
Active Directory (AD) migration affects people's daily work: logging in and authorizing access to mail, applications, files and devices. If you design the identity model poorly, it's not a „minor glitch,” it's a real risk of losing access to key resources or giving access to key resources to people who absolutely should not have access.
The second common mistake is to try to move the environment „1:1”, without cleanup. Then you take old accounts, redundant groups, outdated permissions and dependencies into the new access model, which generate maintenance costs, introduce clutter and generate risk, and are sure to be pointed out in any audit.
At ISCG, we guide organizations through identity transformation in the Microsoft ecosystem. Below you have the three most common architecture scenarios and a list of pitfalls to close before the project enters the implementation phase.
Why is AD migration the best time to clean up your identity?
AD migration is rarely an end in itself. Most often, it is a necessary step to implement Microsoft 365, implement a Zero Trust approach or a new way of controlling access. In practice, identity becomes the „control center”: who has access, from where, on what device and under what conditions.
Before you go any further, sort out the things that come back like a boomerang later:
- accounts and groups (Enter a consistent naming convention, define what is really used and what is „inheritance from deceased ancestors”),
- privileged rights and access to critical resources,
- login standard (MFA as a minimum, risk-dependent access rules),
- application dependencies (whether they need a domain or just „that's the way it's always been”).
The result is simple: fewer surprises in the pilot and less risk on the day of the switch.
Three target scenarios that are encountered most often
1) Hybrid: AD on-prem + Entra ID
The most common choice in organizations with history and on-prem dependencies (applications, file servers, devices). Entra ID is „pinned” to local AD, and synchronization works through Entra Connect or (in some scenarios) Cloud Sync.
A hybrid makes sense when:
- You have applications that depend on AD DS / domain and you will not upgrade them quickly,
- Some of the infrastructure stays on-prem for longer,
- you want to go in stages: order in identity and access → gradual reduction of on-prem.
2) Cloud-only: Entra ID as primary identity
The cloud-only model works best when the organization relies on SaaS, modern logging and device management via Intune (Entra join / Autopilot). This approach is usually the simplest operationally - as long as there are no hard domain dependencies.
Cloud-only makes sense when:
- Most applications support SSO and modern protocols,
- devices can be Entra-joined and centrally managed,
- files and collaboration are in SharePoint/OneDrive/Teams.
Important clarification: cloud-only is viable if you don't have critical LDAP/Kerberos/NTLM or domain GPO type dependencies. If you have - go to scenario 3.
3) Cloud-first with legacy: Entra ID + Entra Domain Services
This is a common „bridge”: you want to restrict your own domain controllers, but still have applications or VMs that require AD DS (domain join, LDAP, Kerberos/NTLM, Group Policy).
Entra Domain Services gives these functions as a managed service - without maintaining your own DCs in the cloud.
Consider this option when:
- You need LDAP/Kerberos/NTLM for some of the systems,
- You want to avoid putting up and maintaining your own DCs in Azure,
- You modernize applications in stages, but you don't want to block the transformation.
Entra Connect or Cloud Sync - briefly and practically
In a hybrid, the question quickly becomes, „Connect or Cloud Sync?” It's a technical decision, but it affects the migration plan and operational risks.
Bottom line:
- Entra Connect is more likely to be found in older and extended environments and projects „with history.”.
- Cloud Sync is sometimes convenient in newer deployments when you want a simpler agent architecture and management closer to Entra.
If you're not sure, this is one of the topics worth resolving at the readiness stage - before the pilot.
Are you planning to consolidate or migrate Active Directory?
Let's do a quick review of dependencies and choose a scenario (trusts / migration / standardization) before the project enters costly patches.
The most common design pitfalls and how to avoid them
1) Base migration on ADMT without an alternative plan
ADMT has limitations and is not compatible with new versions of systems. In practice, this tool should not be the „only way”.The most difficult problems usually come out with user profiles on devices.
How to approach safely: Treat ADMT as an option, not a foundation. Plan for Option B (especially for equipment and profiles).
2) UPN/domain conflicts in tenant-to-tenant and lack of identity mapping
In cross-tenant migrations, the biggest problems come from unprepared UPN, alias and domain changes. If you don't have identity mapping, you risk access problems after the switch.
How to approach: Determine target UPNs, domains and mapping strategy before touching the schedule.
3) Moving the GPO „in its entirety”
Old GPOs are often years of exceptions and settings „along the way”. Copying 1:1 usually ends up with station instability and a long „unscrew”.
Safer: select critical policies, recreate them consciously, and align them with the target management model (e.g., Intune).
4) Leaving privileged accounts for last
Admin accounts and access rules should go into the „Priority 1” list, not „Priority for later.” If you leave them for later, the risk of serious errors during the project increases.
Identity-readiness in 2-4 weeks: a plan that wraps up decisions
Week 1: inventory and dependencies
Week 2: cleaning up identity
Week 3: target model and pilot
Week 4: schedule and switching plan
How to get started without stalling your project - a starter checklist
To come up with a sensible architecture and schedule is usually enough:
- The number of users, devices and servers in the domain,
- The list of applications and the method of authentication (ADFS/LDAP/SSO),
- Business purpose: merger, demerger, consolidation, moving away from server rooms,
- Device management model (SCCM/Intune/others),
- Legacy dependencies: domain join, LDAP, Kerberos/NTLM, GPO - if any, consider Entra Domain Services as a bridge.
This makes it possible to quickly establish a scenario and work plan without a multi-week preliminary phase.
FAQ - The most common questions about Active Directory migration
Will users lose access to computers and files during the migration?
It doesn't have to be that way. The safest approach is a phased approach: pilot, gradual switchover and maintenance of access during the transition. The biggest risk usually comes from an unprepared identity model, not from the „switchover day” itself.
Does cloud-only mean that we no longer need a „domain”?
Cloud-only is possible if your applications and devices don't require classic AD DS services. If you need LDAP/Kerberos/NTLM, domain join or domain policies, Entra Domain Services often works as a bridge.
What is Entra Domain Services and when does it make sense?
It's a managed domain service in Azure that provides, among other things, domain join, Group Policy, LDAP and Kerberos/NTLM without maintaining its own domain controllers.
Entra Connect or Cloud Sync - which to choose?
It depends on the requirements of the environment and the hybrid scenario. In practice, the choice affects the migration plan and operational risks, so it is worth deciding before the pilot.
Is ADMT a good choice for domain migration?
It has limitations and is not developed for newer systems. If you use it, have an alternative plan - especially for devices and profiles.
What is the most common risk in tenant-to-tenant?
Unplanned UPN/domain changes and lack of identity mapping. If you don't work it out beforehand, the problems usually come out after the switch.
Let's talk about the target identity architecture and migration plan
Learn about our other services

Business applications
Services for applications and turnkey solutions in the area of process digitization and modern work environment.

Full support and optimization of IT infrastructure, ensuring stable development of your business.
IT infrastructure

Security of deployment and maintenance of Microsoft 365 and Azure services that enable flexible management and cost optimization.

