When you need it
Your staff keep separate passwords for many applications, and the rest sign in through an old AD FS server nobody wants to touch. A merger, rebrand or new cloud adds yet another directory, and people who leave keep access to tools nobody remembered to close.
What sets the quote
- Sized by users, applications, domains and tenants; a typical engagement takes 2–6 weeks.
- A typical scope is one Entra tenant, one on-premises Active Directory forest, up to 1,000 users and up to 3 custom domains.
- Applications move in batches of five, up to 20 in a typical engagement, each supporting SAML or OpenID Connect.
- Cloud sign-in covers AWS IAM Identity Center with Entra ID or Google Workspace as the identity provider, and Entra ID sign-in to Google Cloud through Cloud Identity or workforce identity federation.
- Tenant and domain moves are planned one move at a time. More forests, tenants or applications are quoted after sizing.
What changes
- Staff and vendors sign in to business applications and cloud consoles with one corporate identity and MFA.
- When someone leaves, disabling one account ends their sign-in everywhere, and applications with SCIM provisioning remove the account as well.
- On-premises and cloud directories stay in sync, so AD FS and other old federation servers can be retired.
- Tenant and domain moves follow a tested runbook with a rollback at every step.
What you get
- Application inventory with the sign-in method, owner and migration path for each application
- Entra ID single sign-on (SAML or OpenID Connect) for the agreed applications, with SCIM provisioning where the application supports it
- AD FS or other legacy federation retired once its last application has moved
- Hybrid sync with Entra Connect Sync or Entra Cloud Sync, with the sign-in method agreed with you
- Tenant and domain migration plan, cutover runbook and rollback steps
- AWS IAM Identity Center connected to Entra ID or Google Workspace, with SCIM provisioning and permission sets mapped to groups
- Runbooks and a handover session for your IT team
Pair this package with the Microsoft 365 security baseline. Once every application signs in through Entra ID, one set of Conditional Access policies and MFA protects all of them.
Not included
- Moving mailboxes, OneDrive, SharePoint and Teams content between tenants, quoted separately
- Re-joining devices to a new tenant and re-enrolling them in Intune
- Applications that support neither SAML nor OpenID Connect; we assess them and quote the options
- Licences, including the single sign-on tier some SaaS vendors charge extra for
What we need from you
- Entra roles, time-limited: Hybrid Identity Administrator for sync, Application Administrator for single sign-on and provisioning, and Domain Name Administrator for domain moves.
- Active Directory: Domain Admins or Enterprise Admins rights during the sync setup, time-limited, and a Windows Server for the sync agent.
- AWS: administrator access to IAM Identity Center. Google Workspace: a super admin for the SAML app and provisioning.
- Application owners who test each batch, and your DNS admin for domain verification records.
How it works
Free 30-minute call, then the counts that size the work (users, applications, domains, tenants) and a written fixed quote.
Inventory of applications, directories and domains, and a migration order that starts with the lowest-risk applications.
Applications and users move in waves, each with a tested rollback.
Old sign-in paths are retired and the runbooks handed over.
At a glance
- Duration
- 2–6 weeks
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
PKI review
A one-week review of your PKI and certificates, covering the CA hierarchy, certificate inventory, TLS settings and revocation, rated red, amber or green, with an expiry risk list and a roadmap.
Domain and external attack surface check
A one-week, non-intrusive check of your domains, DNS, email authentication and internet-facing endpoints, with every finding tied to evidence and a fix. It is not a penetration test.
Microsoft 365 security baseline
Conditional Access, phishing-resistant MFA and just-in-time admin rights for Microsoft 365, plus Intune policies, Defender for Endpoint and disk encryption for Windows and macOS, designed and rolled out in 1–3 weeks.