Microsoft Entra Domain Services

Domain services for virtual machines and directory-aware applications

Microsoft Entra Domain Services provides scalable, high-performance, managed domain services such as domain-join, LDAP, Kerberos, Windows Integrated authentication, and group policy. With the click of a button, administrators can enable managed domain services for virtual machines and directory-aware applications deployed in Azure Infrastructure Services. By maintaining compatibility with Windows Server Active Directory, Microsoft Entra Domain Services allows administrators to easily migrate legacy on-premises applications to the cloud and to centralize management of all applications and all identities in Azure Active Directory.

Pricing Details

Microsoft Entra Domain Services usage is charged per hour, based on the SKU selected by the tenant owner. Azure Active Directory is available in User Forest and Resource Forest.

STANDARD ENTERPRISE PREMIUM
AAD DS Core Service
Suggested Auth Load (peak, per hour) 1 0 to 3,000 3,000 to 10,000 10,000 to 70,000
Suggested Object Count 2 0 to 25,000 25,000 to 100,000 100,000 to 500,000
Backup Frequency Every 5 Days Every 3 Days Daily 3
Resource Forest Trusts N/A 5 10
Instances
Resource Forest N/A ¥4.07/hour ¥16.282/hour
User Forest 4 ¥1.526/hour ¥4.07/hour ¥16.282/hour

1 Transactions are given as guidelines for selecting SKU and are not SLA. Directory performance may vary depending on the needs of your applications and amount of authentication requests.

2 Object count is given as a guideline for selecting SKU and not limited in the product.

3 Daily backups will be retained 7 days, with every 3rd backup being retained 30 days.

4 Each instance consists of 2 domain controllers for high availability, spread across 2 availability zones (if available in region).

Support & SLA

We provide technical support for Microsoft Entra Domain Services. Billing and subscription management support is provided at no cost.

SLA — We guarantee at least 99.9% of Microsoft Entra Domain Services requests for domain authentication of user accounts belonging to the managed domain, LDAP bind to the root DSE, or DNS lookup of records will complete successfully. Learn more about our SLA . This SLA does not apply to the Resource Forest Enterprise while in preview.