Inventory
Every account, group, administrative right, direct permission grant and policy object, exported and reviewed against your staff list.
Active Directory & Entra ID
Firewalls matter less every year and accounts matter more. We design and clean up Active Directory and Entra ID: group structure that reflects how you work, group policy that is understandable, permissions without accumulated exceptions, and an offboarding process that removes access the same day.
Overview
Active Directory rewards good structure and punishes drift. A domain set up carefully in 2016 and left to evolve now has accounts for people who left, groups whose purpose nobody remembers, permissions granted directly to individuals during an urgent request, and four accounts with domain administrator rights that are also used to read email.
The consequence is not theoretical. Credential theft is the most common route into a small business, and what an attacker can do afterward depends entirely on what that account could reach. A user account with unnecessary administrative rights turns a phishing click into a domain-wide incident. Cleaning up identity buys more security per hour spent than almost anything else a small business can do, and it costs time rather than licenses.
We build organizational units around how you are actually organized, not around a diagram from a training course. Security groups map to job functions, and permissions are granted to groups only, never to individuals, because individual grants are invisible in a group audit and survive long after the reason for them has gone.
Group policy gets the same treatment. Most domains we inherit have dozens of policy objects, several of them contradictory, some applying to nothing, and none documented. We consolidate to a small set with clear names and written purposes, test the resulting policy against real accounts, and remove what is dead. A policy set an engineer can read in ten minutes is worth more than a comprehensive one nobody understands.
Most Arizona businesses we work with are hybrid: a domain controller on site for file and application authentication, synchronized to Entra ID for Microsoft 365. That works well when there is one authoritative source and the synchronization rules are understood. It works badly when accounts are created in both places, when filtering excludes objects nobody knows about, or when password writeback was assumed but never enabled.
We establish a single source of truth, verify what is synchronizing and what is not, and document the rules. Some clients are ready to go cloud-only with Entra ID and Intune, which removes the domain controller entirely; we will tell you honestly whether your applications allow that yet, because plenty of line-of-business software still expects a domain. The wider platform view is on our Microsoft 365 page and at microsoft365.orcait.io.
Offboarding hygiene is where the most damage hides. When someone leaves, disabling their Windows account is not enough. Sessions and tokens need revoking, mailbox access needs converting, cloud application access needs removing, VPN and remote access certificates need revoking, shared credentials they knew need changing, and any personal permissions granted directly to them need finding. We write a checklist for your business and run it the same day, every time.
Privileged access gets separated properly: administrative accounts that are distinct from daily-driver logins, MFA on all of them, and a documented list of who holds what. Combined with the controls on our cyber security page, that is what stops one compromised mailbox becoming a company-wide event. A full inventory of accounts and permissions is part of every network audit we run.
A direct grant to an individual is invisible in a group review and outlives the reason it was created. It is the single most common source of access nobody intended.
What We Fix
Each of these turns up in the majority of environments we inherit.
Domain and global admin rights spread across several people who also use those accounts for daily email and browsing.
Enabled logins for staff who left months or years ago, often with valid passwords and access to shares nobody has reviewed.
Access given to individuals during an urgent request and never removed, invisible to any review that looks at group membership.
Dozens of policy objects, some contradictory, some applying to nothing, none documented and all inherited from a previous provider.
Hybrid setups where accounts exist in both directories, filtering excludes objects nobody knows about, or writeback was never enabled.
Windows account disabled but sessions still valid, cloud applications still accessible and shared credentials never rotated.
How It Works
Every account, group, administrative right, direct permission grant and policy object, exported and reviewed against your staff list.
Organizational unit and group structure mapped to job functions, with a permission model that uses groups exclusively.
Dormant accounts disabled, admin rights reduced and separated, direct grants converted to groups, policy objects consolidated and tested.
A written joiner, mover and leaver process, plus periodic access reviews so the same drift does not accumulate again.
Dormant accounts are disabled before deletion and permissions are staged, so a mistake is a five-minute reversal rather than a lost afternoon.
It depends on your applications. Plenty of line-of-business software, older file server setups and some print environments still expect domain authentication. If your applications are cloud or web based, Entra ID with Intune can replace the domain entirely. We check your specific dependencies rather than assuming either direction.
Active Directory is the on-premises directory that authenticates domain-joined computers and servers on your network. Entra ID is Microsoft's cloud identity service behind Microsoft 365 and other cloud applications. They are separate systems that are commonly synchronized together in a hybrid setup, and they are not simply two versions of the same thing.
As few as possible, each separate from the person's daily login, each with MFA, and each documented. Two or three for a small business is usually right, so there is redundancy without sprawl. Using an administrative account to read email is the habit that turns a single phishing click into a full compromise.
Same day: disable the account, revoke active sessions and tokens, convert the mailbox to shared and reassign OneDrive content, remove cloud application access, revoke VPN certificates, rotate any shared credentials they knew, and collect the hardware. We write that checklist for your business so it is repeatable rather than remembered.
Almost always. We inventory every policy object, work out what each actually applies to, test the resulting policy against real accounts and consolidate to a small documented set. Contradictory and orphaned policies are removed carefully with a rollback available at each step.
Because a permission granted directly to a person is invisible in any group-based review and survives long after the reason for it disappeared. Group-based permissions mean access changes when someone's role changes, and an access review actually reflects reality.
Yes, by staging it. Dormant accounts are disabled before deletion, permission changes are made in groups with the old access left in place briefly, and policy changes are tested against a pilot set of users. Anything that goes wrong is reversed in minutes.
Nearly all of it, so we support clients across all 50 states. Directory work, policy consolidation, synchronization and access reviews are all administrative tasks over the network. Only physical domain controller replacement needs someone on site, which for us means the Phoenix metro.
An identity review lists every account, admin right and direct grant in your environment.
Talk to Your Pod
An identity review lists every account, every admin, every dormant login and every permission granted directly to a person instead of a group. It is usually an uncomfortable read and a very useful one.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.