# What cloud directory services work best for replacing Active Directory and LDAP in a hybrid environment where some workloads are still on-premise?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Hey G2 community, what cloud directory services work best for replacing Active Directory and LDAP in a hybrid environment where some workloads are still on-premise? I have been collecting notes on this because it comes up constantly in <a class="a a--md" elv="true" href="https://www.g2.com/categories/cloud-directory-services">cloud directory services</a> research, and hybrid is where generic advice falls apart: the honest answer depends on whether you want to extend AD, replace it, or keep real AD but stop hosting it. Recent reviews split cleanly along those three paths:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/jumpcloud/reviews"><strong>JumpCloud</strong></a> (4.5/5.0, 4,017 reviews): The replace path. The sentiment across reviews from smaller companies is that it delivers the best parts of AD without the downsides of an on-prem setup, and it ships cloud LDAP and RADIUS for the legacy pieces. The recurring warning in reviews is that the actual migration from traditional AD takes planning, with setup complexity the most cited pain.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/microsoft-entra-id/reviews"><strong>Microsoft Entra ID</strong></a> (4.5/5.0, 911 reviews): The extend path. Reviewers praise how it simplifies identity across cloud and hybrid environments, though some flag real friction migrating shared mailboxes and other AD objects, so the hybrid sync layer is where the work lives.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/okta/reviews"><strong>Okta</strong></a> (4.5/5.0, 1,304 reviews): The unify-on-top path. Its on-premise identity repository support scores 9.4 against a category average of 8.7 on G2, and admins describe managing lifecycle across both cloud and on-prem applications with minimal end user friction.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/managed-microsoft-ad/reviews"><strong>Managed Microsoft AD</strong></a> (4.4/5.0, 29 reviews): The keep-real-AD path, hosted by Google Cloud. Worth knowing about if applications genuinely require domain-joined AD, though the review base is small, so treat it as a shortlist candidate to validate rather than a review-backed verdict.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Which path did your team pick, and if you fully retired your domain controllers, how long did the last on-prem dependency actually take to die?</p>

##### Post Metadata
- Posted at: 3 months ago
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;&lt;span style=&quot;color: rgb(0, 0, 0);&quot;&gt;For the unify-on-top path specifically, Okta&#39;s on-premise identity repository support scoring well above the category average is the detail I&#39;d lean on. Managing lifecycle across cloud and on-prem apps with minimal friction is what you want if full replacement isn&#39;t realistic yet.&lt;/span&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: 9 days ago
- Author title: Marketing



### Comment 2

&lt;p&gt;&lt;span style=&quot;color: rgb(0, 0, 0);&quot;&gt;JumpCloud is built for exactly this, unifying identity and device management to replace or bridge AD and LDAP in hybrid environments where some workloads are still on-prem.&lt;/span&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: 10 days ago



### Comment 3

&lt;p&gt;The three-paths framing is the most useful thing in this post, and I&#39;d add that what decides the timeline is almost never the users, it&#39;s one stubborn dependency. Usually a file server whose permissions were built on nested groups nobody documented, a printer fleet doing Kerberos, or a single line-of-business app that only knows how to LDAP bind. Any one of those keeps a domain controller alive by itself, which is why the honest planning question is &quot;which single thing can&#39;t move&quot; rather than &quot;how long is the migration.&quot; JumpCloud shipping cloud LDAP and RADIUS points straight at the app and network half of that list, which is often the difference between retiring the DC and keeping one running for one service.&lt;/p&gt;

##### Comment Metadata
- Posted at: 11 days ago
- Author title: Tech Consultant



### Comment 4

&lt;p&gt;&lt;span style=&quot;background-color: transparent; color: rgb(0, 0, 0);&quot;&gt;The three-path framing (extend, replace, or cloud-host real AD) is genuinely clarifying, most conversations about hybrid directory get stuck because the two people are describing different paths without realising it.&lt;/span&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: 2 months ago
- Author title: Marketing Executive





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


