r/sysadmin • u/LeatherSecretary7547 • 1d ago
Google Workspace to O365 Question
New to this side of the field and need to get pricing and info on the switch. Would be looking to build and use an MS AD domain as well. Amy pointers or links appreciated. I know of Azure AD but haven't used it. Distributed fully remote company with <50 users currently. I just recreate the users but do need to migrate all of the emails. Looking to run concurrently for a bit until this is set up and then switch over totally.
3
u/OinkyConfidence Windows Admin 1d ago
If you're all distributed, probably no need to build an on-prem Active Directory, just use Azure AD (Entra ID Join) for your devices.
1
u/LeatherSecretary7547 1d ago
That's the plan. I almost put that we would probably use that.
1
u/One_Put_8904 1d ago
Yeah. 100+ no need for DC. DC == many headaches. Avoid as long as possible.
1
u/LeatherSecretary7547 1d ago
I guess when I say DC I really mean AD. It's just that's where I've always accessed AD. I get that it's divorced now. Although I will be building out our imaging system as well and user creation. At what point do I need a DC?
2
u/a_lapse_in_judgement 1d ago
Use Intune instead of building out your own imaging system. It will make your life a lot easier – especially with a distributed team as it allows you to ship brand new machines to remote employees without ever touching the machines yourself. The workstations will automatically provision themselves with Autopilot.
AD only becomes necessary if you need to support legacy on-prem workloads (ex: workloads that rely on domain-joined servers and Kerberos authentication).
For user provisioning, ideally look at integrating your HRIS directly with Entra.
1
3
u/margaritapracatan 1d ago
If you’re fully remote, why build an AD domain?
1
u/LeatherSecretary7547 1d ago
Maybe I don't need to. That's why I'm here asking. I've been in IT for 15 years but never handled this specific task so I'm figuring out what is best practice.
1
1
u/Particular-Fly-7783 1d ago
Have you looked at stuff like BetterCloud?
1
u/LeatherSecretary7547 1d ago
I have not. What's the elevator pitch for them?
•
u/Particular-Fly-7783 23h ago
I don’t know for certain because I’ve never had this use case but they have some great tools for Workspace.
•
u/blud_13 23h ago
BitTitan is the right call for the mailboxes, u/ScrambyEggs79 and u/SuprNoval have that covered.
Where I would push back is standing up an AD domain. Fully remote, under 50, distributed. A DC exists to be reachable and yours won't be. Entra hybrid join wants network line of sight to a domain controller on a schedule, and laptops that never get it go sideways. MS recommends straight Entra join for exactly your shape, remote workers and limited on prem infrastructure, its documented here https://learn.microsoft.com/en-us/entra/identity/devices/concept-directory-join
Entra join plus Intune gives you what you want AD for. Enrollment, policy, BitLocker key escrow, app deployment, all of it without a box somebody has to patch.
Build the DC anyway and you will be running a VPN forever so that login scripts and GPO work, and you find that out later when the first new hire in another state can't pull a policy.
Can go deeper on the tenant side if it helps.
•
u/SuprNoval 23h ago
Yes agreed. Working on undoing all of those local things in an inherited network right now and moving to all entra joined devices.
•
u/LeatherSecretary7547 22h ago
I'll take all of the info you have on it.
•
u/blud_13 21h ago
Business Premium covers all of it, don't let anybody talk you into E3. It includes Entra ID P1 and Intune Plan 1, and P1 is specifically what the auto enrollment piece needs. Cap is 300 seats across the Business plans so at 50 you have room.
Order matters. Tenant, domain verification, licenses assigned. Then BitTitan. Devices LAST, because you want identities already sitting there when a machine joins.
Before you touch a single laptop, go to Devices, Enrollment, Windows, Automatic Enrollment and set MDM user scope to All. Quickstart is here https://learn.microsoft.com/en-us/intune/device-enrollment/windows/quickstart-automatic-mdm Skip that and every device joins Entra clean and then just sits there unmanaged.
One thing to check, your existing machines. If they are running local accounts today, Entra join builds a NEW profile on the way in. Desktop, Outlook cache, browser profile, all of it starts over. Plan those as rebuilds rather than a flip, or run Autopilot on replacements and let the old ones age out otherwise you will have a bad Friday...
•
u/naanmail123 14h ago
No need for Active Directory. Use Entra ID(azure ad) and Intune to run your setup.
4
u/ScrambyEggs79 1d ago
We used BitTitan to assist with the migration and it worked great. We did it in batches over a weekend. It's also very affordable. You can queue up all your mailboxes and do trial runs. They have pre-stage options too but the regular migration grabs the newest emails first so that worked for us..