Off legacy on-premise, onto Entra ID and Intune
Ageing Active Directory and legacy device management, replaced with a cloud-native, reportable estate.
The challenge
The business was running on ageing on-premise Active Directory alongside legacy mobile device management. Devices were managed inconsistently, patching could not be evidenced, and encryption status across the estate was unknown. In a regulated setting, not being able to produce that evidence is itself the problem, regardless of whether the underlying devices happen to be secure.
What I did
I designed and built the cloud-native replacement: Entra ID for identity, Intune for device management, Autopilot for provisioning, Conditional Access for sign-in control, and proper patch management underneath. Users and devices were migrated in phases rather than in one cutover. Legacy on-premise systems and file shares moved to Azure and SharePoint as part of the same programme.
The outcome
A fully cloud-native estate where device compliance is reportable on demand. New starters can be sent a laptop that configures itself on first sign-in, cutting provisioning from hours to minutes.
At a glance
- Entra ID and Intune replacing on-premise AD and legacy MDM
- Autopilot for zero-touch new starter provisioning
- Patch and encryption status reportable across the estate
- File shares migrated to SharePoint and Azure
- Phased migration to limit user disruption
Related service
This work falls under Intune & device management. If you are facing something similar, that page explains how I approach it.
Response times: within 2 hours during working hours, and never more than 24 hours.
Other case studies
Three phone systems merged into one cloud platform
Read case study →Zero-trust rebuild after a suspected data theft
Read case study →Replacing Salesforce with an in-house CRM module
Read case study →Facing something similar?
Tell me what you are dealing with and I will give you a straight view on how I would approach it.