Using a primary IdP other than Entra ID

Posted by BWMerlin@reddit | sysadmin | View on Reddit | 5 comments

I have started a new job at a small health care company because they hate their MSP and want to bring everything in house. Most of the users are on the road seeing to our clients are only licensed under Microsoft 365 Business Basic so they can get email while the few office staff are Microsoft 365 Business Standard.

We hardly use any of the Microsoft suite of products in total so I am considering up if we should move more into the Microsoft stack or keep the light foot print we currently have and look at alternatives. We are experiencing growth and plan to outgrow the 300 user limit of Microsoft 365 Business (I read the Microsoft FAQ and it seems that this is a soft cap so long as you don't exceed more than 300 users on any one business plan).

I am tossing up around our IdP if I should just stick with Entra ID or if I should look at alternatives like Okta and have the external IdP feed into Entra ID Free tier for user provisioning and Office and Windows authentication.

One of the ideas that I have tossed to leadership was that we move away from Microsoft 365 Business Basic for the bulk of our users and look for an external mail host and intergrate that with our IdP for provisioning and SSO for those that just need email.

For those that use an IdP other than Entra ID when and why did it make sense for you? Does this quiet probable hair brain idea to use something other than Entra ID make sense for an organisation of our size? Should I just not worry so much and drink the Microsoft coolaid?