On-premises Active Directory to Microsoft Entra ID Transition — Cloud Identity Migration
On-premises Active Directory to Microsoft Entra ID Transition moves your identity management from on-premises Active Directory to a cloud-only model on Microsoft Entra ID — a real, Microsoft-supported direction, not a one-click switch. IT Partner inventories what depends on your domain controllers, maps Group Policy to Intune policy where devices are managed, transitions Windows devices to Microsoft Entra join, sequences the decommissioning of directory synchronization, and plans around the honest blockers: applications that still need Kerberos or NTLM authentication. The service is $4,950 per project, runs 3 weeks, and is managed by Roman Sotnik.
What this engagement is
Going cloud-only is a Microsoft-supported direction: Microsoft Entra ID provides sign-on, credential management, and user reporting and control without identity servers in your office. Getting there safely is the work of this service. IT Partner starts with an inventory of everything that depends on on-premises Active Directory — Group Policy, file shares, printers, VPN and Wi-Fi authentication, LDAP binds, and applications with Kerberos or NTLM dependencies — because these, not the directory itself, are what block a clean transition. From there the engagement maps Group Policy settings to Microsoft Intune policy where devices are managed, transitions in-scope Windows devices to Microsoft Entra join, validates sign-in with a pilot group, and sequences the decommissioning of Microsoft Entra Connect or Cloud Sync — a step planned deliberately, with its irreversibility cautions stated, and executed only after dependent workloads are validated. Where applications still require Kerberos, options such as Microsoft Entra Kerberos (cloud Kerberos trust) or a retained hybrid footprint are identified honestly rather than promised away. The engagement runs from planning and execution through troubleshooting and documentation.
Success criteria
What you receive
How the work unfolds
Confirm project scope, schedule, stakeholders, communication channels, administrative access, and any tenant or licensing prerequisites before technical work begins.
Review the existing on-premises Active Directory structure, users, groups, domains, device join state, Group Policy usage, identity dependencies, Microsoft Entra ID tenant configuration, and current Microsoft 365 or Azure services that rely on identity.
Identify blockers such as unsupported devices, stale user objects, duplicate UPNs, invalid domains, missing licenses, DNS issues, Kerberos/NTLM and other legacy authentication dependencies, or applications that may require additional configuration.
Define the agreed identity model, sign-in method, naming and UPN approach, administrator roles, device transition approach (Microsoft Entra join), Group Policy to Intune policy mapping where in scope, and the validation process for Microsoft Entra ID.
Transition and validate a limited pilot group, confirm sign-in, access to key Microsoft cloud services, device behavior, and user-impact items before wider rollout.
Execute the approved transition plan for in-scope users and devices, coordinate customer communications, and monitor sign-in and identity-related issues during the transition window.
Validate Microsoft Entra ID sign-in, administrative access, key user scenarios, and any agreed reporting or control checkpoints. Document exceptions and remaining actions, including the recommended sequence for decommissioning directory synchronization and on-premises domain controllers where applicable.
Provide documentation, review the completed configuration with the customer, confirm known limitations or optional follow-on work, and close the engagement.
Prerequisites
Who does what
IT Partner
- Lead project kickoff, confirm scope, and identify technical dependencies and risks.
- Provide a customized migration plan to fit your organization's needs, and support the transition from planning and execution to troubleshooting and documentation.
- Review the existing Active Directory and Microsoft Entra ID environment at the practical level required for the transition, including Group Policy and legacy authentication dependencies.
- Prepare the transition plan, validation checklist, and recommended cutover and synchronization-decommissioning sequence.
- Configure in-scope Microsoft Entra ID identity settings required for the agreed transition approach.
- Support pilot and production transition activities for in-scope users and devices.
- Troubleshoot identity-related issues encountered during the engagement within the agreed scope.
- Provide post-transition documentation and handoff guidance.
Your team
- Provide required administrative access, tenant access, domain access, and environment information in a timely manner.
- Confirm licensing availability and purchase any required Microsoft licenses not already in place.
- Identify in-scope users, devices, groups, administrators, applications, and business-critical authentication scenarios.
- Provide knowledgeable technical and business contacts for discovery, approvals, testing, and user communications.
- Approve the migration plan, pilot group, transition schedule, and any change windows.
- Communicate expected sign-in, profile, and device changes to users.
- Ensure in-scope devices are available, powered on, connected, and accessible when transition activities are scheduled.
- Participate in pilot and post-transition validation, including confirming that users can access key services.
- Maintain backups and recovery readiness for customer-managed systems, user data, and on-premises infrastructure.
- Own remediation of issues outside the agreed scope, such as application modernization, endpoint repair, cabling, network outages, or unsupported operating systems.
What's not included
Limitations & technical notes
Frequently asked questions
What is IT Partner's On-premises Active Directory to Microsoft Entra ID Transition service?
It moves identity management from on-premises Active Directory to a cloud-only model on Microsoft Entra ID (formerly Azure AD). The engagement covers planning, execution, troubleshooting, and documentation: dependency inventory, Group Policy to Intune mapping where devices are managed, Microsoft Entra join for Windows devices, pilot validation, and a sequenced plan for decommissioning directory synchronization.
Is going cloud-only actually supported, or is this a workaround?
It is a Microsoft-supported direction. Microsoft Entra ID, Intune, and Microsoft Entra join are the documented building blocks for organizations retiring on-premises Active Directory. What Microsoft does not provide is a one-click conversion — the transition succeeds or fails on the dependencies, which is why this service starts with a full inventory of what still relies on your domain controllers.
How much does the service cost, and how long does it take?
The service is $4,950 per project and runs 3 weeks, quoted fixed-price in writing before work begins. Optional add-ons — such as profile data transfer to OneDrive for Business — are scoped and priced separately.
What are the most common blockers to leaving Active Directory?
Applications that authenticate with Kerberos or NTLM, LDAP-bound systems, RADIUS/NPS-backed Wi-Fi or VPN, mapped drives and print servers, and Group Policy-dependent configurations. IT Partner identifies each during discovery and documents a recommendation: remediate, replace, use Microsoft Entra Kerberos (cloud Kerberos trust) where Microsoft supports it, or retain a reduced hybrid footprint.
What happens to Group Policy when we move to Entra ID?
Group Policy Objects do not apply to cloud-only devices, and they do not convert one-for-one. Where device management is in scope, IT Partner inventories your GPOs and maps the settings that matter to Microsoft Intune configuration and compliance policies, flagging any settings without a cloud equivalent for a decision.
Will users get new Windows profiles after connecting to Microsoft Entra ID?
Yes. When a device is joined to Microsoft Entra ID, a new user profile is created on it, and local profile content such as Desktop, Documents, and Favorites does not move automatically. Transferring that data to OneDrive for Business or SharePoint Online is available as an optional add-on.
What happens to Microsoft Entra Connect or Cloud Sync?
Directory synchronization is decommissioned as one of the final, deliberately sequenced steps — only after in-scope users, devices, and workloads are validated on Microsoft Entra ID. The sequencing matters because disabling synchronization is difficult to reverse; IT Partner plans it with the cautions stated rather than treating it as a checkbox.
Will the transition affect daily business operations?
The service is designed to minimize impact: a pilot group validates sign-in and device behavior before production waves, and transition windows are agreed in advance. Some user-visible changes are unavoidable — new device profiles, possible re-authentication, and MFA registration — and the service does not guarantee zero downtime.
What prerequisites are required before the transition starts?
An active Microsoft Entra ID tenant, appropriate Microsoft licenses for the agreed identity and device management model, administrative access to both Active Directory and Microsoft Entra ID, DNS/domain access where needed, a reasonably healthy source environment, an agreed inventory of in-scope users and devices, and a pilot group with approval of the transition plan and change windows.
Does this service decommission our domain controllers?
No — decommissioning on-premises Active Directory servers is not included in the base transition. It should happen only after every dependent workload is identified and remediated; IT Partner documents the recommended sequence, and the work can be scoped separately.
What is not included in this service?
Profile data transfer to OneDrive for Business or SharePoint Online (optional add-on), large-scale endpoint remediation or OS upgrades, application modernization and custom SSO integration, full Intune deployment and Autopilot rollout, Conditional Access and MFA architecture, mailbox/file/SharePoint migration, remediation of pre-existing Active Directory health issues, and ongoing managed support. 24/7 support, continuous monitoring, and ongoing maintenance are available as optional extra-cost add-ons through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
What happens after the transition is completed?
You receive administrator handoff documentation with configuration notes, validation results, known exceptions, and recommended next steps — including the sequence for retiring synchronization and domain controllers where applicable. Follow-on work such as Intune expansion, Conditional Access design, or decommissioning can be scoped separately.