Guide · Active Directory & Entra ID

Hybrid Active Directory or Entra ID only: the inventory that decides it

Nobody wants a directory. They want the laptop to open, the files to appear, the VPN to connect, and the new hire to have all three on Monday. Whether that needs a domain controller in the office is a question about what is on the floor, not about which is more modern, and the answer comes out of an inventory that takes an afternoon.

Published 8 September 2026 · From the enterprise IT practice in Houston, Texas. Business hours, US Central; an engineer replies within one business day.

The three shapes

On-premises Active Directory only: a domain controller or two in the office, Group Policy, file servers, and Microsoft 365 either absent or bolted on with separate passwords. Increasingly rare, and the least secure of the three, because everything depends on the box under the desk.

Hybrid: Active Directory stays, Entra Connect or Cloud Sync copies the accounts and password hashes to Entra ID, devices are hybrid-joined, and one sign-in opens the desktop, the mail, and the cloud. This is where most mid-sized Texas companies we read actually are, and for good reasons.

Entra ID only: no domain controller, devices joined to Entra ID and managed by Intune, files in SharePoint or OneDrive, Group Policy replaced by configuration profiles, local admin handled by Windows LAPS. Simpler and cheaper to run, if nothing on the floor needs the old directory.

The inventory: what authenticates where

Walk the building and the server room with one question: what asks a directory for permission, and which directory can answer? The usual list:

  • File servers: Windows file shares authenticate against Active Directory, and moving them means SharePoint, OneDrive, or a cloud file service that understands Entra ID
  • Applications that bind to the directory: anything with an LDAP setting, Windows authentication into SQL Server, or a service account in the domain
  • Print servers, and the copiers that scan to a shared folder
  • Wi-Fi and VPN that authenticate users by certificate or RADIUS, which usually means a Network Policy Server joined to the domain
  • Warehouse scanners and shop-floor machines that cannot join Entra ID at all, and the Windows versions they run
  • Remote desktop or terminal servers, which are domain-joined by nature
  • Every Group Policy object that does real work: mapped drives, printers, software installs, security settings; each needs an Intune equivalent before it can go
  • Anything that still speaks NTLM, because Entra ID does not

When Entra ID only is the right answer

The fleet is laptops and browsers, and the office lives in Microsoft 365. Files already sit in SharePoint or could. The applications are SaaS or authenticate with Entra ID. There is no print server, or Universal Print would replace it. Nothing needs Kerberos from an on-premises domain. In that estate a domain controller is a machine to patch, back up, and lose in a power cut, for no benefit, and Intune with conditional access and Windows Hello gives better security than Group Policy ever did.

The move is also the moment to clean up: a cloud-only device is enrolled fresh through Autopilot, so the fleet arrives with a standard image and no local admin accounts left over from 2019.

When hybrid stays

Anything from the inventory list that cannot move this year keeps Active Directory, and the honest plan is a well-run hybrid: two domain controllers rather than one, Entra Connect with password hash sync so that sign-in to Microsoft 365 survives the domain controllers going dark, hybrid-joined devices so conditional access still applies, and a written map of which system depends on which directory.

Hybrid is not a failure state. It is where a company with a file server, a legacy application, and a warehouse belongs, and it can run cleanly for years. What makes it painful is the version run with defaults: sync scoped to every organizational unit, a non-routable domain suffix on every account, and two half-finished device states in the same fleet.

The order to move, if you are moving

  1. Files first: shares into SharePoint or a cloud file service, with the permissions rebuilt rather than copied
  2. Applications next: each one either authenticates with Entra ID, is replaced, or is accepted as the reason the domain stays for another year
  3. Device management to Intune while the devices are still hybrid-joined, so the policies exist before the domain goes
  4. New devices cloud-joined through Autopilot; existing devices re-enrolled at their next refresh rather than converted in place
  5. The domain kept running for whatever remains, with a date on it, and retired when the list is empty

The mistakes we get called about

  • Entra Connect installed on the domain controller with every default accepted, syncing service accounts and disabled users into the tenant
  • Users created in both places by hand, so the same person exists twice and the sync joins the wrong pair
  • A sign-in name inside the company that does not match the email address outside it, which breaks single sign-on and confuses every user once a day
  • Devices in three states at once: domain-joined, hybrid-joined, and Entra-joined, with three different policy sets and no list of which is which

Every one of those is fixed by the same inventory the decision was supposed to start with. That inventory is the first deliverable of the Active Directory and Entra ID work on our Enterprise IT services page.

Sources, so you can check the summary against the original: Microsoft Entra hybrid joined devices (Microsoft Learn); What is Microsoft Entra Connect? (Microsoft Learn).

Where this sits on the IT page

One row of our Enterprise IT services page does this work: Active Directory & Entra ID. The page covers the eight layers together, on-site across Greater Houston and remote across Texas, and starts every engagement with an inventory of what you have.

More guides

Other tickets this page gets

Active Directory & Entra ID

Your only IT person quit. What to lock down in the first 48 hours

Nothing needs rebuilding today. The order of work for two days: the accounts that own everything, the leaver's own access, what would break next, and what to write down.

Read the guide →
Active Directory & Entra ID

The only domain controller died. What still works, what doesn't, and the order to bring it back

Cached sign-ins keep working for a while; DNS stops at once. What runs, what stops, restore or rebuild, and the order to bring it back, then the second one so it never repeats.

Read the guide →
Printers, Scanners & Peripherals

Why a network printer keeps going offline in the office, and the four settings that fix it

Usually addressing, not hardware: a reserved address, a standard TCP/IP port, one driver from one place, and power settings that leave the network interface awake.

Read the guide →
Get in touch

Describe what is on the floor.

How many people, whether there is a file server, which applications sign in with a Windows account, and what the warehouse runs. You get back which shape fits, what the inventory would confirm, and what would move first.

Prefer to talk?

Call 832-598-8234 or email msco@stoneagesoftware.com. Houston, Texas — serving Houston, The Woodlands, Conroe, Sugar Land, Katy, Pearland, and the Greater Houston metro.

What happens next

We read your message, an engineer replies with questions or a straight answer, and if it's worth a call we book one. No drip campaign, no handoff to sales.

No obligation — we reply within one business day. This form sends your details to Stone Age Software LLC so we can respond to you. See our privacy policy for how we handle them. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.