Skip to main content
Straventa

Identity & access · Straventa Accounts

An Entra ID alternative for organisations that need identity onshore

Entra ID is where most Microsoft estates end up by default rather than by decision. It is a SaaS directory in Microsoft's global tenancy, priced per user per month and tiered by feature plan, and the deeper you go the harder it is to leave. Straventa Accounts covers application sign-on from inside your own infrastructure, on standard OpenID Connect, with no tenancy to be coupled to.

Why teams move

What actually pushes organisations off Microsoft Entra ID

Identity is in Microsoft's global tenancy, not yours

AD Connect synchronises your directory upward. It does not put Entra in your data centre. For an organisation with an onshore data-residency position, that direction of travel is the problem.

The features you need are one tier up

Per-user pricing tiered by feature plan means the control you actually want — conditional access, the better governance tooling — is a plan upgrade across your whole user base, not a line item for the twenty people who need it.

Leaving means untangling Microsoft 365

Entra is not just your login. It is coupled across the Microsoft estate, so an exit is a programme rather than a repointed issuer URL.

Subsidiaries become separate tenants

A holding company with a dozen subsidiaries ends up with cross-tenant work to do something that should be a hierarchy. Accounts models the hierarchy natively, with descendant-scoped permissions.

What does not carry over

Entra ID ships SAML 2.0 and SCIM provisioning, and it does things Accounts does not attempt: it is a directory for the Microsoft estate, with device registration, conditional access, and Microsoft 365 integration. Straventa Accounts is an application sign-on layer — OpenID Connect and OAuth 2.0 only. It will not manage your Windows devices or your Microsoft 365 licensing, and it does not ship SAML or SCIM today. The realistic shape is Accounts in front of your web and mobile applications, with Microsoft keeping the Microsoft estate.

Straventa vs Microsoft Entra ID

Straventa Accounts compared with Microsoft Entra ID

Written for the person who has to defend the choice in a board pack. Competitor rows describe each vendor's publicly documented model at time of writing.

Straventa Accounts compared with Microsoft Entra ID
CriterionStraventa AccountsMicrosoft Entra ID
Deployment modelSelf-hosted on your Kubernetes or Docker, or Straventa-managed at accounts.straventa.com. Your choice, same product.SaaS only — AD Connect syncs to it, it does not run in your data centre.
Where identity data livesYour infrastructure, in Indonesia. Nothing leaves your environment on the self-hosted deployment.Microsoft global tenancy.
Pricing modelPer deployment, annual. Not per seat — headcount growth does not change the invoice.Per user, per month, tiered by feature plan.
Who operates itYou, or Straventa under contract. Start managed and take it in-house later without re-platforming.Vendor.
Who answers at 03:00A named Straventa engineering contact, on terms set in your contract, in your timezone.Your Microsoft support plan.
ProtocolsOpenID Connect / OAuth 2.0 — PKCE, discovery, JWKS. SAML and SCIM are not shipped today; see the FAQ.OIDC and SAML.
Multi-tenant / group structureNative tenant hierarchy with descendant-scoped permissions — built for holdings with subsidiaries.Separate tenants, cross-tenant work required.
Ships integrated with your payments and ops stackYes — Payops and the Ops platform already authenticate against it and resolve permissions through it on day one.An integration project.
Exit costStandard OIDC. Your apps point at an issuer URL — repoint them and leave.Deep tenant coupling across Microsoft 365.

Competitor rows describe each vendor’s publicly documented model at time of writing; confirm current terms with the vendor before making a decision.

Migration

Moving off Microsoft Entra ID, without a flag day

Both systems run in parallel until the last application is across. There is no single evening on which everything has to work.

  1. Step 1

    Draw the line between app sign-on and the Microsoft estate

    Separate the applications that only need OIDC sign-on from everything genuinely coupled to Microsoft 365 and device management. The first group is what moves.

  2. Step 2

    Deploy Accounts inside your infrastructure

    Stood up beside Entra with nothing cut over. Identity records, sessions, and authentication logs stay in your environment from the first day it is running.

  3. Step 3

    Move applications, keep Microsoft for Microsoft

    Repoint OIDC applications at your Accounts issuer. Entra keeps doing what it is genuinely good at; it just stops being the login for everything else.

  4. Step 4

    Model the subsidiaries as a hierarchy

    Group structure moves onto the native tenant hierarchy with descendant-scoped permissions, so an access review across the group becomes one query.

Straight answers

Questions we get from Microsoft Entra ID teams

Does this replace Azure AD / Entra ID completely?
For application sign-on, yes. For the Microsoft estate, no, and we would not pretend otherwise. Device registration, conditional access on Windows endpoints, and Microsoft 365 licensing stay with Microsoft. What moves is the login layer for your web and mobile applications, which for most organisations is the majority of the identity surface and all of the per-user cost pressure.
We are a holding company with subsidiaries. How is that modelled?
As a hierarchy, natively. Accounts has a tenant tree with descendant-scoped permissions, so a group-level administrator can be scoped to a branch rather than granted everything. That is the case it was built for — it is how the Straventa platform serves its own customers.
Where does the data actually sit?
On a self-hosted deployment, entirely inside your infrastructure, in Indonesia. Identity records, sessions, and authentication logs never leave your environment. On Straventa-managed it sits in our Indonesian infrastructure. There is no third option where it quietly goes abroad.

Draw the line before you sign the renewal.

Bring your application inventory and your data-residency position. We will show you which half of your estate can move onto an onshore issuer and which half genuinely belongs with Microsoft.