Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Organizations are increasingly modernizing identity, access, and device management by reducing their dependence on on-premises Active Directory and adopting cloud-native capabilities in Microsoft Entra ID. Whether the goal is complete Active Directory retirement or a smaller, more secure on-premises footprint, this guidance helps you plan and execute that transformation.
This content provides guidance to move:
From Active Directory and other non-cloud-based services, either on-premises or infrastructure as a service (IaaS), that provide identity management (IDM), identity and access management (IAM), and device management.
To Microsoft Entra ID and other Microsoft cloud-native solutions for IDM, IAM, and device management.
Note
In this content, Active Directory refers to Windows Server Active Directory Domain Services.
Transformation must be aligned with and achieve business objectives, including increased productivity, reduced costs and complexity, and improved security posture. To better understand the costs versus value of moving to the cloud, see Forrester TEI for Microsoft Entra ID and Cloud economics.
The AD minimization journey
Moving from Active Directory to Microsoft Entra ID progresses through five stages. Each stage describes where your environment is on the journey and is paired with a single strategic phase that describes the primary focus of work in that stage. Across every stage, three streams of progress (users and groups, applications, and devices) advance, and they can move independently of one another.
Cloud Attached (Identification): Establish a baseline by discovering your current identity, application, and device landscape. Active Directory Domain Services remains authoritative while cloud identity is attached but not yet primary. The focus is on visibility and determining which workloads are ready to move.
Hybrid (Modernization): Move beyond synchronizing identities and begin using cloud identity to strengthen security, resilience, and user experience while on-premises environments remain in place. Identify dependent apps and services, and enable capabilities such as conditional access and self-service password reset.
Cloud-First (Adoption): Treat Microsoft Entra ID as the default authority for new investments and shift the identity control plane to the cloud. New users, groups, applications, and devices are provisioned as cloud-native by default.
On-premises AD minimized (Reduction): Reduce Active Directory from a default dependency to an exception. Actively shrink the on-premises footprint by replacing legacy workloads with cloud alternatives and migrating identity lifecycle workflows to Microsoft Entra ID.
Cloud Only (Optimization): Remove remaining on-premises identity dependencies and operate identity as a fully cloud-native service. All users, groups, and devices are managed in Microsoft Entra ID, enabling Active Directory to be decommissioned. Moving from Active Directory to Microsoft Entra ID progresses through five stages. Each stage describes where your environment is on the journey and is paired with a single strategic phase that describes the primary focus of work in that stage. Across every stage, three streams of progress (users and groups, applications, and devices) advance, and they can move independently of one another.