Case Study: Moving Large Enterprises from AD FS to Modern Authentication
At a glance
- Client type: Two large New Zealand enterprises
- Problem: Microsoft 365 authentication still depended on legacy AD FS designs and projects had stalled for years.
- Finding: AD FS application dependencies, relying party trusts, MFA, Conditional Access, and SSO all needed careful sequencing.
- Outcome: Modern Entra ID authentication adopted, with AD FS dependency removed or materially reduced.
- Related service: Security and identity / modern authentication
Problem
Two large New Zealand enterprises were still using AD FS as a major part of their Microsoft 365 authentication model. Both organisations wanted to move toward modern authentication with Entra ID, Conditional Access, and stronger MFA control.
The projects had stalled because AD FS was not only a sign-in component. It had accumulated application dependencies, relying party trusts, operational habits, and risk that had to be understood before cutover.
Context
Moving from AD FS to modern authentication is rarely just a switch in Microsoft 365. Existing applications, claims rules, MFA behaviour, SSO expectations, certificates, and operational ownership all matter.
The organisations needed a migration path that reduced AD FS dependency without breaking access for users or important applications.
For both organisations, AD FS had become difficult to operate, difficult to secure, and difficult to decommission. Internal teams had attempted to remove it several times over multiple years, but the work repeatedly stalled because of complexity, uncertainty, legacy application dependencies, and limited internal experience with federation services.
Internal teams understood that AD FS should eventually be removed, but decommissioning it had repeatedly been placed into the "too hard" category. Projects were started, paused, closed, and restarted because the risk of breaking authentication was high.
AD FS is not inherently bad. It served an important purpose for many enterprises adopting Microsoft 365 and federated identity.
What was accomplished
Our team reviewed the federation setup, mapped dependencies, and helped sequence the move to Entra ID authentication controls.
| Area | Work completed |
|---|---|
| Federation review | Assessed Microsoft 365 federation and AD FS configuration. |
| Application dependencies | Reviewed AD FS applications and relying party trusts before migration decisions. |
| MFA and access control | Aligned MFA and Conditional Access behaviour with the target Entra ID model. |
| SSO design | Supported Entra ID SSO adoption where it reduced reliance on AD FS. |
| Migration sequencing | Planned changes so authentication risk was reduced gradually and visibly. |
Key decisions and trade-offs
The main trade-off was speed versus confidence. A fast cutover could remove AD FS quickly, but it could also expose hidden relying party or claims dependencies.
The better approach was to identify dependencies first, move suitable services to Entra ID controls, and reduce the AD FS footprint in a controlled way.
Result
Both organisations moved forward after years of stalled progress. Modern authentication controls were adopted, and AD FS was either removed from the main Microsoft 365 path or materially reduced as a dependency.
The result was a cleaner identity model, stronger Conditional Access and MFA control, and less operational risk tied to legacy federation infrastructure.
The result was not just removal of servers. It was a shift to a cleaner and more secure identity operating model.
Conclusion
AD FS migrations fail when they are treated as a simple authentication switch.
This capability is valuable because many organisations know AD FS should be removed, but do not have the internal confidence or practical experience to complete the work safely.
A practical security and identity review should map the dependencies first, then move the organisation toward Entra ID authentication with enough control to avoid disruption.
Related
Book a discovery call
If any of this sounds familiar, book a quick call and have a chat with one of our senior security and identity consultants with 20+ years of enterprise IT experience.
This is a space where you will not hit first-line support or people without relevant enterprise experience.
Turn hidden access risk into clear, practical remediation.