{"id":113074,"date":"2024-07-23T11:30:00","date_gmt":"2024-07-23T15:30:00","guid":{"rendered":"https:\/\/jumpcloud.com\/?p=113074"},"modified":"2024-08-15T15:18:13","modified_gmt":"2024-08-15T19:18:13","slug":"how-to-plan-an-active-directory-migration","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration","title":{"rendered":"How to Plan an Active Directory Migration"},"content":{"rendered":"\n<p>Microsoft\u2019s Active Directory (AD) runs your Windows network and keeps mission-critical legacy apps and workflows running at some organizations. <a href=\"https:\/\/jumpcloud.com\/blog\/better-alternative-active-directory\">Replacing<\/a> can be a big commitment and migration planning is an essential step to undertake before kicking off your project.<\/p>\n\n\n\n<p>Big commitments are made for very good reasons. Consider that AD has become a top target for cyber attackers and doesn&#8217;t meet modern IT requirements. AD makes it difficult to support hybrid and decentralized organizations that use a variety of device types, and has become progressively harder to administer. AD also requires a suite of other solutions in order to connect identities to cloud infrastructure, web applications, networking gear, and more.<\/p>\n\n\n\n<p>Those are some of the drivers behind why many organizations are eliminating or modernizing AD with cloud directories. Successful migrations start with understanding your objectives and continue on through support, feedback, and validation.&nbsp;<\/p>\n\n\n\n<p>Every migration is different, but every organization requires a migration plan. Organizations that inherit extensive customizations and custom, homegrown applications may still require AD, but can reduce its usage and attack surface area. Most organizations can migrate to a modern cloud directory completely, enabling them to benefit from greater efficiency, security, and simplicity.<\/p>\n\n\n\n<p>This article is a guide to determine whether AD should be contained or replaced. Then you\u2019ll learn about why cloud directories work differently and how to draft a detailed migration plan. Many organizations have successfully migrated to independent cloud directory services, and you can rest assured that they all invested some time upfront for planning and preparation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-replace-ad\">Why Replace AD<\/h2>\n\n\n\n<p>AD is a 25+ year-old technology that was built for a Window\u2019s centric, on-premises world. It\u2019s <a href=\"https:\/\/jumpcloud.com\/blog\/active-directory-modernization-is-mandatory\">officially a legacy product<\/a> that\u2019s often the <a href=\"https:\/\/www.crowdstrike.com\/resources\/videos\/introduction-to-active-directory-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">weakest link<\/a> in any security platform. It doesn&#8217;t even matter how skilled and experienced the admins are. The costs, complexity, and risks of using AD will always be a problem, but there are solutions depending on how it\u2019s being used.<\/p>\n\n\n\n<div class=\"wp-block-cgb-notification-card-wysiwyg notification-card note\"><div class=\"notification-card-content\"><div class=\"notification-card-icon\"><p><img decoding=\"async\" src=\"\/wp-content\/themes\/jumpcloud\/assets\/images\/gutenberg-blocks\/note-icon.png\"\/><\/p><\/div><div class=\"notification-card-copy is-type-body-default\"><div><strong class=\"notification-card-type\">Note:<\/strong> \n<p>Capital costs, energy, and labor costs combined with supply chain challenges have made running a data center <a href=\"https:\/\/journal.uptimeinstitute.com\/data-center-costs-set-to-rise-and-rise\/#:~:text=The%20past%20two%20years%2C%20however,expensive%20in%202023%20and%20beyond.\" target=\"_blank\" rel=\"noreferrer noopener\">more expensive<\/a>. Learn about the <a href=\"https:\/\/jumpcloud.com\/blog\/costs-microsoft-active-directory\">hidden costs<\/a> of using AD.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n<p>Microsoft recommends using AD in a hybrid configuration with Azure Active Directory\u2019s (now called Entra ID) most premium subscription plan. That means maintaining your data center or a colocation facility while adopting cloud services. Still, it doesn\u2019t stop there. Microsoft\u2019s popular Microsoft 365 (M365) bundles don\u2019t include everything that\u2019s needed for your protection.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-microsoft-s-strategy-for-ad-sell-more-products\">Microsoft\u2019s Strategy for AD: Sell More Products<\/h3>\n\n\n\n<p>Defender for Identity and Defender for Servers are security products to safeguard identities against attacks that hackers use to steal credentials and move laterally through networks. Otherwise, you run the risk of AD being compromised and becoming a pathway to your systems and data. Running AD without protection is <a href=\"https:\/\/www.crowdstrike.com\/blog\/attackers-set-sights-on-active-directory-understanding-your-identity-exposure\/\" target=\"_blank\" rel=\"noreferrer noopener\">increasingly risky<\/a> as attackers set their sights on AD to exploit its architectural limitations. Microsoft understands that problem too.<\/p>\n\n\n\n<p>Eliminating or containing AD is a more straightforward approach. Cloud directories provide IT simplification and modernization with unified identity, device, and access management. Microsoft has moved in this direction with its cloud identity and security products. It has given less emphasis to improving AD; it sells security products instead of eliminating AD\u2019s defects.<\/p>\n\n\n\n<p>The next section will help you understand when it\u2019s better to replace or contain AD. You\u2019ll also have to decide whether Microsoft\u2019s prescribed path is what\u2019s best for your organization. We\u2019ll share more about JumpCloud to help you make that comparison after plotting out the migration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-prerequisites-for-migrations\">Prerequisites for Migrations<\/h2>\n\n\n\n<p>AD may not be as irreplaceable as you may believe. Most organizations can modernize it and begin to benefit from cloud directories without any breaking changes. For example, your firewall, WiFi infrastructure, or core switch can likely handle DHCP\/DNS for your office networks. Every organization has unique requirements and available resources that will inform its migration decisions.<\/p>\n\n\n\n<p>First, it helps to spend some time learning about cloud architecture.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-learn-about-cloud-architecture\">Learn About Cloud Architecture<\/h3>\n\n\n\n<p>Cloud directories don\u2019t always provide a 1:1 replacement to AD, but that should be viewed as an opportunity to increase IT efficiency and security. Cloud directories are built to overcome many of the weaknesses of AD\u2019s legacy architecture using open web standards and modern identity and access management (IAM). Other AD services can be substituted out as needed.<\/p>\n\n\n\n<p>Nested groups are a prime example of why AD\u2019s legacy approach to access control <a href=\"https:\/\/jumpcloud.com\/blog\/nested-groups\">doesn\u2019t exist in the cloud<\/a>. Cloud directories handle authorization via groups rather than through an indirect inheritance from the parent group object. It\u2019s easier for admins to determine why a user object has a particular entitlement. This more mature approach to managing entitlements can increase IT efficiency with automated membership changes. The immediate benefits are easier on\/off boarding, increased efficiency, and more responsiveness to meet business objectives.<\/p>\n\n\n\n<div class=\"wp-block-cgb-notification-card-wysiwyg notification-card note\"><div class=\"notification-card-content\"><div class=\"notification-card-icon\"><p><img decoding=\"async\" src=\"\/wp-content\/themes\/jumpcloud\/assets\/images\/gutenberg-blocks\/note-icon.png\"\/><\/p><\/div><div class=\"notification-card-copy is-type-body-default\"><div><strong class=\"notification-card-type\">Note:<\/strong> \n<p>We offer a free and comprehensive Active Directory to cloud <a href=\"https:\/\/jumpcloud.com\/blog\/the-active-directory-to-cloud-translation-guide\">&#8220;translation&#8221; guide<\/a>.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n<p>Understanding the differences in architecture between AD and the cloud is the first step in planning a migration strategy. AD can be replaced or enhanced to strengthen IAM with modern authentication and other features that reduce reliance on AD \u2026 and its downsides and risks.<\/p>\n\n\n\n<p>The next step is knowing which approach to take for AD: replace it or contain it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-know-when-to-replace-ad\">Know When to Replace AD<\/h3>\n\n\n\n<p>These criteria are generally a \u201cgreenlight\u201d for a migration to a cloud directory:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Having domain-bound Windows devices and unbound cross-OS device types&nbsp;<\/li>\n\n\n\n<li>Having Windows servers including Windows File Servers<\/li>\n\n\n\n<li>Using M365, Azure resources, and on-device Office installations<\/li>\n\n\n\n<li>Deploying third-party Windows applications that use open standards (OIDC, SAML, LDAP, etc.)<\/li>\n\n\n\n<li>Having multiple domains, multiple forests, multiple OUs<\/li>\n\n\n\n<li>Having multi-organization trust situations; cloud directories will flatten security groups and OUs, using attributes to strengthen access control<\/li>\n<\/ul>\n\n\n\n<p>Only enterprises with custom, homegrown applications that cannot utilize modern authentication standards such as OIDC and\/or SAML will not be able to fully migrate. A containment strategy where these apps and AD become ring-fenced can be implemented.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-know-when-to-contain-ad\">Know When to Contain AD<\/h3>\n\n\n\n<p>Here are some example of when AD modernization is the best strategy:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Having legacy and custom applications that can\u2019t update to modern authentication protocols (this may change in the future)<\/li>\n\n\n\n<li>Having highly customized AD schema and SharePoint workflows&nbsp;<\/li>\n\n\n\n<li>Having certificate-based authentication for network access (this may change in the future)<\/li>\n\n\n\n<li>Having some multi-organization forest trust situations (this may change in the future)<\/li>\n<\/ul>\n\n\n\n<p>Begin drafting a migration plan once you\u2019ve determined which scenario describes your organization. A migration plan is crucial to minimize downtime, manage risks, and ensure data integrity during the transition. It helps allocate resources effectively, maintain a positive user experience, and meet compliance requirements.<\/p>\n\n\n\n<div class=\"wp-block-cgb-notification-card notification-card note\"><div class=\"notification-card-content\"><div class=\"notification-card-icon\"><p><img decoding=\"async\" src=\"\/wp-content\/themes\/jumpcloud\/assets\/images\/gutenberg-blocks\/note-icon.png\"\/><\/p><\/div><div class=\"notification-card-copy is-type-body-default\"><p><strong>Note:<\/strong> A well-structured plan provides post-migration support to quickly address any issues, ensuring system stability and user satisfaction.<\/p><\/div><\/div><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-creating-an-ad-migration-plan\">Creating an AD Migration Plan<\/h2>\n\n\n\n<p>Migrating from AD involves several critical steps to ensure a smooth transition. Here\u2019s a plan outline and checklist that will help you along your way.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-assessment-and-planning\">Assessment and Planning<\/h3>\n\n\n\n<p><strong>Inventory the current environment<\/strong>: Begin by documenting all AD objects, including users, groups, and computers. Be sure to include your organizational unit (OU) structure, group policies, and domain levels. Then, focus on what else you may not know.<\/p>\n\n\n\n<p>Take time to assess your current environment to discover all dependencies (like application tie-ins), configurations, and potential issues that you may encounter. This is a good time to audit your environment for <a href=\"https:\/\/jumpcloud.com\/blog\/shadow-it\">shadow IT<\/a> that may be supporting some important business processes. Shadow IT can be something as simple as an Office macro, and local or SaaS apps.<\/p>\n\n\n\n<p>Some other helpful tips are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Perform an inventory of employee and company-owned devices that will be accessing your resources. Those devices (and their \u201cowners\u201d) will have to be enrolled into your new system and managed. Even <a href=\"https:\/\/jumpcloud.com\/blog\/making-byod-work-safely\">BYOD devices<\/a> like laptops and smartphones should be managed.<\/li>\n\n\n\n<li>Determine whether access to non-Windows systems such as network hardware is required.<\/li>\n\n\n\n<li>Determine whether you\u2019ll need to reconfigure your applications or reconfigure <a href=\"https:\/\/jumpcloud.com\/platform\/single-sign-on\" target=\"_blank\" rel=\"noreferrer noopener\">single sign-on<\/a> (SSO) once you adopt <a href=\"https:\/\/jumpcloud.com\/platform\/multi-factor-authentication-mfa\" target=\"_blank\" rel=\"noreferrer noopener\">multi-factor authentication<\/a> (MFA) or change the log-in process. Think of the impact that those changes will have on the <a href=\"https:\/\/jumpcloud.com\/blog\/the-human-challenges-of-rolling-out-multi-factor-authentication-mfa\">people<\/a> of your organization. Technical considerations have an impact on people too.<\/li>\n\n\n\n<li>Decide on the cloud directory service that best fits your needs.<\/li>\n\n\n\n<li>Determine whether you have in-house organizational skills or require professional services for cloud adoption. Creating a cross-functional team of stakeholders with well defined roles and responsibilities is important for successful cloud adoption.<\/li>\n<\/ul>\n\n\n\n<p><strong>Define your goals<\/strong>: Clearly outline what you want to achieve with the migration such as technical considerations like improving security, reducing costs, or greater IT efficiency. This is when you\u2019ll document your desired end state and clearly define what you want your new environment to look like. It will be your yardstick for whether you\u2019ve been successful or not.&nbsp;<\/p>\n\n\n\n<p>Also consider:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Business outcomes<\/li>\n\n\n\n<li>Financial impacts<\/li>\n\n\n\n<li>Communicating objectives with business leaders<\/li>\n<\/ul>\n\n\n\n<p><strong>Perform a risk assessment<\/strong>: Identify potential risks and develop mitigation strategies such as conducting pilot migrations, thorough testing, and having a rollback plan in case of issues. The importance of these activities cannot be understated. Effective contingency planning ensures that the migration can proceed smoothly, even if unexpected issues arise.<\/p>\n\n\n\n<p><strong>Compliance<\/strong>:<strong> <\/strong>Ensure that your migration plan meets all regulatory and compliance requirements before getting started.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-design\">Design<\/h3>\n\n\n\n<p><strong>Organization design<\/strong>: Decide on the structure of your new environment (e.g., hybrid or cloud). A hybrid structure will keep your existing OUs in place but a migration will flatten the organizational structure within your directory using groups to separate administrative units.<\/p>\n\n\n\n<p><strong>Security considerations<\/strong>: Plan for security enhancements, such as improved authentication protocols and encryption. Cloud directories can offer phishing-resistant authentication or even passwordless access. They also offer <a href=\"https:\/\/jumpcloud.com\/platform\/cloud-radius\" target=\"_blank\" rel=\"noreferrer noopener\">RADIUS<\/a> that secures access to your Wi-Fi networks and\/or VPNs even with certificates.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Other considerations include determining whether authentication will pass through to AD or occur within the cloud directory. Many identity providers (IdP) offer <a href=\"https:\/\/community.jumpcloud.com\/t5\/jumpcloud-product-news\/federated-authentication-is-here\/m-p\/4292\" target=\"_blank\" rel=\"noreferrer noopener\">federation<\/a>, which makes it possible to collaborate with external users and other organizations. Understanding these authentication flows will make it easier to transition.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-preparation\">Preparation<\/h3>\n\n\n\n<p><strong>Test environment<\/strong>: Set up a test environment to simulate the migration process.<\/p>\n\n\n\n<p><strong>Backup<\/strong>: Ensure you have a complete backup of your current AD environment even if you are planning to use a test environment completely. Ideally, you could test with some real world data, devices, and users to ensure that everything is as close to your production environment as possible.<\/p>\n\n\n\n<p><strong>Migration planning<\/strong>: Create a detailed migration plan that includes timelines, resource allocation, and risk management strategies. Ensure flexibility to adapt to any unforeseen challenges. Other tips include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ensure your network is configured to support the cloud directory.<\/li>\n\n\n\n<li>Review and update security policies to align with cloud best practices. Technically, GPOs don\u2019t exist in the cloud but pre-built policies and mobile device management (MDM) do.<\/li>\n\n\n\n<li>Engage stakeholders i.e. business leaders to align your motivations and objectives.<\/li>\n<\/ul>\n\n\n\n<p><strong>Migration tools<\/strong>: Choose the right tools for the migration. Consider migrating in phases to manage the process more effectively and reduce the impact on users.<\/p>\n\n\n\n<p><strong>Schedule<\/strong>: Create a detailed migration schedule, including timelines for each phase.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-execution\">Execution<\/h3>\n\n\n\n<p><strong>Pilot migration<\/strong>: Conduct a pilot migration with a small subset of users, apps, and devices to identify any issues. Cloud directories enable you to select users for migration. Select users who are representative of their departments. They can become champions to assist their cohorts.<\/p>\n\n\n\n<p>A simple checklist can be a very helpful tool to ensure a smoother transition. Having a methodology in place to measure business outcomes at this stage may also be helpful. For example: \u201cwas IT able to onboard a new hire better than before the pilot?\u201d<\/p>\n\n\n\n<p><strong>Full migration<\/strong>: Execute the full migration based on the results of the pilot. All users and users and groups will be synced to the cloud directory at this point in time.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Migrate users and groups to the cloud directory; ensure that all user attributes and group memberships are correctly transferred<\/li>\n\n\n\n<li>Move devices to the new directory service<\/li>\n\n\n\n<li>Update applications to authenticate against the cloud directory<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-post-migration\">Post-Migration<\/h3>\n\n\n\n<p><strong>Validation<\/strong>: Verify that all objects and settings have been correctly migrated. All users, groups, devices, and applications should be functioning correctly.<\/p>\n\n\n\n<p><strong>Decommission AD (optional)<\/strong>: Gradually phase out the old AD infrastructure once the migration is confirmed successful. The server can be repurposed for development, training, and or backups.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-monitoring-and-support\">Monitoring and Support<\/h3>\n\n\n\n<p><strong>Monitor<\/strong>: Continuously monitor the new directory environment for any issues.<\/p>\n\n\n\n<p><strong>Support<\/strong>: Provide support to users and address any post-migration issues promptly. Training is an important step and shouldn\u2019t be disregarded. Consider sharing a few reference cards.<\/p>\n\n\n\n<p><strong>Feedback loop<\/strong>: Work to optimize configurations for performance and security. Gather feedback from users and IT staff to make necessary adjustments. Iterate and improve your systems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-jumpcloud-s-ad-migration-options\">JumpCloud\u2019s AD Migration Options<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"512\" height=\"434\" src=\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/flow-chart.png\" alt=\"JumpCloud's AD migration options\" class=\"wp-image-113080\" srcset=\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/flow-chart.png 512w, https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/flow-chart-300x254.png 300w\" sizes=\"(max-width: 512px) 100vw, 512px\" \/><\/figure>\n\n\n\n<p>JumpCloud\u2019s <a href=\"https:\/\/jumpcloud.com\/blog\/active-directory-integration\">Active Directory Integration<\/a> (ADI) and AD <a href=\"https:\/\/jumpcloud.com\/blog\/automate-active-directory-migration-tool\">Migration Utility<\/a> tools can be used to migrate identities away from AD. ADI supports multiple workflows, providing flexibility while keeping necessary services for DHCP, DNS, faxing, file sharing, printing, virtualization, and more.<\/p>\n\n\n\n<p>ADI continuously syncs users, groups, and passwords between AD and JumpCloud. Its components are installed on a member server and configured to import and sync identities for each domain. It provides several options for authentication flows: bi-directional syncing and one-way syncing (in either direction). Pass-through authentication back to AD is supported to uphold security and compliance requirements for local authentication and authorization.<\/p>\n\n\n\n\n\n<div class=\"wp-block-cgb-notification-card notification-card note\"><div class=\"notification-card-content\"><div class=\"notification-card-icon\"><p><img decoding=\"async\" src=\"\/wp-content\/themes\/jumpcloud\/assets\/images\/gutenberg-blocks\/note-icon.png\"\/><\/p><\/div><div class=\"notification-card-copy is-type-body-default\"><p><strong>Note:<\/strong> Keeping your identity provider (IdP) separate from Microsoft can protect against lateral movement that could occur between AD and Entra ID.<\/p><\/div><\/div><\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-additional-resources\">Additional Resources<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Get step-by-step recommendations for how to decommission Active Directory based on your directory goals and how you currently use AD in this free <a href=\"https:\/\/jumpcloud.com\/resources\/modernizing-active-directory-third-party-research-report\" target=\"_blank\" rel=\"noreferrer noopener\">research report<\/a> from the team at EMA, a third-party analyst firm.<\/li>\n\n\n\n<li>Why would Pos Malaysia, a national courier service that has been in operation for over 200 years, <a href=\"https:\/\/jumpcloud.com\/blog\/jumpcloud-modernizes-legacy-it-systems-for-pos-malaysia\">select JumpCloud<\/a> to replace its legacy domain-based systems? JumpCloud\u2019s open directory platform meets the requirements for a future architecture that will drive its next phase of sustainable growth.<\/li>\n\n\n\n<li>UnternehmerTUM is a nonprofit organization that serves as a startup incubator for more than 50 companies each year. In addition to serving as an Active Directory replacement, JumpCloud has transformed the way the nonprofit manages its devices.&nbsp;Check out the <a href=\"https:\/\/jumpcloud.com\/resources\/unternehmertum-uses-jumpcloud\" target=\"_blank\" rel=\"noreferrer noopener\">case study<\/a>.<\/li>\n<\/ul>\n\n\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-jumpcloud-can-help-you-migrate-ad\">JumpCloud Can Help You Migrate AD<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"512\" height=\"202\" src=\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/architecture.png\" alt=\"JumpCloud Architecture\" class=\"wp-image-105128\" srcset=\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/architecture.png 512w, https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/architecture-300x118.png 300w\" sizes=\"(max-width: 512px) 100vw, 512px\" \/><\/figure>\n\n\n\n<p>JumpCloud pairs the ability to manage every endpoint with an open directory platform for IAM to secure every identity. This unified approach delivers strong access control while consolidating IT management tools into a single console for increased operational efficiency. Unified device and identity management provides detailed reporting to track events, identities, and other IT assets.&nbsp;<\/p>\n\n\n\n<p>It does a lot of what AD does for you today: from policies to user management. You can even temporarily elevate local account permissions on a time-bound basis, execute PowerShell commands, provide remote assistance, and deploy software \u2014 all from a single pane of glass.<\/p>\n\n\n\n<p>JumpCloud also offers an optional password manager and the ability to configure phishing-resistant authentication and single sign-on for your users with <a href=\"https:\/\/jumpcloud.com\/resources\/jumpcloud-go-technical-white-paper\" target=\"_blank\" rel=\"noreferrer noopener\">JumpCloud Go<\/a>\u2122. Connect to whatever resources you need, including AD, Google Workspace, HRIS platforms, and more. You can <a href=\"https:\/\/console.jumpcloud.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">try JumpCloud for free<\/a> to help decide whether it\u2019s right for your organization.<\/p>\n\n\n\n<p>We\u2019ve been doing this since 2013. Our team will work with you to understand the unique requirements for your migration and what you\u2019ll need to replace AD (if that\u2019s your ultimate goal). JumpCloud has expertise in mapping roles, services, and features from AD to the cloud.<\/p>\n\n\n\n<div class=\"wp-block-cgb-notification-card-wysiwyg notification-card note\"><div class=\"notification-card-content\"><div class=\"notification-card-icon\"><p><img decoding=\"async\" src=\"\/wp-content\/themes\/jumpcloud\/assets\/images\/gutenberg-blocks\/note-icon.png\"\/><\/p><\/div><div class=\"notification-card-copy is-type-body-default\"><div><strong class=\"notification-card-type\">Note:<\/strong> \n<p>You can\u2019t capture what you\u2019re not aware of. <a href=\"https:\/\/jumpcloud.com\/blog\/jumpcloud-acquires-resmo-for-integrated-asset-management\">JumpCloud is enhancing its platform<\/a> to unify SaaS, IT security, and <a href=\"https:\/\/jumpcloud.com\/blog\/what-is-it-asset-management-itam\">asset management<\/a> to uncover Shadow IT.<\/p>\n <\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Plan your migration away from Active Directory and learn how to phase out or contain legacy systems.<\/p>\n","protected":false},"author":150,"featured_media":113082,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","inline_featured_image":false,"footnotes":""},"categories":[2781,2753],"tags":[],"collection":[2779,2777],"platform":[],"funnel_stage":[3015],"coauthors":[2535],"class_list":["post-113074","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-how-to","category-unification","collection-directory-services","collection-integrations","funnel_stage-mid-funnel"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.3.1 (Yoast SEO v25.3.1) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to Plan an Active Directory Migration - JumpCloud<\/title>\n<meta name=\"description\" content=\"Plan your migration away from Active Directory and learn how to phase out or contain legacy systems.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Plan an Active Directory Migration\" \/>\n<meta property=\"og:description\" content=\"Plan your migration away from Active Directory and learn how to phase out or contain legacy systems.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration\" \/>\n<meta property=\"og:site_name\" content=\"JumpCloud\" \/>\n<meta property=\"article:published_time\" content=\"2024-07-23T15:30:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-15T19:18:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/803690862.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"750\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"David Worthington\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"David Worthington\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#article\",\"isPartOf\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration\"},\"author\":{\"name\":\"David Worthington\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/185ca12034835ee50ee17b100abdfb2e\"},\"headline\":\"How to Plan an Active Directory Migration\",\"datePublished\":\"2024-07-23T15:30:00+00:00\",\"dateModified\":\"2024-08-15T19:18:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration\"},\"wordCount\":2618,\"publisher\":{\"@id\":\"https:\/\/jumpcloud.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/803690862.jpg\",\"articleSection\":[\"How-To\",\"Unification\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration\",\"url\":\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration\",\"name\":\"How to Plan an Active Directory Migration - JumpCloud\",\"isPartOf\":{\"@id\":\"https:\/\/jumpcloud.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#primaryimage\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/803690862.jpg\",\"datePublished\":\"2024-07-23T15:30:00+00:00\",\"dateModified\":\"2024-08-15T19:18:13+00:00\",\"description\":\"Plan your migration away from Active Directory and learn how to phase out or contain legacy systems.\",\"breadcrumb\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#primaryimage\",\"url\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/803690862.jpg\",\"contentUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/803690862.jpg\",\"width\":1000,\"height\":750,\"caption\":\"woman at her desk looking over options\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/jumpcloud.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Plan an Active Directory Migration\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/jumpcloud.com\/#website\",\"url\":\"https:\/\/jumpcloud.com\/\",\"name\":\"JumpCloud\",\"description\":\"Daily insights on directory services, IAM, LDAP, identity security, SSO, system management (Mac, Windows, Linux), networking, and the cloud.\",\"publisher\":{\"@id\":\"https:\/\/jumpcloud.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/jumpcloud.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/jumpcloud.com\/#organization\",\"name\":\"JumpCloud\",\"url\":\"https:\/\/jumpcloud.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png\",\"contentUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png\",\"width\":598,\"height\":101,\"caption\":\"JumpCloud\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/185ca12034835ee50ee17b100abdfb2e\",\"name\":\"David Worthington\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/image\/7b9fc7ce4c2d405140b6160c0aa4fab7\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/9112406c85528af35e36c8a8a0707d90ec7f59204ad9153229161d102ca94e9e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/9112406c85528af35e36c8a8a0707d90ec7f59204ad9153229161d102ca94e9e?s=96&d=mm&r=g\",\"caption\":\"David Worthington\"},\"description\":\"I'm the JumpCloud Champion for Product, Security. JumpCloud and Microsoft certified, security analyst, a one-time tech journalist, and former IT director.\",\"sameAs\":[\"https:\/\/jumpcloud.com\/blog\",\"david.worthington@jumpcloud.com\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"How to Plan an Active Directory Migration - JumpCloud","description":"Plan your migration away from Active Directory and learn how to phase out or contain legacy systems.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration","og_locale":"en_US","og_type":"article","og_title":"How to Plan an Active Directory Migration","og_description":"Plan your migration away from Active Directory and learn how to phase out or contain legacy systems.","og_url":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration","og_site_name":"JumpCloud","article_published_time":"2024-07-23T15:30:00+00:00","article_modified_time":"2024-08-15T19:18:13+00:00","og_image":[{"width":1000,"height":750,"url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/803690862.jpg","type":"image\/jpeg"}],"author":"David Worthington","twitter_card":"summary_large_image","twitter_misc":{"Written by":"David Worthington","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#article","isPartOf":{"@id":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration"},"author":{"name":"David Worthington","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/185ca12034835ee50ee17b100abdfb2e"},"headline":"How to Plan an Active Directory Migration","datePublished":"2024-07-23T15:30:00+00:00","dateModified":"2024-08-15T19:18:13+00:00","mainEntityOfPage":{"@id":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration"},"wordCount":2618,"publisher":{"@id":"https:\/\/jumpcloud.com\/#organization"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/803690862.jpg","articleSection":["How-To","Unification"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration","url":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration","name":"How to Plan an Active Directory Migration - JumpCloud","isPartOf":{"@id":"https:\/\/jumpcloud.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#primaryimage"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/803690862.jpg","datePublished":"2024-07-23T15:30:00+00:00","dateModified":"2024-08-15T19:18:13+00:00","description":"Plan your migration away from Active Directory and learn how to phase out or contain legacy systems.","breadcrumb":{"@id":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#primaryimage","url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/803690862.jpg","contentUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2024\/07\/803690862.jpg","width":1000,"height":750,"caption":"woman at her desk looking over options"},{"@type":"BreadcrumbList","@id":"https:\/\/jumpcloud.com\/blog\/how-to-plan-an-active-directory-migration#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/jumpcloud.com\/"},{"@type":"ListItem","position":2,"name":"How to Plan an Active Directory Migration"}]},{"@type":"WebSite","@id":"https:\/\/jumpcloud.com\/#website","url":"https:\/\/jumpcloud.com\/","name":"JumpCloud","description":"Daily insights on directory services, IAM, LDAP, identity security, SSO, system management (Mac, Windows, Linux), networking, and the cloud.","publisher":{"@id":"https:\/\/jumpcloud.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/jumpcloud.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/jumpcloud.com\/#organization","name":"JumpCloud","url":"https:\/\/jumpcloud.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/","url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png","contentUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png","width":598,"height":101,"caption":"JumpCloud"},"image":{"@id":"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/185ca12034835ee50ee17b100abdfb2e","name":"David Worthington","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/image\/7b9fc7ce4c2d405140b6160c0aa4fab7","url":"https:\/\/secure.gravatar.com\/avatar\/9112406c85528af35e36c8a8a0707d90ec7f59204ad9153229161d102ca94e9e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9112406c85528af35e36c8a8a0707d90ec7f59204ad9153229161d102ca94e9e?s=96&d=mm&r=g","caption":"David Worthington"},"description":"I'm the JumpCloud Champion for Product, Security. JumpCloud and Microsoft certified, security analyst, a one-time tech journalist, and former IT director.","sameAs":["https:\/\/jumpcloud.com\/blog","david.worthington@jumpcloud.com"]}]}},"_links":{"self":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/113074","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/users\/150"}],"replies":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/comments?post=113074"}],"version-history":[{"count":3,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/113074\/revisions"}],"predecessor-version":[{"id":114192,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/113074\/revisions\/114192"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/media\/113082"}],"wp:attachment":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/media?parent=113074"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/categories?post=113074"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/tags?post=113074"},{"taxonomy":"collection","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/collection?post=113074"},{"taxonomy":"platform","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/platform?post=113074"},{"taxonomy":"funnel_stage","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/funnel_stage?post=113074"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/coauthors?post=113074"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}