Skip to content
Retail · 40,000 employees

National Retail Enterprise

Hybrid Identity Modernization

Entra IDActive Directory16 weeks
3 → 1
AD forests consolidated
100%
Sign-in MFA coverage
6
ADFS servers retired

The challenge

After two acquisitions, the retailer operated three separate Active Directory forests with overlapping accounts, an aging ADFS farm, and inconsistent MFA. Store associates frequently held duplicate identities, and the security team could not enforce a uniform Conditional Access policy. An upcoming cyber-insurance renewal required demonstrable MFA coverage across the workforce.

The approach

  1. 1

    Ran a full discovery of all three forests, mapping duplicate identities and application dependencies on ADFS.

  2. 2

    Designed a target hybrid architecture with a single Entra ID tenant, Password Hash Sync with Seamless SSO, and a layered Conditional Access framework.

  3. 3

    Migrated relying-party applications off ADFS to Entra ID authentication in prioritized waves.

  4. 4

    Piloted with corporate users, then rolled out to stores region by region with a documented runbook and rollback plan.

  5. 5

    Decommissioned the ADFS farm and legacy sync servers after validation.

The outcome

Every employee now has one authoritative identity with enforced MFA and Conditional Access. The legacy ADFS attack surface was eliminated, and the retailer met its cyber-insurance requirements ahead of renewal.

Duplicate accounts removed
11,000+
Legacy auth endpoints retired
100%
Insurance MFA requirement
Met early

Ready to secure your identity foundation?

Book a free 30-minute discovery call. We'll talk through your environment and where the biggest wins are — no obligation.

Book a Call