Service · System administration

Active Directory and Entra ID

The headcount at a forty-room boutique hotel in Bodrum swings from twenty-five in winter to sixty in summer. Reception, housekeeping, kitchen and bar teams arrive in April and most depart in October. Mixed in are students on compulsory placements, travel agency staff with access to the booking engine, and the accountant who reviews the ledgers at month end. When logins are created and removed by hand, the outcome is predictable: dozens of stale accounts still working in November, one reception password everybody knows, and an employee who moved from front office to accounts now holding the rights of both. Identity management really comes down to three moments: someone joins, someone moves internally, someone leaves. We connect those moments to notifications from HR, attach permissions to jobs instead of names, make fixed-term accounts expire on their own and protect every login with a second factor. In our first conversation we find out whether you run purely on Entra ID and Microsoft 365, keep an on-premises Active Directory, or operate both side by side.

Job roles
replace one-off grants
Fixed-term logins
expire automatically
MFA
on every login
Quarterly
managers re-approve access

What the work covers in practice

At the heart of the work is what happens to a person's account along their journey through the company. The scope covers each stop on that journey plus the infrastructure behind it.

Agree the scope with the engineer who will do the work

Arrival

A single HR notice creates the account, places it in the right job group, and mailboxes, folders and apps follow automatically. Accounts for seasonal workers and interns receive an end date at the moment they are created.

Internal moves

When someone changes department, the old role comes off and the new one goes on. No more accounts that gather rights from every team and end up opening every door.

Departure

The login is locked that day, live sessions are terminated and device access is revoked. Mailbox and files pass to the line manager, and the licence is freed.

Shared terminals

Windows Hello or a FIDO2 key lets each person sign in quickly with their own identity on reception, warehouse or workshop PCs. Personal logins replace the shared password without slowing anyone down.

Sign-in methods

Microsoft Authenticator, passkeys or hardware keys. We pick what your staff will actually use, introduce it team by team and explain it on a single sheet.

Conditional access and guests

Company data reachable only from managed devices, sign-ins from unexpected countries blocked, and external people such as your accountant or architect given guest access limited to the folders they need and reconfirmed at intervals.

On-premises Active Directory

Simpler organisational units and group policies, synchronisation via Entra Connect, hardened domain controllers, and a timetable for what migrates to the cloud.

How we approach the job, from first call to handover

We make changes without interrupting daily work. Every new rule runs in a small pilot group before being applied company-wide.

01

Account census

We extract every account, group, admin role and licence. Ownerless, duplicate or excessively privileged entries are gathered into one list.

02

Role catalogue

With management, we write down the jobs in your company and what each job should reach. The catalogue also names who approves which rights.

03

HR link

We agree which form, from whom, triggers each join, move and exit. No account is created without that notice.

04

Quarterly sign-off

Every three months each manager reviews and approves the access held by their team. Anything not approved is removed.

Keep your daily login and your admin login apart. In plenty of companies the IT lead or the owner reads mail and browses the web with the same identity that holds global administrator rights. A single click on a link in a phishing message can then give an attacker the whole directory. We move admin privileges to dedicated accounts used purely for administration and guarded by strong MFA. The everyday login behaves like any normal user; the admin login receives no email and never touches a web browser for general use.

Frequently asked questions

The shared mailbox stays; the shared sign-in goes. Each employee logs in within seconds using a FIDO2 key or Windows Hello and opens the reception mailbox through their own account. That way the logs show who deleted a booking or sent a particular email.

A FIDO2 key clipped to a keyring, or Windows Hello on the shared terminal. Neither relies on a personal smartphone, and the cost per head is modest.

Features such as conditional access and Intune depend on the licence type. Microsoft 365 Business Premium includes them, for instance, while more basic plans do not. We establish which users really need which licence and weed out waste. We do not resell licences; you buy the right plan from your supplier.

A permission matrix showing who reaches personal data, individual accounts and sign-in logs are central to the technical and organisational measures recommended by Turkey's data protection authority. We do not offer legal opinions, but we produce the technical evidence behind those measures.

Depending on your licence, Entra ID flags risky sign-ins and logins from unusual places. We watch those alerts, lock accounts where needed and inform you. To close the account of someone leaving, simply write to helpme@apply.tr.

Let's put your accounts in order

Tell us your headcount, whether you hire seasonal staff and how people log in at present. We will answer with a proposal for where to begin.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.