SALES: 1-800-867-1380

Azure Active Directory Premium and Basic

Published: November 21, 2013

Updated: September 3, 2014

Applies To: Azure

Built on top of a large set of free capabilities in Microsoft Azure Active Directory, Active Directory Premium and Azure Active Directory Basic editions provide a set of more advanced features to help empower enterprises with more demanding identity and access management needs. When you subscribe to Azure, you get your choice of the following free and paid editions of Azure AD:

  • Active Directory Free - With the Free edition of Azure AD, you can manage user accounts, synchronize with on-premises directories, get single sign on across Azure, Office 365, and thousands of popular SaaS applications like Salesforce, Workday, Concur, DocuSign, Google Apps, Box, ServiceNow, Dropbox, and more.

  • Active Directory Basic - Azure AD Basic provides the application access and self-service identity management requirements of task workers with cloud-first needs. With the Basic edition of Azure AD, you get all the capabilities that Azure AD Free has to offer, plus group-based access management, Self-Service Password Reset for cloud applications, customizable environment for launching enterprise and consumer cloud applications, and an enterprise-level SLA of 99.9 percent uptime.

  • Active Directory Premium - With the Premium edition of Azure AD, you get all of the capabilities that Azure AD Free and Azure AD Basic have to offer, plus additional feature-rich enterprise-level identity management capabilities explained below.

To sign up and start using Active Directory Premium today, see Getting started with Azure AD Premium.

noteNote
Azure AD Premium and Azure AD Basic are not currently supported in China. Please contact us at the Azure Active Directory Forum for more information.

Active Directory Basic edition is a paid offering of Azure AD and includes the following features:

  • Company branding – To make the end user experience even better, you can add your company logo and color schemes to your organization’s Sign In and Access Panel pages. Once you’ve added your logo, you also have the option to add localized versions of the logo for different languages and locales.

    For more information, see Add company branding to your Sign In and Access Panel pages.

  • Group-based application access – Use groups to provision users and assign user access in bulk to thousands of SaaS applications. These groups can either be created solely in the cloud or you can leverage existing groups that have been synced in from your on-premises Active Directory.

    For more information, see Assign access for a group to a SaaS application.

  • Self-service password reset – Azure has always allowed directory administrators to reset passwords. With Azure AD Basic, you can now reduce helpdesk calls when your users forget a password by giving all users in your directory the capability to reset their password, using the same sign in experience they have for Office 365.

    For more information, see Self-service password reset for users.

  • Enterprise SLA of 99.9% - We guarantee at least 99.9% availability of the Azure Active Directory Basic service.

Active Directory Premium edition is a paid offering of Azure AD and includes the following features:

  • Company branding – To make the end user experience even better, you can add your company logo and color schemes to your organization’s Sign In and Access Panel pages. Once you’ve added your logo, you also have the option to add localized versions of the logo for different languages and locales.

    For more information, see Add company branding to your Sign In and Access Panel pages.

  • Group-based application access – Use groups to provision users and assign user access in bulk to over thousands of SaaS applications. These groups can either be created solely in the cloud or you can leverage existing groups that have been synced in from your on-premises Active Directory.

    For more information, see Assign access for a group to a SaaS application.

  • Self-service password reset – Azure has always allowed directory administrators to reset passwords. With Azure AD Premium, you can now reduce helpdesk calls when your users forget a password by giving all users in your directory the capability to reset their password, using the same sign in experience they have for Office 365.

    For more information, see Self-service password reset for users.

  • Self-service group management - Azure AD Premium simplifies day-to-day administration of groups by enabling users to create groups, request access to other groups, delegate group ownership so others can approve requests and maintain their group’s memberships.

    For more information, see Self-service group management for users.

  • Advanced security reports and alerts – Monitor and protect access to your cloud applications by viewing detailed logs showing more advanced anomalies and inconsistent access pattern reports. Advanced reports are machine learning-based and can help you gain new insights to improve access security and respond to potential threats.

    For more information, see View your access and usage reports.

  • Multi-Factor Authentication - Multi-Factor Authentication is now included with Premium and can help you to secure access to on-premises applications (VPN, RADIUS, etc.), Azure, Microsoft Online Services like Office 365 and Dynamics CRM Online, and thousands of Non-MS Cloud services preintegrated with Azure AD. Simply enable Multi-Factor Authentication for Azure AD identities, and users will be prompted to set up additional verification the next time they sign in.

    For more information, see Adding Multi-Factor Authentication to Azure Active Directory.

  • Microsoft Forefront Identity Manager (MIM) - Premium comes with the option to grant rights to use a MIM server (and CALs) in your on-premises network to support any combination of Hybrid Identity solutions. This is a great option if you have a variation of on-premises directories and databases that you want to sync directly to Azure AD. There is no limit on the number of FIM servers you can use, however, MIM CALs are granted based on the allocation of an Azure AD premium user license.

    For more information, see Deploy MIM 2010 R2.

  • Enterprise SLA of 99.9% - We guarantee at least 99.9% availability of the Azure Active Directory Premium service.

    For more information, see Active Directory Premium SLA

  • More features coming soon – The following premium features are currently in public preview and will be added soon:

Azure AD Basic and Azure AD Premium have more advanced capabilities to help streamline enterprise-level administrative tasks and make an administrator’s life easier. The following table describes common admin benefits and how signing up for Azure AD Basic or Azure AD Premium help simplify them.

 

Admin Benefits Features Free edition Basic edition Premium edition

Manage your cloud directory and how your accounts are synchronized

Directory as a service

       Checklist
Up to 500K objects1

        Checklist
No object limit

        Checklist
No object limit

Directory synchronization tool – For syncing between on-premises Active Directory and Azure AD

       Checklist

        Checklist

        Checklist

Forefront Identity Manager (FIM) server licenses – For syncing between on-premises databases and/or directories and Azure AD

        Checklist

High availability SLA uptime (99.9%)

        Checklist

        Checklist

Centrally administer accounts and control access to your applications

User and group management using UI or Windows PowerShell cmdlets

       Checklist

        Checklist

        Checklist

User-based application access management and provisioning

       Checklist

        Checklist

        Checklist

Access Panel portal for SSO-based user access to SaaS and custom applications

       Checklist
Up to 10 apps per user2

       Checklist
Up to 10 apps per user2

        Checklist
No app limit

Group-based application access management and provisioning

        Checklist

        Checklist

Customization of company logo and colors to the Sign In and Access Panel pages

        Checklist

        Checklist

Empower your users & reduce support costs

Self-service password change for cloud users

       Checklist

        Checklist

        Checklist

Self-service group management for cloud users

        Checklist

Self-service password reset for cloud users

        Checklist

        Checklist

Monitor security and enforce additional verification methods to mitigate risks

Standard security reports

       Checklist

        Checklist

        Checklist

Advanced anomaly security reports (machine learning-based)

        Checklist

Advanced application usage reporting

        Checklist

Multi-Factor Authentication service for cloud users

        Checklist

Multi-Factor Authentication server for on-premises users

        Checklist

1 The 500k object limit does not apply for Office 365, Windows Intune or any other Microsoft online service that relies on Azure AD for directory services.

2 With Azure AD Free and Azure AD Basic, end users who have been assigned access to each SaaS app, can see up to 10 apps in their Access Panel and get SSO access to them (assuming they have first been configured with SSO by the admin). Admins can configure SSO and assign user access to as many SaaS apps as they want with Free, however end users will only see 10 apps in their Access Panel at a time.

See Also

Was this page helpful?
(1500 characters remaining)
Thank you for your feedback
Show:
© 2014 Microsoft