Can You Retire On-Premises Active Directory? The Cloud-Only Path with Entra ID and Intune, and What Breaks Along the Way
The question usually arrives after the last Exchange server is gone and the file shares have moved to SharePoint: do we still need the two domain controllers in the closet? Sometimes the answer is no. More often it is "not yet, and here is the list." This article is the readiness test we run for 20–500-seat organizations, the device change that surprises people, what replaces what, when Entra Domain Services is the halfway house, and the checklist for demoting the last domain controller.
What cloud-only means, and the honest readiness test
Cloud-only means users, groups and devices exist only in Entra ID, devices are Entra joined and managed by Intune, there is no Entra Connect server, and nothing authenticates with Kerberos, NTLM or LDAP against your domain. Anything that still does has to be replaced, rehosted, or given a managed domain.
The readiness test is a dependency list:
- Line-of-business applications that bind to LDAP or use Windows integrated authentication
- SQL Server instances using Windows authentication and domain service accounts
- File servers with NTFS permissions granted to AD groups
- Print servers, and multifunction devices that scan to an SMB share
- NPS or RADIUS for Wi-Fi and VPN, and AD CS certificates for 802.1X
- Hybrid joined Windows devices and the Group Policy Objects that still apply to them
- Service accounts and scheduled tasks on servers
- Entra Connect itself, and any HR system that writes into AD
If every line has a named replacement, you can go cloud-only. If two or three lines remain, you are choosing between Entra Domain Services and one small domain controller.
Finding the dependencies you forgot
Let the domain controllers tell you. Enable LDAP bind logging on each domain controller and collect the client addresses for a month; the copier and the badge system will show up. In the security log, Kerberos service ticket events (4769) list which service principal names are still requested, and network logon events (4624, logon type 3) show which service accounts still authenticate to which servers.
For devices, export the Intune device list with its join type column. For policy, run Group Policy analytics and sort the results as described in Group Policy to Intune: what translates and what does not. The output of this step is a spreadsheet with an owner, a replacement and a date against every dependency.
Devices: hybrid joined to Entra joined means re-provisioning
Microsoft's Autopilot documentation (May 2025) recommends deploying new devices as cloud-native with Microsoft Entra join and says hybrid join for new devices is not recommended, including through Autopilot. Existing hybrid joined devices do not flip over: the profile setting "Convert all targeted devices to Autopilot" registers them with the service but, in Microsoft's words (June 2025), does not convert a hybrid joined device into an Entra joined device. The path is a reset or reimage and Autopilot user-driven provisioning.
The practical plan: turn on OneDrive Known Folder Move first so Desktop and Documents survive; inventory the apps per device; point Windows LAPS at Entra ID, because the backup directory has to match the join type; then reset in batches of ten to twenty devices a day. Pair the work with the Windows 11 refresh if you are still on Windows 10, since ESU year one ends on 13 October 2026. Our Device migration automation for Windows ($6 per seat + $4,500 tenant fee, 2 weeks) scripts the state capture, reset and re-enrollment.
An Entra joined device can still open an on-premises file share while the user is synced from AD and the device has line of sight to a domain controller (Microsoft, June 2025). What stops working is anything that authenticates the computer rather than the user, because the device has no computer object in AD.
Files, printers, Wi-Fi and apps: what replaces what
Files. Team files go to SharePoint and personal files to OneDrive. Where an SMB share has to stay, Azure Files with Microsoft Entra Kerberos authentication serves hybrid and cloud-only identities without a domain controller, with one identity source per storage account (Microsoft, September 2026). Azure Files Implementation is $3,500 per project.
Printers. Universal Print replaces the print server. Every printer is registered in the service, Intune deploys them to Windows devices, and each user needs a Universal Print license (Microsoft, May 2026), which several Microsoft 365 plans include.
Wi-Fi and VPN. Certificate-based Wi-Fi needs a certificate authority and a RADIUS server, and NPS needs AD. The cloud pattern is Intune-issued device certificates, through SCEP with a connector or Microsoft Cloud PKI (an Intune Suite feature), plus a cloud RADIUS service. For remote access, Microsoft Entra Private Access ($3,950 per project) removes the VPN and its NPS dependency. Scanners move to scan-to-email or scan-to-SharePoint.
SQL Server and line-of-business apps. Move to SQL authentication or, on Azure SQL, to Entra authentication. If the vendor insists on a domain, that one application decides between Entra Domain Services and a lone domain controller.
Entra Domain Services: the halfway house
Microsoft Entra Domain Services is a managed domain: two Windows Server domain controllers deployed into an Azure virtual network you choose, providing domain join, Group Policy, LDAP and Kerberos/NTLM authentication (Microsoft, February 2026). Synchronization is one way from Entra ID, and cloud-only users must change their password once so that the Kerberos and NTLM hashes exist (Microsoft, February 2025). You cannot extend the schema or be a domain administrator, and you manage it through a management VM. It comes in Standard, Enterprise and Premium tiers sized by object count, priced per managed domain (Microsoft, June 2026).
Where it fits: a legacy application lifted into Azure VMs that needs LDAP or a domain join. Where it does not fit: office workstations. It is a service for servers in Azure, not a replacement domain for a branch office. If the remaining dependency is a single on-premises box, a small domain controller moved to new hardware or an Azure VM (Domain Services and Active Directory Roles Migration, $900 per project) is often simpler, and it can be retired later.
The last domain controller checklist
- Password hash synchronization is on and has been the sign-in method for weeks.
- Every workstation is Entra joined and Intune compliant; Group Policy is unlinked.
- DHCP, DNS, NPS, AD CS, file and print have moved or been retired.
- Freeze changes. Export users, groups, memberships and GPOs, take a system-state backup of one domain controller, and keep it for at least a year.
- Turn off directory synchronization in Entra ID so synced users become cloud-managed. Microsoft documents a waiting period before the change completes; check the current steps on Microsoft Learn first.
- Uninstall Entra Connect and remove its synchronization service account from the tenant.
- Demote the domain controllers, the last one removing the forest, then wipe the servers.
- Clean up what pointed at AD: Conditional Access rules that required hybrid join, the Intune Connector for Active Directory, DNS records, firewall rules.
- Watch the help desk queue for two weeks; anything that still tried LDAP will fail loudly.
The clean tenant baseline and Zero Trust in production describe the end state.
Licensing and what it costs
Nothing here requires a new Microsoft product for a tenant on Microsoft 365 Business Premium or Microsoft 365 E3, because both include Entra ID P1 (Conditional Access) and Intune Plan 1. Microsoft list prices, September 2026 price list, annual commitment: Microsoft 365 Business Premium $264.00 per user per year ($22.00 per month equivalent); Microsoft Entra ID P1 on its own $84.00 per year ($7.00 per month). Entra Domain Services and Azure Files are Azure consumption, billed to you by Microsoft.
Our On-premises Active Directory to Microsoft Entra ID Transition ($4,950 per project, 3 weeks) runs the dependency inventory, the sync and sign-in changes, the decommission checklist and the cleanup. If your domain controllers run Windows Server 2016, support ends on 12 January 2027, which is the usual forcing function.
Frequently asked questions
Can I get rid of Active Directory completely?
Yes, if no application, server or network service still needs Kerberos, NTLM or LDAP against your domain. The usual holdouts are a line-of-business app, a SQL Server, and Wi-Fi authentication.
What happens to hybrid joined computers when I demote the domain controller?
They keep working with cached credentials but lose Group Policy, domain password changes and computer account trust. Re-provision them as Entra joined before the demotion.
Do I lose file server permissions when I retire AD?
Files moved to SharePoint or OneDrive get permissions rebuilt against Microsoft 365 groups during migration. Files moved to Azure Files with Entra Kerberos keep Windows ACLs on Entra identities.
How long does it take to decommission Active Directory?
Three weeks for the identity work once the dependency list is clean. The dependency list and the device re-provisioning set the real timeline: two to four months for 100 to 300 devices.
Sources
- Microsoft Learn source files on GitHub (MicrosoftDocs/memdocs), opened: "Enrollment for Microsoft Entra hybrid joined devices" (Autopilot), ms.date 05/29/2025; "Windows Autopilot for existing devices", ms.date 06/13/2025; "Overview of Windows LAPS with Microsoft Intune", ms.date 05/29/2025; "Configure Universal Print policy", ms.date 05/13/2026; "Microsoft Cloud PKI fundamentals", ms.date 12/06/2024
- Microsoft Learn source files on GitHub (MicrosoftDocs/entra-docs), opened: "How SSO to on-premises resources works on Microsoft Entra joined devices", ms.date 06/27/2025; Entra Domain Services "Overview", ms.date 02/16/2026, "Management concepts", ms.date 06/22/2026, "How synchronization works", ms.date 02/19/2025, and "Compare Microsoft directory-based services", ms.date 06/30/2025
- Microsoft Learn source file on GitHub (MicrosoftDocs/azure-docs), opened: "Azure Files identity-based authentication overview", ms.date 09/18/2026
- Microsoft Learn: Universal Print service description and the directory synchronization turn-off procedure, as reported by search results on 27 September 2026; not opened; verify on Microsoft Learn
- IT Partner blog: content/blog/new/group-policy-to-intune-migration-what-translates-and-what-does-not.json; clean-microsoft-365-tenant-2026-baseline.json; microsoft-365-zero-trust-production-controls.json; the Windows 10 ESU and Windows Server 2016 end-of-support articles
- IT Partner pages: content/services/ITPWW360MIGOT, ITPWW540MIGOT, ITPWW390MIGOT and ITPWW500IMPOT; Microsoft 365 Business Premium (CFQ7TTC0LCHC); Microsoft Entra ID P1 (CFQ7TTC0LFLS)
- IT Partner engineering notes, September 2026
| Dependency | Cloud replacement | Keep a domain (or Entra Domain Services) if |
|---|---|---|
| Windows devices and Group Policy | Entra join, Intune compliance and settings catalog | Devices cannot be re-provisioned soon |
| File shares | SharePoint, OneDrive, Azure Files with Entra Kerberos | An application writes to an SMB path with a machine account |
| Print server | Universal Print through Intune | Printers cannot be registered |
| Wi-Fi and VPN with NPS | Intune certificates plus a cloud RADIUS service; Entra Private Access | 802.1X with NPS must stay |
| AD CS | Cloud PKI (Intune Suite) or SCEP with a connector | Servers and appliances need certificates from the internal CA |
| SQL Server with Windows authentication | SQL authentication, or Azure SQL with Entra authentication | The vendor supports Windows authentication only |
| LDAP-bound line-of-business app | Vendor's Entra ID or SAML option, or rehost in Azure | The app has no cloud identity option |
| Service accounts and scheduled tasks | Managed identities, service principals, Intune remediations | Jobs run on domain-joined servers that are staying |
| Entra Connect | Turn off directory synchronization | Any line above keeps a domain |
Key takeaways
- Cloud-only means no Kerberos, NTLM or LDAP against your domain; the readiness test is a dependency list with a replacement for each line.
- Hybrid joined devices do not convert in place; they are reset and re-provisioned with Autopilot, so plan it as a device project.
- Files, printers, Wi-Fi and SQL Server each have a cloud pattern; the holdout is usually one line-of-business app that insists on a domain.
- Entra Domain Services is a managed domain for servers in Azure, with one-way sync and no domain admin; it is not a replacement domain for office workstations.
- Demote the last domain controller only after sign-in, devices, DHCP, DNS and every service have moved, with an export and a system-state backup kept for a year.
If you want the dependency inventory and the decommission run by people who have done it before, On-premises Active Directory to Microsoft Entra ID Transition is $4,950 per project over 3 weeks, fixed price, paid after approval. Device migration automation for Windows ($6 per seat + $4,500 tenant fee, 2 weeks) handles the hybrid-to-Entra-join re-provisioning, and Domain Services and Active Directory Roles Migration ($900 per project, 3 days) covers the case where one domain controller has to stay and move. Book a call with your device count and the list of servers still in the closet.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.