First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/On-premises Active Directory to Microsoft Entra ID Transition
Migration

On-premises Active Directory to Microsoft Entra ID Transition — Cloud Identity Migration

On-premises Active Directory to Microsoft Entra ID Transition moves your identity management from on-premises Active Directory to a cloud-only model on Microsoft Entra ID — a real, Microsoft-supported direction, not a one-click switch. IT Partner inventories what depends on your domain controllers, maps Group Policy to Intune policy where devices are managed, transitions Windows devices to Microsoft Entra join, sequences the decommissioning of directory synchronization, and plans around the honest blockers: applications that still need Kerberos or NTLM authentication. The service is $4,950 per project, runs 3 weeks, and is managed by Roman Sotnik.

Timeline 3 weeksService owner Roman SotnikMicrosoft Azure

What this engagement is

Going cloud-only is a Microsoft-supported direction: Microsoft Entra ID provides sign-on, credential management, and user reporting and control without identity servers in your office. Getting there safely is the work of this service. IT Partner starts with an inventory of everything that depends on on-premises Active Directory — Group Policy, file shares, printers, VPN and Wi-Fi authentication, LDAP binds, and applications with Kerberos or NTLM dependencies — because these, not the directory itself, are what block a clean transition. From there the engagement maps Group Policy settings to Microsoft Intune policy where devices are managed, transitions in-scope Windows devices to Microsoft Entra join, validates sign-in with a pilot group, and sequences the decommissioning of Microsoft Entra Connect or Cloud Sync — a step planned deliberately, with its irreversibility cautions stated, and executed only after dependent workloads are validated. Where applications still require Kerberos, options such as Microsoft Entra Kerberos (cloud Kerberos trust) or a retained hybrid footprint are identified honestly rather than promised away. The engagement runs from planning and execution through troubleshooting and documentation.

Success criteria

01Identity management for in-scope users is transitioned from on-premises Active Directory to Microsoft Entra ID with minimal impact on daily operations.
02The Microsoft Entra ID tenant is prepared and configured for the agreed identity transition approach.
03In-scope users, groups, and identity objects are reviewed, prepared, and transitioned according to the approved migration plan.
04In-scope devices are connected to Microsoft Entra ID or otherwise prepared for the agreed end-state identity model, subject to device readiness and licensing.
05A pilot or validation group successfully signs in using Microsoft Entra ID before broader transition activities proceed.
06Dependencies that cannot move to a cloud-only model — such as Kerberos/NTLM-dependent applications — are identified, with a documented recommendation for each.
07Administrative handoff documentation is delivered, including configuration notes and known post-migration actions.
08Any exceptions, unresolved dependencies, or out-of-scope remediation items are documented for customer review.

What you receive

Customized migration plan to fit the organization's needs, including execution and troubleshooting support through the transition.
Discovery summary covering current Active Directory, Microsoft Entra ID tenant readiness, identity dependencies (including Group Policy, legacy authentication, and application dependencies), and high-level migration risks.
Target-state identity configuration plan for the agreed Microsoft Entra ID transition model, including the Group Policy to Intune policy mapping approach where device management is in scope.
Pre-migration readiness checklist and cutover plan, including the directory synchronization decommissioning sequence where applicable.
Pilot validation results or transition validation checklist.
Post-transition administrator handoff notes, including key configuration settings and recommended next steps.

How the work unfolds

Kickoff and access confirmation

Confirm project scope, schedule, stakeholders, communication channels, administrative access, and any tenant or licensing prerequisites before technical work begins.

Environment discovery

Review the existing on-premises Active Directory structure, users, groups, domains, device join state, Group Policy usage, identity dependencies, Microsoft Entra ID tenant configuration, and current Microsoft 365 or Azure services that rely on identity.

Readiness and remediation planning

Identify blockers such as unsupported devices, stale user objects, duplicate UPNs, invalid domains, missing licenses, DNS issues, Kerberos/NTLM and other legacy authentication dependencies, or applications that may require additional configuration.

Target-state design

Define the agreed identity model, sign-in method, naming and UPN approach, administrator roles, device transition approach (Microsoft Entra join), Group Policy to Intune policy mapping where in scope, and the validation process for Microsoft Entra ID.

Pilot transition

Transition and validate a limited pilot group, confirm sign-in, access to key Microsoft cloud services, device behavior, and user-impact items before wider rollout.

Production transition

Execute the approved transition plan for in-scope users and devices, coordinate customer communications, and monitor sign-in and identity-related issues during the transition window.

Post-transition validation

Validate Microsoft Entra ID sign-in, administrative access, key user scenarios, and any agreed reporting or control checkpoints. Document exceptions and remaining actions, including the recommended sequence for decommissioning directory synchronization and on-premises domain controllers where applicable.

Handoff and closeout

Provide documentation, review the completed configuration with the customer, confirm known limitations or optional follow-on work, and close the engagement.

Prerequisites

An active Microsoft Entra ID tenant is available, or the customer approves use or creation of the appropriate tenant before migration activities begin.
Required Microsoft licensing is available for all in-scope users and devices. Licensing may vary depending on the agreed identity, device management, security, and single sign-on requirements.
Customer provides Global Administrator or equivalent delegated administrative access to Microsoft Entra ID and Microsoft 365 services needed for the engagement.
Customer provides appropriate administrative access to the existing on-premises Active Directory environment, including domain information and access to required management tools.
Public DNS ownership and access are available for any domains that need to be verified or updated in Microsoft Entra ID or Microsoft 365.
The on-premises Active Directory environment is healthy enough for transition activities, with no unresolved critical domain controller, DNS, replication, or account consistency issues that would block the project.
In-scope users, groups, devices, and administrative accounts are identified before execution.
Customer provides a pilot user group and agrees to participate in validation testing.
In-scope Windows devices meet Microsoft-supported requirements for the agreed Microsoft Entra ID join or registration approach.
Customer confirms any applications, line-of-business systems, VPNs, file shares, printers, or authentication dependencies that currently rely on on-premises Active Directory.
Customer has a communication plan for user impact, including the note that connecting users to Entra ID creates new device profiles unless profile migration is separately scoped.
Backups, rollback expectations, and change windows for customer-managed infrastructure are confirmed before production transition.

Who does what

IT Partner

  • Lead project kickoff, confirm scope, and identify technical dependencies and risks.
  • Provide a customized migration plan to fit your organization's needs, and support the transition from planning and execution to troubleshooting and documentation.
  • Review the existing Active Directory and Microsoft Entra ID environment at the practical level required for the transition, including Group Policy and legacy authentication dependencies.
  • Prepare the transition plan, validation checklist, and recommended cutover and synchronization-decommissioning sequence.
  • Configure in-scope Microsoft Entra ID identity settings required for the agreed transition approach.
  • Support pilot and production transition activities for in-scope users and devices.
  • Troubleshoot identity-related issues encountered during the engagement within the agreed scope.
  • Provide post-transition documentation and handoff guidance.

Your team

  • Provide required administrative access, tenant access, domain access, and environment information in a timely manner.
  • Confirm licensing availability and purchase any required Microsoft licenses not already in place.
  • Identify in-scope users, devices, groups, administrators, applications, and business-critical authentication scenarios.
  • Provide knowledgeable technical and business contacts for discovery, approvals, testing, and user communications.
  • Approve the migration plan, pilot group, transition schedule, and any change windows.
  • Communicate expected sign-in, profile, and device changes to users.
  • Ensure in-scope devices are available, powered on, connected, and accessible when transition activities are scheduled.
  • Participate in pilot and post-transition validation, including confirming that users can access key services.
  • Maintain backups and recovery readiness for customer-managed systems, user data, and on-premises infrastructure.
  • Own remediation of issues outside the agreed scope, such as application modernization, endpoint repair, cabling, network outages, or unsupported operating systems.

What's not included

Data transfer from existing profiles, such as Documents, Desktop, and Favorites, to OneDrive for Business or SharePoint Online is available as an optional add-on.
User profile migration, profile merging, folder redirection cleanup, or local data copy from old Windows profiles is not included unless purchased as an add-on.
Large-scale endpoint remediation, operating system upgrades, device replacement, hardware troubleshooting, or repair of unhealthy Windows installations is not included.
Remediation of pre-existing Active Directory health issues, domain controller failures, DNS failures, replication failures, or unsupported domain configurations may require separate work.
Application modernization, custom SSO integration for third-party or line-of-business applications, SAML/OIDC application configuration, or application code changes are not included unless explicitly scoped.
Full Microsoft Intune deployment, endpoint compliance policy design, software packaging, Autopilot deployment, and mobile device management rollout are not included unless separately scoped.
Conditional Access architecture, MFA rollout, identity governance, Privileged Identity Management, access reviews, and advanced security hardening are not included unless explicitly added to the project.
Mailbox migration, file server migration, SharePoint migration, Teams migration, OneDrive migration, and broader Microsoft 365 tenant migration are not included in the base identity transition service.
Ongoing managed support, 24/7 support, continuous monitoring, ongoing maintenance, help desk support, user training sessions, or post-project administration are not included in the base service. 24/7 support, continuous monitoring, and ongoing maintenance are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
Microsoft licensing costs, third-party tools, backup tools, identity migration software, and infrastructure costs are not included in the listed service price unless otherwise stated in a signed proposal.

Limitations & technical notes

!When users connect to Entra ID, a new user profile is created on their devices. Local Windows profile data does not automatically move into the new profile; data transfer to OneDrive for Business or SharePoint Online is an optional add-on.
!Microsoft Entra ID is not a direct one-for-one replacement for every on-premises Active Directory feature. Some workloads may still require on-premises Active Directory, Microsoft Entra Domain Services, application changes, or a hybrid identity design.
!Applications with Kerberos or NTLM dependencies are the most common blockers to a fully cloud-only model. Options such as Microsoft Entra Kerberos (cloud Kerberos trust) apply only where Microsoft supports them; remaining dependencies are documented with recommendations.
!Legacy applications, mapped drives, printers, VPN clients, Wi-Fi authentication, RADIUS/NPS, LDAP binds, and Group Policy-dependent configurations may require additional remediation or alternate designs. Group Policy settings do not convert one-for-one to Intune policy.
!Disabling directory synchronization (Microsoft Entra Connect or Cloud Sync) is a sequenced step that is difficult to reverse; it is planned deliberately and executed only after dependent workloads are validated.
!Microsoft Entra join, registration, synchronization, Conditional Access, and security capabilities depend on Microsoft licensing, device operating system support, network connectivity, and tenant configuration.
!A low-impact transition depends on customer readiness, user availability, device availability, accurate inventory, and timely approvals. The service does not guarantee zero downtime.
!Removing or decommissioning on-premises Active Directory servers should only occur after all dependent workloads are identified and remediated. Decommissioning is not included in the base transition unless explicitly scoped.
!Some identity changes may require user sign-out/sign-in, password reset, device reboot, profile recreation, or reconfiguration of cached credentials.

Frequently asked questions

What is IT Partner's On-premises Active Directory to Microsoft Entra ID Transition service?

It moves identity management from on-premises Active Directory to a cloud-only model on Microsoft Entra ID (formerly Azure AD). The engagement covers planning, execution, troubleshooting, and documentation: dependency inventory, Group Policy to Intune mapping where devices are managed, Microsoft Entra join for Windows devices, pilot validation, and a sequenced plan for decommissioning directory synchronization.

Is going cloud-only actually supported, or is this a workaround?

It is a Microsoft-supported direction. Microsoft Entra ID, Intune, and Microsoft Entra join are the documented building blocks for organizations retiring on-premises Active Directory. What Microsoft does not provide is a one-click conversion — the transition succeeds or fails on the dependencies, which is why this service starts with a full inventory of what still relies on your domain controllers.

How much does the service cost, and how long does it take?

The service is $4,950 per project and runs 3 weeks, quoted fixed-price in writing before work begins. Optional add-ons — such as profile data transfer to OneDrive for Business — are scoped and priced separately.

What are the most common blockers to leaving Active Directory?

Applications that authenticate with Kerberos or NTLM, LDAP-bound systems, RADIUS/NPS-backed Wi-Fi or VPN, mapped drives and print servers, and Group Policy-dependent configurations. IT Partner identifies each during discovery and documents a recommendation: remediate, replace, use Microsoft Entra Kerberos (cloud Kerberos trust) where Microsoft supports it, or retain a reduced hybrid footprint.

What happens to Group Policy when we move to Entra ID?

Group Policy Objects do not apply to cloud-only devices, and they do not convert one-for-one. Where device management is in scope, IT Partner inventories your GPOs and maps the settings that matter to Microsoft Intune configuration and compliance policies, flagging any settings without a cloud equivalent for a decision.

Will users get new Windows profiles after connecting to Microsoft Entra ID?

Yes. When a device is joined to Microsoft Entra ID, a new user profile is created on it, and local profile content such as Desktop, Documents, and Favorites does not move automatically. Transferring that data to OneDrive for Business or SharePoint Online is available as an optional add-on.

What happens to Microsoft Entra Connect or Cloud Sync?

Directory synchronization is decommissioned as one of the final, deliberately sequenced steps — only after in-scope users, devices, and workloads are validated on Microsoft Entra ID. The sequencing matters because disabling synchronization is difficult to reverse; IT Partner plans it with the cautions stated rather than treating it as a checkbox.

Will the transition affect daily business operations?

The service is designed to minimize impact: a pilot group validates sign-in and device behavior before production waves, and transition windows are agreed in advance. Some user-visible changes are unavoidable — new device profiles, possible re-authentication, and MFA registration — and the service does not guarantee zero downtime.

What prerequisites are required before the transition starts?

An active Microsoft Entra ID tenant, appropriate Microsoft licenses for the agreed identity and device management model, administrative access to both Active Directory and Microsoft Entra ID, DNS/domain access where needed, a reasonably healthy source environment, an agreed inventory of in-scope users and devices, and a pilot group with approval of the transition plan and change windows.

Does this service decommission our domain controllers?

No — decommissioning on-premises Active Directory servers is not included in the base transition. It should happen only after every dependent workload is identified and remediated; IT Partner documents the recommended sequence, and the work can be scoped separately.

What is not included in this service?

Profile data transfer to OneDrive for Business or SharePoint Online (optional add-on), large-scale endpoint remediation or OS upgrades, application modernization and custom SSO integration, full Intune deployment and Autopilot rollout, Conditional Access and MFA architecture, mailbox/file/SharePoint migration, remediation of pre-existing Active Directory health issues, and ongoing managed support. 24/7 support, continuous monitoring, and ongoing maintenance are available as optional extra-cost add-ons through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.

What happens after the transition is completed?

You receive administrator handoff documentation with configuration notes, validation results, known exceptions, and recommended next steps — including the sequence for retiring synchronization and domain controllers where applicable. Follow-on work such as Intune expansion, Conditional Access design, or decommissioning can be scoped separately.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4,950 per project
3 weeks
Book a meeting