Service · System administration

Active Directory and Entra ID

A hotel in Tyrol employs twice as many people in winter as in summer. Reception, restaurant and kitchen staff arrive in December and most leave again in April. Whoever creates their accounts by hand ends up in May with twenty logins nobody needs that still work, plus a shared reception account whose password is taped under the keyboard. A milder version of this pattern exists in almost every company: accounts do not follow people, they are simply left lying around. We structure your directory so that permissions attach to functions rather than individuals, time-limited accounts expire by themselves and every sign-in is protected by a second factor. Whether you run purely on Entra ID and Microsoft 365, still operate an on-premises Active Directory, or connect the two, is the first thing we establish.

Roles
instead of one-off permissions
Time-limited accounts
expire automatically
MFA
on every sign-in
Quarterly
access re-confirmed

Everything this covers

The aim is a directory that mirrors your organisation rather than the history of your IT. To get there we work with management and whoever handles HR.

Settle the details with an engineer

Role model

Groups for functions such as reception, accounts, project management or warehouse. A new starter receives the matching role and with it the mailboxes, folders and applications they need.

Temporary and seasonal accounts

Accounts for seasonal staff, summer interns or project partners get an expiry date when they are created. Anyone who stays longer is extended; everyone else loses access without further action.

Shared devices

At reception, in the workshop or the warehouse we configure devices so each person signs in quickly with their own account, for example with Windows Hello or a FIDO2 key, instead of sharing a generic login.

MFA and passkeys

Microsoft Authenticator, passkeys or hardware keys, depending on what your staff will accept. We roll it out department by department with a one-page guide.

Conditional Access and Intune

Company data reachable only from managed or verified devices, risky sign-ins blocked and legacy authentication methods switched off.

Guests and external partners

Your tax adviser, an architecture practice or a software supplier receive guest access with precisely the rights they need, plus a periodic check on whether they still need them.

On-premises Active Directory

Tidying organisational units and Group Policy, synchronisation via Entra Connect, hardening the domain controllers and a plan for what moves to the cloud over time.

Our working method

We change things without disrupting work. Every adjustment is tried with a handful of people before it applies to everyone.

01

Inventory

All accounts, groups, admin roles, licences and sign-in methods. We flag what is orphaned, duplicated or over-privileged.

02

Defining roles

Together with you we set out functions, responsibilities and who may approve which permissions.

03

Gradual switch-over

Roles, MFA and access rules one department at a time. Problems are solved within the pilot group, not across the whole company at once.

04

Regular review

Every quarter the people in charge confirm the permissions in their area, and we correct any discrepancies immediately.

Shared accounts are convenient and dangerous in equal measure. A “reception” account with one password for everyone cannot be protected with MFA, because no second factor belongs to several people, and the audit log just says “reception” for every action. When a booking is deleted or an email sent, nobody knows who did it. Shared mailboxes combined with personal sign-ins fix both problems without slowing down the front desk.

Frequently asked questions

As soon as we hear about it. A message to helpme@apply.at is enough: we block the account, end active sessions and revoke device access. The mailbox is kept as a shared mailbox until you decide how long to retain it.

With a FIDO2 key on a keyring or Windows Hello on the shared device. Neither needs a personal smartphone, and the cost per person is small.

That depends on what still relies on it. Older line-of-business applications, local file shares or Wi-Fi authentication often do. We list those dependencies and propose a way to retire them one by one.

Yes, as a guest in Entra ID with access to the shared folders only. It is safer than sending attachments by email. We set it up so the access has to be re-confirmed periodically and ends when the engagement does.

It does. Traceable permissions, personal accounts and sign-in logs are basics expected both under the GDPR and under NIS2 for essential and important entities. We do not provide the legal classification of your company, but we deliver the technical evidence.

Let us put your accounts in order

How many people work for you, do you employ seasonal staff and how do they sign in today? We will reply with a proposal for the first step.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.