Servers and Cloud

Active Directory Setup and Entra ID Hybrid Identity

User accounts, computers, password policies and file permissions managed from one directory, with the same identity working in Microsoft 365. We build Active Directory from scratch, or clean up years of accumulated sprawl and move it onto supported, up-to-date servers.

CybUP TeamLast updated: 7 min read

In short

Active Directory setup is the design and deployment of domain controllers (DCs) that authenticate and manage the users and computers on a company network from one place. With an Entra ID hybrid configuration, the same accounts also sign in to Microsoft 365. CybUp builds redundant DCs, DNS and DHCP, Group Policy and separated admin rights, and sets up Entra Connect or Cloud Sync.

What does an Active Directory setup cover?

An Active Directory setup starts with choosing the domain name and continues with the design of organisational units (OUs), groups, the password policy, DNS zones and Group Policy Objects. You live with these decisions for years. For example, using a subdomain of a domain you own on the internet for the internal domain (something like ad.company.com.tr) saves headaches later with certificates and Microsoft 365 integration.

Even in a small office we install at least two domain controllers. With a single DC, when that server fails nobody can sign in, file shares become unreachable and DNS resolution stops. The second DC belongs on a separate physical host or at a separate site; if both sit on the same Hyper-V host, the redundancy exists only on paper.

DNS is set up as Active Directory-integrated zones, with forwarders for external names. For DHCP we use the Windows Server DHCP failover feature to share scopes between two servers. With branch offices, we use Sites and Services to define each branch’s subnet and nearest DC, so a user signing in at Kadıköy is not sent to a server in İzmir.

What can you manage with Group Policy?

Group Policy is how you push computer and user settings out from the centre. Typical examples are screen lock timeouts, USB storage restrictions, BitLocker, Windows Update scheduling, mapped drives, printers, Microsoft Edge settings, and automatic rotation of local administrator passwords with Windows LAPS.

A problem we see often is dozens of GPOs built up over the years, with nobody sure who created them or why. We report on them one by one and weed out the ones that conflict, the empty ones and the ones that no longer apply, then reorganise what is left into a structure where each GPO has a clear purpose and a consistent name. Changes are trialled on a pilot OU first.

How should administrator privileges be separated?

Attackers usually go after the Domain Admins group; if one of those accounts is compromised, the whole network should be treated as compromised. Microsoft’s enterprise access model builds on the older AD tier model: domain controllers and identity systems sit in the top control plane, and privilege escalation from lower tiers into that plane must be blocked.

In practice we apply it like this. Everyday accounts and admin accounts are kept apart. Domain Admins membership is limited to one or two people. Separate, narrowly scoped groups handle server administration and desktop administration. A GPO stops admin accounts from signing in on user workstations. The basis for all of it is the least-privilege principle in Microsoft’s guidance on securing Active Directory.

  • Separate admin accounts and a slimmed-down Domain Admins group
  • Role-based delegation (helpdesk, servers, file permissions)
  • Local administrator password rotation with Windows LAPS
  • Service account inventory and removal of excess rights
  • Audit policy and alerts on changes to privileged groups

“Implement a least-privilege administrative model. Don't use highly privileged accounts for everyday administrative tasks if you can avoid it.”

— Microsoft Learn — Best practices for securing Active Directory

Entra Connect or Cloud Sync: which should you use?

Microsoft offers two tools for bringing on-premises Active Directory accounts into Microsoft 365. Microsoft Entra Connect is a sync application installed on a server in your network; it supports password hash synchronisation (PHS), pass-through authentication (PTA) and federation through AD FS. On the same page Microsoft describes Cloud Sync as the future of synchronisation and recommends evaluating Cloud Sync before moving to Connect V2.

Microsoft Entra Cloud Sync keeps its configuration in the cloud. On premises, only a lightweight provisioning agent runs, and it makes outbound connections only. Installing several agents gives you redundancy, and disconnected forests can sync into a single tenant. Which tool fits depends on whether you need Exchange hybrid and which features you use; we make the choice with you against Microsoft’s comparison table.

For most SMEs we recommend password hash sync with multi-factor authentication in Entra ID. That way users can still sign in to Microsoft 365 even if the on-premises servers are unreachable. If mailboxes are moving too, the Exchange to Microsoft 365 migration can be planned within the same project.

“Microsoft Entra Cloud Sync is the future of synchronization for Microsoft. It replaces Microsoft Entra Connect.”

— Microsoft Learn — What is Microsoft Entra Connect

How do you migrate off old domain controllers?

DCs still running on Windows Server 2012 R2 or 2016 are something we come across a lot. Rather than upgrading the old server in place, we build a new server and add it to the domain as an extra DC. Once dcdiag and repadmin output confirms replication is healthy, we transfer the FSMO roles. Microsoft’s guide to upgrading domain controllers describes the same route.

Before shutting the old DC down, we track down every device using it as a DNS server: printers, cameras, servers with static IPs, LDAP definitions on the firewall. Miss one and, on the day the DC goes off, someone reports that “the internet is down”. The last step is to demote the old server properly, clean up its metadata and raise the functional level. For the server side as a whole, see our Windows Server 2016 migration page.

Say an accountancy firm with 80 users and two offices has a single DC on 2012 R2, and the same server also handles file sharing. We would first build two new DCs, move file sharing to its own server, then retire the old machine. For users, the job ends one morning when they sign in and nothing has changed.

Why does Active Directory need cleaning up?

Over the years, directories fill up with accounts of people who have left, computer objects for machines that no longer exist, service accounts whose passwords never change, and groups that everyone belongs to. These objects make administration harder and leave usable doors open for an attacker. Access control checks under KVKK, Türkiye’s Personal Data Protection Law (Law No. 6698), also need an up-to-date directory; for the full set of technical measures, see our KVKK technical measures page.

During a clean-up we report inactive accounts by last sign-in date, disable them first with your approval, leave them for a holding period, then delete them. Share permissions are moved from individual users to groups. What you end up with is a directory where a report can show who has access to what.

What you receive

  • Design document for the domain, OUs, groups and naming conventions
  • At least two domain controllers, AD-integrated DNS and DHCP failover
  • A reviewed Group Policy structure and Windows LAPS
  • Separated administrator privileges and an audit policy
  • Entra Connect or Cloud Sync setup with password hash sync
  • Safe retirement of old DCs and a clean-up report

How we work

  1. 1

    Free review

    We report on your current directory, DCs, replication health, GPOs and privileged groups, and rank the problems by priority.

  2. 2

    Design

    We present the target structure, DC placement, privilege model and hybrid identity choice to you in writing.

  3. 3

    Build and migration

    New DCs are added, roles transferred and DNS/DHCP configured, with GPOs trialled on a pilot group.

  4. 4

    Hybrid identity

    Entra Connect or Cloud Sync is installed, and the sync scope and sign-in method are checked with test users.

  5. 5

    Clean-up and handover

    Old DCs are demoted, inactive objects removed and the administration document handed over.

Frequently asked questions

How many domain controllers do we need?

At least two. With a single DC, sign-in, DNS and file access all stop when that server fails. Where there are branch offices, we consider an extra DC or a read-only DC at the branch, depending on its size and the quality of the link.

Will users be affected during the migration?

When a DC migration is done properly, users usually notice nothing. Adding new DCs, transferring roles and demoting the old server can all happen during working hours, although we still schedule DNS changes out of hours.

Does Entra Connect need a licence?

Microsoft states that Entra Connect is free to use and included in your subscription. Some monitoring features, such as Connect Health, require an Entra ID P1 licence. We check what your Microsoft 365 plan includes during the review.

Do we have to rename our existing domain?

Usually not. Hybrid identity can be set up with a non-routable name such as .local; users’ sign-in names (UPNs) are changed to your real domain. Renaming a domain is a risky job, and we only recommend it when there is a serious reason.

We still use Azure AD Connect V1. Is that a problem?

Yes. Microsoft says Azure AD Connect V1 was retired on 31 August 2022 and may stop working unexpectedly. In that case we plan a move to Cloud Sync or Entra Connect V2 as a priority.

How should we handle an account when someone leaves?

Disable the account the same day, remove group memberships and, in a hybrid setup, check that the change has synced to Microsoft 365. We can help you turn this into a checklist or an automated process.

Can you work remotely?

Almost all Active Directory work can be done over a secure remote connection. When a new server needs mounting or a branch needs hardware, we come on site in Istanbul.

How much does an Active Directory setup cost?

We give you a written quote once we have reviewed the scope, and the review is free. The main factors are the number of users and branches, the state of the existing DCs and whether you need hybrid identity.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.