Service

Active Directory & Identity

Secure, well-structured identity, from domain controllers through to Entra ID and conditional access.

Identity is the foundation of every Microsoft environment. When Active Directory is healthy and well structured, sign-in, access and policy simply work. When it is not, every other project inherits the problems.

I deploy and upgrade domain controllers across physical, virtual and Azure environments, raise forest and functional levels, and bring Group Policy and certificate services under control, then extend identity securely into Entra ID with conditional access.

Common challenges

  • Domain controllers running on ageing or unsupported Windows Server versions
  • Forest and domain functional levels holding back current features
  • Years of accumulated, overlapping Group Policy objects
  • Hybrid identity configured inconsistently between on-premises and cloud
  • Sign-in protection that relies on passwords alone

What's included

Domain controller deployment and migration

New domain controllers across physical, virtual and Azure infrastructure, with roles transferred from legacy servers and old controllers decommissioned cleanly.

Forest and functional level upgrades

Planned upgrades that unlock current Active Directory capabilities, including multi-site environments.

Group Policy design and clean-up

GPOs rationalised, security filtering applied and processing optimised so policy is predictable and fast.

Certificate services

Active Directory Certificate Services deployment and maintenance for internal PKI requirements.

Entra ID and conditional access

Identity, licensing, directory synchronisation and conditional access policies that balance security with usability.

Health checks and recovery

Replication, DNS and FSMO reviews, plus Active Directory recovery when something goes wrong.

Approach

  1. Assess

    Review replication, DNS, FSMO roles, sites, Group Policy and hybrid configuration.

  2. Plan

    Sequence builds, role transfers and upgrades with agreed change windows and rollback points.

  3. Implement

    Deploy, migrate and upgrade with validation at every step.

  4. Document

    Hand over updated topology, policy and recovery documentation.

Proven in practice

  • Three-site domain controller deployment and forest upgrade for a legal sector client
  • Domain controller migrations from legacy servers to new builds across multiple customers
  • Cloud-hosted domain controllers in Azure alongside on-premises sites
  • Active Directory recovery and Group Policy optimisation for managed services clients

Technologies

  • Active Directory Domain Services
  • Group Policy
  • Active Directory Certificate Services
  • DNS
  • DHCP
  • Entra ID
  • Directory synchronisation
  • Conditional Access
  • Windows Server
  • Microsoft Azure

Tools change. Good engineering doesn't. I work with the platforms already in place and adapt quickly to new ones.

Frequently asked questions

Is it safe to raise the forest functional level?

Yes, once every domain controller runs a supported Windows Server version and replication is healthy. A pre-upgrade assessment confirms readiness, and the change is scheduled with a clear rollback plan.

Can domain controllers run in Azure?

Yes. Cloud-hosted domain controllers are a common design for hybrid environments and site resilience, provided networking, DNS and security are designed correctly.

What does conditional access add over MFA alone?

Conditional access applies MFA and other controls based on user, device, location and risk. It enforces strong protection where it matters, including phishing-resistant authentication for sensitive access, without adding friction everywhere.

Discuss your requirements

Share the details of your Active Directory & Identity project and I will outline a practical approach for your environment.

Get In Touch