Identity foundations

Every serious breach ends up in your directory.

Active Directory decides who is allowed to be who inside your network, so attackers do not stop until they own it. Most environments we see were built quickly years ago by someone who has since left: flat structures, a dozen accounts with domain admin rights, group policies nobody dares change. We design the directory properly, migrate you onto it without weekend outages, connect it cleanly to Microsoft 365, and hand back a documented tiered model your own IT team can run.

Clay-style illustration of a central directory hub connected to smaller user nodes in a hierarchy
Zero-downtime
Migration and domain upgrade approach
Tier 0/1/2
Privileged access model as standard
Documented
Handover your own IT team can operate

Sound familiar?

If two of these describe your week, this is the service that fixes it.

  • Too many people hold domain admin rights and nobody remembers why.

  • Ex-employee accounts are still enabled, and service accounts have passwords set years ago.

  • Group policy has grown by accretion — hundreds of settings, no owner, no documentation.

  • A single domain controller in one cupboard is the difference between working and not working.

What the service covers

How the work is actually done, day to day.

01

Design before deployment

Forest and domain layout, sites, an organisational unit structure that matches how you actually work, naming standards and a DNS plan. Written down first, so the build is boring and repeatable.

02

Build, migrate or rescue

Greenfield domains, workgroup-to-domain migrations, cross-forest consolidation after an acquisition, or repairing replication, FSMO roles and DNS on a domain that has been limping for years.

03

Privilege separated properly

A tiered admin model with dedicated admin accounts, protected groups, jump hosts and no daily-driver laptop ever holding domain rights — the single change that most reduces ransomware blast radius.

04

Group policy you can read

Baselines for workstations, servers and admins mapped to CIS benchmarks, with legacy policies retired rather than layered over, and every setting documented with the reason it exists.

05

Clean hybrid identity

Entra ID Connect, single sign-on, MFA and conditional access wired so cloud and on-premises agree on one identity — and so disabling a leaver removes access everywhere at once.

06

Resilience and monitoring

Redundant domain controllers, tested authoritative restore of the directory, and Kerberos, replication and privileged-group changes fed into monitoring so misuse is visible on day one.

What you receive

Documents you can hand to an auditor.

  • As-is assessment with a ranked list of directory risks
  • Low-level design document for forest, domains, sites and OU structure
  • Built and tested environment with redundant domain controllers
  • Tiered privileged access model and admin account inventory
  • Group policy baseline set aligned to CIS benchmarks
  • Hybrid identity configuration for Microsoft 365 with MFA and conditional access
  • Backup and directory recovery runbook, proven by a live restore test
  • Handover documentation and training for your IT team

Platforms we work with

Fluent in the tools, loyal to none of them.

Windows Server 2019/2022/2025 AD DSEntra ID ConnectGroup Policy & CIS benchmarksPingCastle / BloodHound reviewADMT & migration tooling

If you already hold licences, we operate them — no resale margin, no forced migration. When a change genuinely closes a gap or saves money, you see both cost models side by side before anyone recommends anything.

Onboarding

How active directory deployment goes live.

  1. 01

    A 45-minute conversation

    What you run, what worries you, and what a bad week has already cost you. No slides and no product pitch — we are working out whether we can genuinely help.

  2. 02

    Posture assessment

    We examine the estate, compare it against a recognised framework and hand you a prioritised list of gaps. The report is yours to keep whether or not you buy anything.

  3. 03

    Onboarding and a rehearsal

    Log sources, agents, access and escalation contacts are agreed, then we run a live drill of a real incident before we call the service live. Untested escalation paths are decoration.

  4. 04

    Steady-state operations

    Monitoring, response and reporting run to a written SLA, with a quarterly review that changes the plan whenever your business changes.

Questions

What buyers ask about active directory deployment.

Hand active directory deployment to people who do this daily.

Tell us how big the estate is and what deadline you are working to. Within three business days you will have a scope, a timeline and a flat monthly number — no discovery fee to get there.