Key takeaways

  • Active Directory organises accounts, computers, groups and permissions on a business's local network.
  • Microsoft Entra ID manages identities and access primarily in cloud services, including Microsoft 365.
  • For many businesses, a cloud or hybrid model is best, rather than automatically creating a new on-premises domain.
  • Permissions should be assigned to groups and roles rather than directly to each user.
  • An employee's departure should trigger a defined process for blocking accounts, sessions and access.

Why does this matter?

In small businesses, accounts are often created as new systems are introduced. A new employee is given access based on the previous person's access, some team members use shared accounts, and the permissions list is not updated after a change of role. While the organisation is small, these problems may remain hidden. As the number of users grows, however, so does the risk of errors, unauthorised access and loss of accountability.

Centralised management does not solve every problem by itself, but it makes it possible to build a single model for accounts, devices, groups and policies. This makes it easier to prepare a workstation, revoke access after an employee leaves, enforce security requirements and check who may use a particular resource.

When should you look into this topic?

The business is growing rapidly

Creating accounts and access manually is beginning to cause mistakes and delays.

You use many systems

Employees have separate accounts for email, VPN, on-premises applications and cloud services.

Work is hybrid

Users need secure access to resources both in and outside the office.

Documentation is missing

It is unclear who has administrative permissions and access to critical data.

Key concepts

User account
An identity used to sign in to a computer, email, an application or a service.
Group
A set of users that can collectively be granted access to resources.
GPO
Group policies that automatically configure computer and account settings.
Microsoft Entra ID
An identity and access management service for Microsoft 365 and cloud applications.
MFA
An additional identity check beyond a password, such as confirmation in a mobile app.

How do you assess the current situation?

Before choosing a technology, it is worth answering a few practical questions:

  • Does every employee have their own account?
  • Is access blocked on the same day when an employee leaves?
  • Do you know who has administrator permissions?
  • Is access to folders assigned through groups?
  • Are administrator accounts separate from standard accounts?
  • Do critical accounts have MFA?
  • Is there a list of systems to which an employee is granted access?
  • Are permissions reviewed regularly?

Key decisions

On-premises or cloud environment?

An on-premises domain may be justified when a business uses servers and applications that require authentication on the internal network. Organisations working mainly in Microsoft 365 can base user and device management on Entra ID and cloud solutions. Businesses with on-premises systems often use a hybrid model.

Individual or group permissions?

Assigning access directly to users is only quick at the beginning. Later, it makes permissions harder to control and revoke. Groups corresponding to roles, departments or access levels are easier to inspect and maintain.

Available solution options

On-premises Active Directory

Well suited to on-premises servers and applications. It offers extensive control, but requires a server, backups, updates and administration.

Microsoft Entra ID

Suitable for businesses working primarily in Microsoft 365 and cloud services. It reduces the need to maintain an on-premises domain, but requires access and MFA to be configured correctly.

Hybrid model

Combines on-premises AD with cloud services. It can be practical with existing infrastructure, but is the most complex option to maintain.

AreaOn-premises ADEntra IDHybrid
Primary useLocal network and serversMicrosoft 365 and cloudCombination of both environments
Working without Internet accessPossible locallyLimitedDepends on the resource
ComplexityMediumMediumHighest

Which approach works most often?

For a business that mainly uses Microsoft 365, works in a hybrid arrangement and has no on-premises server applications, implementing a new domain is not always justified. Entra ID, MFA and device management can be the starting point. An on-premises domain remains important where applications, files or devices require a local environment. The decision should follow from existing dependencies rather than the popularity of the technology alone.

Common mistakes

Shared user accounts

Without individual accounts, it is impossible to determine who made a change or accessed a resource. Separate accounts and permission groups are a better approach.

Permissions granted indefinitely

Access is added, but no one reviews it later. Reviews should be carried out after a change of role and at defined intervals.

One administrator account for everything

Using a privileged account for day-to-day work increases the impact of a compromised password. The administrator account should be separate from the standard account.

Security and risks

  • Enable MFA for privileged accounts and critical services.
  • Apply the principle of least privilege.
  • Separate administrator accounts from day-to-day accounts.
  • Back up configurations and test their recovery.
  • Monitor sign-ins and unusual events.
  • Document the onboarding and offboarding process.

What determines the cost?

The cost of a solution depends on the number of users and devices, the number of locations, existing servers, applications in use, remote access requirements, the level of security, the scope of migration and the documentation required. The assessment should include not only licences and hardware, but also maintenance, updates, backup, administrator time and the cost of downtime.

Step-by-step action plan

  1. Inventory the environment. List users, devices, systems and accounts.
  2. Identify dependencies. Determine which applications require an on-premises domain.
  3. Define requirements. Include remote work, MFA, devices and critical data.
  4. Compare options. Assess on-premises, cloud and hybrid models.
  5. Prepare a test. Plan a pilot, a change window and a rollback method.
  6. Document and maintain. Record the configuration, responsibilities and review cycle.

Checklist

  • Every employee has an individual account.
  • The administrator list is up to date.
  • Permissions derive from groups or roles.
  • There is an employee departure procedure.
  • Privileged accounts have MFA.
  • The configuration is covered by backups.
  • Sign-ins and errors are monitored.
  • Documentation is updated after changes.

What can a business do itself?

You can begin by listing users, devices and systems, identifying data owners, preparing an access list and describing the process for an employee joining and leaving the business. It is also worth establishing who has administrator permissions and which resources are critical.

When is specialist support needed?

Support is particularly useful when the environment combines on-premises servers with Microsoft 365, documentation is missing, a migration is planned, a change may affect many users, or there is no way to test the rollback safely.

Frequently asked questions

Does a small business need Active Directory?

Not always. The decision depends on the number of users, on-premises servers, applications, working arrangements and the need for centralised management.

Does Microsoft 365 replace Active Directory?

Entra ID is not a direct equivalent of every feature of on-premises AD. A cloud model is sufficient for some businesses, while others need a hybrid arrangement.

Can you move from an on-premises domain to the cloud?

Yes, but applications, devices, user profiles, permissions and computer management need to be analysed.

Does everyone need a separate account?

Yes. Shared accounts make access control, change auditing and incident response more difficult.

How often should permissions be reviewed?

Regularly, and after a change of role, responsibilities or the end of a working relationship. The frequency should be matched to the organisation's scale and risk.

Related service

Do you need to organise your domain, GPO, accounts or identity integration with Microsoft 365?

See the access management service

Read also

Microsoft 365 and the work environmentIdentity, collaboration and security in the cloud.Onboarding and offboardingHow to provision and securely close an employee's access.Essential IT securityThe most important measures for protecting accounts and data.