Active Directory has quietly run the identity backbone of small businesses for roughly twenty years: logins, permissions, group policies, that one shared printer that only works if you restart the spooler, all of it tied to a domain controller sitting in a server rack somewhere on-site, or, let's be honest, in that same closet from our first article. Moving away from it is one of the most valuable upgrades a small business can make. It is also one of the easiest projects to get wrong if it gets rushed into a single frantic weekend, which is a mistake made by IT people far more experienced than whoever inherited this job at your company, so don't feel singled out.
If your business still runs on-prem Active Directory, that's not a sign you're behind the times. It's a sign the system worked well enough, for long enough, that nobody had a burning reason to touch it. That's actually a compliment to whoever set it up originally. The reason to move now isn't that the old way was wrong. It's that the new way is meaningfully better, cheaper to maintain, and doesn't depend on one physical box in your building staying alive forever.
The domain controller is usually one of the oldest, least-monitored pieces of infrastructure in the entire building, and it's a single point of failure for literally every login in the company, from the front desk computer to the owner's laptop. Cloud identity platforms remove that physical dependency, add modern security features like conditional access and multi-factor authentication essentially by default, and quietly retire a piece of hardware that was going to need replacing eventually regardless.
For most staff, the login experience barely changes at all, which is genuinely the goal. Nobody wants forty confused emails asking why the computer looks different. What does change is where identity actually lives, how permissions get managed, and how new devices and applications get connected going forward. This is exactly why the migration touches so much more than it initially appears to: printers, line-of-business software, VPN access, and shared drives may all have been quietly leaning on the old domain in ways absolutely nobody wrote down, including, almost certainly, the aforementioned Dave.
It's almost never the core migration itself that causes real trouble. It's the forgotten dependency: a piece of accounting software quietly authenticating against the old domain in a way nobody documented, a network printer configured a decade ago by someone who's since left, a VPN appliance that never got updated when everything else did. This is precisely why the inventory step matters more than any other single part of the process, even though it's the least exciting part and the part everyone is most tempted to rush through.
There's a persistent belief that this kind of migration is a heroic, sleep-deprived weekend project, and that belief is exactly how bad weekends happen. For a business with a few dozen users and a handful of line-of-business applications, a properly planned migration typically runs a few calm weeks from inventory to full cutover, not sixty caffeinated hours. If your migration plan involves the phrase "we'll just do it all Saturday night," that's the moment to slow down, not speed up.
Staff anxiety during an identity migration usually comes from uncertainty, not from the actual technical change. A short, plain-English heads-up, "your login will look the same, some behind-the-scenes things are changing, here's who to call if anything looks weird", prevents ninety percent of the confused messages you'd otherwise get on cutover day.
For most small businesses, expect a few weeks of calm, methodical work rather than a single dramatic event. The inventory and dependency-mapping phase alone is often worth more than the technical cutover itself, because it's where all the surprises get found while there's still time to plan around them instead of firefighting them live.
We start every identity migration by mapping what you actually have today, dependencies and mystery printers included, before touching anything. It's slower up front and considerably less dramatic everywhere else, which is exactly the trade we'd make every time.