
Industry: Industrial Automation & Precision Manufacturing Region: Michigan, Ohio & Indiana, United States Engagement Model: White-label delivery for an MSP partner Core Services: Active Directory consolidation, identity cleanup, security & compliance remediation
A multi-site industrial manufacturing company had grown through acquisitions for over two decades — and their Active Directory environment showed every scar of it. Three separate forests, 2,400+ user accounts for a workforce of 850, 1,800+ security groups, 120+ conflicting Group Policy Objects, and logon times stretching past five minutes. They’d already failed two security audits.
TechMonarch was brought in through the client’s MSP partner to redesign and consolidate the entire environment into a single, clean domain — without disrupting operations across three active manufacturing facilities. The result: onboarding dropped from 3–4 days to about 30 minutes, logon times fell under 30 seconds, and Domain Admins went from 27 members down to 4, fully documented.
This client is an industrial automation and precision manufacturing company running production across three facilities, supporting roughly 850 employees on manufacturing execution systems, CAD platforms, and a stack of enterprise applications critical to daily operations.
Like a lot of companies that grow through acquisition, every merger left its mark on their IT environment. By the time they came to us, their Active Directory wasn’t just messy — it was fragile enough to be a genuine security and operational risk.
(Note: client details have been anonymized at the customer’s request. This is a real engagement delivered through one of TechMonarch’s MSP partners.)
Here’s what the environment actually looked like when we got involved:
Three AD forests, loosely stitched together. The trusts connecting them had never been properly rationalized. Nobody fully trusted them, either.
Way more accounts than employees. The primary domain alone had over 2,400 user accounts for a workforce of about 850. Most of the difference was duplicate, orphaned, undocumented service, and shared accounts — the kind of clutter nobody wants to be the one to clean up.
Security groups had spiraled out of control. More than 1,800 groups existed, many unused or named in ways that told you nothing about what they actually did. The OU structure followed no consistent logic — a patchwork of department, acquisition, and location that made basic troubleshooting a chore.
Group Policy was a minefield. 120+ GPOs, plenty of them conflicting or flat-out obsolete. At some sites, logon times stretched to 5–7 minutes — long enough for employees to notice and complain every single morning.
Permissions were essentially uncontrolled. File share ACLs had hundreds of entries each. The Domain Admins group had 27 members, some of them former employees who should have been removed long ago. The company had already failed two security audits because nobody could clearly explain who had access to what.
The infrastructure itself was inconsistent. Domain controllers spanned Server 2012, 2016, and 2019 across the three forests. Replication issues caused intermittent authentication outages. Onboarding a new employee took 3–4 days. Licensing costs were inflated by thousands of accounts nobody was using. And the MSP partner was burning hours just keeping the lights on, with little room to do anything proactive.
The client engaged TechMonarch through their MSP partner with one clear mandate: redesign, clean up, and consolidate the entire AD environment — without disrupting three live manufacturing facilities in the process.
We don’t do lift-and-shift on Active Directory projects like this. When the existing environment is this tangled, moving the mess just relocates the problem. So we rebuilt it properly, in phases.
Using Netwrix Auditor and PowerShell-based inventory, we documented everything: all users, groups, OUs, and GPOs; every permission; forest trusts, domain functional levels, domain controllers, and FSMO roles.
What we found:
Stakeholder interviews also surfaced 45 line-of-business applications, 12 of which had direct AD dependencies — critical context for planning the migration waves later.
We designed a single-forest, single-domain architecture built to actually make sense:
Before touching production, we ran a full cleanup: disabling and quarantining orphaned users, consolidating duplicate accounts, rebuilding the service account inventory, eliminating generic shared accounts, removing stale DNS records and orphaned SIDs, and auditing file-share permissions department by department with actual data owners.
This gave us a genuinely clean baseline before a single production object moved.
We built the new domain in parallel with the old one still running — fully patched and monitored Server 2022 DCs, a pre-built clean OU and GPO structure, RBAC security groups already created, and Azure AD Connect configured and tested.
Using Quest Migration Manager with SID History, we migrated in controlled waves over six weeks:
Every wave came with structured communication, authentication validation, application testing, and immediate hypercare support — nobody was left figuring things out on their own.
After two weeks of read-only validation, we removed the trusts, demoted the old domain controllers, fully decommissioned the legacy forests, and archived final compliance snapshots for the record.
Post-migration, we put ongoing safeguards in place: automated inactive account cleanup, privilege escalation monitoring, GPO change tracking, and group membership auditing.
We also delivered complete documentation — AD architecture and replication design, a full GPO catalog, the RBAC security model, AD disaster recovery procedures, and daily operations SOPs — followed by structured knowledge transfer sessions with the MSP partner’s operations team.
Beyond the numbers, the new single-domain environment eliminated the trust complexity that had been silently causing outages for years, improved the outcome of subsequent security audits, and gave the organization a genuinely future-ready identity foundation for SSO and zero-trust initiatives.
The client’s MSP partner brought in TechMonarch for our experience with large-scale, multi-forest AD consolidations, a risk-controlled phased methodology, and the ability to preserve user access throughout the process using SID history and controlled cutovers.
Because the engagement was delivered white-label, the MSP retained full ownership of the client relationship while leaning on our deep network administration expertise behind the scenes. We insisted on pre-migration cleanup rather than a straight lift-and-shift, which meant the environment wasn’t just relocated — it was actually rebuilt.
Thorough documentation and structured knowledge transfer meant the MSP’s team could run the new environment confidently long after we closed the project — including the security and compliance reporting processes that had tripped up two prior audits.
How do you consolidate multiple Active Directory forests without disrupting operations? By migrating in controlled waves rather than all at once. In this engagement, users were moved in five sequenced waves over six weeks using SID History to preserve access, with authentication validation and hypercare support built into every wave.
Why did this manufacturing company have over 2,400 AD accounts for 850 employees? The excess came from years of acquisitions — duplicate accounts, orphaned users, undocumented service accounts, and generic shared logins that had never been cleaned up across three merged environments.
What causes slow logon times in a legacy Active Directory environment? Conflicting or bloated Group Policy Objects, inconsistent domain controller versions, and unresolved replication issues are common culprits. In this case, consolidating 120+ GPOs down to 18 core policies and standardizing domain controllers cut logon times from 5–7 minutes to under 30 seconds.
Can an AD consolidation project like this be delivered white-label for an MSP’s clients? Yes — this entire engagement was delivered white-label, with TechMonarch handling the technical delivery while the MSP retained full ownership of the client relationship.
Planning a complex Active Directory project for one of your clients? TechMonarch delivers AD design, consolidation, and optimization projects for MSP partners across the United States through a white-label engagement model. Let’s talk.