Service · Systems administration

Active Directory and Entra ID

In almost every inventory we run, the number of live accounts is larger than the number of people actually on the payroll. Last summer's intern, a shared mailbox that became a personal login, a workshop account whose password has circulated for three years, the access given to the agency that rebuilt the website in 2022. At fifteen or twenty staff you can still hold all of that in your head. Beyond that you need a directory: one identity per person, rights that follow from the department they work in, and a departure as clean as the arrival. We work in Entra ID, in classic Active Directory, or in the two joined together.

1 identity
per person, not per desk
MFA
across every account
Same day
to close an access
Every quarter
a review of who holds what

Where this service reaches

Only half of this is technical. The rest is settled with you and with the people who handle recruitment: who signs off a permission, and what belongs in a first working day.

Put your scope to an engineer

Tidying the accounts

Leavers, test logins, generic identifiers shared by a whole department. Every account gets an owner or goes away, and shared mailboxes replace shared sign-ins.

Administrative roles

Global administrator kept for two break-glass accounts outside daily use; everything else split into narrow roles, switched on for the length of a task rather than permanently.

Conditional access

Mail and SharePoint open only from a known device, and a sign-in from a country where you employ nobody is blocked before the password prompt appears.

Intune and policies

BitLocker encryption, screen lock, updates, Defender and printers distributed from one place. Where a local domain survives, group policy still plays its part.

Groups by department

Folders and applications hand their permissions to groups, and those groups populate themselves from the department recorded against each person when they are hired.

Forgotten passwords

A locked-out colleague proves who they are in the app and lets themselves back in, rather than waiting in a queue at a quarter to eight on Monday.

Trails and records

Sign-in history is retained for an agreed period. It answers an internal enquiry as readily as it fills the record of processing activities GDPR expects you to hold.

The way an engagement runs

Duration depends on the size of the company and the state of the tenant. Nothing is switched on in one go: nobody should lose their mailbox on a Tuesday morning.

01

Tenant review

Roles, accounts, security settings and synchronisation with the local directory where one still exists.

02

Pilot

One department tries the new rules first. Whatever gets in the way is fixed before anyone else sees it.

03

Rollout

MFA, conditional access and device enrolment, department by department, with a one-page guide for the people using it.

04

Procedures

A joiner and leaver form for HR, then a quarterly review of permissions with the managers.

The account that causes trouble is rarely an employee's. It belongs to a former supplier. Global administrator, created for a migration, no strong authentication, still live two years later and tied to a mailbox nobody reads. Those are the first accounts we hunt for. What no longer serves a purpose is closed, and partner access is replaced by named invitations, time-limited and visible in the logs.

Questions and answers

A message to helpme@apply.fr is the whole procedure on your side. The account is blocked, live sessions on handset and laptop are torn down, and the mailbox becomes a shared one the line manager can open. Deleting the account outright would take the OneDrive contents with it, so it is suspended instead, for a retention period you set and record in your processing register. A laptop still sitting at the person's home can be wiped from here.

With Windows Autopilot and Intune the laptop configures itself at first sign-in: policies, applications, disk encryption, printers. Your reseller registers the hardware and ships it straight to the person; we act only remotely, before the box is even opened.

Often yes, seldom straight away. First we find what still depends on it: a file server, printers, an old payroll package, Wi-Fi authentication through RADIUS. Files move to SharePoint, the rest finds an online equivalent, and the controller is switched off on the day nothing queries it any more.

Yes, and it is more a matter of method than of product. Text message codes give way to notifications in the app or to passkeys, and conditional access cuts the number of prompts on company-managed machines. Within a few weeks most people stop noticing it is there.

Entra ID logs show sign-ins, permission changes and activations of administrative roles over the period requested. We add the list of groups, their owners and the minutes of the quarterly reviews: precisely the evidence a GDPR inspection or an ISO 27001 style exercise expects to see.

Let us find out who can reach what

Give us the number of people and the way they sign in today. We begin with a review of the accounts and roles inside your tenant.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.