Greater security for advanced users
Customer situation
One of the largest providers of diagnostic services in Europe and the only provider offering laboratory, imaging and pathology specialties under one group.
- Size: 12,000 employees, 200 laboratories,
- 18 branches
- Industry: Medical
Proposed solution
The new Active Directory was designed as a source of identities used in granting access to Office 365 services. For this reason, it was necessary to design a mechanism to synchronize selected objects from AD to Azure AD and to configure appropriate authentication mechanisms to ensure that our client's users can reliably access Office 365 services using their AD (AADP) accounts.
We started with a solution-oriented workshop, demonstrating AIP features in a test environment of Office 365 and Azure.
After a successful demonstration, we moved on to a pre-implementation technical analysis covering 2 main areas: Connectivity (verification of required prerequisites) and Deployment (automatic software deployment to workstations). After determining the technical requirements together with the client's IT team. We then provided the client with a pilot implementation of AIP on a test group (IT department). After confirming that AIP was correctly configured with the models and defined roles, and that the labels worked as expected in the test group, we moved on to further deployment on a wider user group. To date, ISCG continues to support the solution under a monthly maintenance contract.
Key factors
Directory synchronization for accounts was required for the transition to Federated Identities (accounts synchronized with Office 365). The main goal was to streamline solution and service management and provide centralized support with an appropriate SLA.
Benefit provided
User objects - 14715, including Enabled User Objects - 10295,
Group facilities - 3558, including:
- Global security groups - 2621
- Universal security groups - 202
- The most reliable authentication method is provided
- RBAC model - the right roles for the right users
- The roles of users and administrators have been separated
- Self-service portal for password reset
- Reduce licensing and support costs for the organization.

Added value
- Microsoft AADP won out over the other technologies under consideration because of its speed of deployment and ease of integration.
- The number of administrative accounts has been reduced.
- A strong authentication mechanism has been introduced.
- A role-based management model (RBAC) was introduced.
- We provided Microsoft licenses along with management and maintenance services.
- We have developed a CSP management portal that allows billing of licenses by country, which is our competitive advantage.
Conclusions of the project
- The complexity of the infrastructure prolonged the analysis stage.
- The support effort in the early stages of the project was much higher than expected.
- The complexity of the client's infrastructure has been streamlined as a result of the migration.
Ursula Gorska
- Support and development of Microsoft and Nintex based applications
- Application design and development including digital processes
- Invoice management
- Requisition management
- Contract management
- Modern Intranet
ISCG sp. z o.o.
Al. Jerozolimskie 178, 02-486 Warsaw
NIP: 5262798378
KRS: 0000220621
Phone