Forests, domains and trust
Assess domain and forest topology, trust relationships, UPN design, group strategy, attributes, stale identities and privileged groups.
Hybrid identity
MAITS designs and modernises hybrid identity across Active Directory, Microsoft Entra Connect, Cloud Sync, authentication, directory attributes and operational ownership.
A topology decides which source is authoritative, how objects are matched, which attributes can flow, what can write back and how failure is detected.
Hybrid architecture
Active Directory, cloud identity and relying services must share an explicit model for authority, matching, lifecycle and supported writeback.
Directory foundation
Assess domain and forest topology, trust relationships, UPN design, group strategy, attributes, stale identities and privileged groups.
Define which system owns each identity and attribute, how existing cloud objects are matched, and which immutable identity assumptions must survive migration.
Evaluate password hash synchronisation, pass-through authentication or remaining federation dependencies against resilience, risk and operating effort.
Design agent placement, staging or redundancy, monitoring, change control and recovery so synchronisation failure is visible and supportable.
Entra Connect or Cloud Sync
Microsoft Entra Connect Sync runs provisioning on an on-premises synchronisation server. Microsoft Entra Cloud Sync stores configuration and runs the provisioning service in Microsoft’s cloud, using lightweight on-premises agents.
Cloud Sync can support multiple disconnected Active Directory forests and scoped synchronisation. Entra Connect remains relevant where its established topology, advanced synchronisation rules or particular hybrid dependencies are required.
MAITS assesses coexistence, migration, agent placement, scoping, attribute mapping, source anchors, authentication and operational constraints before recommending a path.
Microsoft Cloud Sync overviewSynchronisation engineering
Map single or multiple forests, domains, network boundaries, target tenants and coexistence constraints.
Define organisational-unit or group scope, filtering, transformations, extension attributes and authoritative ownership.
Control identity matching, duplicate handling and immutable identity decisions before enabling production flow.
Rehearse transitions between sync technologies with rollback criteria, reconciliation and cutover evidence.
Writeback & Exchange identity
Writeback support varies by technology and scenario. MAITS validates the current Microsoft support boundary before including it in a design.
Where licensed and supported, connect cloud password reset or change to the on-premises directory with appropriate policy and monitoring.
Use current Cloud Sync group provisioning where it meets requirements; treat legacy Entra Connect group writeback modes and migration constraints precisely.
Retain only for supported hybrid scenarios that genuinely depend on on-premises device objects, rather than as a default modern design.
Account for mail-related attributes, recipients, contacts, groups, Exchange Online and remaining on-premises directory management dependencies.
Microsoft’s supported writeback capabilities and prerequisites change over time. The implementation design is validated against current documentation and the organisation’s exact Entra, Active Directory and Exchange topology.
Modernisation path
Inventory directories, connectors, rules, attributes, sign-in dependencies, writeback and operational ownership.
Set source authority, target topology, authentication, scope, flows, monitoring and supported reverse paths.
Stage representative identities, reconcile results and test failure, recovery and Exchange consequences.
Transition using explicit decision points, rollback criteria, validation and controlled retirement.
Legacy identity migration
Older estates may include Microsoft Identity Manager, Forefront Identity Manager, custom management agents, federation platforms or bespoke provisioning engines. Their connectors and metaverse logic can carry business rules that are not visible elsewhere.
Microsoft Entra does not replace every MIM or legacy IGA use case one-for-one. MAITS maps the authoritative sources, transformations, joins, workflows and target-system constraints first, then sequences coexistence, migration, validation and retirement around the capability that must remain.
Start a conversation
Bring your forests, current sync topology and cloud target. MAITS can establish a practical modernisation path.