Infrastructure / Identity / Microsoft Entra ID
A single directory determines everything else.
Your applications, workstations, and access all depend on it.Microsoft Entra ID is the directory that contains your accounts, and it is this directory that Microsoft 365your applications and workstations query every time you log in. A misconfigured directory won’t be noticed on the first day—it becomes apparent the day someone accesses something they shouldn’t, or the day no one can access anything at all.
Three questions determine the project
You ask yourself these questions before making any decision, and the answer to each one narrows down your options for the other two. None of them pertains to a specific product: they concern what you already have, who should be included, and what you’re willing to lose in the event of a failure.
What You Already Have at Home
Most companies have a Active Directory server, installed ten or fifteen years ago, that contains the accounts and groups. It doesn’t disappear—it synchronizes. The decision is which part of the directory is uploaded, and which server remains the master for what.
We look at the current situation before setting the goal.
Who is required to register without being an employee
An agent, an auditor, a vendor, an application that checks a mailbox at night. These accounts don’t follow an employee’s lifecycle: no one reports when they leave. They are the leading cause of access that lingers for years after a term of office has ended.
An account with no end date is an account that remains open.
What Happens When Your Servers Stop Responding
If password verification takes place on your end, an outage in your network or on your servers will prevent your users from accessing their email— including those working from home, who don’t actually need anything from your building.
That's the first question people ask, and almost no one has asked it.
The authentication method must be selected before synchronization
This is the opposite of the usual order, and it’s what distinguishes a successful identity project from one that has to be redone two years later. Synchronization is a tool; the authentication method is an architectural decision, and it affects the availability of everything else.
We measure what you can't stop
Email, files, business applications, and access for teams who are never in the office. For each of these, there’s just one question: How long can it remain inaccessible without costing you anything?
This measure determines the method, and nothing else determines it.
You choose where the password is verified
At Microsoft, or at your site. If the verification is done at Microsoft, a failure of your servers goes unnoticed; if it's done at your site, it brings everything to a halt. Based on what you've just measured, the three possible configurations are therefore not equivalent.
This is the only one of the four decisions that is difficult to reverse later on.
Adjust the synchronization accordingly
Which accounts are being synced, which attributes, which groups, and which of the two directories takes precedence over what. Microsoft Entra Connect—the tool formerly known as Azure AD Connect—does this work from a server on your premises.
Set up this way, it can be adjusted without breaking anything.
We open the access, then close it again
The accounts are up and running, and then the rules kick in: two-step verification, access requirements, and time-limited administrative privileges. With this system in place, no one finds themselves locked out on a Monday morning.
What is open at first closes without any drama; the reverse is not true.
The three methods, and what sets them apart
All three address the same issue— verifying the password —but they have different consequences in the event of a system failure. These three mechanisms are documented by Microsoft; we double-check them before each proposal.
| The Method | Who verifies the password? | What You Need at Home | If your servers stop responding |
|---|---|---|---|
| Password Hash Synchronization | Microsoft. A password hash is sent to your tenant; the password itself never leaves your servers. | A server running Entra Connect. Nothing else to publish externally. | Your users can continue working. Email and files remain accessible, even from home. |
| Direct Authentication | Pass-throughAuthentication | Your servers. An agent installed on your system submits the password to your Active Directory and sends the response back. | At least two operators, working on two machines, so that if one stops, it won't hold anyone up. | No one will log in, no matter where they are, as long as your agents or your Active Directory don’t respond. |
| AD Federation(FS) or equivalent | Your own federation service, to which the connection is redirected. | The most time-consuming of the three: servers, external publishing, and certificates that need to be renewed. | No one is logging in anymore, and the outage involves infrastructure that you maintain on your own. |
Fingerprint synchronization includes a failover mechanism: if your servers stop responding, the verification process switches to Microsoft without your users noticing. This is the only one of the three configurations that survives a failure on your end.
We know how to implement all three, and that's what enables us to advise you.
Federation is justified when a constraint requires it—a smart card, an identity provider other than Microsoft, or an internal policy that nothing else can satisfy. It is not justified simply because it has been in place since 2016. A service provider who can only implement one of the three methods will always claim that it’s the one you need; we prefer to show you the costs associated with each one and let you decide based on your specific needs.
How Single Sign-On Changes Things for Your Users
A single identity provides access to Microsoft 365your externally hosted applications and some of your internal applications. The benefit isn’t just convenience—it’s that a resignation can be processed in one go, rather than being tracked across six different applications.
A departure is processed in a single step
The account is deactivated in the directory, and access is revoked wherever the directory is authoritative. Otherwise, the deactivation must be handled on a per-application basis, and there’s always one left.
Passwords reset themselves
A user who has forgotten their password can change it themselves after verifying their identity. This is the most common reason for contacting customer support, and it is no longer an issue.
Rights are determined by the groups
Membership in a group grants access, and it can be determined based on a specific attribute—such as department, location, or role. This means that when a new person joins, no further action is required.
Every connection is logged
Who logged in, from which country, using which device, and what was blocked. This is the log we review after an incident, and it cannot be reconstructed after the fact.
Accounts that are not employees
They are the ones who pose a problem, because no one reports when they leave. When an employee leaves, Human Resources issues a notice; a contractor whose contract has quietly expired retains access until someone notices.
Outsiders
An agent, an auditor, and a client working on a joint project. They log in using their own accounts—you don't have to create one for them—and each invitation can have an expiration date.
What needs to be settled: who has the right to invite, what the invitation is for, and what happens on the scheduled date.
Apps that connect on their own
A backup system that reads mailboxes, a connector that writes to a website, an automated system that sends invoices. They often have very broad permissions and a secret that never expires.
What needs to be taken care of: the minimum amount actually needed, and a renewal date noted somewhere.
Accounts That Can Do Anything
Those that create, delete, and grant permissions. On many of the instances we discover, there are more than expected, and some also serve as everyday accounts.
What needs to be addressed: separating administrative functions from day-to-day use, and limiting access rights over time.
The device that connects is a requirement, not an account feature.
Determining whether a resource is compliant—encrypted, up-to-date, and managed—and then denying access to others is the job of two related pages: Intune determines the device’s compliance, and conditional access determines the rule that uses it.
A directory is the one component of your IT infrastructure on which all your other projects depend.
A mail system that goes down disrupts email. An improperly configured directory service disrupts email, files, workstations, business applications, and phones—all at once, and for everyone. That’s why it must be addressed first, and calmly.
It is set once
Authentication methods, synchronization, and administrative privileges are established at the beginning of a term. If set up correctly, they never need to be adjusted; if set up incorrectly, they must be adjusted under pressure when a system failure occurs.
He can't see himself
No one ever thanks a directory that works. That’s precisely why it’s the last to be checked—and the first to catch you off guard: excess admin accounts and invitations with no expiration dates quietly pile up.
He's taking it from here
Two-factor authentication, access controls, workstation management, and file sharing all rely on it. None of the four can function if the directory doesn't accurately identify who is who.
What You Need to Know Before Committing
Four points that we set for ourselves at the start of our term, because they determine the schedule and the budget. Each one is flexible; none of them is a reason to give up.
Account sorting comes before the migration
A Active Directory fifteen-year-old database contains accounts of people who have left, empty groups, and duplicates. Synchronizing them as-is is like moving boxes without opening them.
This sorting is done in collaboration with you and is priced separately: it’s a measurable task, not an unknown quantity. Once it’s done, it never has to be done again.
Some older applications cannot authenticate in any other way
Business software that requires an older protocol will not be able to support two-step verification. This is the most common constraint, and it determines the order in which the project is carried out.
Instead of delaying everything, we isolate it: the application retains its path, the rest moves forward, and its replacement is scheduled without blocking the others.
What you can enable depends on your subscriptions
Some of what is described here—the temporary increase in administration fees, certain access rules—is not included everywhere. The levels and their contents change several times a year.
We review your subscriptions before making any recommendations, and we fill in any gaps rather than discovering them along the way.
The first administrative account must not depend on anything
If all administrative logins go through the same verification process, a failure in that verification process will lock you out of your own tenant. This does happen.
Two backup accounts, not subject to any rules, with a long password stored separately: that's the first thing we set up, and we test it twice a year.
Verification and Access Rules
The directory is a "Who's Who." The criteria for inclusion and the conditions under which access is granted are discussed elsewhere.
Multifactor Authentication
Verification methods, what really sets them apart, and how to implement them without leaving anyone out on Monday morning.
Read the page RulesConditional Access
Who is accessing the system, from which device, to which application, and under what conditions. Report mode, rule order, and fallback exclusion.
Read the page DepartmentInfrastructure and Cloud
What the team responsible for installing directories, servers, email systems, and workstations does: what it handles, and what it doesn't do.
View the departmentLet's start by taking a look at your tenant
Spend an hour with the engineers who will be doing the work, reviewing your directory as it stands today: the current authentication method, the administrator accounts, and invitations with no expiration date. You'll leave knowing exactly where you stand.
Renens, Sion, Châtel-Saint-Denis. +41 21 806 37 15 — [email protected]

