Hybrid Identity Workshop — AD to Entra cutover for Australian organisations
Plan and execute a safe hybrid Active Directory to Microsoft Entra ID transition
A two-day intensive that walks identity architects and Active Directory administrators through every decision, control and rollback step required to move from hybrid identity to cloud-only Microsoft Entra ID without breaking authentication for Australian workforces.

At a Glance
Who it's for
- Identity and access architects designing the target Entra ID state
- Active Directory administrators responsible for Entra Connect and AD FS
- Microsoft 365 engineers running coexistence and device join programmes
- Security and risk leads accountable for the cutover risk register
Course Details
Course Overview
Microsoft retired Azure AD Connect v1 on 31 August 2022 and is steadily moving customers from federation and on-premises sync towards cloud-only identity. This workshop helps Australian organisations sequence that journey safely. Across two intensive days you will compare Entra Connect Sync, Entra Cloud Sync and federation topologies, design coexistence patterns for devices and groups, and rehearse a federation-to-cloud-authentication cutover with a documented rollback path. The course is grounded in Microsoft Learn reference guidance and the identity expectations in the ACSC Information Security Manual and ASD Essential Eight maturity model. You will leave with a tailored cutover plan, a risk register template, a decommissioning checklist for AD FS and unused domain controllers, and the post-cutover hygiene routines required to keep hybrid joined devices, group writeback and single sign-on healthy.
What You'll Learn
Course Curriculum
Module 1: Hybrid identity topology choices
3 hours- Comparing Entra Connect Sync, Entra Cloud Sync and federation
- Microsoft Entra Connect v2 requirements and the v1 retirement notice
- Sizing, high availability and Australian data residency considerations
- Choosing password hash sync, pass-through authentication or federation
- Mapping topology choices to ACSC ISM identity controls
Module 2: Coexistence patterns
3.5 hours- Group writeback v2 and lifecycle management for Microsoft 365 groups
- Hybrid Entra joined devices and Windows Hello for Business rollout
- Seamless single sign-on, Kerberos and primary refresh tokens
- Application coexistence: Kerberos, header-based and SAML apps
- Conditional Access design for mixed device estates
Module 3: Migrating from federation to cloud authentication
3.5 hours- Inventorying AD FS relying parties and custom claim rules
- Staged rollout to password hash sync or pass-through authentication
- Handling legacy authentication, smart cards and certificate-based sign-in
- Cutting over Microsoft 365, Azure resources and third-party SaaS
- Validating MFA, Conditional Access and break-glass accounts post-cutover
Module 4: Cutover risk register and rollback strategies
3 hours- Building a risk register covering authentication, devices and apps
- Defining rollback triggers, owners and recovery time objectives
- Reverting from cloud authentication to federation safely
- Communications plan for users, service desk and executives
- Privacy Act 1988 and OAIC notifiable data breach considerations
Module 5: Post-cutover hygiene
3 hours- Decommissioning AD FS, Web Application Proxy and dbConfig backups
- Retiring redundant domain controllers and cleaning DNS, SCP and SPNs
- Tightening Entra Connect Sync rules and on-premises attribute flows
- Ongoing monitoring with Entra ID sign-in logs and Microsoft Sentinel
- Maturity uplift against ASD Essential Eight Restrict Administrative Privileges and MFA
Who Should Attend
- Identity and access architects designing the target Microsoft Entra ID state
- Active Directory administrators responsible for Entra Connect Sync and AD FS
- Microsoft 365 engineers running device join, group writeback and coexistence programmes
- Security and risk leads accountable for the cutover risk register and rollback decision
- Infrastructure managers planning domain controller and AD FS farm decommissioning
- Consultants sequencing hybrid-to-cloud identity migrations for Australian clients
Prerequisites
Before enrolling, please ensure you meet these requirements:
- • Working knowledge of Active Directory Domain Services, Group Policy and DNS
- • An established hybrid identity environment using Entra Connect Sync or AD FS
- • Familiarity with Microsoft Entra ID tenants and Conditional Access policy
- • Access to a non-production tenant and lab AD forest for the hands-on exercises
- • Global Administrator and Domain Admin rights in the lab environment
Delivery, Format and Logistics
Delivery Mode
Two-day live online workshop with live Q&A
Self-paced online with live Q&A sessions
What You'll Need
- Working knowledge of Active Directory Domain Services and Group Policy
- Familiarity with Microsoft Entra ID (formerly Azure AD) tenants and Conditional Access
- Access to a non-production tenant and lab AD forest for the hands-on labs
- Global Administrator and Domain Admin rights in the lab environment
What You'll Receive
- 16 hours of workshop instruction across five modules
- Hands-on labs in your own non-production tenant and lab AD forest
- A tailored cutover plan you build during the workshop, not a generic template
- Cutover risk register template mapping technical, regulatory and user-experience risks
- Federation rollback runbook with defined triggers, owners and recovery time objectives
- Decommissioning checklist for AD FS, Web Application Proxy and redundant domain controllers
- Post-cutover hygiene routines for hybrid joined devices, group writeback and seamless SSO
- Certificate of completion
Frequently Asked Questions
Not Ready to Enrol?
Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.
Early-bird rate — apply your promo code at checkout.
Secure payment via Stripe · Promo codes accepted
Next Intake
September 2026 — register your interest at educ4te.com
Format
Two-day live online workshop with live Q&A
Group & Enterprise Options
Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.
What's Included
- 16 hours of workshop instruction across five modules
- Hands-on labs in your own non-production tenant and lab AD forest
- A tailored cutover plan you build during the workshop, not a generic template
- Cutover risk register template mapping technical, regulatory and user-experience risks
- Federation rollback runbook with defined triggers, owners and recovery time objectives
- Decommissioning checklist for AD FS, Web Application Proxy and redundant domain controllers
- Post-cutover hygiene routines for hybrid joined devices, group writeback and seamless SSO
- Certificate of completion
Have questions about this course?