# Which CIEM platforms provide granular role-based controls and manage Active Directory and EntraID groups properly?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Curious how G2 reviewers have actually handled the AD/EntraID side of this. Which CIEM platforms provide granular role-based controls and manage Active Directory and EntraID groups properly, since a lot of CIEM tools handle the cloud side well but treat AD/EntraID as an afterthought.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Most CIEM tools solve the cloud side well. AD and EntraID are usually where the actual gaps live. A few on G2's<a class="a a--md" elv="true" href="https://www.g2.com/categories/cloud-infrastructure-entitlement-management-ciem"> </a><a class="a a--md" elv="true" href="https://www.g2.com/categories/cloud-infrastructure-entitlement-management-ciem">CIEM</a> list are built specifically around that gap:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/microsoft-entra-permissions-management/reviews"><strong>Microsoft Entra Permissions Management</strong></a> (4.3/5, 15+ reviews): purpose-built to detect and right-size unused permissions and enforce least privilege across Azure, AWS, and GCP under the Entra umbrella.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/sailpoint/reviews"><strong>SailPoint</strong></a> (4.5/5, 200+ reviews): identity governance built around automated access reviews and policy enforcement, with a large enough review base to judge role-based control maturity.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/beyondtrust-entitle-just-in-time-access/reviews"><strong>BeyondTrust Entitle Just-in-Time Access</strong></a> (4.3/5, 10+ reviews): specializes in granular, temporary access rather than standing permissions, with detailed auditing for every grant.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For anyone managing this in a hybrid AD/EntraID environment: is the gap usually in the tooling, or in how the groups were structured to begin with?</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p>

##### Post Metadata
- Posted at: 15 days ago
- Author title: Tech Consultant
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;The tooling gap often exposes an underlying identity-design gap: even strong CIEM won’t fully compensate for poorly structured AD or Entra ID groups. I’d compare group-to-role mapping, nested-group visibility, entitlement reviews, and whether least-privilege changes can be enforced without breaking existing access paths.&lt;/p&gt;

##### Comment Metadata
- Posted at: 14 days ago
- Author title: Marketing Executive





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


