Comparison
Entra ID vs Ping Identity
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
Entra ID vs Ping Identity (PingOne, PingFederate, ForgeRock): federation depth, hybrid deployment, and CIAM against Entra's bundled workforce identity.
4 min read
Entra ID vs Ping Identity is a comparison most organisations meet in one of two situations: a large enterprise with PingFederate deep in its application estate asking whether Microsoft 365 licensing makes Ping redundant, or a company choosing a customer identity (CIAM) platform and wondering whether Microsoft's External ID is enough. In both, the honest answer is that Entra ID is the default for workforce identity in a Microsoft 365 shop, and Ping remains the specialist for complex federation, hybrid or self-hosted deployment, identity orchestration, and large-scale CIAM.
The Entra fundamentals are in What is Microsoft Entra ID; the customer-identity side in Entra External ID vs Azure AD B2C. The closer workforce comparison is Entra ID vs Okta.
Where each one comes from
Ping Identity grew from PingFederate, the enterprise federation server that let banks and governments do SAML, WS-Federation, OAuth, and OIDC across internal apps, partners, and clouds — on their own infrastructure. PingOne added a cloud platform with SSO, MFA, a directory, and DaVinci, a no-code orchestration engine for building authentication journeys. The 2023 merger with ForgeRock brought a mature CIAM stack (ForgeRock Identity Cloud, Access Management, Identity Governance) and a large customer-identity installed base. Ping's customers are typically large, regulated, and hybrid.
Microsoft Entra ID is the cloud directory and IdP for Microsoft 365 and Azure with SSO, SCIM, Conditional Access, MFA and passwordless, Identity Protection, PIM, and ID Governance for workforce; External ID for customer and partner identity; and the Entra Suite for network access and Verified ID. It runs only as Microsoft's cloud service; the on-premises story is Entra Connect synchronisation and, for legacy federation, AD FS (which Microsoft has been steering customers away from for years).
Decision criteria
| Criterion | Entra ID | Ping Identity | | --- | --- | --- | | Workforce SSO to SaaS | App gallery, SAML/OIDC, SCIM | PingOne SSO; PingFederate for complex/legacy | | Complex or legacy federation | Standard protocols; limited custom token flows | PingFederate: WS-Trust, custom adapters, token exchange, on-prem | | Deployment model | Cloud only | Cloud (PingOne), self-hosted (PingFederate, ForgeRock AM), or hybrid | | Authentication orchestration | Conditional Access + authentication strengths; custom flows via External ID | DaVinci no-code journeys; ForgeRock Journeys | | MFA / passwordless | Authenticator, FIDO2, Windows Hello, CBA | PingID, FIDO2, and third-party integrations | | Customer identity (CIAM) | External ID (successor to B2C); simpler, cheaper, less flexible | ForgeRock/PingOne for Customers: highly customisable, high scale | | Governance | ID Governance | ForgeRock/Ping Identity Governance | | Microsoft 365 / Intune / Defender integration | Native | Federated; device and risk signals need integration | | Licensing | Bundled in M365 (P1/P2), Suite add-on; External ID per MAU | Per-user workforce, per-MAU customer; quote-based; self-hosted licensing separate |
Cost model
For workforce identity, Entra ID P1 is included in Microsoft 365 Business Premium, E3, E5, and the F-plans, P2 in E5; standalone P1 lists at approximately 6 USD and P2 at approximately 9 USD per user per month (as of 2026-09; check Microsoft). External ID for customers is priced per monthly active user with a free tier.
Ping is priced per user for workforce and per monthly active user for customer identity, quote-based, with PingFederate and ForgeRock self-hosted components licensed and operated separately — which means infrastructure, patching, and specialist skills on top of the subscription. Ping is rarely chosen on price; it is chosen because a requirement cannot be met otherwise, or because it is already in place and load-bearing.
Choose Entra ID if
- Workforce identity for a Microsoft 365 organisation with mainstream SaaS: Conditional Access with Intune and Defender signals is the deciding integration.
- You want to retire AD FS and on-premises federation infrastructure entirely (the retiring on-prem AD guide covers what still blocks that).
- Customer identity needs are moderate — sign-up, sign-in, social, MFA, branding — and External ID's model fits.
- Budget and skills favour a managed cloud service over self-hosted identity infrastructure.
Choose Ping if
- Federation requirements Entra cannot meet: legacy protocols, custom token exchange, partner federations with bespoke claims, or a mandate that the IdP be self-hosted.
- Large-scale, highly customised CIAM with orchestration across many journeys, brands, and regions.
- A regulated environment with an existing PingFederate or ForgeRock estate that applications depend on, where migration risk dwarfs licence savings.
- Identity must be independent of the productivity and cloud vendor.
Run both if
Ping handles federation and CIAM; Entra ID is the Microsoft 365 directory federated to Ping, or Ping's apps trust Entra as the IdP for the workforce while Ping serves customers. This split — Entra for employees, Ping/ForgeRock for customers — is the most common coexistence and the least painful, because the two populations rarely overlap. Workforce federation from Entra to Ping works but hands Conditional Access fewer signals, so keep break-glass accounts cloud-native and MFA policy owned by one side.
What people get wrong
Keeping PingFederate for one legacy app and paying enterprise federation costs for it — inventory what still needs it, as with the unused enterprise apps cleanup. Choosing Ping for CIAM without pricing the operational overhead of self-hosted components. And assuming Entra External ID is B2C with a new name: it is a new platform with a different feature set, and a migration in its own right.
Frequently asked questions
- What is the difference between PingOne, PingFederate, and ForgeRock?
- PingFederate is Ping's long-standing on-premises or self-hosted federation server, popular in large enterprises and regulated industries for complex SAML/OIDC/WS-Fed flows. PingOne is its cloud platform (SSO, MFA, DaVinci orchestration, directory). ForgeRock, acquired by Ping's owner Thoma Bravo and merged in 2023, brought a full identity platform strong in customer identity (CIAM) and identity governance. Ping now sells all of these under one brand with a roadmap to converge them.
- Is Ping mainly for customer identity (CIAM)?
- It is strong there — the ForgeRock heritage and DaVinci orchestration make Ping a leading CIAM choice for banks, retailers, and telcos with millions of consumer identities. But its workforce products (PingFederate, PingOne for Workforce) are also widely deployed, especially where federation to hundreds of internal and partner applications, including legacy protocols, is the requirement.
- Can Entra ID handle complex federation like PingFederate?
- For standard SAML 2.0 and OIDC apps, yes, and it federates with partner IdPs through cross-tenant access and External ID. Where Entra falls short is bespoke federation: custom claim transformations beyond its claims-mapping policies, WS-Trust and older protocols, token exchange scenarios, and on-premises federation without a cloud dependency. Organisations that need those keep PingFederate (or AD FS) alongside Entra.
Further reading
Spot something wrong or want a topic covered? Send it through the contact form.