

ForgeRock and Microsoft Entra External ID compete in identity and access management, each offering unique benefits. Microsoft Entra External ID has the upper hand with seamless Azure integration and potentially quicker ROI through bundled services.
Features: ForgeRock offers dynamic authorization, identity orchestration, and rich API capabilities for customization. Microsoft Entra External ID features strong Azure service integration, allowing streamlined processes and substantial scalability. The key difference is ForgeRock's focus on a customizable experience, while Entra emphasizes integration within Microsoft systems.
Ease of Deployment and Customer Service: Microsoft Entra External ID has an intuitive setup process, benefiting from native Azure integration and strong support channels for quick resource access and assistance. ForgeRock requires more complex initial deployment but offers robust customization. Microsoft stands out in deployment due to a streamlined process leveraging existing infrastructures.
Pricing and ROI: ForgeRock has a higher initial setup cost but justifies it with long-term ROI through customization and scalability. Microsoft Entra External ID offers competitive pricing beneficial for those integrated into Azure, providing potentially quicker ROI through reduced infrastructure changes. The distinction lies in ForgeRock's long-term customization benefits versus Entra's cost-effective integration.
On a B2B level, it opened up the market for TomTom to sell its services in a more efficient way to car companies.
We can use a Linux image from ForgeRock with different systems, applications, websites, and mobile apps to create various types of access for users.
I can definitely see that fewer employees are needed compared to using different SaaS applications.
It has led to cost savings as well as time savings because I can use a single solution for all applications.
Companies can leverage it for setting up external identities without needing to develop their own solutions.
In terms of return on investment, prior to using this product, our company managed our own mail server with all internal authentication happening on premises, resulting in a ROI in the thousands every year.
The support portals offer comprehensive documentation, troubleshooting guides, and community forums that have been helpful for resolving common issues independently.
For standard support tickets, response times were very decent, and the support team was helpful in identifying configuration issues, especially with authentication trees, token settings, and directory replications.
The customer support is very flexible and supportive, particularly in the area of automation and customer deployments.
Companies without a Microsoft license for Entra ID or Azure portal cannot add Azure AD B2C, creating logistical issues for some of my clients who are unable to evaluate the platform.
The support for business applications, infrastructure support, and Entra has been mostly positive with highly skilled technicians.
The documentation is very thorough, reducing the need for support.
The access management layer is stateless, so I can scale horizontally by adding more nodes behind a load balancer as traffic increases.
The platform provides flexible authentication trees, enabling us to design custom MFA flows tailored for different user groups and risk profiles.
We scaled up with ForgeRock. My team received an award for implementing it for a 60 million customer base, which was the largest implementation at that time.
This is one of EID's weak points compared to Azure AD B2C, which offers customizable authentication options, including attribute and password combinations.
End-user workloads experience increased latency in a cloud environment compared to on-premises resources.
Microsoft Entra External ID is quite scalable, and I would rate its scalability between eight and nine out of ten.
ForgeRock supports integration with legacy systems in our organization by offering a wide range of connectors and APIs.
ForgeRock is very stable because it manages access, authentication, and authorization effectively.
I'd rate the stability of the Microsoft Entra External ID as a 10.
The stability of this solution is very good.
I have not encountered any stability issues with Microsoft Entra External ID.
ForgeRock needs to focus on low-code, no-code solutions that allow for drag-and-drop functionality with good orchestration.
It would be better if they were available for support whenever the customer needs it, especially during migration or go-live time periods.
The main area is complexity. ForgeRock is extremely flexible, but the learning curve can be steep.
This is particularly challenging during enterprise agreement renewals, as it's difficult for customers to review costs leading to lengthy negotiations.
Enhanced customizable login options and the ability to use attribute password logins are critical features that are required for Microsoft Entra External ID to gain dominance in the authentication market.
I would like to see a more detailed alert system that provides a summary of why alerts are generated, who is generating them, and the reasons behind it.
The pricing, setup cost, and licensing are very straightforward, which is a good success.
One has to spend considerable time trying to understand the different modules and different needs for those modules on the licensing front.
Regarding pricing, the cost seems high for single sign-on, especially for external applications like Oracle.
Microsoft's pricing is complex and difficult to fathom due to a range of different licensing options.
The cost can be a factor for Microsoft Entra External ID, but in general, it offers a scalable and efficient solution compared to deploying individual solutions.
Centralized management makes the biggest difference because it allows us to define, update, and enforce security and compliance rules from a single location.
ForgeRock positively impacts our organization as we manage a large number of users with ease, providing a standard IAM solution that simplifies our processes.
ForgeRock has positively impacted my organization by allowing us to migrate from the older system to the newer ForgeRock component, enabling us to go live with many products across geographies, enhancing security as it is all cloud-based, and with the company taking care of availability, it has reduced costs for the company.
It is crucial for hybrid environments, especially for integrating existing on-site infrastructures with cloud-based Active Directory, such as in Office 365 implementations.
EID unifies workforce users with external business partners, which is a very strong feature.
The detailed monitoring and reporting in Microsoft Entra External ID support compliance efforts effectively.
| Product | Mindshare (%) |
|---|---|
| ForgeRock | 7.6% |
| Microsoft Entra External ID | 4.5% |
| Other | 87.9% |
| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 5 |
| Large Enterprise | 18 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 2 |
| Large Enterprise | 6 |
ForgeRock offers robust integration, customization, and identity management with support for SAML, OAuth 2.0, and DevOps readiness, ensuring enhanced security and scalability.
ForgeRock stands out in identity and access management featuring flexible authentication flows, risk-based authentication, centralized policy management, and comprehensive data protection. Its open-source foundation and cloud capabilities allow versatility and ease of use. While it provides excellent user path orchestration through the Journey feature, challenges exist in integration support and user-friendly customization. Improved documentation and streamlined interfaces are necessary to overcome deployment complexities. Additionally, the cost and support model may be burdensome for smaller organizations.
What are the key features?ForgeRock is widely utilized in industries like telecommunications, insurance, and open banking for secure user authentication and access management. It supports microservice authentications, customer identity management, single sign-on, and multi-factor authentication, integrating effectively with existing infrastructures to enhance security and user experience.
Microsoft Entra External ID provides streamlined identity management with features like Active Directory integration, multi-factor authentication, and centralized user management, supporting both B2C and B2E needs. It's designed to enhance security while simplifying access management across applications.
Microsoft Entra External ID enhances identity management by offering easy setup, robust monitoring, and centralized user management. It supports compliance with comprehensive reporting and integrates seamlessly with Azure. While it facilitates cross-company collaboration, user lifecycle management, and B2B guest access, users note the need for improved technical support, faster synchronization speeds, and more customizable interfaces. Integration with open-source software, legacy tools, and ERP systems is advised along with a more predictable pricing model and improved federated login security. Current licensing complexity and the need for more user-friendly interfaces are areas for development.
What are the most important features?In sectors like IT, finance, and healthcare, Microsoft Entra External ID is utilized for managing complex access needs and compliance requirements, supporting projects involving Active Directory, Microsoft Teams, and cloud-based infrastructures. These industries leverage its capabilities for managing identities and improving secure collaboration while ensuring alignment with existing on-premises systems.
We monitor all Customer Identity and Access Management (CIAM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.