IntermediateHYB-ID-WS-001

Hybrid Identity Workshop — AD to Entra cutover for Australian organisations

Plan and execute a safe hybrid Active Directory to Microsoft Entra ID transition

A two-day intensive that walks identity architects and Active Directory administrators through every decision, control and rollback step required to move from hybrid identity to cloud-only Microsoft Entra ID without breaking authentication for Australian workforces.

16 hours
New course
Certificate Included
Hybrid Identity Workshop — AD to Entra cutover for Australian organisations

At a Glance

Who it's for

  • Identity and access architects designing the target Entra ID state
  • Active Directory administrators responsible for Entra Connect and AD FS
  • Microsoft 365 engineers running coexistence and device join programmes
  • Security and risk leads accountable for the cutover risk register

Course Details

Duration:16 hours
Format:Two-day live online workshop with live Q&A
Next intake:September 2026 — register your interest at educ4te.com
Alignment:Aligned to Microsoft Learn hybrid identity reference architecture and ACSC Information Security Manual identity controls

Course Overview

Microsoft retired Azure AD Connect v1 on 31 August 2022 and is steadily moving customers from federation and on-premises sync towards cloud-only identity. This workshop helps Australian organisations sequence that journey safely. Across two intensive days you will compare Entra Connect Sync, Entra Cloud Sync and federation topologies, design coexistence patterns for devices and groups, and rehearse a federation-to-cloud-authentication cutover with a documented rollback path. The course is grounded in Microsoft Learn reference guidance and the identity expectations in the ACSC Information Security Manual and ASD Essential Eight maturity model. You will leave with a tailored cutover plan, a risk register template, a decommissioning checklist for AD FS and unused domain controllers, and the post-cutover hygiene routines required to keep hybrid joined devices, group writeback and single sign-on healthy.

What You'll Learn

Select the right hybrid identity topology (Entra Connect Sync, Entra Cloud Sync or federation) for your tenant size, geography and compliance posture
Design coexistence patterns covering group writeback, hybrid Entra joined devices and seamless single sign-on for Australian workforces
Migrate authentication from AD FS federation to cloud authentication using password hash sync or pass-through authentication with staged rollout
Build a cutover risk register that maps technical, regulatory and user-experience risks to mitigations and rollback triggers
Execute a rehearsed rollback to federation or to a previous sync server within agreed recovery time objectives
Decommission AD FS farms, Web Application Proxy and redundant domain controllers without leaving orphaned trust or certificate dependencies
Apply post-cutover hygiene controls aligned to ASD Essential Eight and ACSC ISM identity guidance
Communicate the cutover plan and residual risks to executives, auditors and the OAIC-aligned privacy function

Course Curriculum

Module 1: Hybrid identity topology choices

3 hours
  • Comparing Entra Connect Sync, Entra Cloud Sync and federation
  • Microsoft Entra Connect v2 requirements and the v1 retirement notice
  • Sizing, high availability and Australian data residency considerations
  • Choosing password hash sync, pass-through authentication or federation
  • Mapping topology choices to ACSC ISM identity controls

Module 2: Coexistence patterns

3.5 hours
  • Group writeback v2 and lifecycle management for Microsoft 365 groups
  • Hybrid Entra joined devices and Windows Hello for Business rollout
  • Seamless single sign-on, Kerberos and primary refresh tokens
  • Application coexistence: Kerberos, header-based and SAML apps
  • Conditional Access design for mixed device estates

Module 3: Migrating from federation to cloud authentication

3.5 hours
  • Inventorying AD FS relying parties and custom claim rules
  • Staged rollout to password hash sync or pass-through authentication
  • Handling legacy authentication, smart cards and certificate-based sign-in
  • Cutting over Microsoft 365, Azure resources and third-party SaaS
  • Validating MFA, Conditional Access and break-glass accounts post-cutover

Module 4: Cutover risk register and rollback strategies

3 hours
  • Building a risk register covering authentication, devices and apps
  • Defining rollback triggers, owners and recovery time objectives
  • Reverting from cloud authentication to federation safely
  • Communications plan for users, service desk and executives
  • Privacy Act 1988 and OAIC notifiable data breach considerations

Module 5: Post-cutover hygiene

3 hours
  • Decommissioning AD FS, Web Application Proxy and dbConfig backups
  • Retiring redundant domain controllers and cleaning DNS, SCP and SPNs
  • Tightening Entra Connect Sync rules and on-premises attribute flows
  • Ongoing monitoring with Entra ID sign-in logs and Microsoft Sentinel
  • Maturity uplift against ASD Essential Eight Restrict Administrative Privileges and MFA

Who Should Attend

  • Identity and access architects designing the target Microsoft Entra ID state
  • Active Directory administrators responsible for Entra Connect Sync and AD FS
  • Microsoft 365 engineers running device join, group writeback and coexistence programmes
  • Security and risk leads accountable for the cutover risk register and rollback decision
  • Infrastructure managers planning domain controller and AD FS farm decommissioning
  • Consultants sequencing hybrid-to-cloud identity migrations for Australian clients

Prerequisites

Before enrolling, please ensure you meet these requirements:

  • • Working knowledge of Active Directory Domain Services, Group Policy and DNS
  • • An established hybrid identity environment using Entra Connect Sync or AD FS
  • • Familiarity with Microsoft Entra ID tenants and Conditional Access policy
  • • Access to a non-production tenant and lab AD forest for the hands-on exercises
  • • Global Administrator and Domain Admin rights in the lab environment

Delivery, Format and Logistics

Delivery Mode

Two-day live online workshop with live Q&A

Self-paced online with live Q&A sessions

What You'll Need

  • Working knowledge of Active Directory Domain Services and Group Policy
  • Familiarity with Microsoft Entra ID (formerly Azure AD) tenants and Conditional Access
  • Access to a non-production tenant and lab AD forest for the hands-on labs
  • Global Administrator and Domain Admin rights in the lab environment

What You'll Receive

  • 16 hours of workshop instruction across five modules
  • Hands-on labs in your own non-production tenant and lab AD forest
  • A tailored cutover plan you build during the workshop, not a generic template
  • Cutover risk register template mapping technical, regulatory and user-experience risks
  • Federation rollback runbook with defined triggers, owners and recovery time objectives
  • Decommissioning checklist for AD FS, Web Application Proxy and redundant domain controllers
  • Post-cutover hygiene routines for hybrid joined devices, group writeback and seamless SSO
  • Certificate of completion

Frequently Asked Questions

Not Ready to Enrol?

Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.

By subscribing, you agree to receive email updates from Educ4te. You can unsubscribe at any time. We respect your privacy and will never share your information.

$799AUD
$999EARLY BIRD

Early-bird rate — apply your promo code at checkout.

1

Secure payment via Stripe · Promo codes accepted

Next Intake

September 2026 — register your interest at educ4te.com

Format

Two-day live online workshop with live Q&A

Group & Enterprise Options

Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.

What's Included

  • 16 hours of workshop instruction across five modules
  • Hands-on labs in your own non-production tenant and lab AD forest
  • A tailored cutover plan you build during the workshop, not a generic template
  • Cutover risk register template mapping technical, regulatory and user-experience risks
  • Federation rollback runbook with defined triggers, owners and recovery time objectives
  • Decommissioning checklist for AD FS, Web Application Proxy and redundant domain controllers
  • Post-cutover hygiene routines for hybrid joined devices, group writeback and seamless SSO
  • Certificate of completion

Have questions about this course?