As companies migrate from 'on prem' to Azure cloud, is native Azure Active Directory used or are the applications still authenticating with Traditional Active Directory?

5k viewscircle icon3 Comments
Sort by:
Chief Information Officer3 months ago

Active Directory and Azure Active Directory is different product. Even though the name is almost the same (with Azure at the front), it's a little bit confusing for customer at first. It's a good thing that Microsoft finally realized this and changed the name to Entra (with additional suite of product of course), so people will not get confused between those two. 

Active Directory usually used in on-premise environment as directory services, LDAP, GPO & authentication (which used NTLM & Kerberos). While Entra is mainly built for Cloud-based identity and access management, does not support LDAP & GPO (unless combined with additional Entra Domain Services) & authentication (with different protocol as AD which used OAuth, SAML, OpenID Connect, and password hash)

Therefore to answer your question, depends on the type of applications that you want to migrate, whether you want to keep the apps using NTLM/Kerberos, or you also want to modernize application as well to use the industry standard for cloud based application like OAuth or OpenID Connect, with extra benefit of having highly reliable services that you don't have to manage by yourself. It takes time of course to modernize the apps, and Microsoft provide "bridge" to do this (you can explore Entra Application Proxy). 

It's better if you look back at the motivation why you want to migrate (refer to Cloud Adoption Framework). Is it due to critical business event like data center exit, M&A, end of support critical system, or innovation motivation like creating new product, scale to meet market/geographic demand, etc? Based on that, would be better if you create a realistic roadmap to achieve what you want in a few phase of migration.

Hope it helps.

IT Analyst4 months ago

Every company and every architecture will be different on how and/or if they fully migrate from AD on-prem to Azure AD/Microsoft Entra ID. At a minimum, most companies would take a phased approach when switching from on-prem AD to Azure AD. Companies with smaller and less complex IT environments will probably be able to fully move and transition rather quickly. Companies with larger and more complex environments (100s/1000s of applications and on prem/multi-cloud infrastructure) will likely have a hybrid architecture that relies both on AD on prem and Azure AD (for Azure cloud resource access and Azure AD Groups) for a lengthy period. These companies could eventually transition to fully on Azure AD/Microsoft Entra but there are risks to weigh such as cloud environment misconfigurations, data breaches, regulatory considerations, and service disruptions. There are many layers of security that can be used to protect the cloud environment but if AD is comprised then obviously this is a massive threat for any organization. The decision on when and how to migrate from on-prem AD and Azure AD/Microsoft AD can be a big undertaking and every organization should take a measured approach to consider what is right for them.
Hope that helps a bit.

Lightbulb on1
IT Manager in Manufacturing4 months ago

we use both. Cloud applications typically use Azure AD. 

Content you might like

Yes, it is part of my vision and mission 39%

Yes but I have difficulty to enroll in 43%

I know them but I don't believe they are a must be32%

Our business is focused on the ROI, period.9%

I am not sure, let's discuss in the comments.

View Results

Yes, I have addressed it43%

Yes, I didn't have the courage to address it30%

I have heard about it16%

No, I haven't faced or heard about it11%

View Results