Identity is in Microsoft's global tenancy, not yours
AD Connect synchronises your directory upward. It does not put Entra in your data centre. For an organisation with an onshore data-residency position, that direction of travel is the problem.
Identity & access · Straventa Accounts
Entra ID is where most Microsoft estates end up by default rather than by decision. It is a SaaS directory in Microsoft's global tenancy, priced per user per month and tiered by feature plan, and the deeper you go the harder it is to leave. Straventa Accounts covers application sign-on from inside your own infrastructure, on standard OpenID Connect, with no tenancy to be coupled to.
Why teams move
AD Connect synchronises your directory upward. It does not put Entra in your data centre. For an organisation with an onshore data-residency position, that direction of travel is the problem.
Per-user pricing tiered by feature plan means the control you actually want — conditional access, the better governance tooling — is a plan upgrade across your whole user base, not a line item for the twenty people who need it.
Entra is not just your login. It is coupled across the Microsoft estate, so an exit is a programme rather than a repointed issuer URL.
A holding company with a dozen subsidiaries ends up with cross-tenant work to do something that should be a hierarchy. Accounts models the hierarchy natively, with descendant-scoped permissions.
Entra ID ships SAML 2.0 and SCIM provisioning, and it does things Accounts does not attempt: it is a directory for the Microsoft estate, with device registration, conditional access, and Microsoft 365 integration. Straventa Accounts is an application sign-on layer — OpenID Connect and OAuth 2.0 only. It will not manage your Windows devices or your Microsoft 365 licensing, and it does not ship SAML or SCIM today. The realistic shape is Accounts in front of your web and mobile applications, with Microsoft keeping the Microsoft estate.
Straventa vs Microsoft Entra ID
Written for the person who has to defend the choice in a board pack. Competitor rows describe each vendor's publicly documented model at time of writing.
| Criterion | Straventa Accounts | Microsoft Entra ID |
|---|---|---|
| Deployment model | Self-hosted on your Kubernetes or Docker, or Straventa-managed at accounts.straventa.com. Your choice, same product. | SaaS only — AD Connect syncs to it, it does not run in your data centre. |
| Where identity data lives | Your infrastructure, in Indonesia. Nothing leaves your environment on the self-hosted deployment. | Microsoft global tenancy. |
| Pricing model | Per deployment, annual. Not per seat — headcount growth does not change the invoice. | Per user, per month, tiered by feature plan. |
| Who operates it | You, or Straventa under contract. Start managed and take it in-house later without re-platforming. | Vendor. |
| Who answers at 03:00 | A named Straventa engineering contact, on terms set in your contract, in your timezone. | Your Microsoft support plan. |
| Protocols | OpenID Connect / OAuth 2.0 — PKCE, discovery, JWKS. SAML and SCIM are not shipped today; see the FAQ. | OIDC and SAML. |
| Multi-tenant / group structure | Native tenant hierarchy with descendant-scoped permissions — built for holdings with subsidiaries. | Separate tenants, cross-tenant work required. |
| Ships integrated with your payments and ops stack | Yes — Payops and the Ops platform already authenticate against it and resolve permissions through it on day one. | An integration project. |
| Exit cost | Standard OIDC. Your apps point at an issuer URL — repoint them and leave. | Deep tenant coupling across Microsoft 365. |
Competitor rows describe each vendor’s publicly documented model at time of writing; confirm current terms with the vendor before making a decision.
Migration
Both systems run in parallel until the last application is across. There is no single evening on which everything has to work.
Separate the applications that only need OIDC sign-on from everything genuinely coupled to Microsoft 365 and device management. The first group is what moves.
Stood up beside Entra with nothing cut over. Identity records, sessions, and authentication logs stay in your environment from the first day it is running.
Repoint OIDC applications at your Accounts issuer. Entra keeps doing what it is genuinely good at; it just stops being the login for everything else.
Group structure moves onto the native tenant hierarchy with descendant-scoped permissions, so an access review across the group becomes one query.
Straight answers
Comparing something else?
Bring your application inventory and your data-residency position. We will show you which half of your estate can move onto an onshore issuer and which half genuinely belongs with Microsoft.