Alright, I need to vent a little and hopefully give some of you a head's up before you dive into a similar migration. We just completed a full lift-and-shift from our on-premises Active Directory to Microsoft Entra ID (formerly Azure AD) for our ~300 person organization. While the end goal of a cloud-only identity model is fantastic, the journey was... bumpier than expected. And I say this as someone who generally loves digging into the nitty-gritty of complex platforms!
We had a classic hybrid setup for years, but with our shift to Microsoft 365 and a mostly remote team, moving to Entra ID seemed like the logical next step. We planned for months, but reality had some surprises in store.
Here’s what went wrong, or rather, what we weren't fully prepared for:
* **Application Proxy Confusion:** We have a handful of legacy on-prem web apps. Entra ID's Application Proxy seemed like the perfect fit. What we underestimated was the sheer *configuration nuance* for each one. It's not just flipping a switch. Specific headers, translating on-prem AD claims to tokens, and dealing with Kerberos Constrained Delegation in a new way created a week-long fire drill for two of our apps. The documentation is there, but it's a different mindset from a traditional VPN or direct publish.
* **Device Join & The "Hybrid" Hangover:** We went for a pure Entra ID join for new devices, but we had a ton of existing Hybrid Entra ID joined machines. The cleanup and user experience during the transition was messy. Users on those hybrid devices got hit with unexpected authentication prompts for things like OneDrive or Teams that suddenly couldn't find the old DC. Our communication to staff about what to expect wasn't nearly detailed enough on this front.
* **Conditional Access Policy Shock:** This is a powerful feature, but moving from an "everyone's on the VPN/inside the network" mentality to a zero-trust model overnight caused major friction. We rolled out a basic policy requiring MFA and a compliant device for all cloud apps. Suddenly, people using personal phones for Outlook, or old laptops that couldn't meet the compliance bar, were locked out. We had to create a ton of temporary break-glass exclusions and stage the policy rollout much more slowly, which felt like a step backward.
* **The Subtlety of Group Management:** This sounds silly, but moving from AD security groups to Microsoft 365 Groups and Entra ID Security Groups requires a real process change. We had scripts and habits built around on-prem AD group management. The dynamic groups feature in Entra ID is amazing for things like "All Marketing Users," but we fumbled the initial setup and had some groups not populating correctly, which affected access to SharePoint sites.
The biggest lesson? It's not a like-for-like migration. It's a **transformation project**. You're moving from a directory service to an identity and access management platform with incredible power (and complexity).
For those who've made this jump, what was your biggest "oh, we didn't think of that" moment? Specifically, I'd love to hear how you handled the user communication piece and training for the new authentication flows—that was our weakest link.
—Aurora
don't spam bro