Somewhere in your server room, or in a rack you rent, two domain controllers are doing less than they have ever done. Your mail left years ago. Intune manages the laptops. Users sign in against Entra all day and touch the domain only when a file share or an old application asks. The question this series answers is whether those two machines can go, what has to be true first, and in what order. The answer for most small and mid-size estates is yes, in stages, on your own calendar, mostly with licensing you already pay for.
What zero actually means
Before anything else, be precise about the finish line, because there are three of them and most arguments about this migration are really arguments about which one is meant. Zero on-prem domain controllers means no DC in your buildings, though a directory might still run somewhere on your behalf. Zero self-hosted AD means nobody on your team patches a domain controller ever again, which a managed domain service technically satisfies. Zero AD means there is no Active Directory anywhere in your world: no Kerberos realm, no LDAP endpoint, no domain to join. Entra is the only identity system you have.
This series aims at the third line and says so honestly when an estate can only reach the first. The distinction matters because there is a popular shortcut that reaches the middle line and gets sold as the finish: move the directory into a managed service, power off the local DCs, declare victory. You have not eliminated the dependency, you have changed who patches it. Later in the series I take that option apart properly. For now, hold the definition: when I say zero, I mean no directory at all, and every stage is measured against that.
The estate this series carries
Abstract advice about AD migration is nearly worthless, because the whole problem is particular. So this series walks one concrete company from start to finish, the same estate in every article, and everything I recommend gets tested against it. CatSnackJack is 140 people, one office plus remote workers, on Microsoft 365 Business Premium. One forest, one domain, catsnackjack.com, with two domain controllers, DC01 and DC02, on Windows Server 2019. The DCs predate the company’s certificate authority rebuild, which is why they run an older platform than the CA estate; that is ordinary, and nothing in this series requires upgrading them on the way out. Entra Connect runs password hash sync with seamless SSO. Every Windows 11 laptop is Intune-managed and hybrid joined. Mail is Exchange Online only, with the usual leftovers in the schema and nothing in production.
Then the part that actually pins the domain. A file server, FS01, holds departmental shares and redirected folders. An NPS box, NPS01, does 802.1X for the Wi-Fi with device certificates from the internal issuing CA. A line-of-business application called SnackTrack runs against SQL Server 2019 on SQL01 using Windows authentication, and the vendor is not returning calls. Two multifunction printers, MFP-01 and MFP-02, scan to \\FS01\scans as svc-scan and look up addresses over LDAP. None of that is exotic. Every one of those items is a reason the domain cannot be turned off today, every one has a documented disposition, and the whole set is small enough to walk. If your estate looks like this, the series was written for you. If it looks like this plus four other things, the method still holds and the four other things get the same treatment.
Seven stages, and why measurement is first
The path is seven stages, and the order is a dependency statement, not a schedule. Stage 0 is measurement: finding out what actually authenticates against your domain, with instruments rather than recollection, because every failed migration I have seen started with a dependency list built from memory. Stage 1 is identity: transferring a pilot wave of users to cloud-managed, verifying them, then cutting the sync for the tenant, which converts everyone else in the same act. Stage 2 is devices: retiring hybrid join in favor of Entra join, on the hardware refresh rhythm wherever possible, because there is no supported in-place conversion and pretending otherwise wastes months. Stage 3 moves the services: files, print, certificates, and Wi-Fi each go to a replacement that no longer needs a directory behind it. Stage 4 confronts whatever refuses to move, worked down a ladder that ends in an honest admission when an application genuinely cannot leave. Stage 5 is proof: a census of everything the domain controllers are still quietly doing, which is the article that stops you from powering off too early. Stage 6 is the decommission itself, with an observation window, a deliberate order of operations, and insurance.
The stages are pausable by design, and the order is a dependency statement rather than a schedule: do Stage 1 in March and Stage 3 in September if that is what the business allows. Each one ends in a gate, a short set of checkable facts that must be true before the next stage starts, and between gates you can stop for as long as you need. A real company does this work around its actual life: budget cycles, a busy season, a hardware refresh that was already planned. What you should not do is reorder the stages. Devices before identity means users whose sign-in model changes twice. Services before measurement means migrating a file server while an application you forgot still authenticates through the domain. The order exists because each stage removes the risk from the one after it.
What it costs, and what you already own
Here is the licensing reality. Business Premium, at its current 22 dollars a seat, carries the core path end to end. Entra ID P1 is in it, which covers Conditional Access, Entra join with automatic Intune enrollment, and Connect Health while you still need it. Windows Hello with cloud Kerberos trust, the mechanism that keeps on-prem file access working from cloud-joined laptops during the transition, requires no premium license at all. Windows LAPS backing up to Entra is free. Group Policy analytics comes with the Intune license you have. Azure Files identity authentication carries no per-user charge, and Universal Print is included with a pooled hundred jobs per license per month, which at 140 seats is more than an SMB prints.
What sits above that line is short. Cloud PKI is a 2 dollar add-on below E5, and since July it is simply included at E5, for the estates where device certificates survive the move. Risk-based Conditional Access and the rest of the P2 posture is a security upgrade, not a migration requirement; nothing in this path needs it, and I will say so again when we reach the stages where a vendor would love you to believe otherwise. Private Access at 5 dollars, or the Entra Suite at 12, enters only if you retire a VPN along the way. The one real unbudgeted line item is Wi-Fi authentication, because Microsoft ships no cloud RADIUS at all, and the honest answers there are a third-party service or a deliberate simplification of the wireless design. That absence is load-bearing and Stage 3 treats it with the respect it deserves.
Against those numbers, put what the domain costs you now: two Windows Server licenses, two VMs of compute, storage, backup, and patching, the Connect server, and the audit surface of Active Directory itself, which carries that burden precisely because every attack toolkit ever written assumes it is there. The hard savings are low four figures a year at this size. The real return is attention, and the shrinking of the thing you have to defend.
One clock that is not yours
This path has no deadline, with one narrow exception worth knowing before it arrives. On September 30, 2026, Microsoft enforces a minimum version on Entra Connect Sync, and synchronization stops on anything older than 2.5.79.0 until it is upgraded. If your Connect server has been quietly doing its job unattended since 2023, that is the date it stops. The fix is an upgrade you should do regardless, and the deeper point is the one to sit with: the sync engine you are planning to retire is itself a maintained product with version floors and enforcement dates. Keeping hybrid forever was never the neutral, zero-effort default it pretends to be.
Who this series is not for
Some estates cannot reach zero, and it serves nobody to pretend otherwise. If you still run mailboxes on an Exchange Server, that server requires Active Directory and is supported to keep requiring it well into the next decade; finish the mail migration first, this series waits. If your directory is multi-forest or lives on trusts, Entra has no concept of a trust, and the collapse into one forest is its own project that precedes this one. If you run an air-gapped or OT network that needs Windows authentication inside the gap, a domain controller stays inside the gap, and the honest goal becomes shrinking the domain rather than ending it. And if Stage 0 turns up a long list of applications that genuinely cannot move, not merely applications nobody has touched, then what this series gives you is an accurate map of a migration you should not yet start. That is worth more than optimism.
It is also worth saying plainly, because the marketing around this topic will not: Active Directory is not dying. Microsoft shipped a substantial feature wave for it in Windows Server 2025 and documents an AD-minimized posture as a durable end state. What is being demolished, on Microsoft’s own published clock, is the protocol floor that frozen applications stand on. NTLM is deprecated and its oldest version is already gone from current Windows. So the pressure on your estate is real, but it is specific: the untouchable application’s position gets worse every year, while the directory itself would happily run forever. Understanding which of those two clocks applies to you is most of the strategy.
Active Directory is not going away. The floor under your frozen applications is. Those are different clocks, and only one of them is yours to manage.
To Stage 0
CatSnackJack enters the path where most companies do: convinced it knows what depends on the domain, and wrong in ways that will surface at the worst moment unless they are measured now. The next article is Stage 0, where we stop guessing. The domain controllers keep a record of every client that authenticates against them, every legacy bind a printer makes, every service ticket an application requests. You do not need to remember your dependencies. You need to turn on the instruments and read them, and that is where the work begins.
AD to Azure
Next: [AD 2] What Is Actually Pinning Your Domain ›




