Identity & Active DirectoryWide moat

Microsoft (MSFT) — moat facet

Whoever answers 'who may log in to what' owns the enterprise's nervous system — and that answer is Entra.

Active Directory, and its cloud successor Entra, is the quiet keystone1 of Microsoft's enterprise lock-in, because it answers the single most fundamental question a company's computing must answer: who is this person, and what are they allowed to touch? Once an organization's entire notion of identity — every employee, every group, every permission — lives inside Microsoft's directory, that system becomes the thing every other application must consult before it does anything at all. Owning the login is very nearly owning the enterprise.

Microsoft 365 Commercial, FY2026: what grew and by how much (%)+17%Cloud revenue+16%Total revenue+13%On-premises products+6%Paid seatsForm 10-K FY2026 — revenue per user, not user count, carried the year
Six per cent more people paid sixteen per cent more money. Owning the login is what lets Microsoft charge the same directory more each year.

The reason this binds so tightly is that identity is not a feature bolted onto the software; it is the foundation the rest of the building sits on. The email checks the directory, the file server checks the directory, the thousand line-of-business applications a large company runs each check the directory to decide who may see what. Rip out Microsoft's identity system and you have not swapped one component — you have pulled the foundation out from under every application at once.

Microsoft has extended this from the office into the cloud with real cunning. Entra became the single sign-on that lets an employee log in once and reach everything — Microsoft's own products and a great many third-party ones besides. Every application that trusts Microsoft to vouch for the user is one more strand tying the enterprise to Microsoft, and single sign-on, sold as a convenience, is also one of the most effective lock-in mechanisms ever devised.

For a long-term owner the beauty of identity is that it is invisible and indispensable at once. Employees never think about it, executives rarely see it as a distinct line on an invoice, and yet nothing works without it. A moat the customer cannot even see is a moat the customer never thinks to attack — which is exactly why identity is the deepest and quietest thread in the whole knot.

Moat trajectory: Widening

Widening. Entra ID (the old Active Directory) has become the identity backbone that thousands of outside SaaS apps federate into, and identity is the hardest thing in all of IT to rip out — touch it and everything breaks. The AI era makes it deeper still: agents and Copilots need to know who a user is and what they're allowed to see, and that authorization lives in Entra. Every new app and every AI agent that trusts Microsoft for identity widens a moat that was already among the company's stickiest.

The number that tests this moat
Reported
Microsoft 365 Commercial seat growth
6% in FY2026, on 16% revenue growth

Identity is sold per seat, so seats measure how many people are inside the directory and revenue measures what each is worth. Six per cent more people paying sixteen per cent more money is the signature of a franchise growing on price rather than reach. Seat growth turning negative would mean the directory itself had started to leak.

Source: Microsoft Form 10-K, FY2026 ↗
⚠ Threats to the moat
References
  1. ReportedEntra ID is the single sign-on across Microsoft's products and thousands of third-party apps.
    Microsoft — Active Directory / Entra ID (enterprise identity & single sign-on; capable tiers included in Microsoft 365 plans) — Current product documentation · publ. 2023–2026 · source ↗
Sources
Generated September 22, 2026