interface could be improved, it's not very user friendly."
"There are a number of things that need to be simplified, but it's mostly costs. It needs to be simplified because it's pretty expensive."
"There is a lot of room for improvement, so I would rate it a six out of ten overall."
"One thing that would help engineers adopt it better is the documentation."
"For larger enterprises, they need to adjust the scalability."
"Integrating some notifications, not necessarily all, but at least for important events or alerts, would be beneficial as it would function as a team solution or something similar."
"Identity labeling and sensitivity needs improvement."
"There is room for improvement in the ability for Entra ID Protection to inherit roles and configurations from whatever solution I am migrating from, so that these don't have to be built from the ground up during the implementation process."
"Microsoft has not offered control over how they calculate high or low-risk scenarios."
"The product's initial setup phase is not easy."
"Microsoft has room for improvement in simplifying their integration with third-party solutions and making the licensing model more understandable."
"Entra ID lacks a function to synchronize from the cloud to the local directory. This is a significant issue since there is no write-back feature from the cloud to local, which would allow me to use my own credentials from the cloud tenant securely."
"Microsoft has not offered control over how they calculate high or low-risk scenarios. While they mention if a low risk is found by Microsoft, the triggered policy isn't customizable."
 

Pricing and Cost Advice

"I rate the product pricing a five out of ten."
"Azure Firewall is more expensive. If Microsoft can make Azure Firewall cheaper, I can see that all clients will think of using it. One client used FortiGate because it is much cheaper. Some clients ask me for Cisco, but in the cloud estimate, I found its cost is the same as Azure Firewall."
"Before choosing this solution, we evaluated others, and we found this to be the most cost-effective."
"The licensing module is good."
"The pricing of Azure Firewall is pay-as-you-go. Fortinet also has a pay-as-you-go model, but Azure's pricing is higher and, with FortiGate, you also have the license."
"It is pay-as-you-go. So, you pay based on the usage. If I remember it well, there is a basic fee, and there is a traffic fee. It is not per month. It is per hour or something like that. It is not so expensive."
"Azure Firewall is expensive."
"Azure Firewall comes with Azure native services. We did not buy any kind of license for it. Whether you have a free subscription or a pay-as-you-go model, you can deploy the Azure Firewall service... The amount that you use will determine how much you pay."
"Azure Active Directory Identity Protection is not very expensive."
"The price of Azure AD is not expensive."
"The pricing is competitive in the SMA segment and runs $5-$6 per user."
"From one to ten, if one is cheap and ten is expensive, I rate the tool a seven out of ten."
"The product cost is on the expensive side."
report
Use our free recommendation engine to learn which Microsoft Security Suite solutions are best for your needs.
851,491 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
10%
Government
10%
Manufacturing Company
7%
Computer Software Company
17%
Financial Services Firm
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firewall is easy to use and provides excellent support. Valuable features include int...
How does Azure Firewall compare with Palo Alto Networks VM Series?
Both products are very stable and easily scalable. The setup of Azure Firewall is easy and very user-friendly and the overall cost is reasonable. Azure Firewall offers a solid threat awareness, can...
Which would you recommend - FortiGate VM or Azure Firewall?
Both of these solutions are excellent options that provide flexible scalability and solid security. Fortinet Fortigate VM integrates well and has excellent centralized reporting. It is very easy to...
What is your experience regarding pricing and costs for Azure Active Directory Identity Protection?
The pricing for Microsoft Entra ID protection is not expensive. It varies based on the company's size and quality.
What needs improvement with Azure Active Directory Identity Protection?
I have set up my Active Directory locally for the same domain. However, Entra ID lacks a function to synchronize from the cloud to the local directory. This is a significant issue since there is no...
 

Also Known As

No data available
Azure Active Directory Identity Protection, Azure AD Identity Protection
 

Overview

Find out what your peers are saying about Azure Firewall vs. Microsoft Entra ID Protection and other solutions. Updated: April 2025.
851,491 professionals have used our research since 2012.