Cloud or hybrid
Pure Entra ID for modern offices, or Active Directory synchronised through Entra Connect where local servers and older applications remain.
Once you pass 15 to 20 employees, handling access by hand becomes a burden. A shared directory fixes that: one sign-in for Microsoft 365, the computer and business systems, settings pushed out centrally, and a leaver disabled in a single step rather than a tour of fifteen applications. We build it in Entra ID, in classic Active Directory or as a hybrid of the two.
The directory is only the tool. The real value lies in the procedures around it: how people join, move between departments, leave and receive permissions.
Pure Entra ID for modern offices, or Active Directory synchronised through Entra Connect where local servers and older applications remain.
Users and devices organised by department and role rather than dumped into one long list.
Screen lock, BitLocker, mapped drives and printers delivered through Intune or Group Policy, depending on the environment.
Permissions go to groups, never to individuals. Otherwise nobody can make sense of the structure two years later.
Two-step verification for everyone and rules that, for example, block sign-ins from countries where you have no staff.
Checklists for joining, moving and leaving with named owners, so nothing relies on somebody remembering.
For a company with up to 100 users, a fresh setup usually takes one and a half to two weeks, including device enrolment.
Departments, groups, naming conventions and the order in which devices will be moved across.
Tenant settings, synchronisation, MFA, Conditional Access and baseline device policies.
Devices are enrolled one department at a time. The employee restarts and signs in, and Intune plus our remote tool handle the rest.
Documentation, a walkthrough with your IT lead or HR, and clear procedures that keep working when we are not involved.
A single global administrator without MFA is the weakness we find most often in Microsoft 365. If that account is compromised, the attacker holds the keys to everything. We create at least two strongly protected emergency accounts and give everyday admins only the roles they genuinely need.
Not necessarily. If everything runs in Microsoft 365 and SaaS, pure Entra ID with Intune is often the simplest route. If you still have a local file server or an older ERP system that needs domain sign-in, a hybrid model makes sense until that system is retired. Where only one domain controller exists, we add a virtual second one.
The account is blocked, sessions and devices are signed out, and the mailbox becomes a shared mailbox the manager can read. The account is not deleted straight away, because files and history would disappear with it. With a fixed procedure it all happens on the same day, including for staff working from home.
Both expect you to control and document who can access what. A structured directory with groups, logging and MFA is what lets you answer Datatilsynet or an auditor with facts instead of guesses.
Tell us how many users you have and whether you use Active Directory, Entra ID or both. We will suggest a structure and a plan with no downtime.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.