Orca IT Solutions

Active Directory & Entra ID

Identity is the real perimeter now

Firewalls matter less every year and accounts matter more. We design and clean up Active Directory and Entra ID: group structure that reflects how you work, group policy that is understandable, permissions without accumulated exceptions, and an offboarding process that removes access the same day.

🛡 Group Based Permissions Clean Offboarding💰 Least Privilege Hybrid Identity

Overview

Directories accumulate mess, quietly

Active Directory rewards good structure and punishes drift. A domain set up carefully in 2016 and left to evolve now has accounts for people who left, groups whose purpose nobody remembers, permissions granted directly to individuals during an urgent request, and four accounts with domain administrator rights that are also used to read email.

The consequence is not theoretical. Credential theft is the most common route into a small business, and what an attacker can do afterward depends entirely on what that account could reach. A user account with unnecessary administrative rights turns a phishing click into a domain-wide incident. Cleaning up identity buys more security per hour spent than almost anything else a small business can do, and it costs time rather than licenses.

Structure that reflects the business

We build organizational units around how you are actually organized, not around a diagram from a training course. Security groups map to job functions, and permissions are granted to groups only, never to individuals, because individual grants are invisible in a group audit and survive long after the reason for them has gone.

Group policy gets the same treatment. Most domains we inherit have dozens of policy objects, several of them contradictory, some applying to nothing, and none documented. We consolidate to a small set with clear names and written purposes, test the resulting policy against real accounts, and remove what is dead. A policy set an engineer can read in ten minutes is worth more than a comprehensive one nobody understands.

Hybrid identity, done once

Most Arizona businesses we work with are hybrid: a domain controller on site for file and application authentication, synchronized to Entra ID for Microsoft 365. That works well when there is one authoritative source and the synchronization rules are understood. It works badly when accounts are created in both places, when filtering excludes objects nobody knows about, or when password writeback was assumed but never enabled.

We establish a single source of truth, verify what is synchronizing and what is not, and document the rules. Some clients are ready to go cloud-only with Entra ID and Intune, which removes the domain controller entirely; we will tell you honestly whether your applications allow that yet, because plenty of line-of-business software still expects a domain. The wider platform view is on our Microsoft 365 page and at microsoft365.orcait.io.

Offboarding hygiene is where the most damage hides. When someone leaves, disabling their Windows account is not enough. Sessions and tokens need revoking, mailbox access needs converting, cloud application access needs removing, VPN and remote access certificates need revoking, shared credentials they knew need changing, and any personal permissions granted directly to them need finding. We write a checklist for your business and run it the same day, every time.

Privileged access gets separated properly: administrative accounts that are distinct from daily-driver logins, MFA on all of them, and a documented list of who holds what. Combined with the controls on our cyber security page, that is what stops one compromised mailbox becoming a company-wide event. A full inventory of accounts and permissions is part of every network audit we run.

Permissions to groups, never to people

A direct grant to an individual is invisible in a group review and outlives the reason it was created. It is the single most common source of access nobody intended.

What We Fix

Six identity problems we find constantly

Each of these turns up in the majority of environments we inherit.

Too many administrators

Domain and global admin rights spread across several people who also use those accounts for daily email and browsing.

Dormant accounts

Enabled logins for staff who left months or years ago, often with valid passwords and access to shares nobody has reviewed.

Direct permission grants

Access given to individuals during an urgent request and never removed, invisible to any review that looks at group membership.

Group policy sprawl

Dozens of policy objects, some contradictory, some applying to nothing, none documented and all inherited from a previous provider.

Broken synchronization

Hybrid setups where accounts exist in both directories, filtering excludes objects nobody knows about, or writeback was never enabled.

Incomplete offboarding

Windows account disabled but sessions still valid, cloud applications still accessible and shared credentials never rotated.

How It Works

Cleaning up identity without breaking access

01

Inventory

Every account, group, administrative right, direct permission grant and policy object, exported and reviewed against your staff list.

02

Design

Organizational unit and group structure mapped to job functions, with a permission model that uses groups exclusively.

03

Remediate

Dormant accounts disabled, admin rights reduced and separated, direct grants converted to groups, policy objects consolidated and tested.

04

Maintain

A written joiner, mover and leaver process, plus periodic access reviews so the same drift does not accumulate again.

Nothing gets removed blind

Dormant accounts are disabled before deletion and permissions are staged, so a mistake is a five-minute reversal rather than a lost afternoon.

Get a Free Assessment

Active Directory and Entra ID questions

Do we still need an on-premises domain controller?

It depends on your applications. Plenty of line-of-business software, older file server setups and some print environments still expect domain authentication. If your applications are cloud or web based, Entra ID with Intune can replace the domain entirely. We check your specific dependencies rather than assuming either direction.

What is the difference between Active Directory and Entra ID?

Active Directory is the on-premises directory that authenticates domain-joined computers and servers on your network. Entra ID is Microsoft's cloud identity service behind Microsoft 365 and other cloud applications. They are separate systems that are commonly synchronized together in a hybrid setup, and they are not simply two versions of the same thing.

How many administrator accounts should we have?

As few as possible, each separate from the person's daily login, each with MFA, and each documented. Two or three for a small business is usually right, so there is redundancy without sprawl. Using an administrative account to read email is the habit that turns a single phishing click into a full compromise.

What should happen when an employee leaves?

Same day: disable the account, revoke active sessions and tokens, convert the mailbox to shared and reassign OneDrive content, remove cloud application access, revoke VPN certificates, rotate any shared credentials they knew, and collect the hardware. We write that checklist for your business so it is repeatable rather than remembered.

Our group policy is a mess. Can it be simplified?

Almost always. We inventory every policy object, work out what each actually applies to, test the resulting policy against real accounts and consolidate to a small documented set. Contradictory and orphaned policies are removed carefully with a rollback available at each step.

Why does it matter that permissions go to groups?

Because a permission granted directly to a person is invisible in any group-based review and survives long after the reason for it disappeared. Group-based permissions mean access changes when someone's role changes, and an access review actually reflects reality.

Can you clean this up without disrupting people?

Yes, by staging it. Dormant accounts are disabled before deletion, permission changes are made in groups with the old access left in place briefly, and policy changes are tested against a pilot set of users. Anything that goes wrong is reversed in minutes.

Do you do this work remotely?

Nearly all of it, so we support clients across all 50 states. Directory work, policy consolidation, synchronization and access reviews are all administrative tasks over the network. Only physical domain controller replacement needs someone on site, which for us means the Phoenix metro.

Find out who can reach what

An identity review lists every account, admin right and direct grant in your environment.

Talk to Your Pod

Talk to Your Pod

Who still has access that should not?

An identity review lists every account, every admin, every dormant login and every permission granted directly to a person instead of a group. It is usually an uncomfortable read and a very useful one.

(602) 677-0779

Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced

Same-day response No long contracts Flat, honest pricing Five-star service

Get your free IT consultation

A few details and your pod gets right back to you, usually the same business day.

Spam-protected with a quick CAPTCHA. Your message goes straight to our team in Gilbert. We only use your details to help with your request. Never sold, never shared.