Skip to content

AWS vs. Azure: which cloud is better for Microsoft 365 and enterprise software integration?

The Entra ID tenant behind Microsoft 365 can sign users in to Azure and AWS, though each workload still needs its own setup

Comparison 8 min Updated Aug 13, 2026

Azure is the simpler home for Windows Server licenses covered by Software Assurance, because Azure Hybrid Benefit accepts them whenever they were bought. AWS takes customer-owned Windows Server licenses only on dedicated hardware and only under the older terms described below, according to its Windows FAQ. AWS fits a company that is content to rent Windows by the hour, or whose licenses worth moving are mostly SQL Server under Software Assurance, which both clouds accept.

The Entra ID tenant behind Microsoft 365 can sign people in to AWS through IAM Identity Center as well as to Azure. On both clouds, each workload still needs its own setup before that tenant controls who reaches it.

We reviewed Microsoft and AWS documentation, Microsoft's licensing FAQ and US list prices as of October 1, 2026. Your agreement's terms can differ from these pages, so confirm your license position with your reseller or Microsoft account team, as Microsoft's License Mobility page advises, before a migration plan depends on it.

Does Microsoft 365 sign-in carry over to Azure and AWS workloads?

Access path Azure AWS
Cloud console and account access Entra accounts sign in directly; Conditional Access can target the Windows Azure Service Management API app (Microsoft) Entra signs users in over SAML and provisions them over SCIM; access comes from permission sets assigned in IAM Identity Center (AWS)
Server sign-in Entra login on supported Windows and Linux VMs after setup (Windows, Linux) Domain join to AWS Managed Microsoft AD, which can trust your existing Active Directory (AWS)
Apps that need LDAP or Kerberos Entra Domain Services, synced one way from Entra ID (Microsoft) AWS Managed Microsoft AD as a resource forest, or its Hybrid Edition extending your own AD (AWS)

An Azure VM doesn't accept Microsoft 365 credentials until someone sets it up. Microsoft's Windows VM guide requires a system-assigned managed identity, the Entra sign-in extension and one of two VM login roles, since Owner or Contributor alone grants no sign-in. The VM then becomes Entra joined and can't also join an on-premises Active Directory domain, so servers you lift and shift with their domain membership keep using AD credentials.

A Conditional Access policy scoped to SharePoint doesn't cover Azure SQL until it includes the Azure SQL Database app or all resources. Microsoft's Azure SQL guide adds that these policies need at least Entra ID P1 and apply to users, not to service principals or managed identities. For Windows VMs, Microsoft's VM guide names a sign-in app to target with Conditional Access. The same guide also says Conditional Access isn't supported for Windows Server with the Entra sign-in extension, so test the policy before you count on it.

On AWS, Entra stays the identity provider and IAM Identity Center keeps a provisioned copy of your users and groups. AWS's setup guide notes two gaps in that copy: Entra's provisioning service doesn't pick up members of nested groups, and an attribute removed in Entra stays on the IAM Identity Center user. Because IAM Identity Center is added as an Entra gallery application, Conditional Access can target it like any other registered app.

Microsoft's identity model guide separates cloud-only accounts, which live in Entra ID with no sync tools, from hybrid accounts that originate in on-premises Active Directory and need Entra Connect. In the hybrid case, that sync stays in place whichever cloud you choose. The guide treats federation to a separate identity provider as an optional model, typically for sign-in requirements Entra ID doesn't support natively, and AWS's Entra setup doesn't call for it.

Where can Windows Server licenses you've bought run?

Windows Server has no License Mobility rights, so AWS can't run customer-owned Windows Server licenses on shared EC2 instances, according to its prescriptive guidance. Microsoft's FAQ says licenses obtained from October 1, 2019 onward can't run on dedicated cloud hardware from any Listed Provider, a group that includes AWS, even when Software Assurance covers them. Azure Dedicated Host is exempt through Azure Hybrid Benefit, and the enrollment true-ups described below are exempt as well. Workloads under those newer licenses run on AWS only as license-included instances, where AWS supplies Windows and bills it by the hour.

Perpetual Windows Server licenses bought before that cutoff, or picked up as a true-up inside an Enterprise Enrollment that took effect earlier, can go onto EC2 Dedicated Hosts without Software Assurance, according to the same AWS guidance. The deployed version must also predate that date, which makes Windows Server 2019 the last eligible release. Microsoft's FAQ adds that upgrading an older license to a release that came out after the cutoff ends that treatment for the upgraded deployment. A license assigned to a server under these terms also can't move to another within 90 days, because the reassignment rule still applies.

Azure Hybrid Benefit accepts Windows Server licenses from either side of that date. It requires at least eight core licenses per VM, even a four-core one, and when coverage lapses you must renew it, turn the benefit off or remove those VMs, per Microsoft's Hybrid Benefit page.

What does a Windows VM cost on each cloud?

On October 1, 2026, the license-included Windows rate was the same on both clouds for the comparable sizes we priced. An on-demand m6i.xlarge in AWS US East (N. Virginia) listed at $0.376 an hour with Windows and $0.192 with Linux, per EC2 pricing. A pay-as-you-go D4s v5 in Azure East US listed at the same two rates, per Azure's Windows VM pricing. Both sizes have 4 vCPUs and 16 GiB of RAM (D4s v5 specs), though they run on different hardware.

The $0.184 hourly gap, $134.32 over a 730-hour month, is the Windows license charge on each bill. Hybrid Benefit bills an Azure VM at the Linux rate, so an Azure customer with eligible licenses stops paying that charge on future VM hours. You still pay separately for the Software Assurance coverage or subscription behind those licenses, so the gap is not a net saving.

On shared-tenancy EC2, that charge stays on Windows Server instances unless Microsoft has approved custom terms for you, according to AWS's Windows FAQ. Bringing pre-2019 licenses onto Dedicated Hosts changes the bill to a per-host rate that you pay however many instances the host runs, so the result depends on how fully you pack each host. Our pricing and TCO comparison adds reserved and committed-use rates for Linux VMs on each cloud.

How does SQL Server licensing differ between the two clouds?

SQL Server licenses with Software Assurance in force can move to either cloud. On AWS, License Mobility lets them run on default-tenancy EC2, and Microsoft's License Mobility page asks for a License Verification Form within 10 days of deploying. Amazon RDS for SQL Server also takes your own licenses through bring your own media for Enterprise and Standard editions of SQL Server 2019, 2022 and 2025. You upload the installation media yourself, still pay Windows OS fees and remain responsible for license compliance.

On Azure, Hybrid Benefit covers Azure SQL Managed Instance and Azure SQL Database on the provisioned vCore tier, but not the DTU model or serverless tier, according to Microsoft's SQL Hybrid Benefit page. One Enterprise Edition core on premises covers four vCores of the General Purpose tier, a conversion that License Mobility doesn't offer. RDS bring your own media has its own limits, with no SSAS or SSRS, and major version upgrades require a new instance.

Which rules cover running the same license in two places during a migration?

Windows Server Standard licenses can run on premises and in Azure simultaneously once, for a maximum of 180 days, under Microsoft's Hybrid Benefit rules. Datacenter licenses assigned to Azure VMs can run in both places indefinitely, while Datacenter licenses placed on Azure Dedicated Host get 180 days from allocation. SQL Server licenses applied to Azure SQL Database or Managed Instance also get 180 days, after which they count only in Azure (SQL page).

The AWS licensing pages we reviewed describe no dual-use period for EC2. AWS's License Manager guide describes running migrated instances on AWS-provided licenses during cutover and switching them to your own licenses afterward without redeploying. Its conversion prerequisites narrow that path: a Windows instance qualifies only if it was first launched from your own VM image, not an Amazon-provided AMI, and SQL Server must have been installed from your own media. Bringing the Windows Server license itself still depends on the pre-2019 dedicated-hardware terms above.

How do Dynamics 365 and Microsoft 365 data reach each cloud?

Microsoft's built-in links for analyzing Dynamics 365 data point to Microsoft services. Azure Synapse Link for Dataverse copies tables with change tracking turned on into an Azure Data Lake Storage Gen2 account in the same Entra tenant. Link to Fabric exposes the data in OneLake through shortcuts, with no storage account of your own, while the replica stays in Dataverse and counts against its storage. For bulk Microsoft 365 data, Graph Data Connect delivers datasets through Fabric, Azure Synapse or Azure Data Factory and bills its consumption to an Azure subscription.

On AWS, Amazon AppFlow has connectors that can read from Dynamics 365, SharePoint Online and Teams but can't write to any of them. The Dynamics 365 connector calls your instance's CRM web API and needs an app registration in your Entra tenant with a client secret, admin consent and the API permissions AWS lists. An AWS-centered data team can pull Microsoft data in this way, while flows that write back into Dynamics 365 need a different integration that we didn't review.