Everyone's praising the "seamless" migration and "integrated" experience. Let's talk about the actual bill.
Our move from OneLogin to Entra ID for 500 users. The promise was consolidation and savings. The reality is a 40% cost increase for the core SSO functionality we actually use.
* **OneLogin (Advanced):** Flat $6/user/month. No surprises.
* **Entra ID (P1):** $6/user/month **plus** the hidden tax.
* Conditional Access policies? That's P1. Need basic security defaults? Good luck.
* Our app provisioning workflows required custom SCIM. More compute time on the sync servers = higher consumption charges. It adds up.
```json
// OneLogin provisioning config: set-it-and-forget-it.
"provisioning": { "enabled": true }
// Entra ID 'equivalent' to avoid premium features? Goodbye automation.
// To get parity, you're in P1 or writing Azure Functions.
```
The "integration" means you're now locked into their ecosystem. Cost optimization becomes an exercise in navigating license bundles, not engineering.
Show the math: 500 users * $6 * 12 months = $36k base. Add 15% for the auxiliary Azure services to replicate old workflows = **$41.4k total**. Previous OneLogin spend: $36k flat.
show the math
I'm a senior platform engineer at a financial services firm with ~1200 employees. We run a hybrid stack of on-prem Java services and cloud-native Go microservices in Kubernetes, with both OneLogin and Entra ID (for different divisions) in production for SSO and SCIM provisioning.
**Core Comparison**
1. **Pricing Model & Predictability:** OneLogin's per-user tier is transparent and static. Entra ID P1 is a gateway license; operational costs scale with usage in Azure's ecosystem. In my environment, Entra ID's core $6/user/month ballooned by an average of 22% due to Log Analytics ingestion for provisioning audit trails and Azure App Service hosting for custom provisioning logic Microsoft's tools couldn't handle.
2. **SCIM Provisioning Complexity:** OneLogin's provisioning is a configured service. Entra ID's is a platform. For standard apps, it works. For custom or legacy apps, you often exceed the out-of-box connector's capability. We had to write and maintain a lightweight provisioning webhook hosted on Azure Functions, which added ~$1400/month in compute and monitoring costs for syncing ~800 users.
3. **Conditional Access & Security Baseline:** OneLogin's Advanced tier includes policy-driven MFA and access rules. Entra ID's comparable security requires P1. Without it, you're stuck with security defaults, which are inflexible. To achieve parity with our OneLogin rules (geo-blocking, device compliance for a subset of apps), we needed P1. There is no intermediate step.
4. **Administrative Overhead:** OneLogin's admin console is purpose-built. Entra ID's is a slice of the Azure portal. The learning curve is steeper, and permission granularity (RBAC) is more powerful but also more complex to manage correctly. We spent three engineer-weeks refining Azure RBAC roles to match our IT support tiers, a task that took two days in OneLogin.
I would recommend sticking with OneLogin if your primary needs are reliable SSO and straightforward SCIM provisioning for a defined set of SaaS apps, and you value predictable, all-inclusive billing. Choose Entra ID P1 if you are already heavily invested in the Microsoft ecosystem (Microsoft 365, Intune) and need deep, conditional integration with those services, or require its advanced identity protection features. To make a clean call, tell us what percentage of your apps need custom provisioning logic, and whether your security team mandates conditional access policies beyond simple MFA.
Latency is a liability