Active Directory Minimization: Migrate and Modernize Your Estate onto Microsoft Entra ID
de Simplicity IT Inc.
Eliminate 80% of your domain controller footprint on a costed path to Microsoft Entra ID.
Built for the IT Director who is paying to run domain controllers, a VPN, and a federation service purely so that a shrinking set of legacy applications keeps working. This engagement will eliminate the majority of the on-premises identity footprint and lower the cost and attack surface it carries.
Who this is for
Organizations that have completed the easy part of cloud identity, meaning Microsoft 365 works, and are now carrying the expensive remainder: domain controllers in every site, an AD FS farm, a VPN whose main job is authentication, and a handful of applications nobody wants to touch. The IT Director owns the cost, the CISO wants the attack surface gone, and finance is usually the one who asks why there is still a datacenter.
What we deliver
- Application dependency mapping across every workload still bound to on-premises Active Directory, classified into what moves to Entra ID now, what moves with Entra Private Access or Application Proxy, what moves to Microsoft Entra Domain Services, and what genuinely has to stay.
- Wave-based migration of authentication off AD FS onto Microsoft Entra ID with password hash sync or pass-through authentication, retiring the federation farm rather than leaving it running alongside.
- Cloud Kerberos trust and Windows Hello for Business deployment so users authenticate to remaining on-premises file and print resources without a domain controller on the network path or a VPN connection.
- A domain controller and site decommissioning plan executed in stages, each with a defined rollback, plus a written statement of the residual estate and what would be required to retire it.
Outcomes our customers see
A 3,100-seat customer went from 14 domain controllers across 9 sites to 2 in a single datacenter, an 86 percent reduction, over 8 months. AD FS retirement removed 6 servers and 4 public certificates, and closed 3 audit findings that had been carried for over 700 days. Cloud Kerberos trust removed the VPN authentication dependency for 2,400 remote users, cutting VPN concurrent license cost by 61 percent.
How this compares
Most identity modernization stalls at the application dependency question, because nobody can produce the list and nobody will sign off retiring a domain controller without it. This engagement starts there, with actual dependency evidence rather than a survey, and every wave is sized so it can be approved on its own merits. Compared with a rip-and-replace proposal, the deliverable is a staged reduction where each stage pays for itself in removed infrastructure and closed audit findings.
Architecture and Microsoft alignment
The target state is Microsoft Entra ID as the primary directory with Entra ID joined devices, Windows Hello for Business over Cloud Kerberos trust for residual on-premises resource access, Microsoft Entra Private Access replacing VPN-based application access, and Microsoft Entra Domain Services where a legacy application genuinely requires LDAP or classic domain join. Microsoft Entra Connect Cloud Sync replaces the legacy sync agent where the topology allows. AD FS is retired in favor of Entra ID native authentication. Aligned to the Microsoft solution plays Migrate and Modernize Your Estate and Secure AI Productivity.
Plans
Plans, prices, and full scope per plan are on the Plans tab of this listing.
Prerequisites
Microsoft Entra ID P1 as a floor, with P2 recommended for the governance and risk capabilities used during the waves. An accurate current-state inventory of domain-joined servers and applications, or agreement to fund the discovery phase that produces one. Global Administrator and Domain Administrator consent, and a named application owner per business unit for the dependency sign-offs.
Limitations
Applications that require classic Kerberos or NTLM against a real domain controller and cannot use Entra Domain Services will keep some on-premises footprint; this engagement identifies and isolates them rather than pretending otherwise. Line-of-business application remediation or replacement is out of scope. Certificate services migration is a separate engagement where an internal PKI is in use.
How to buy
Buy through the Azure portal, using Get it in Azure portal on this listing, so the purchase is billed through your existing Microsoft agreement. Private offers on request.
Next step
Get it now in the Azure portal, or request a private offer if the scope or the price needs adjusting first.