Top 8 Cloud Directory Solutions (2026)
Which cloud directory should you pick? JumpCloud, Entra ID (formerly Azure AD), Okta, Google Cloud Identity and four more, compared on protocols, devices, and price.

A cloud directory is a vendor-hosted service that stores your users, groups, and devices and decides who can sign in to what, replacing the on-premises Active Directory servers IT teams used to patch and back up themselves. The short answer: pick JumpCloud for small and mid-sized teams with mixed Windows, macOS, and Linux fleets, and Microsoft Entra ID (formerly Azure Active Directory) if you run on Microsoft 365. Pick Google Cloud Identity if you run on Google Workspace, and Okta Universal Directory if you need a vendor-neutral hub across many apps and directories.
The rest of this guide compares the eight cloud directory solutions worth shortlisting, with pricing checked against each vendor's own pricing page, the protocols each supports (LDAP, RADIUS, SAML, OIDC, SCIM), and which ones manage devices as well as identities.
Last verified: September 2026. Pricing pages, product documentation, release notes, and ownership changes were checked for every vendor listed.
Which cloud directory should you choose?
- Replacing Active Directory in a small or mid-sized business: JumpCloud. It bundles the directory, cloud LDAP, RADIUS, SSO, and cross-platform device management in one console.
- Growing company that wants HR to drive IT access: Rippling. Hiring, role changes, and terminations in the HR record provision and revoke app access automatically.
- Microsoft 365 or Azure shop: Microsoft Entra ID (formerly Azure AD). Its Conditional Access engine is the deepest policy framework in this list.
- Many apps, several directories, no single platform vendor: Okta Universal Directory, a meta-directory with more than 8,000 pre-built integrations.
- Google Workspace organization: Google Cloud Identity. The free edition covers 50 users and includes basic endpoint management.
- Mid-market SSO with risk-based login: OneLogin (part of One Identity).
- Large enterprise running its own high-volume LDAP directory: Oracle Unified Directory or PingDS (formerly ForgeRock Directory Services).
Quick Comparison
| Product | Best For | Pricing (verified Sept 2026) | Key Feature | Cross-Platform Devices | MDM Built-In |
|---|---|---|---|---|---|
| JumpCloud | SMBs replacing Active Directory | 30-day free trial; packages from $9/user/mo (annual) | Directory + cloud LDAP/RADIUS + device management | Yes (Windows, macOS, Linux) | Yes |
| Rippling | Fast-growing SMBs linking HR and IT | Custom quote, per employee per month | HR-driven provisioning | Yes | Yes |
| Microsoft Entra ID (formerly Azure AD) | Microsoft 365 and Azure enterprises | Free tier; P1 $7, P2 $10, Entra Suite $12 per user/mo | Conditional Access | Partial | Via Intune |
| Okta Universal Directory | Vendor-neutral identity hub | Suites from $6/user/mo; $1,500 annual minimum | Meta-directory, 8,000+ integrations | Yes | No |
| Google Cloud Identity | Google Workspace environments | Free for 50 users; Premium $7.20/user/mo (Flexible Plan) | Native Workspace identity + endpoint management | Partial | Yes |
| OneLogin (One Identity) | Mid-market SSO and directory | Tiered per user/mo; quote | SmartFactor risk-based authentication | Yes | No |
| Oracle Unified Directory | Large Oracle-invested enterprises | Custom licensing | Directory consolidation and sync | Yes | No |
| PingDS (formerly ForgeRock Directory Services) | High-volume, regulated enterprises | Custom licensing | High-performance LDAP and REST directory | Yes | No |
1. JumpCloud Directory Platform
JumpCloud is a cloud-native directory built to replace Active Directory for organizations that no longer want domain controllers. Users authenticate against JumpCloud for web app SSO, LDAP-bound resources, RADIUS-protected Wi-Fi and VPN, and local accounts on Windows, macOS, and Linux machines, all from one cloud directory.
Key Features
- Unified identity management: one user record drives access to SaaS apps, workstations, and network resources, so policy stays consistent and credentials do not sprawl.
- Cross-platform device management: administrators enforce disk encryption, manage OS patches, deploy software, apply Group Policy-style settings, and lock or wipe Windows, macOS, and Linux devices remotely.
- Cloud LDAP and RADIUS-as-a-Service: legacy apps and network gear keep working without on-premises LDAP or RADIUS servers.
- SSO and MFA: single sign-on to cloud apps plus built-in multi-factor and passwordless options.
Pros
- The most complete Active Directory replacement here for mixed Windows, macOS, and Linux fleets.
- Built-in MDM, LDAP, and RADIUS remove three separate infrastructure components.
- Package pricing is published, which makes budgeting easier than quote-only vendors.
Cons
- The breadth of features (directory, MDM, RADIUS, LDAP, SSO) means a real learning curve for admins coming from siloed tools.
- Integration depth for niche applications can trail best-of-breed single-purpose products.
- The long-running free tier for up to 10 users is gone; the pricing page now offers a 30-day free trial instead.
Pricing
JumpCloud's pricing page lists three packages billed per user per month: Device Management at $9 (annual) or $11 (monthly), SSO at $11 or $13, and Device Identity Management at $13 or $15. The full platform comes in Platform Essentials (capped at 300 users), Platform, and Platform Prime tiers, all quoted by sales.
Best For
Small and mid-sized businesses running cloud-first or hybrid IT with a mixed device fleet, and companies retiring on-premises Active Directory who still have LDAP or RADIUS dependencies.
Bottom Line
JumpCloud is the best overall cloud directory for teams that want identity and device management in one cloud-native product. Expect to pay for it now that the free tier has been retired.
2. Rippling Unified Platform
Rippling combines HR, payroll, and IT on a single employee record. Its identity and access management and device management products read department, role, location, and employment status directly from HR data, which is the differentiator compared with pure directory products.
Key Features
- User provisioning and deprovisioning: accounts in Google Workspace, Microsoft 365, Slack, and hundreds of other SaaS tools are created on hire and revoked on termination, all at once.
- Device management: set up company devices, enforce security policies, deploy software, and wipe data remotely.
- Application management: grant, revoke, and audit access to third-party apps from one console.
- Directory services: a cloud directory of users, groups, and attributes that acts as the source of truth for downstream automation.
- Workflow automation: custom workflows for software requests, hardware provisioning, and lifecycle events.
Pros
- HR changes drive access changes, which closes the orphaned-account gap that manual offboarding leaves open.
- One vendor for HR, IT, and identity reduces the number of systems a small team runs.
- Automation scales with headcount instead of IT staff.
Cons
- The IT products assume you run your people data in Rippling. Companies committed to another HRIS get less of the value.
- No public price list, and integration depth varies for niche applications.
- The breadth of modules (HR, payroll, IT, finance) makes implementation a project, not an afternoon.
Pricing
Rippling's pricing page quotes custom prices: most products bill per employee per month, and some carry a monthly base fee. There are no published list prices for the IT modules.
Best For
Fast-growing small and mid-sized businesses where manual onboarding and offboarding cannot keep pace with hiring, especially if they are choosing an HR platform at the same time.
Bottom Line
Rippling is the best value when HR and IT are being consolidated together. As a standalone directory it makes less sense.
3. Microsoft Entra ID (formerly Azure AD)
Microsoft Entra ID is the cloud identity service Microsoft called Azure Active Directory until its 2023 rename. The product, licenses, and APIs carried over; only the name changed, so "Azure AD" and "Entra ID" search results describe the same service. It handles identity for Microsoft 365 natively and federates to third-party SaaS apps over SAML and OIDC.
Key Features
- Identity and access management: central users and groups, SSO to thousands of apps, SCIM provisioning, and B2B guest collaboration.
- Conditional Access: policies combine user identity, device compliance, app sensitivity, network location, real-time sign-in risk, and session controls. You can require MFA for risky sign-ins, block non-compliant devices, and shorten sessions for sensitive apps.
- Hybrid identity: Microsoft Entra Connect and Cloud Sync (successors to Azure AD Connect) synchronize on-premises Active Directory to the cloud.
- Managed domain services: Microsoft Entra Domain Services provides managed LDAP, Kerberos, and domain join in Azure for legacy apps.
- Privileged Identity Management and ID Protection in the P2 tier.
Pros
- The default choice for Microsoft 365 and Azure, with no extra identity vendor to integrate.
- Conditional Access is the most sophisticated policy engine in any cloud directory we reviewed.
- Proven at very large scale, with thousands of pre-integrated SaaS apps.
Cons
- Harder to run as a standalone directory for organizations that are not on Microsoft 365.
- Device management for macOS, iOS, and Android requires Intune licensing.
- Conditional Access, PIM, and risk-based policies sit in the paid P1 and P2 tiers, and list prices rose to $7 and $10.
Pricing
Microsoft's Entra pricing page lists Entra ID Free (included with Microsoft cloud subscriptions), Entra ID P1 at $7.00 per user per month, Entra ID P2 at $10.00, and the Microsoft Entra Suite at $12.00, all paid yearly. Entra ID Governance is a $7.00 add-on. Many organizations already own P1 or P2 through Microsoft 365 E3 or E5.
Best For
Organizations of any size that already run Microsoft 365, Azure, or Dynamics 365, and enterprises that need granular, risk-based access policy.
Bottom Line
If Microsoft is your productivity platform, Entra ID is the cloud directory you already have. Budget for P1 or P2 to get the features that make it worth using. For a full list of options if you are moving off it, see our Microsoft Entra ID (Azure AD) alternatives guide.
4. Okta Universal Directory
Okta Universal Directory is a meta-directory: it aggregates identity data from Active Directory, LDAP directories, HR systems such as Workday, and other identity providers into one profile per user. Profile mastering rules decide which source is authoritative for each attribute, which resolves conflicts when the same person exists in several systems.
Key Features
- Lifecycle management: attribute-based policies provision and deprovision accounts across integrated apps as people join, move, and leave.
- Application integration: the Okta Integration Network lists more than 8,000 pre-built integrations covering SSO, provisioning, and API access.
- Flexible schema: custom attributes on user profiles for business-specific data.
- Directory synchronization: bidirectional sync with Active Directory and LDAP, plus an LDAP Interface that exposes Okta data to LDAP-dependent apps.
- Security policies: access rules based on attributes, groups, device posture, and location.
Pros
- Vendor-neutral, so it works as the identity hub across Microsoft, Google, and everything else without platform lock-in.
- The broadest integration catalog in this list.
- Mature lifecycle automation with deep Salesforce, Workday, ServiceNow, and AWS connectors.
Cons
- More than a small business with a handful of apps needs.
- No built-in device management; pair it with a separate MDM.
- The $1,500 annual contract minimum and quote-only upper tiers push up cost for small teams.
Pricing
Okta now sells Workforce Identity as suites. Its pricing page lists Starter at $6 per user per month (Universal Directory included), Core Essentials at $14, Essentials at $17, and quote-only Professional and Enterprise suites, all billed annually with a $1,500 annual contract minimum.
Best For
Mid-sized and large organizations with diverse app portfolios, several identity sources, and a Zero Trust program that needs one authoritative user record. Considering a switch? Our Okta Workforce Identity alternatives guide compares the options.
Bottom Line
Okta Universal Directory is the leading vendor-neutral identity hub. It is the right call when no single platform vendor owns your stack.
5. Google Cloud Identity
Google Cloud Identity is the identity layer behind Google Workspace, sold standalone for organizations that want Google-managed users, groups, and devices. It syncs from Active Directory through Google Cloud Directory Sync and federates to third-party apps over SAML.
Key Features
- Identity management: users, groups, and organizational units in one repository.
- SSO and MFA: Google prompts, authenticator apps, and security keys.
- Endpoint management: Android, iOS, ChromeOS, Windows, and macOS, with screen-lock enforcement, app management, remote wipe, and device checks before access. Basic endpoint management is included in the free edition.
- Secure LDAP: lets LDAP-based apps authenticate against Cloud Identity, but only in the Premium edition, per Google's edition comparison.
Pros
- Native to Gmail, Drive, Calendar, and the rest of Workspace.
- Built-in endpoint management avoids separate MDM licensing.
- A genuinely free edition, which is now rare in this category.
Cons
- Shallower integration with non-Google apps and on-premises directories than Okta or Entra ID.
- Some advanced controls are tied to Workspace itself rather than standalone Cloud Identity.
- Secure LDAP requires Premium.
Pricing
Cloud Identity Free provides 50 user licenses by default. Cloud Identity Premium costs $7.20 per user per month on the Flexible Plan, according to Google's billing plan comparison, and is billed through your Google Workspace account.
Best For
Organizations that run on Google Workspace and mostly cloud tools, especially small and mid-market companies with no on-premises directory to keep.
Bottom Line
For Workspace organizations, Cloud Identity is the lowest-friction cloud directory. Its reach into non-Google systems is narrower than Okta's or Microsoft's.
6. OneLogin (One Identity)
OneLogin has been part of One Identity since its 2021 acquisition and continues to operate under the OneLogin brand inside One Identity's Unified Identity Security Platform. Its directory connects Active Directory, LDAP, Google Workspace, and Microsoft Entra ID into one user base, with SSO and MFA on top.
Key Features
- Directory integration: connects to Active Directory, LDAP, and cloud sources, and ties identity lifecycle to HR system status.
- SSO: a large catalog of pre-built application connectors.
- SmartFactor Authentication: uses machine learning to score each login by location, device, time, and behavior, then steps up to more factors, shows a CAPTCHA, or blocks access when risk rises.
- MFA: push, SMS, TOTP, and hardware tokens.
- Provisioning, reporting, and auditing for access changes and compliance evidence.
Pros
- Administrators and end users generally find the interface easy to learn.
- Risk-based SmartFactor login is included in the product line rather than bolted on.
- Automated onboarding and offboarding tied to HR status.
Cons
- Deep customization beyond standard directory and SSO setups takes specialist effort.
- SmartFactor and advanced lifecycle features sit in higher tiers.
- No built-in device management.
Pricing
OneLogin sells tiered per-user, per-month plans billed annually. Confirm current list prices on the OneLogin pricing page or through One Identity sales, since contract pricing varies with user count and term.
Best For
Mid-market organizations with many cloud and on-premises apps that want SSO, a unified directory, and risk-based MFA without an enterprise-scale project.
Bottom Line
OneLogin is a solid mid-market directory and SSO platform. One Identity ownership also gives it a path into governance and privileged access if you need them later.
7. Oracle Unified Directory
Oracle Unified Directory (OUD) is an LDAPv3 directory server, proxy, and synchronization hub. Unlike the SaaS entries above, it is software you deploy and operate yourself, on premises or on cloud infrastructure. The current release is OUD 14c (14.1.2.1.0), part of Oracle Identity and Access Management 14c, which Oracle released in March 2025 with a planned eight years of premier and extended support. Oracle shipped a January 2026 proactive bundle patch.
Key Features
- Identity consolidation: unifies identities from legacy directories, databases, and cloud apps into one authoritative directory, a common need after mergers.
- Directory synchronization: real-time and scheduled bidirectional sync with Active Directory, other LDAP directories, and Oracle databases.
- High availability: multi-master replication, load balancing, and horizontal scaling.
- Schema management and security: flexible schema, fine-grained access control, encryption, and audit logging.
Pros
- Built for high transaction volumes and hundreds of thousands of identities.
- Standards-based LDAP plus tight integration with the Oracle stack.
- A published, long support horizon for the 14c release.
Cons
- You run it, patch it, and scale it; it is not directory-as-a-service.
- Steep learning curve and specialist skills required.
- Licensing and support costs are significant for smaller organizations.
Pricing
OUD is licensed standalone or within Oracle's identity management suites. Pricing is quoted by Oracle sales based on users, features, and support level.
Best For
Large, Oracle-invested enterprises with fragmented directories and strict availability requirements.
Bottom Line
OUD is a consolidation workhorse for large estates. Choose it when you need to own the directory, not rent it.
8. PingDS (formerly ForgeRock Directory Services)
Ping Identity completed its acquisition of ForgeRock in August 2023, under Thoma Bravo ownership. ForgeRock Directory Services now ships as PingDS, an LDAPv3 and REST directory; version 8 is current, per the PingDS release notes. It is the directory underneath Ping's Advanced Identity Software (the former ForgeRock Identity Platform) and can be self-managed or consumed through Ping's cloud.
Key Features
- High availability and scale: multi-master replication and horizontal scaling for continuous availability under very high authentication volumes.
- Schema management: custom attributes and object classes to model complex identity data.
- Security and compliance: fine-grained access control, LDAPS/TLS, and audit logging for financial services, healthcare, and government requirements.
- Low-latency reads: tuned for real-time authentication, which is why it is common in consumer-facing identity where latency affects conversion.
Pros
- Top-tier throughput for organizations processing millions of identity transactions a day.
- On-premises, cloud, and hybrid deployment options.
- Integrates with Ping's access management, governance, and orchestration products.
Cons
- Needs dedicated identity engineering expertise.
- A significant investment for organizations without enterprise budgets.
- Product naming is mid-transition, so ForgeRock and Ping documentation both still circulate.
Pricing
Ping licenses PingDS based on identities managed and modules deployed. Pricing is quoted by Ping Identity sales. See also our Ping Identity vendor profile.
Best For
Large enterprises in regulated industries with high-volume directory workloads, and existing ForgeRock customers.
Bottom Line
PingDS is the performance choice for enterprises that need a highly available directory at massive scale and have the team to run it.
Best Cloud Directory by Use Case
| Situation | Recommendation |
|---|---|
| Small or mid-sized organization replacing Active Directory | JumpCloud: the most complete replacement, with MDM, LDAP, RADIUS, and cross-platform support. Start with the 30-day trial. |
| Growing SMB combining HR and IT | Rippling: HR events drive provisioning, so access keeps pace with hiring. |
| Microsoft-centric enterprise | Microsoft Entra ID with P1 or P2 for Conditional Access and risk policies. |
| Multi-vendor identity hub | Okta Universal Directory: vendor-neutral meta-directory with 8,000+ integrations. |
| Google Workspace organization | Google Cloud Identity: native Workspace identity with built-in endpoint management. |
| Mid-market organization needing broad SSO | OneLogin: large connector catalog and SmartFactor risk-based login. |
| Large Oracle enterprise with fragmented directories | Oracle Unified Directory: consolidation and sync into one authoritative source. |
| High-volume regulated enterprise | PingDS: performance at scale with self-managed or cloud deployment. |
| Legacy apps that need managed Active Directory in the cloud | A hosted AD service such as AWS Managed Microsoft AD or Microsoft Entra Domain Services, alongside one of the directories above. |
How We Evaluated
Each product was assessed on five criteria: the directory model (native store, meta-directory, or self-managed LDAP server), protocol coverage (LDAP, RADIUS, SAML, OIDC, SCIM), device management, hybrid coexistence with on-premises Active Directory, and pricing transparency. Every price in this guide comes from the vendor's own pricing page or documentation, not from third-party listings. Ownership and product names were checked against vendor announcements and documentation.
This guide is written by Deepak Gupta, who founded LoginRadius, a customer identity platform he scaled to over a billion users. That work sits on the customer identity side, but the same lesson applies to workforce directories: the directory is the system of record every other access control reads from, so migration effort and protocol coverage matter more than feature checklists.
Last verified: September 2026. Changes since the previous version: JumpCloud replaced its free tier with a 30-day trial and published package pricing. Entra ID P1 and P2 list prices are now $7 and $10. Okta moved to suites with a $1,500 minimum. Cloud Identity Premium is listed at $7.20 on the Flexible Plan, and ForgeRock Directory Services is now PingDS.
Conclusion
Start from the platform you already run. Microsoft 365 points to Entra ID, Google Workspace to Cloud Identity, and a mixed or device-heavy SMB environment to JumpCloud. Okta earns its cost when no single vendor owns your stack, while Oracle Unified Directory and PingDS suit enterprises that need to run a high-volume directory themselves. Shortlist two or three, map your apps and protocols against each, and run a pilot with real users before committing. For a wider view of identity vendors, see the identity-map directory category, and if you still manage on-premises AD during the transition, our guide to Active Directory management tools.
Frequently Asked Questions
What is a cloud directory, and what is directory-as-a-service?
A cloud directory is an identity directory hosted and managed by a vendor rather than run on your own servers. It stores user accounts, groups, and device records, then authenticates and authorizes access to apps and resources. Directory-as-a-service (DaaS) is the subscription model for it: you pay per user and connect users, apps, and devices through standard protocols without installing directory software. This workforce model is distinct from customer identity and access management, which our CIAM Compass covers in depth.
What are the best cloud directory services in 2026?
JumpCloud leads for small and mid-sized businesses that need identity and cross-platform device management together. Microsoft Entra ID is the best fit for Microsoft 365 and Azure environments, Google Cloud Identity for Google Workspace, and Okta Universal Directory for a vendor-neutral hub. Rippling is the pick when HR and IT are being consolidated. Choose by your platform mix and existing stack.
Can a cloud directory fully replace on-premises Active Directory?
For many organizations, yes. On-premises AD runs on domain controllers you own and secure, while a cloud directory moves that work to a provider and is built for remote workers and SaaS apps. Organizations with apps that need Kerberos, Group Policy, or on-premises file share permissions may still need AD, a hybrid setup through Microsoft Entra Connect, or a managed AD service. Cloud LDAP and RADIUS from vendors like JumpCloud cover many legacy cases. Moving to a provider also shifts who owns compliance evidence, so cross-check candidates in a GRC and compliance directory when requirements are strict.
Is Microsoft Entra ID the same as Azure AD?
Yes. Microsoft renamed Azure Active Directory to Microsoft Entra ID in 2023; the service, licenses, and capabilities are the same, and Azure AD P1 and P2 became Entra ID P1 and P2. Entra ID is a cloud directory focused on the Microsoft 365 and Azure ecosystem. It is not a drop-in replacement for on-premises Active Directory, which uses Kerberos and LDAP rather than the web protocols Entra ID uses for app access.
What is the difference between a cloud directory and an identity provider?
A cloud directory stores identity data: attributes, credentials, group memberships, and reporting relationships. An identity provider (IdP) authenticates users and federates that identity to applications over SAML or OIDC. Most modern platforms, including Entra ID, Okta, and JumpCloud, do both. The distinction matters when one system (often on-premises AD) stays the identity source while a cloud IdP handles SSO.
Do cloud directories support LDAP-dependent applications?
Most do, in different ways. JumpCloud offers cloud-hosted LDAP that apps bind to directly. Microsoft Entra Domain Services provides managed LDAP and Kerberos in Azure. Okta offers an LDAP Interface, and Google Cloud Identity offers Secure LDAP in its Premium edition only. Oracle Unified Directory and PingDS are LDAP servers natively. List your apps and their protocols (SAML, OIDC, SCIM, LDAP, RADIUS) and confirm each candidate covers them before comparing price.
Which cloud directories include device management?
JumpCloud manages Windows, macOS, and Linux from one console, and Rippling includes device management in its IT platform. Google Cloud Identity covers Android, iOS, ChromeOS, Windows, and macOS, with basic management in the free edition. Entra ID manages devices through Microsoft Intune, licensed separately. Okta, OneLogin, Oracle Unified Directory, and PingDS need a third-party MDM.
More like this
All Identity & CIAM- Identity & CIAMIdentity Management in Cloud ComputingCloud identity management decides who can reach which resource, when, and how. A practical look at IAM and CIAM in the cloud era.
- Identity & CIAMWhat Is Identity Attack Surface Management (IASM)?IASM discovers every identity in your estate, maps what each can reach, and closes the paths attackers use. How it relates to ITDR,…
- Identity & CIAMSecuring Cloud Applications: SCIM's Role in Modern Identity ManagementSCIM automates user provisioning and de-provisioning across cloud apps through a standard JSON schema and REST API. Here is how SCIM 2.0…
Get new Identity & CIAM writing
Enjoyed this? Subscribe and tell us what you read most. Identity & CIAM is already ticked for you. No tracking pixels, unsubscribe with one click.