{"id":61014,"date":"2023-01-03T11:38:37","date_gmt":"2023-01-03T03:38:37","guid":{"rendered":"https:\/\/version-2.com\/?p=61014"},"modified":"2023-01-06T11:42:05","modified_gmt":"2023-01-06T03:42:05","slug":"total-cost-of-ownership-of-azure-ad","status":"publish","type":"post","link":"https:\/\/version-2.com\/zh\/2023\/01\/total-cost-of-ownership-of-azure-ad\/","title":{"rendered":"Total Cost of Ownership of Azure AD"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"61014\" class=\"elementor elementor-61014\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-35fe5dd post-content elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"35fe5dd\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;cef08c3&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-409a2e9a\" data-id=\"409a2e9a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5a8be8f elementor-widget elementor-widget-text-editor\" data-id=\"5a8be8f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<article class=\"is-type-body-default is-important\"><p><em>Editor\u2019s Note: Given the fast-paced nature of technology, it is possible that some of the information presented in this article is out-of-date, or incomplete, in some fashion. The author periodically reviews and revises this article to ensure information contained within is as accurate as possible.<\/em><\/p><hr \/><p>Microsoft<sup>\u00ae<\/sup> Azure<sup>\u00ae<\/sup> is an umbrella for a variety of cloud services, including Azure Active Directory (AAD). On its face, Azure AD might <a href=\"https:\/\/jumpcloud.com\/blog\/active-directory-without-a-server\">seem like a replacement<\/a> for on-prem Active Directory (AD) or a cloud-based solution for organizations in need of a directory service, but more factors come into play for IT admins making purchasing decisions, including complicated SKUs and licensing. This article examines the total cost of ownership (TCO) of AAD for the type of configuration that a small and medium-sized enterprise (SME) would require for its identity management lifecycle.<br \/><br \/>AAD was created to extend on-prem AD identities to Azure in order to provide user management for Microsoft Office applications, and now single sign-on (SSO) for service providers (SP). It\u2019s available as a standalone product, but is also bundled with Microsoft 365 (M365) subscriptions. Microsoft has positioned AAD as the connective tissue within a broader identity and access management (IAM) ecosystem. That extends from users and devices to its security portfolio. Add-ons and integrations are almost inescapable, because AAD is very interwoven with those products. It\u2019s not even possible to implement Microsoft\u2019s <a href=\"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices\">best practices for AAD<\/a> without paying more.<\/p><h2 id=\"heading1\">A Codependent Approach<\/h2><p>Significantly, Microsoft manages endpoints separately from identities even though experts recommend making <a href=\"https:\/\/jumpcloud.com\/blog\/2022-fal-con-event-recap\">identity the new perimeter<\/a> in cybersecurity. Device management (outside of AD) is only bundled with some of its premium M365 SKUs, but not AAD. Organizations that aren\u2019t using M365 will have to purchase a separate subscription to manage their devices.<\/p><p>Microsoft\u2019s reference architecture suggests an array of Microsoft-based tools to fully leverage AAD, so even Microsoft-heavy IT shops will encounter more IT infrastructure and maintenance costs. You\u2019ll have limited administrative capabilities if you use AAD without on-prem AD, or aren\u2019t subscribed to premium tiers and add-on services. For example, you won\u2019t be able to employ the suite of group policy objects (GPOs) to on-prem Windows devices, and you\u2019ll struggle with authenticating local IT resources such as applications and file servers.\u00a0<\/p><p>AAD is also not an open directory, so working with external identities from other identity providers (IP) and connecting users to IT resources (RADIUS, LDAP) requires even more solutions. Some are cloud-based, but others expand its footprint on-premise, and are reliant on AD.<\/p><h2 id=\"heading2\">Costs of Azure Active Directory<\/h2><p>To fully assess the TCO of Azure AD, it\u2019s necessary to account for tangential, but necessary, costs. Fortunately, we\u2019ve developed an equation to help you understand the TCO of AAD:<\/p><blockquote class=\"wp-block-quote\"><p>Costs of Azure Active Directory = Azure AD Premium Package + Add-Ons for device management + External Identities + Azure AD DS + <a href=\"https:\/\/jumpcloud.com\/blog\/what-is-the-tco-of-active-directory\/\">Active Directory<\/a> + LDAP Server + RADIUS Server + Integration\/Management Time for your implements<\/p><\/blockquote><p>Let\u2019s begin by assessing AAD\u2019s pricing and then branch outward to the other components.<\/p><h3>Standalone Azure AD and M365<\/h3><p>Standalone AAD has three SKUs:<\/p><ul><li><strong>AAD Free<\/strong> \u2013 AAD Free provides SSO to Microsoft apps and federation to other <a href=\"https:\/\/jumpcloud.com\/blog\/what-is-saml\">SAML<\/a>\/<a href=\"https:\/\/jumpcloud.com\/blog\/saml-vs-openid\">OIDC<\/a> services. This version is feature-limited with no group management, limited MFA configurations, limits on directory objects per user, and various other restrictions.<\/li><li><strong>Premium 1 (P1) \u2013 <\/strong>P1 introduces SSO sign-in page customizations, <a href=\"https:\/\/jumpcloud.com\/blog\/conditional-access-policies-examples\">conditional access <\/a>rules, role-based group assignments to applications, end-user self-service for passwords and MFA, additional cloud security, and options for authenticating users into local Windows apps.\u00a0<\/li><li><strong>Premium 2 (P2)<\/strong> \u2013 P2 adds risk-based identity protection, more self-service capabilities, as well as identity governance and compliance such as privileged access and entitlements management. Logging and reporting is also more comprehensive.<\/li><\/ul><figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-73433\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/1.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/1-300x98.png 300w\" alt=\"Azure Ad pricing\" width=\"512\" height=\"167\" \/><\/figure><figure class=\"wp-block-image size-full\"><img decoding=\"async\" class=\"wp-image-73434\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/2.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/2.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/2-300x175.png 300w\" alt=\"capabilities and use cases for Microsoft\" width=\"512\" height=\"299\" \/><figcaption class=\"wp-element-caption\"><em>Image credit: learn.microsoft.com<\/em><\/figcaption><\/figure><p>M365 subscriptions also bundle AAD. It\u2019s not even possible to use M365 without AAD, which serves as its substrate for managing your users. Some admins encounter AAD through Office.<\/p><p>Its directory features are gated off into multiple tiers:<\/p><ul><li><strong>M365 Business Premium<\/strong> \u2013 This includes device management and security services to protect identities.<\/li><li><strong>M365 E1<\/strong> \u2013 Device management isn\u2019t included and AAD is limited.<\/li><li><strong>M365 E3<\/strong> \u2013 This edition includes device management and AAD P1.<\/li><li><strong>M365 E5<\/strong> \u2013 This edition includes device management and AAD P2.<\/li><li><strong>M365 F3 <\/strong>\u2013 This edition includes device management and AAD P1.<\/li><li><strong>Enterprise Mobility + Security (EMS) E3<\/strong> \u2013 This edition includes device management and AAD P1.<\/li><\/ul><p><strong>EMS E5 \u2013 <\/strong>This edition includes device management and AAD P2.<\/p><figure class=\"wp-block-image size-full\"><img decoding=\"async\" class=\"wp-image-73435\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/3.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/3.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/3-300x102.png 300w\" alt=\"Microsoft 365 pricing\" width=\"512\" height=\"174\" \/><figcaption class=\"wp-element-caption\"><em>Image credit: Microsoft<\/em><\/figcaption><\/figure><h3>Device Management<\/h3><p>AAD sounds a lot like AD, but it <a href=\"https:\/\/jumpcloud.com\/blog\/can-i-replace-ad-with-azure-ad\">doesn\u2019t perform the same role<\/a>; for example, it won\u2019t manage your devices. Microsoft established its Intune product lineup to manage Android\/Chrome, Apple, Linux, and Windows endpoints. It uses AAD to manage identities, Configuration Manager (formerly SCCM), in addition to Windows Defender for security and Autopilot for onboarding Windows devices. Intune may be bundled with M365, depending upon your subscription level. However, Intune is not included with AAD P1 or P2, and that omission will increase your monthly costs per user.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-73436\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/4.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/4.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/4-300x171.png 300w\" alt=\"compared pricing\" width=\"512\" height=\"292\" \/><\/figure><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-73437\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/5.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/5.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/5-300x282.png 300w\" alt=\"availability of Basic Mobility and Security and Intune\" width=\"512\" height=\"482\" \/><\/figure><p>Intune includes enterprise-grade features and can be a useful tool for compliance and managing non-Windows devices for organizations that have many remote workers. However, it also has documented <a href=\"https:\/\/jumpcloud.com\/blog\/comparing-jumpcloud-azure-ad-intune\">downsides<\/a>. SMEs that are accustomed to AD may be unfamiliar with its quirks:<\/p><ul><li>Unpredictable time spent importing the provisioning of devices, assigning profiles, and deploying apps.<\/li><li>Simple mistakes can cause actions to fail, such as a Registry key requirement rule filtering out devices.<\/li><li>Problems with assigning available licenses to new users.<\/li><li>Configuration changes taking a long time to go into effect.<\/li><li>Debugging events and sync logs requiring additional <a href=\"https:\/\/msendpointmgr.com\/intune-debug-toolkit\/\" target=\"_blank\" rel=\"noreferrer noopener\">third-party tooling<\/a>.<\/li><li>Loss of internet connectivity causing Windows Autopilot to fail.<\/li><\/ul><p>The cost of learning, implementing, and supporting Intune is another TCO consideration.<\/p><h3>Azure Active Directory Domain Services<\/h3><p>Intune is not the only option for Microsoft shops. Azure Active Directory Domain Services (Azure AD DS) is billed as a domain controller-as-a-service for virtual machines and legacy applications. It\u2019s charged for the hour, and the price is based on the number of directory objects.<\/p><p><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory-domain-services\/tutorial-create-management-vm\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Per Microsoft<\/a>, \u201cAzure AD DS provides a managed domain for your users, applications, and services to consume. This approach changes some of the available management tasks you can do, and what privileges you have within the managed domain.\u201d<\/p><p>Azure AD DS differs from on-prem AD in a number of ways, including its lack of domain or enterprise administrator privileges. You also cannot add on-prem domain controllers to the managed domain.<\/p><p>If you use AAD and Azure AD DS in conjunction with on-prem AD \u2014 which is necessary if you want full AD capabilities \u2014 you\u2019ll have to factor in the associated costs for that as well.<\/p><h3>Managing External Identities<\/h3><p>Microsoft Entra is necessary to manage external (non-Microsoft) identities and devices. There\u2019s a charge for every single MFA authentication for non-Microsoft identities such as Google Workspace. In addition, AAD P1 or P2 licenses are necessary to work with external identities.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-73438\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/6.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/6.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/6-300x76.png 300w\" alt=\"compared pricing for identities\" width=\"512\" height=\"130\" \/><\/figure><h2>Complex Licensing<\/h2><p>If you think that AAD is the right solution for your organization, you\u2019ll have to dig through the pricing and SKUs outlined above. It goes without saying that the pricing model is complicated, and non-system access needs may also obligate you to purchase more <a href=\"https:\/\/jumpcloud.com\/blog\/cals-client-access-licenses\/\">CALs<\/a>. You should begin by understanding your current situation. If you have a Microsoft Enterprise Agreement, Open Volume agreement, or are part of the Cloud Solutions Program, you will have a right to certain functionality (Basic and Premium depending upon your specific agreement).<\/p><p>If your IT organization isn\u2019t a part of any of those programs, yet you\u2019ve purchased <a href=\"https:\/\/jumpcloud.com\/blog\/office-365-azure-active-directory\/\">Azure or M365<\/a>, you can purchase the right Premium Azure AD services. It\u2019s possible for SMEs to overspend on AAD or be upsold by a Microsoft partner due to the complexity of its licensing, so it\u2019s important to take the time to understand your requirements versus what you\u2019re paying for.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-73439\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/7.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/7.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/7-300x180.png 300w\" alt=\"reddit feed\" width=\"512\" height=\"307\" \/><figcaption class=\"wp-element-caption\"><em>Image credit: Reddit<\/em><\/figcaption><\/figure><h2 id=\"heading3\">Complicated Setup and Migrations<\/h2><p>The breadth of potential configurations, critical need to understand <a href=\"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices#heading2\">security best practices<\/a>, and overall complexity can make adopting AAD a major initiative. Most SMEs aren\u2019t experts in Microsoft licensing and seek assistance for their implementations. For instance, AAD\u2019s default settings can place your users at risk of phishing attacks that can even bypass MFA. IT teams that are migrating from products such as <a href=\"https:\/\/jumpcloud.com\/blog\/what-is-adfs\">AD FS<\/a> or have multiple domains in a forest will face some technical considerations that may be unclear and unfamiliar. Microsoft\u2019s <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/architecture\/reference-architectures\/identity\/azure-ad\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">guidance<\/a> states:<\/p><p>\u201cIf you have multiple on-premises domains in a forest, we recommend storing and synchronizing information for the entire forest to a single Azure AD tenant. Filter information for identities that occur in more than one domain, so that each identity appears only once in Azure AD, rather than being duplicated. Duplication can lead to inconsistencies when data is synchronized. For more information, see the Topology section below.\u201d\u00a0<\/p><p>That can be significant work for an SME.<br \/><br \/>The realization that adopting AAD can be very cumbersome has given rise to a <a href=\"https:\/\/azure.microsoft.com\/en-us\/partners\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">cottage industry of consultants<\/a>, and many organizations purchase blocks of hours to support their deployments. In-house resources may not be enough. Factor implement costs into your TCO calculations.<\/p><h2 id=\"heading4\">Cost of Active Directory<\/h2><p><a href=\"https:\/\/jumpcloud.com\/blog\/what-is-the-tco-of-active-directory\/\">Active Directory represents a number of costs<\/a> for organizations, including servers, software, and licensing. SMEs will also have to maintain a server room, which can add significant costs.<\/p><h3>Servers: Domain Controllers<\/h3><p>If you use Azure AD with on-prem AD, servers are an obvious cost. You either need to maintain a server room or spin up AD in a virtual environment, both of which must factor into the TCO of Azure AD. You need to budget for the costs of redundant servers, too, in case your primary domain controller (DC) fails. High availability (HA) is automatic whenever there\u2019s more than one DC. That makes it possible to shut down a server for maintenance without impacting your end users.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-73440\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/8.png\" sizes=\"(max-width: 456px) 100vw, 456px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/8.png 456w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/8-300x91.png 300w\" alt=\"A task from an IT department\u2019s project to set up high availability\" width=\"456\" height=\"139\" \/><figcaption class=\"wp-element-caption\"><em>A task from an IT department\u2019s project to set up high availability<\/em><\/figcaption><\/figure><p>Objects are automatically replicated throughout the server cluster and administration is more complex: e.g., add-on apps must be installed and updated on each DC. Adding additional servers to achieve HA may increase licensing, management, and other infrastructure costs.<\/p><h3>Software: Windows Server<\/h3><p>Beyond the cost of the servers themselves, you\u2019ll need to purchase the software to be installed on them. Since 2016, Windows Server licensing has been on a per <a href=\"https:\/\/techlibrary.hpe.com\/us\/en\/enterprise\/servers\/licensing\/index.aspx\" target=\"_blank\" rel=\"noreferrer noopener\">CPU core pricing structure<\/a>, rather than the previous per socketed CPU structure. Admins can purchase those licenses in 2- or 16-packs. You may need to stand up multiple servers for all of the required server roles.<\/p><h3>Licensing: Client Access Licenses<\/h3><p>Another important cost to consider is <a href=\"https:\/\/jumpcloud.com\/blog\/cals-client-access-licenses\/\">client access licenses (CALs)<\/a>, which you purchase based either on user count or device count. Core licensing has become <a href=\"https:\/\/jumpcloud.com\/blog\/microsoft-server-core-licensing-costs-more\">even more expensive<\/a>.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-73441\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/9.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/9.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/9-300x121.png 300w\" alt=\"An example of new CALs being required without Software Assurance volume licensing\" width=\"512\" height=\"206\" \/><figcaption class=\"wp-element-caption\"><em>An example of new CALs being required without Software Assurance volume licensing<\/em><\/figcaption><\/figure><h3>Hardening AD for Security<\/h3><p>It can take more than a work week to secure AD to <a href=\"https:\/\/jumpcloud.com\/blog\/active-directory-faq#heading7\">recommended best practices<\/a>. Maintaining AD alongside AAD could dramatically increase IT overhead and administrative costs.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-73442\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/10.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/10.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/10-300x188.png 300w\" alt=\"A statement of work to harden a domain controller\" width=\"512\" height=\"320\" \/><figcaption class=\"wp-element-caption\"><em>A statement of work to harden a domain controller \u2014 the total cost was $6,485.95<\/em><\/figcaption><\/figure><h3>Advanced Identity Lifecycle Management<\/h3><p>AD isn\u2019t <a href=\"https:\/\/jumpcloud.com\/resources\/zero-trust-security\" target=\"_blank\" rel=\"noreferrer noopener\">Zero Trust<\/a> and identity lifecycle management is a manual process unless SMEs develop automations or use third-party solutions. That increases the risk that users may be over or under-provisioned, or that inactive accounts remain in use. Managing users in AD can be a disjointed, error-prone process. The risk of data exfiltration is higher with manual processes, which creates a financial risk as laws and regulations are treating violations more seriously. AAD\u2019s advanced identity management policies can extend AD and improve upon it, but only with P1, P2 subscriptions. Azure AD Connect is required to sync identities between AD and AAD.<\/p><h3>Server Rooms<\/h3><p>An accumulation of hardware, servers, and network equipment means you\u2019ll be spending more for your server room. Eventually, you\u2019ll require a more powerful core switch or better firewall. \u201cBetter\u201d translates to more expensive and potentially unplanned downtime on your network as well as new annual support costs, change management, and backups of your configurations.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-73443\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/11.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/11.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/11-300x169.png 300w\" alt=\"Support renewal costs for upgraded firewalls at a manufacturing company\" width=\"512\" height=\"288\" \/><figcaption class=\"wp-element-caption\"><em>Support renewal costs for upgraded firewalls at a manufacturing company<\/em><\/figcaption><\/figure><p>Then, you\u2019ll have to establish physical security controls and ideally, fire suppression. An inert gas system requires sealing a room and having dedicated HVAC. Other solutions for special hazards, including in-rack fire suppression, are also costly. See here for an example:<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-73444\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/12.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/12.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/12-300x175.png 300w\" alt=\"Part of a quote for a server room\u2019s fire suppression upgrade\" width=\"512\" height=\"299\" \/><figcaption class=\"wp-element-caption\"><em>Part of a quote for a server room\u2019s fire suppression upgrade<\/em><\/figcaption><\/figure><blockquote class=\"wp-block-quote\"><p>Microsoft promises consolidation, but its solutions can be a wellspring of added administration.<\/p><\/blockquote><p>This next section explores non-systems requirements and challenges AAD creates for SSO.<\/p><h2 id=\"heading5\">LDAP Server<\/h2><p>AAD and AD lack SSO to everything, especially the core protocols that network devices or Wi-Fi networks use. This can lead to identity silos and duplicate authentication flows. Microsoft promises consolidation, but its solutions can be a wellspring of added administration.<\/p><p>If you aren\u2019t hosting all your server infrastructure in Azure, you\u2019ll also need to manage the associated identity management costs to manage user access to other cloud infrastructure providers such as AWS<sup>\u00ae<\/sup> and GCP. Some of these platforms offer their own managed Active Directory services, so you can potentially leverage those managed AD services, but you\u2019ll need to make sure that they can connect back to your other AD infrastructure and\/or with Azure. None of this work is easy, and it can add a great deal of fragility to your IAM environment.<br \/><br \/>Azure AD doesn\u2019t come with <a href=\"https:\/\/jumpcloud.com\/platform\/ldap\" target=\"_blank\" rel=\"noreferrer noopener\">cloud LDAP<\/a> functionality, so you\u2019ll need to maintain an LDAP server, as well as service on-prem LDAP applications and MFA solution, if required. Azure AD DS is also <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/fundamentals\/auth-ldap\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">required<\/a> to sync passwords and group memberships from Active Directory. Azure AD DS allows organizations to migrate legacy applications to Azure entirely, but that service represents an additional cost as well as the work around the migration of applications which is not an easy task in most instances.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-73445\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/13.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/13.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/13-300x187.png 300w\" alt=\"\" width=\"512\" height=\"319\" \/><figcaption class=\"wp-element-caption\"><em>Image credit: Microsoft<\/em><\/figcaption><\/figure><h2 id=\"heading6\">RADIUS Server<\/h2><p>Azure AD does not come with <a href=\"https:\/\/jumpcloud.com\/product\/cloud-radius\/\" target=\"_blank\" rel=\"noreferrer noopener\">cloud RADIUS functionality<\/a> either. Instead, you\u2019ll need to spin up a RADIUS server, use the NPS server role or another cloud service to have the capability of managing Wi-Fi and VPN access. You\u2019ll also require a secondary authentication method. JumpCloud makes it possible to leverage AAD credentials for <a href=\"https:\/\/jumpcloud.com\/blog\/what-is-delegated-authentication\">delegated authentication<\/a>. Many network devices use RADIUS for authentication, and the lack of support makes initiatives such as compliances more difficult. Auditors often want devices, down to switches, protected by MFA.<\/p><h2 id=\"heading7\">Vendor Lock-In<\/h2><p>This level of platform integration may be beneficial for \u201call Microsoft and Azure\u201d organizations. However, the lack of interoperability through an open directory and continued reliance on AD adds costs, complexity, and administrative overhead. That level of monoculture and high dependence on a single vendor makes it more difficult to adopt \u201cbest-of-breed\u201d solutions.<\/p><p>With the changing IT landscape, the good news is that IT organizations are leveraging a wider range of platforms. This requires a different set of IT management tools, and specifically, it involves the core identity provider. Using Azure AD encourages the use of Azure throughout your entire environment. AAD, like AD, obligates the use of Microsoft infrastructure and services\/applications. This strategy has been successful for Microsoft in the past, and the company is employing it again to work to lock-in customers into Microsoft platforms.<br \/><br \/>Microsoft\u2019s promotion of IT consolidation has been successful from a sales perspective, but it doubles down on vendor lock-in. In contrast, an open directory platform provides <em>value<\/em> lock-in.<\/p><h2>Evaluating Azure Active Directory<\/h2><p>Azure AD might be the solution for a Microsoft shop that already has AD established and needs to extend their IT resource management to the cloud. However, organizations should assess their existing stack and whether Azure AD will address all their needs before making the purchase. Beyond Azure AD, organizations will likely need to purchase Intune for device management. Azure AD DS is also necessary to maintain Azure AD Connect (along with their on-prem AD instance), as well as RADIUS and LDAP instances and other add-ons. These all represent cost centers. Azure AD is not an all-in-one solution, but does meet certain use cases.<\/p><h2>Resource to Calculate TCO<\/h2><p>JumpCloud released a <a href=\"https:\/\/jumpcloud.com\/resources\/tco-calculation-guide\" target=\"_blank\" rel=\"noreferrer noopener\">TCO Guide<\/a> and <a href=\"https:\/\/jumpcloud.com\/blog\/how-to-use-jumpclouds-tco-calculator\">TCO Calculator<\/a> to help IT admins understand the complete costs of different solutions used in their environment. We also invite you to try <a href=\"https:\/\/console.jumpcloud.com\/signup?email=&amp;first_touch=Non-Paid&amp;first_touch_timestamp=2022-09-05T06:42:17.230Z&amp;jcsgmtuuid=3e98afb0-b055-44b0-b943-254a1f55d8f7\" target=\"_blank\" rel=\"noreferrer noopener\">JumpCloud<\/a>, which is free and full-featured for 10 uses and devices. It may help extend AD in the way that your organization needs to adapt to change or meet compliance requirements without hassle. JumpCloud is\u00a0<\/p><p>JumpCloud\u2019s open directory platform delivers select features found in AAD, Entra, and Intune with an emphasis on what\u2019s best for SMEs. Those capabilities are available without gated licensing, tethering your team to legacy systems, or complicated workarounds. It\u2019s priced to enable workflows, versus charging more for advanced identity lifecycle management. JumpCloud enables <a href=\"https:\/\/jumpcloud.com\/solutions\/it-unification\" target=\"_blank\" rel=\"noreferrer noopener\">IT unification<\/a>, as opposed to consolidating with a single vendor.<\/p><p>Its benefits include:<\/p><ul><li>AAD and AD <a href=\"https:\/\/jumpcloud.com\/blog\/integrate-ad-jumpcloud#:~:text=Using%20a%20feature%20called%20Active,to%20extend%20the%20other's%20reach.\">integration<\/a> with group syncing<\/li><li>The ability to import identities from your <a href=\"https:\/\/jumpcloud.com\/blog\/how-jumpclouds-hris-integration-works\">HR systems<\/a> at no additional cost<\/li><li>Attribute-base groups that makes <a href=\"https:\/\/jumpcloud.com\/blog\/the-immediate-advantages-of-attribute-based-access-control\">suggested changes<\/a> and automate memberships<\/li><li><a href=\"https:\/\/jumpcloud.com\/platform\/mdm\" target=\"_blank\" rel=\"noreferrer noopener\">Mobile Device Management<\/a> (MDM) and pre-built policies for Apple products, Android (soon), <a href=\"https:\/\/jumpcloud.com\/blog\/new-linux-security-policies-july-2022\">Linux<\/a>, and Windows endpoints<\/li><li><a href=\"https:\/\/jumpcloud.com\/platform\/single-sign-on\" target=\"_blank\" rel=\"noreferrer noopener\">SSO to everything<\/a>, including integrated cloud <a href=\"https:\/\/jumpcloud.com\/platform\/cloud-radius\" target=\"_blank\" rel=\"noreferrer noopener\">RADIUS<\/a> and <a href=\"https:\/\/support.jumpcloud.com\/s\/article\/using-jumpclouds-ldap-as-a-service1\" target=\"_blank\" rel=\"noreferrer noopener\">LDAP<\/a><\/li><li>Environment-wide <a href=\"https:\/\/jumpcloud.com\/platform\/multi-factor-authentication-mfa\" target=\"_blank\" rel=\"noreferrer noopener\">Push MFA<\/a> and TOTP; certificate-based authentication (soon)<\/li><li>Optional <a href=\"https:\/\/support.jumpcloud.com\/s\/article\/Getting-Started-Conditional-Access-Policies\" target=\"_blank\" rel=\"noreferrer noopener\">conditional access policies<\/a> for privileged access management (PAM)<\/li><li>Interoperability with <a href=\"https:\/\/support.jumpcloud.com\/s\/article\/office-365-user-import-provisioning-and-sync1\" target=\"_blank\" rel=\"noreferrer noopener\">M365<\/a>, <a href=\"https:\/\/support.jumpcloud.com\/s\/article\/g-suite-user-import-provisioning-and-sync1\" target=\"_blank\" rel=\"noreferrer noopener\">Google Workspace<\/a>, and <a href=\"https:\/\/support.jumpcloud.com\/s\/article\/ConfiguringOktaDelegatedAuthority\" target=\"_blank\" rel=\"noreferrer noopener\">Okta<\/a><\/li><li>Integrated, <a href=\"https:\/\/support.jumpcloud.com\/s\/article\/JumpCloud-Reports\" target=\"_blank\" rel=\"noreferrer noopener\">pre-built reporting<\/a> on directory and system activities<\/li><li>Optional cross-OS <a href=\"https:\/\/jumpcloud.com\/platform\/patch-management\" target=\"_blank\" rel=\"noreferrer noopener\">patch management<\/a> and a decentralized password manager<\/li><\/ul><p>JumpCloud also offers a variety of Professional Services to help ease the load your employees face. <a href=\"https:\/\/jumpcloud.com\/professional-services\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more<\/a> or <a href=\"https:\/\/hello.jumpcloud.com\/calendar\/team\/t\/58#\/\" target=\"_blank\" rel=\"noreferrer noopener\">schedule a free 30-minute technical consultation<\/a>.<\/p><blockquote class=\"wp-block-quote\"><p>Software renewals come out of the capital expenditures (CAPEX) budget, which is a major long-term expenditure versus operating expenses (OPEX), the day-to-day operational budget. Accounting makes a distinction between software and services. Using services helps your organization to <a href=\"https:\/\/jumpcloud.com\/blog\/it-budgeting-strategies\">lower its income taxes <\/a>and free up cash. Services may make it easier to budget when you already know what the ongoing costs will be.<\/p><\/blockquote><div class=\"blog-post-tags m-t-2\"><ul class=\"blog-post-collections-list\"><li class=\"blog-post-collections-list-item\"><a class=\"blog-post-collections-list-link is-type-body-tiny is-type-weight-semi-bold is-important devices\" href=\"\/blog?collections=devices\">Devices<\/a><\/li><li class=\"blog-post-collections-list-item\"><a class=\"blog-post-collections-list-link is-type-body-tiny is-type-weight-semi-bold is-important directory-services\" href=\"\/blog?collections=directory-services\">Directory Services<\/a><\/li><\/ul><\/div><\/article>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2004c86 elementor-widget elementor-widget-shortcode\" data-id=\"2004c86\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\t\t<div data-elementor-type=\"page\" data-elementor-id=\"18103\" class=\"elementor elementor-18103\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-748947f elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"748947f\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7995c19\" data-id=\"7995c19\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a437045 elementor-widget elementor-widget-image-box\" data-id=\"a437045\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">About Version 2 Digital<\/h3><p class=\"elementor-image-box-description\">Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.\n<br><br>\nThrough an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\n\t\t<div data-elementor-type=\"page\" data-elementor-id=\"57539\" class=\"elementor elementor-57539\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6b25dc0d elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"6b25dc0d\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3cc1b37d\" data-id=\"3cc1b37d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-52c4a230 elementor-widget elementor-widget-text-editor\" data-id=\"52c4a230\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>About JumpCloud<\/strong><br \/>At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Editor\u2019s Note: Given the fast-paced nature of technolog [&hellip;]<\/p>\n","protected":false},"author":149011790,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1016,1075,61],"tags":[1017,1076],"class_list":["post-61014","post","type-post","status-publish","format-standard","hentry","category-jumpcloud","category-year2023","category-press-release","tag-jumpcloud","tag-1076"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Total Cost of Ownership of Azure AD - Version 2<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership\" \/>\n<meta property=\"og:locale\" content=\"zh_HK\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Total Cost of Ownership of Azure AD - Version 2\" \/>\n<meta property=\"og:description\" content=\"Editor\u2019s Note: Given the fast-paced nature of technolog [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership\" \/>\n<meta property=\"og:site_name\" content=\"Version 2\" \/>\n<meta property=\"article:published_time\" content=\"2023-01-03T03:38:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-01-06T03:42:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/1.png\" \/>\n<meta name=\"author\" content=\"tracylamv2\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"tracylamv2\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9810\u8a08\u95b1\u8b80\u6642\u9593\" \/>\n\t<meta name=\"twitter:data2\" content=\"18 \u5206\u9418\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-total-cost-ownership#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/01\\\/total-cost-of-ownership-of-azure-ad\\\/\"},\"author\":{\"name\":\"tracylamv2\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/011bc7c3731c930bcfeecd52fefb6365\"},\"headline\":\"Total Cost of Ownership of Azure AD\",\"datePublished\":\"2023-01-03T03:38:37+00:00\",\"dateModified\":\"2023-01-06T03:42:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/01\\\/total-cost-of-ownership-of-azure-ad\\\/\"},\"wordCount\":3032,\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-total-cost-ownership#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/1.png\",\"keywords\":[\"JumpCloud\",\"2023\"],\"articleSection\":[\"JumpCloud\",\"2023\",\"Press Release\"],\"inLanguage\":\"zh-HK\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/01\\\/total-cost-of-ownership-of-azure-ad\\\/\",\"url\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-total-cost-ownership\",\"name\":\"Total Cost of Ownership of Azure AD - Version 2\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-total-cost-ownership#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-total-cost-ownership#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/1.png\",\"datePublished\":\"2023-01-03T03:38:37+00:00\",\"dateModified\":\"2023-01-06T03:42:05+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-total-cost-ownership#breadcrumb\"},\"inLanguage\":\"zh-HK\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-total-cost-ownership\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-total-cost-ownership#primaryimage\",\"url\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/1.png\",\"contentUrl\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/1.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-total-cost-ownership#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9801\",\"item\":\"https:\\\/\\\/version-2.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Total Cost of Ownership of Azure AD\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"name\":\"Version 2\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/version-2.com\\\/zh\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"zh-HK\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\",\"name\":\"Version 2\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"width\":1795,\"height\":335,\"caption\":\"Version 2\"},\"image\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/011bc7c3731c930bcfeecd52fefb6365\",\"name\":\"tracylamv2\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"caption\":\"tracylamv2\"},\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/author\\\/tracylamv2\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Total Cost of Ownership of Azure AD - Version 2","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership","og_locale":"zh_HK","og_type":"article","og_title":"Total Cost of Ownership of Azure AD - Version 2","og_description":"Editor\u2019s Note: Given the fast-paced nature of technolog [&hellip;]","og_url":"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership","og_site_name":"Version 2","article_published_time":"2023-01-03T03:38:37+00:00","article_modified_time":"2023-01-06T03:42:05+00:00","og_image":[{"url":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/1.png","type":"","width":"","height":""}],"author":"tracylamv2","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"tracylamv2","\u9810\u8a08\u95b1\u8b80\u6642\u9593":"18 \u5206\u9418"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership#article","isPartOf":{"@id":"https:\/\/version-2.com\/2023\/01\/total-cost-of-ownership-of-azure-ad\/"},"author":{"name":"tracylamv2","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/011bc7c3731c930bcfeecd52fefb6365"},"headline":"Total Cost of Ownership of Azure AD","datePublished":"2023-01-03T03:38:37+00:00","dateModified":"2023-01-06T03:42:05+00:00","mainEntityOfPage":{"@id":"https:\/\/version-2.com\/2023\/01\/total-cost-of-ownership-of-azure-ad\/"},"wordCount":3032,"publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/1.png","keywords":["JumpCloud","2023"],"articleSection":["JumpCloud","2023","Press Release"],"inLanguage":"zh-HK"},{"@type":"WebPage","@id":"https:\/\/version-2.com\/2023\/01\/total-cost-of-ownership-of-azure-ad\/","url":"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership","name":"Total Cost of Ownership of Azure AD - Version 2","isPartOf":{"@id":"https:\/\/version-2.com\/zh\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership#primaryimage"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/1.png","datePublished":"2023-01-03T03:38:37+00:00","dateModified":"2023-01-06T03:42:05+00:00","breadcrumb":{"@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership#breadcrumb"},"inLanguage":"zh-HK","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership"]}]},{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership#primaryimage","url":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/1.png","contentUrl":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/01\/1.png"},{"@type":"BreadcrumbList","@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-total-cost-ownership#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9801","item":"https:\/\/version-2.com\/"},{"@type":"ListItem","position":2,"name":"Total Cost of Ownership of Azure AD"}]},{"@type":"WebSite","@id":"https:\/\/version-2.com\/zh\/#website","url":"https:\/\/version-2.com\/zh\/","name":"Version 2","description":"","publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/version-2.com\/zh\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"zh-HK"},{"@type":"Organization","@id":"https:\/\/version-2.com\/zh\/#organization","name":"Version 2","url":"https:\/\/version-2.com\/zh\/","logo":{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","contentUrl":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","width":1795,"height":335,"caption":"Version 2"},"image":{"@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/011bc7c3731c930bcfeecd52fefb6365","name":"tracylamv2","image":{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","caption":"tracylamv2"},"url":"https:\/\/version-2.com\/zh\/author\/tracylamv2\/"}]}},"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbQRKm-fS6","post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/61014","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/users\/149011790"}],"replies":[{"embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/comments?post=61014"}],"version-history":[{"count":4,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/61014\/revisions"}],"predecessor-version":[{"id":61018,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/61014\/revisions\/61018"}],"wp:attachment":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/media?parent=61014"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/categories?post=61014"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/tags?post=61014"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}