Service · Systems administration

Active Directory and Entra ID

Beyond roughly 15-20 people, granting access by hand starts to bite back. A colleague who changed teams three years ago can still log into Allegro, while the new assistant spends two days waiting for the contracts folder. A shared identity directory ends the muddle: each person gets one account for Microsoft 365, their laptop and business apps, and what they can open follows from the team they belong to. We work with Entra ID, traditional Active Directory, or both joined together.

1 account
per employee
MFA
on every account
Minutes
to cut off access
History
of sign-ins on record

Included in this service

The technology is half the job. The other half is agreeing with you and HR who approves access and what a person's first and final day look like.

Talk the scope through with an engineer

Account clean-up

We hunt down leavers' accounts, test users and shared logins. Every account gets an owner or is removed.

Admin roles

Global admin reserved for two break-glass accounts; everyone else receives narrower roles, say for Exchange or Intune, ideally switched on only for the task at hand.

Conditional Access

Mail and SharePoint open only on company-managed devices, and sign-ins from unusual countries are refused.

Intune and policies

BitLocker, screen lock, updates and printers pushed out centrally. Where a local domain remains, we use GPOs as well.

Department-based groups

Folder and app permissions tied to groups that fill themselves from the department HR records.

Self-service password reset

Staff unlock their own account after verifying in the app, instead of raising a ticket at 7:30 on a Monday.

How we work together

Timing depends on company size and the state of the tenant. Changes are rolled out so that nobody loses mail or file access.

01

Tenant review

We inspect roles, accounts, security defaults and the sync with on-site AD, if there is one.

02

Pilot

One department trials the new policies and groups. We smooth out the friction before the rest of the company follows.

03

Rollout

MFA, Conditional Access and Intune enrolment, team by team, with a one-page guide for staff.

04

Routines

A starter and leaver form for HR, plus a quarterly permissions review with line managers.

Shared logins like warehouse1 or reception are a blind spot in every audit. Nobody can say who used them, half the staff know the password, and MFA is usually off because apparently it breaks things. We swap them for named accounts, shared mailboxes and group-based rights, and check along the way that the tenant is not relying on a single global admin without MFA.

Questions and answers

No courier trips required. With Windows Autopilot and Intune the employee signs in with a work account and the machine fetches its policies, apps and BitLocker settings by itself. Your supplier can even deliver new hardware straight to the employee, an InPost locker for example, ready for work after first boot.

A single email to office@apply.pl with Support in the subject is enough. We lock the account, kill live sessions on phone and laptop, and convert the mailbox to a shared one for the manager. Deletion waits, otherwise the OneDrive files would vanish. If the company laptop remains with the leaver, Intune lets us wipe it remotely.

Frequently, though not in one go. First we list what still leans on the domain: a file server, printers, an elderly payroll package, or Wi-Fi authentication via RADIUS. Files go to SharePoint and the rest gets a cloud replacement. Once nothing talks to the controller, we switch it off and you run on Entra ID alone.

Yes. Rather than SMS codes we introduce Microsoft Authenticator push prompts or passkeys, and on trusted company machines Conditional Access trims the number of challenges. Over time most people stop noticing MFA exists.

Let us check who can open what

Give us your headcount and describe how people log in today. We begin with a review of accounts and roles in your tenant.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.