Local AD to Entra ID/Intune Migration + GCC High
A multi-state physical security company, involving both a parent organization and a regulated government services subsidiary, was operating 221 Windows workstations and laptops within an outdated on-premises Active Directory environment. Account management had deteriorated, with numerous blocked or unlicensed mailboxes, 27 devices that hadn’t registered for 60 days, and a confusing array of shared, generic, and lab usernames complicating device-user associations. Due to the federal contract obligations of the subsidiary, a Microsoft 365 GCC High environment was necessary, but utilizing GCC High meetings from the commercial tenant created operational challenges. The objectives included retirement of the on-premises domain and its associated data center, modernization of identity and endpoint management through Entra ID and Intune, and the establishment of a functional GCC High for the regulated subsidiary that everyday users could effectively use. NetTech proposed a phased modernization approach. In Phase 1, an audit of M365 accounts was conducted, resulting in the deletion of blocked accounts and devices inactive for over 60 days, the validation of Business Premium license holders as the primary migration group, and the adjustment of license tiers (Basic at $8/month, Business Premium at $26-40/month, and E3 at $56/month). Devices linked to the active domain are being transitioned from on-prem AD to Entra ID join using Intune MDM and conditional access in batches of about 5 users. Synchronizing passwords with email credentials eliminates the need for user retraining. Tailored Intune policies retain administrative rights for legacy lab software, and Mass360 has been phased out in favor of Intune for integrated MDM and MAM. Phase 2 will tackle shared accounts, local-only devices, and the shutdown of on-prem domain controllers and the data center. The GCC High tenant is now operational, with tested B2B guest access to facilitate cross-tenant meeting workflows, and Windows 365 Cloud PC has been established as an alternative for on-demand full GCC High access. Approximately 30 inactive devices and numerous blocked accounts have been eliminated, leading to a reduction in both licensing costs and management complexity. A clear timeline for the dissolution of the on-prem AD has been established, and multi-factor authentication (MFA) is being implemented.