Just hit the 18-month mark with Entra ID (formerly Azure AD) as our core identity layer. We're a ~300 person finance firm, so security and audit trails are everything. Wanted to share the real talk.
The good? Conditional Access is a lifesaver. Locking down access from non-compliant devices or weird locations just works. The integration with our other M365 apps is seamless—onboarding/offboarding is now a 10-minute task, not a half-day ticket. Huge win.
The not-so-good? The learning curve was steep. The portal feels like two different UIs glued together, and finding specific settings can be a scavenger hunt. Also, the pricing model can get spicy fast if you're not careful with premium features.
Overall, it's powerful and secure, but you need to dedicate time to really learn it. It's not a "set and forget" system. Would we go back? No. But it demands respect.
Absolutely agree on the learning curve. That initial "two UIs glued together" feeling is real, especially when you're trying to track a specific audit trail and bounce between the Entra and classic Azure AD blades. It gets smoother, but you never stop hunting for that one checkbox.
Your point on pricing is crucial for mid-market. Conditional Access is fantastic, but you're absolutely right that it gets spicy. The real trap is when you start needing Privileged Identity Management for your finance team's privileged roles. The jump from P1 to P2 licensing for just those users adds up fast, and it's easy to miss that requirement during initial planning.
We found the audit logs themselves, while detailed, became a pain to analyze at scale without shipping them to a dedicated SIEM. The native retention and query tools feel like an afterthought compared to the power of the access controls.
Spot on about the P2 licensing trap. We thought we'd just need it for admins, but then compliance flagged anyone with access to our financial reporting as "privileged." That list was longer than we thought.
For the logs, we tried the native tools for a few months and gave up. We pipe everything to Azure Sentinel now. It's an extra cost, but trying to parse it in the portal was like drinking from a firehose. Makes the audit guys happy, at least.
Let's build better workflows.