Skip to content
All services
Identity, PKI & domainsBuild

Identity modernisation

Business applications moved from passwords and legacy federation to Entra ID single sign-on, with hybrid sync, tenant and domain moves, and one corporate sign-in for AWS and Google Cloud where you need it.

When you need it

Your staff keep separate passwords for many applications, and the rest sign in through an old AD FS server nobody wants to touch. A merger, rebrand or new cloud adds yet another directory, and people who leave keep access to tools nobody remembered to close.

What sets the quote

  • Sized by users, applications, domains and tenants; a typical engagement takes 2–6 weeks.
  • A typical scope is one Entra tenant, one on-premises Active Directory forest, up to 1,000 users and up to 3 custom domains.
  • Applications move in batches of five, up to 20 in a typical engagement, each supporting SAML or OpenID Connect.
  • Cloud sign-in covers AWS IAM Identity Center with Entra ID or Google Workspace as the identity provider, and Entra ID sign-in to Google Cloud through Cloud Identity or workforce identity federation.
  • Tenant and domain moves are planned one move at a time. More forests, tenants or applications are quoted after sizing.

What changes

  • Staff and vendors sign in to business applications and cloud consoles with one corporate identity and MFA.
  • When someone leaves, disabling one account ends their sign-in everywhere, and applications with SCIM provisioning remove the account as well.
  • On-premises and cloud directories stay in sync, so AD FS and other old federation servers can be retired.
  • Tenant and domain moves follow a tested runbook with a rollback at every step.

What you get

  • Application inventory with the sign-in method, owner and migration path for each application
  • Entra ID single sign-on (SAML or OpenID Connect) for the agreed applications, with SCIM provisioning where the application supports it
  • AD FS or other legacy federation retired once its last application has moved
  • Hybrid sync with Entra Connect Sync or Entra Cloud Sync, with the sign-in method agreed with you
  • Tenant and domain migration plan, cutover runbook and rollback steps
  • AWS IAM Identity Center connected to Entra ID or Google Workspace, with SCIM provisioning and permission sets mapped to groups
  • Runbooks and a handover session for your IT team

Pair this package with the Microsoft 365 security baseline. Once every application signs in through Entra ID, one set of Conditional Access policies and MFA protects all of them.

Not included

  • Moving mailboxes, OneDrive, SharePoint and Teams content between tenants, quoted separately
  • Re-joining devices to a new tenant and re-enrolling them in Intune
  • Applications that support neither SAML nor OpenID Connect; we assess them and quote the options
  • Licences, including the single sign-on tier some SaaS vendors charge extra for

What we need from you

  • Entra roles, time-limited: Hybrid Identity Administrator for sync, Application Administrator for single sign-on and provisioning, and Domain Name Administrator for domain moves.
  • Active Directory: Domain Admins or Enterprise Admins rights during the sync setup, time-limited, and a Windows Server for the sync agent.
  • AWS: administrator access to IAM Identity Center. Google Workspace: a super admin for the SAML app and provisioning.
  • Application owners who test each batch, and your DNS admin for domain verification records.

How it works

  1. Free 30-minute call, then the counts that size the work (users, applications, domains, tenants) and a written fixed quote.

  2. Inventory of applications, directories and domains, and a migration order that starts with the lowest-risk applications.

  3. Applications and users move in waves, each with a tested rollback.

  4. Old sign-in paths are retired and the runbooks handed over.

At a glance

Duration
2–6 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess

PKI review

A one-week review of your PKI and certificates, covering the CA hierarchy, certificate inventory, TLS settings and revocation, rated red, amber or green, with an expiry risk list and a roadmap.

Duration:1 week
Assess Popular

Domain and external attack surface check

A one-week, non-intrusive check of your domains, DNS, email authentication and internet-facing endpoints, with every finding tied to evidence and a fix. It is not a penetration test.

Duration:1 week
Build Popular

Microsoft 365 security baseline

Conditional Access, phishing-resistant MFA and just-in-time admin rights for Microsoft 365, plus Intune policies, Defender for Endpoint and disk encryption for Windows and macOS, designed and rolled out in 1–3 weeks.

Duration:1–3 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.