We’re implementing SSO for our Aras 13.0 part management system and evaluating between Okta and Azure AD as our identity provider. Our environment is hybrid - some on-prem infrastructure and growing cloud presence.
Azure AD makes sense given our Microsoft ecosystem, but Okta’s multi-cloud support is appealing for future flexibility. Policy engine capabilities differ significantly between the two, and cost considerations are important given we’re looking at 500+ users. What are the real-world pros and cons of each for Aras SSO integration?
Both IdPs integrate with Aras Innovator via SAML 2.0 or OAuth 2.0 / OIDC — Aras exposes these through its OAuth Server configuration and the InnovatorServer.config identity provider settings. The choice comes down to your operational context, not Aras compatibility.
Azure AD (Entra ID)
Native integration with M365, Teams, and Windows hybrid-join — minimal extra configuration if users already have Entra identities
Conditional Access policies are deeply integrated; MFA enforcement, device compliance, and location-based rules apply without a separate policy engine
Azure AD Application Proxy simplifies on-prem Aras exposure without a full DMZ reverse proxy
Licensing is often bundled into existing M365 E3/E5 agreements — incremental cost for SSO may be near zero (verify with vendor for current pricing)
Weakness: multi-cloud or non-Microsoft SaaS governance adds complexity; Azure AD B2B for external suppliers requires careful tenant configuration
Okta
Purpose-built identity platform; Universal Directory and policy engine are IdP-agnostic, which maps well to a heterogeneous future-state architecture
Cleaner abstraction layer if you anticipate migrating off Microsoft infrastructure or running parallel cloud environments
Okta Workflows (verify in your version) provides no-code lifecycle automation for provisioning/deprovisioning Aras users — relevant when managing 500+ accounts across PLM and ERP
Licensing is per-user and additive; at 500+ users, total cost of ownership needs explicit modeling against your existing Microsoft entitlements
Hybrid-specific considerations
Both support AD Connect / on-prem AD as a source of truth, so existing LDAP/AD user stores sync to either IdP
For on-prem Aras instances, Okta requires an Okta AD Agent; Azure AD uses AD Connect — both are mature but add infrastructure components to maintain
Group-based role mapping into Aras item permissions works with either; map IdP groups to Aras Identities via claim transformation rules
Practical recommendation signal: If your org is Microsoft-heavy and M365 licensing is already in place, Azure AD wins on cost and operational simplicity. If multi-cloud governance and IdP-agnostic lifecycle management are genuine 12-month roadmap items, Okta’s flexibility justifies the incremental spend.
Verify with vendor for current pricing.
This draft is based on general Aras Innovator knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.
We went with Azure AD for our Aras deployment primarily because of the existing Microsoft investment. The integration was straightforward using SAML 2.0, and conditional access policies work well for our security requirements. The licensing was already covered under our E5 subscriptions, so no additional IdP costs. However, the policy engine is somewhat limited compared to Okta’s more granular controls.
Okta shines in multi-cloud scenarios. If you’re planning to expand beyond Microsoft services, Okta provides better vendor neutrality. Their Universal Directory and lifecycle management are more flexible than Azure AD. We use Okta across AWS, Google Cloud, and on-prem systems, and it handles the complexity well. The policy engine supports sophisticated authentication flows that Azure AD struggles with.
Cost-wise, Azure AD is hard to beat if you already have Microsoft licensing. Okta charges per user per month, which adds up quickly at 500+ users. However, Okta’s support and documentation for enterprise SSO is superior. We’ve found Azure AD’s error messages cryptic when troubleshooting SAML issues, while Okta provides better diagnostic tools and clearer logs.
For hybrid identity scenarios, Azure AD Connect handles on-prem to cloud synchronization seamlessly. If you have Active Directory on-premises, Azure AD hybrid identity is the natural choice. Okta requires additional connectors and agents for on-prem integration, adding complexity. That said, Okta’s API is more developer-friendly if you need custom integrations beyond standard SSO.
Consider your long-term strategy. Azure AD locks you into Microsoft’s ecosystem, which is fine if that’s your direction. Okta provides more strategic flexibility for multi-vendor environments. We chose Okta specifically because we didn’t want vendor lock-in as we diversify our cloud strategy. The premium you pay for Okta is essentially insurance against future architectural constraints.
Having implemented both solutions for Aras deployments, here’s a comprehensive comparison:
Azure AD Hybrid Identity:
Excels in Microsoft-centric environments. Azure AD Connect provides seamless synchronization between on-prem Active Directory and cloud, maintaining a single identity source. For hybrid scenarios with existing AD infrastructure, this is the path of least resistance. Conditional access policies integrate well with Intune for device compliance, and the licensing is often already covered. However, the policy engine is less flexible than Okta’s, and cross-platform scenarios (AWS, GCP) require additional tooling.
Okta Multi-Cloud Support:
Designed for heterogeneous environments. Universal Directory provides a vendor-neutral identity store that integrates with any platform. The policy engine is significantly more sophisticated - you can create complex authentication flows based on user attributes, device posture, network location, and application context. This granularity is valuable for enterprises with diverse infrastructure. The API-first architecture makes custom integrations straightforward, and the admin console is more intuitive than Azure AD’s portal.
Policy Engine Capabilities:
Okta’s policy framework is superior for complex scenarios. You can define step-up authentication, contextual MFA, and dynamic group assignments with more precision than Azure AD. Azure AD’s conditional access is powerful but less granular. For Aras specifically, if you need different authentication requirements based on part classification sensitivity or user location, Okta provides better tools.
Cost Considerations:
Azure AD wins on pure cost if you have E3/E5 licensing. At 500+ users, Okta’s per-user pricing ($3-8/user/month depending on tier) adds $18k-48k annually. However, factor in hidden costs: Azure AD’s limitations might require additional tooling for advanced scenarios, while Okta’s comprehensive feature set reduces need for supplementary solutions. Total cost of ownership depends on your specific requirements beyond basic SSO.
Recommendation: Choose Azure AD if you’re heavily invested in Microsoft ecosystem and have straightforward SSO requirements. Choose Okta if you need sophisticated policy controls, multi-cloud flexibility, or anticipate complex identity scenarios. Both integrate well with Aras 13.0 via SAML 2.0.