Skip to content
Lambert Consulting

Artificial Intelligence: A Cross-Functional Offering

Results first. Infrastructure second.

An assistant for your documents, end-of-line verification, a platform for multiple services. Where artificial intelligence is applied is determined by your data, not by a catalog.

See all solutions
4Comparing Architectures, Criterion by Criterion
2 fieldsSoftware and hardware under one roof
All Use CasesUse cases first, technology last

Our first department

This is what needs to work every morning.

Your servers, your workstations, your phone systems, and your identities. The foundation that no one notices as long as it holds, but that everyone notices the day it fails.

View the department
Multi-siteNational and international projects
3Branches in French-speaking Switzerland
View our client projectsCase Studies and References
Let us know how you're doingGetting a quote is free

How We Work

A piece of advice, not a sales pitch.

Our approach is consultative: we tell you what we think, even when it’s not in our best interest. That’s what makes projects succeed.

About Us
1995First project, using Microsoft SMS
Family-orientedOn a human scale and sustainable

Our Branches

Vaud, headquarters9 Avenue des Baumettes, 1020 Renens+41 21 806 37 15
Valais134 Oscar-Bider Street, 1950 Sion+41 27 552 00 22
FribourgChemin de Montmoirin 18a, 1618 Châtel-Saint-Denis+41 26 322 59 05
Monday through Friday8:00 a.m. – 6:00 p.m.
Contact UsFirst 30-minute consultation, with no obligation

Infrastructure / Identity / Microsoft Entra ID

A single directory determines everything else.

Your applications, workstations, and access all depend on it.

Microsoft Entra ID is the directory that contains your accounts, and it is this directory that Microsoft 365your applications and workstations query every time you log in. A misconfigured directory won’t be noticed on the first day—it becomes apparent the day someone accesses something they shouldn’t, or the day no one can access anything at all.

Formerly Azure AD The service changed its name in 2023. The product, accounts, and settings remain the same.
Microsoft Solutions Partner A case is opened directly with Microsoft when an incident goes beyond what the console shows.
Engineers in French-speaking Switzerland Renens, Sion and Châtel-Saint-Denis. The people who respond to you are the ones doing the work.

Three questions determine the project

You ask yourself these questions before making any decision, and the answer to each one narrows down your options for the other two. None of them pertains to a specific product: they concern what you already have, who should be included, and what you’re willing to lose in the event of a failure.

01

What You Already Have at Home

Most companies have a Active Directory server, installed ten or fifteen years ago, that contains the accounts and groups. It doesn’t disappear—it synchronizes. The decision is which part of the directory is uploaded, and which server remains the master for what.

We look at the current situation before setting the goal.

02

Who is required to register without being an employee

An agent, an auditor, a vendor, an application that checks a mailbox at night. These accounts don’t follow an employee’s lifecycle: no one reports when they leave. They are the leading cause of access that lingers for years after a term of office has ended.

An account with no end date is an account that remains open.

03

What Happens When Your Servers Stop Responding

If password verification takes place on your end, an outage in your network or on your servers will prevent your users from accessing their email— including those working from home, who don’t actually need anything from your building.

That's the first question people ask, and almost no one has asked it.

The authentication method must be selected before synchronization

This is the opposite of the usual order, and it’s what distinguishes a successful identity project from one that has to be redone two years later. Synchronization is a tool; the authentication method is an architectural decision, and it affects the availability of everything else.

01

We measure what you can't stop

Email, files, business applications, and access for teams who are never in the office. For each of these, there’s just one question: How long can it remain inaccessible without costing you anything?

This measure determines the method, and nothing else determines it.

What You Receive A list of your services, with the acceptable downtime for each A summary of what is currently in place
02

You choose where the password is verified

At Microsoft, or at your site. If the verification is done at Microsoft, a failure of your servers goes unnoticed; if it's done at your site, it brings everything to a halt. Based on what you've just measured, the three possible configurations are therefore not equivalent.

This is the only one of the four decisions that is difficult to reverse later on.

What You'll Receive The chosen method, and the two reasons why it was preferred What happens to your users on the day of an outage
03

Adjust the synchronization accordingly

Which accounts are being synced, which attributes, which groups, and which of the two directories takes precedence over what. Microsoft Entra Connect—the tool formerly known as Azure AD Connect—does this work from a server on your premises.

Set up this way, it can be adjusted without breaking anything.

What You Get A written list of what is synced and what is not The authority rule: what changes on your end, what changes online
04

We open the access, then close it again

The accounts are up and running, and then the rules kick in: two-step verification, access requirements, and time-limited administrative privileges. With this system in place, no one finds themselves locked out on a Monday morning.

What is open at first closes without any drama; the reverse is not true.

What You'll Receive The two backup accounts, tested right in front of you The schedule for activating the rules, service by service

The three methods, and what sets them apart

All three address the same issue— verifying the password —but they have different consequences in the event of a system failure. These three mechanisms are documented by Microsoft; we double-check them before each proposal.

The Method Who verifies the password? What You Need at Home If your servers stop responding
Password Hash Synchronization Microsoft. A password hash is sent to your tenant; the password itself never leaves your servers. A server running Entra Connect. Nothing else to publish externally. Your users can continue working. Email and files remain accessible, even from home.
Direct Authentication | Pass-throughAuthentication Your servers. An agent installed on your system submits the password to your Active Directory and sends the response back. At least two operators, working on two machines, so that if one stops, it won't hold anyone up. No one will log in, no matter where they are, as long as your agents or your Active Directory don’t respond.
AD Federation(FS) or equivalent Your own federation service, to which the connection is redirected. The most time-consuming of the three: servers, external publishing, and certificates that need to be renewed. No one is logging in anymore, and the outage involves infrastructure that you maintain on your own.

Fingerprint synchronization includes a failover mechanism: if your servers stop responding, the verification process switches to Microsoft without your users noticing. This is the only one of the three configurations that survives a failure on your end.

What We Say About It

We know how to implement all three, and that's what enables us to advise you.

Federation is justified when a constraint requires it—a smart card, an identity provider other than Microsoft, or an internal policy that nothing else can satisfy. It is not justified simply because it has been in place since 2016. A service provider who can only implement one of the three methods will always claim that it’s the one you need; we prefer to show you the costs associated with each one and let you decide based on your specific needs.

How Single Sign-On Changes Things for Your Users

A single identity provides access to Microsoft 365your externally hosted applications and some of your internal applications. The benefit isn’t just convenience—it’s that a resignation can be processed in one go, rather than being tracked across six different applications.

01

A departure is processed in a single step

The account is deactivated in the directory, and access is revoked wherever the directory is authoritative. Otherwise, the deactivation must be handled on a per-application basis, and there’s always one left.

02

Passwords reset themselves

A user who has forgotten their password can change it themselves after verifying their identity. This is the most common reason for contacting customer support, and it is no longer an issue.

03

Rights are determined by the groups

Membership in a group grants access, and it can be determined based on a specific attribute—such as department, location, or role. This means that when a new person joins, no further action is required.

04

Every connection is logged

Who logged in, from which country, using which device, and what was blocked. This is the log we review after an incident, and it cannot be reconstructed after the fact.

Accounts that are not employees

They are the ones who pose a problem, because no one reports when they leave. When an employee leaves, Human Resources issues a notice; a contractor whose contract has quietly expired retains access until someone notices.

Guests

Outsiders

An agent, an auditor, and a client working on a joint project. They log in using their own accounts—you don't have to create one for them—and each invitation can have an expiration date.

What needs to be settled: who has the right to invite, what the invitation is for, and what happens on the scheduled date.

Services

Apps that connect on their own

A backup system that reads mailboxes, a connector that writes to a website, an automated system that sends invoices. They often have very broad permissions and a secret that never expires.

What needs to be taken care of: the minimum amount actually needed, and a renewal date noted somewhere.

Administration

Accounts That Can Do Anything

Those that create, delete, and grant permissions. On many of the instances we discover, there are more than expected, and some also serve as everyday accounts.

What needs to be addressed: separating administrative functions from day-to-day use, and limiting access rights over time.

The Other Door

The device that connects is a requirement, not an account feature.

Determining whether a resource is compliant—encrypted, up-to-date, and managed—and then denying access to others is the job of two related pages: Intune determines the device’s compliance, and conditional access determines the rule that uses it.

What makes this project different from others
A directory is the one component of your IT infrastructure on which all your other projects depend.

A mail system that goes down disrupts email. An improperly configured directory service disrupts email, files, workstations, business applications, and phones—all at once, and for everyone. That’s why it must be addressed first, and calmly.

It is set once

Authentication methods, synchronization, and administrative privileges are established at the beginning of a term. If set up correctly, they never need to be adjusted; if set up incorrectly, they must be adjusted under pressure when a system failure occurs.

He can't see himself

No one ever thanks a directory that works. That’s precisely why it’s the last to be checked—and the first to catch you off guard: excess admin accounts and invitations with no expiration dates quietly pile up.

He's taking it from here

Two-factor authentication, access controls, workstation management, and file sharing all rely on it. None of the four can function if the directory doesn't accurately identify who is who.

What You Need to Know Before Committing

Four points that we set for ourselves at the start of our term, because they determine the schedule and the budget. Each one is flexible; none of them is a reason to give up.

Account sorting comes before the migration

A Active Directory fifteen-year-old database contains accounts of people who have left, empty groups, and duplicates. Synchronizing them as-is is like moving boxes without opening them.

This sorting is done in collaboration with you and is priced separately: it’s a measurable task, not an unknown quantity. Once it’s done, it never has to be done again.

Some older applications cannot authenticate in any other way

Business software that requires an older protocol will not be able to support two-step verification. This is the most common constraint, and it determines the order in which the project is carried out.

Instead of delaying everything, we isolate it: the application retains its path, the rest moves forward, and its replacement is scheduled without blocking the others.

What you can enable depends on your subscriptions

Some of what is described here—the temporary increase in administration fees, certain access rules—is not included everywhere. The levels and their contents change several times a year.

We review your subscriptions before making any recommendations, and we fill in any gaps rather than discovering them along the way.

The first administrative account must not depend on anything

If all administrative logins go through the same verification process, a failure in that verification process will lock you out of your own tenant. This does happen.

Two backup accounts, not subject to any rules, with a long password stored separately: that's the first thing we set up, and we test it twice a year.

Let's start by taking a look at your tenant

Spend an hour with the engineers who will be doing the work, reviewing your directory as it stands today: the current authentication method, the administrator accounts, and invitations with no expiration date. You'll leave knowing exactly where you stand.

Renens, Sion, Châtel-Saint-Denis. +41 21 806 37 15 — [email protected]