Link to Entra ID vs Keycloak: Summary TableEntra ID vs Keycloak: Summary Table
| Feature | Microsoft Entra ID | Keycloak |
|---|---|---|
| Deployment Model | SaaS only (fully managed by Microsoft) | Self-hosted: deploy on-premises or in any cloud (Docker, Kubernetes, VMs) |
| Operational Responsibility | Microsoft: scaling, patching, DR, uptime | Customer: all infrastructure, scaling, patching, DR |
| Customization/Extensibility | Configuration and limited templates; custom logic not allowed | Deep: custom flows via Java SPIs; full UI theming; server-side extensions |
| Protocol Support | OIDC, SAML (1st-class); no native LDAP | OIDC, SAML, native LDAP integration, brokering with custom providers |
| User, Group, Role Model | Azure AD-centric, groups/roles; token group claims capped (150 SAML/200 JWT) | Multi-realm, multi-client, flexible custom attributes, roles, and mapping |
| Cost Model | Subscription/licensing; indirect infra/ops included | Open source (free license); customer pays for infra/ops and personnel |
| Hybrid/Integration | Integrates with on-premises AD via Microsoft connectors; SaaS extensibility only | Can act as identity broker and protocol bridge between many sources |
| Best Fit | Microsoft-centric, workforce SSO/M365, SaaS-first | Scenarios needing full control, on-prem hosting, custom authentication/flows |
| Common Gotchas | Group claim limits, not an LDAP endpoint, no customer server logic | Operational overhead, need for Java expertise, limited native reporting/GRC |
Link to Deployment Model and Operational OwnershipDeployment Model and Operational Ownership
Microsoft Entra ID is a fully managed cloud identity platform. It is available exclusively as a SaaS service—there is no on-premises or self-hosted option. Microsoft controls patching, disaster recovery, high availability, scaling, and all underlying infrastructure. Users interact with Entra ID through configuration and policy management portals, and integrate applications via documented APIs and protocols.
Keycloak is open source and self-hosted. Organizations install and operate Keycloak on their infrastructure of choice—on-premises, private or public cloud, or using containers orchestrated by Kubernetes or Docker. Full operational responsibility remains with the organization: this includes upgrades, security patching, backup, scaling, disaster recovery, and monitoring.
Implications:
- Entra ID shifts operational burden and risk to Microsoft. There is limited need for in-house identity infrastructure expertise beyond integration and configuration, but also less flexibility in deep system changes.
- Keycloak provides full control, but also makes the organization responsible for uptime, compliance, scale, and all maintenance tasks. For complex customization or on-prem requirements, this tradeoff may be necessary.
Link to Protocol and Federation SupportProtocol and Federation Support
Microsoft Entra ID
- First-class support for OpenID Connect (OIDC) and SAML 2.0.
- Deep integration with Microsoft SaaS (e.g., Microsoft 365).
- Does not function as a general-purpose LDAP endpoint. On-premises Active Directory integration is achieved via federated connectors or directory synchronization tools, not via direct LDAP queries from custom apps.
- Federation supports SSO to SAML/OIDC apps, and inbound federation from external identity providers via supported protocols.
Keycloak
- Native SAML 2.0 and OIDC provider; can act as an identity broker to external IdPs.
- Native support for LDAP user federation: can connect to on-premises LDAP directories to map, authenticate, or synchronize users and groups.
- Supports complex federation scenarios, protocol bridging (e.g., brokering SAML to OIDC), custom identity sources, and integration with non-standard protocols via plugins or extensions.
Typical Integration Patterns:
- Keycloak is suitable as a universal SSO/authentication hub for mixed-protocol and highly customized integration landscapes—including scenarios requiring LDAP, legacy directories, modern SAML/OIDC apps, and custom identity providers.
- Entra ID excels for modern cloud SSO, centralized policy/governance, and Microsoft ecosystem integrations, but is less flexible outside those bounds.
Link to Customization and ExtensibilityCustomization and Extensibility
Microsoft Entra ID
- Customization is primarily via configuration and policy; no option to run arbitrary server-side logic.
- Predefined templates for login and consent screens; limited branding. No deep theme or UI customizations.
- User flows and conditional access are determined by configuration and supported extensibility points—core logic and advanced transformations cannot be altered.
Keycloak
- Provides server-side extensibility through Java SPI (Service Provider Interfaces): implement custom authentication flows, registration processes, and protocol logic.
- Full control over login, registration, and error page theming.
- Easy to insert organization-specific workflows, integrate with external systems, or bridge protocol mismatches.
Risk/Tradeoff:
- With Entra ID, there is less risk to platform integrity and resilience, fewer maintenance surprises, but limited flexibility.
- With Keycloak, there is maximum flexibility, but the maintenance cost, upgrade complexity, and risk of misconfiguration increase—with all resilience and compliance guarantees the responsibility of the operator.
Link to User, Group, and Role ModelingUser, Group, and Role Modeling
Microsoft Entra ID
- Leverages Azure AD's group/role system. Assignment and modeling are robust for common organizational needs.
- Group and role claims can be mapped to tokens (SAML or JWT), but subject to strict limits:
- Maximum of 150 groups in a SAML assertion.
- Maximum of 200 groups in a JWT/OIDC token.
- Exceeding these results in claims being omitted or replaced by an overage indicator, potentially breaking app-level authorization expectations.
- Attribute and claim mapping is possible, but only within allowed policy configuration and templates.
Keycloak
- Distinct separation between realms (logical isolated identity stores), clients (applications), users, groups, and roles.
- No documented hard cap on group/role claims per token (practically limited only by token size and performance).
- Can model hierarchical/grouped roles, custom attributes (per user or per client), and complex claim mapping logic across realms and protocols.
- Full control over user schema extension for bespoke application needs.
Implications:
- Integrations demanding fine-grained role hierarchies, high group counts, or custom attributes favor Keycloak for its flexibility.
- Microsoft Entra ID's group/role emission limits are critical for large organizations or apps relying on granular entitlements.
Link to Cost Structure and Operational TradeoffsCost Structure and Operational Tradeoffs
Microsoft Entra ID
- Billed as a subscription SaaS service; tiers provide varying features and limits.
- Operational costs (infra, scaling, admin, DR, patching) are included.
- Predictable pricing, straightforward for budgeting and support contracts.
- May reduce time-to-market and in-house staff needs, especially when integrating with Microsoft SaaS or in hybrid cloud environments.
Keycloak
- Free to use/open source—no license costs.
- All operational, infrastructure, and DevOps costs are absorbed by the customer: hardware/cloud usage, high availability setups, backup, monitoring, security, and compliance.
- High flexibility can lead to additional time spent on customization, support, upgrades, and technical debt if not actively managed.
- For smaller or less-resourced teams, operational cost and risk can easily eclipse license savings.
Link to Decision Guide and Real-World ScenariosDecision Guide and Real-World Scenarios
When Keycloak is the right choice:
- Self-hosted or hybrid requirement—restrictions on data location mean SaaS cannot be used.
- Need for deeply customized authentication, registration, or business logic during login.
- Requirement for protocol translation (e.g., integrating SAML, OIDC, and LDAP from diverse partners).
- Organizations running multiple, isolated identity realms for different segments (B2B/B2C/multi-tenant).
- Customer-facing IAM (CIAM) projects needing flexible branding, schema, and custom user journeys.
When Microsoft Entra ID is a better fit:
- Modern workforce SSO, especially for Microsoft 365, Teams, and integrating existing Azure AD applications.
- Preference for SaaS (low operational overhead), resilience, and rapid rollout.
- Centralized governance, compliance, and reporting needs dominate over custom authentication logic.
- No requirement for direct on-premises directory (LDAP) querying from applications.
Hybrid/integration patterns:
- Combine Entra ID for workforce and SaaS integrations with Keycloak as a federation or protocol bridge for specialized applications.
- Keycloak can broker between legacy directories, external partners, and Entra ID to unify SSO across mixed environments.
Link to Common MisconceptionsCommon Misconceptions
- "Entra ID and Keycloak can be swapped interchangeably for all SSO scenarios."
- Reality: Deep differences in deployment, supported protocols, extensibility, and claims modeling can block migration or integration.
- "Entra ID is a general-purpose LDAP endpoint for custom apps."
- Reality: There is no direct LDAP server in Entra ID; LDAP integration is only for directory synchronization or via connectors—not for custom LDAP-based app queries.
- "Group and role claims are always complete in Entra ID tokens."
- Reality: Strict group claim emission limits mean applications relying on large group lists may encounter missing or truncated claims.
- "Self-hosting Keycloak is always cheaper than any SaaS."
- Reality: Infrastructure, personnel time, maintenance, and operations costs can outpace SaaS costs quickly, especially at scale or when uptime/compliance is critical.
- "Both platforms provide equivalent enterprise protocol and directory support."
- Reality: Keycloak supports broader protocol brokering and LDAP user federation; Entra ID offers better integration for Microsoft-centric cloud SaaS and has platform-specific protocol limitations.
Link to References and Further ReadingReferences and Further Reading
- Microsoft Entra ID documentation
- SAML authentication with Microsoft Entra ID
- OpenID Connect (OIDC) on the Microsoft identity platform
- What is single sign-on in Microsoft Entra ID?
- Configure group claims for applications by using Microsoft Entra ID
- Keycloak vs Entra External ID: Part 1