Service · Systems administration

Active Directory and Entra ID

The first time a Microsoft 365 tenant is reviewed, it usually holds more active accounts than people on the payroll. You find the intern from the summer before, the reception@ login four people share with one password, the sales rep who left for a competitor and still syncs email to his phone, and the contractor who ran the migration and kept global admin rights. Each is an open door, and under the GDPR each is unjustified access to personal data. The job is to leave one identity per person, permissions driven by role and a leaving process as quick as the joining one, whether in Entra ID, an on-premises Active Directory or both kept in sync.

1 login
per employee, never per desk
MFA
on every account
Same day
access is removed
Each quarter
a permissions review

What falls within the scope of this service

The technical side is half the work. The other half is agreeing with you and with HR who grants each permission and what someone receives on their first day.

Pin down the details with one of our engineers

Account clean-up

Accounts of former staff, test accounts and generic shared logins. Any account without a clear owner is closed; shared mailboxes take the place of common passwords.

Joiners and leavers with HR

The start or leaving date entered in Factorial or A3nom triggers creation or blocking of the account. Nobody has to remember to tell IT.

Painless MFA

Push notifications in Microsoft Authenticator, passkeys or FIDO2 hardware keys for people who would rather not install anything on a personal phone. Text messages remain a last resort.

Conditional access

Mail and SharePoint are reachable only from managed devices or with stronger MFA, and sign-ins from countries where you have no staff are blocked outright.

Least privilege

Two emergency global admin accounts kept out of daily use, with other tasks spread across narrow roles that are switched on only when needed.

Hybrid directory

If you keep an on-premises Active Directory, we sync it to Entra ID with Entra Connect, clean out duplicate objects and retain the group policies that still make sense.

Single sign-on

Apps that support it, such as Factorial, Holded or your adviser's client portal, are connected to Entra ID. Disabling one account then closes all those doors at once.

How the engagement unfolds, one stage at a time

How long it takes depends on headcount and how messy the tenant is. Changes are staged, because locking a whole office out of email is not an acceptable side effect.

01

Tenant review

We audit admin roles, user objects, security defaults, licensing and any link to a local directory.

02

Pilot group

A single team lives with the new policies for a while. Friction they report is ironed out before wider roll-out.

03

Department roll-out

Second-factor sign-in, access policies and device enrolment extended area by area, each with a single-sheet user guide.

04

Quarterly review

Each quarter every manager receives a list of who can access what in their area, to confirm or correct.

The global admin account is not for reading email. At many small firms the managing director works all day in an account holding every privilege in the tenant, with the same password for years and no second factor. If a phishing message steals it, the attacker owns the whole company. We always keep working accounts apart from admin accounts, and emergency accounts are stored away from everyday use with credentials that do not rely on one person's phone.

Common questions

An email to helpme@apply.es is enough. We block the account, end sessions on phone and laptop and turn the mailbox into a shared one for the manager. We hold off deleting it so OneDrive files are not lost; the retention period is agreed with you and entered in the record of processing activities.

It is a fair objection with a workable answer: FIDO2 hardware keys, passkeys stored on the laptop, or Windows Hello. What we do not advise is leaving those accounts without a second factor. The chosen option is worth writing into your internal device use policy.

In most cases yes, but not overnight. We begin by listing its remaining dependants, typically file shares, print queues, a legacy payroll tool and Wi-Fi logins. Documents go to SharePoint, the rest is replaced by cloud equivalents, and the box is retired when it has gone quiet.

Conditional access and Intune management come with Microsoft 365 Business Premium, usually the sensible choice for up to 300 users. With Business Standard, Entra ID P1 and Intune must be added separately. We look at what you already pay for before suggesting anything.

Entra ID keeps records of logins, rights changes and privileged role use for the period in question. On top of that we supply group membership with named owners and minutes of each quarterly review. That is precisely what an AEPD inspection or an ENS alignment exercise asks for.

Let us see who can access what

Give us an idea of headcount and the way people log in at present. Our first step is an audit of the identities and admin roles in your tenant.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.