Industry: Industrial Automation & Precision Manufacturing Region: Michigan, Ohio & Indiana, United States Engagement Model: White-label delivery for an MSP partner Core Services: Active Directory consolidation, identity cleanup, security & compliance remediation

Quick Summary

A multi-site industrial manufacturing company had grown through acquisitions for over two decades — and their Active Directory environment showed every scar of it. Three separate forests, 2,400+ user accounts for a workforce of 850, 1,800+ security groups, 120+ conflicting Group Policy Objects, and logon times stretching past five minutes. They’d already failed two security audits.

TechMonarch was brought in through the client’s MSP partner to redesign and consolidate the entire environment into a single, clean domain — without disrupting operations across three active manufacturing facilities. The result: onboarding dropped from 3–4 days to about 30 minutes, logon times fell under 30 seconds, and Domain Admins went from 27 members down to 4, fully documented.


Meet the Client

This client is an industrial automation and precision manufacturing company running production across three facilities, supporting roughly 850 employees on manufacturing execution systems, CAD platforms, and a stack of enterprise applications critical to daily operations.

Like a lot of companies that grow through acquisition, every merger left its mark on their IT environment. By the time they came to us, their Active Directory wasn’t just messy — it was fragile enough to be a genuine security and operational risk.

(Note: client details have been anonymized at the customer’s request. This is a real engagement delivered through one of TechMonarch’s MSP partners.)

The Challenge: Two Decades of Acquisitions, One Fragile Directory

Here’s what the environment actually looked like when we got involved:

Three AD forests, loosely stitched together. The trusts connecting them had never been properly rationalized. Nobody fully trusted them, either.

Way more accounts than employees. The primary domain alone had over 2,400 user accounts for a workforce of about 850. Most of the difference was duplicate, orphaned, undocumented service, and shared accounts — the kind of clutter nobody wants to be the one to clean up.

Security groups had spiraled out of control. More than 1,800 groups existed, many unused or named in ways that told you nothing about what they actually did. The OU structure followed no consistent logic — a patchwork of department, acquisition, and location that made basic troubleshooting a chore.

Group Policy was a minefield. 120+ GPOs, plenty of them conflicting or flat-out obsolete. At some sites, logon times stretched to 5–7 minutes — long enough for employees to notice and complain every single morning.

Permissions were essentially uncontrolled. File share ACLs had hundreds of entries each. The Domain Admins group had 27 members, some of them former employees who should have been removed long ago. The company had already failed two security audits because nobody could clearly explain who had access to what.

The infrastructure itself was inconsistent. Domain controllers spanned Server 2012, 2016, and 2019 across the three forests. Replication issues caused intermittent authentication outages. Onboarding a new employee took 3–4 days. Licensing costs were inflated by thousands of accounts nobody was using. And the MSP partner was burning hours just keeping the lights on, with little room to do anything proactive.

The client engaged TechMonarch through their MSP partner with one clear mandate: redesign, clean up, and consolidate the entire AD environment — without disrupting three live manufacturing facilities in the process.

The Solution: A Seven-Phase, Risk-Controlled AD Consolidation

We don’t do lift-and-shift on Active Directory projects like this. When the existing environment is this tangled, moving the mess just relocates the problem. So we rebuilt it properly, in phases.

Phase 1: Discovery & Assessment

Using Netwrix Auditor and PowerShell-based inventory, we documented everything: all users, groups, OUs, and GPOs; every permission; forest trusts, domain functional levels, domain controllers, and FSMO roles.

What we found:

  • 847 active employee accounts (out of 2,400+ total)
  • 156 service accounts
  • 89 shared/generic accounts
  • 1,300+ orphaned accounts
  • Roughly 60% of all security groups were unused or redundant

Stakeholder interviews also surfaced 45 line-of-business applications, 12 of which had direct AD dependencies — critical context for planning the migration waves later.

Phase 2: Target-State Design

We designed a single-forest, single-domain architecture built to actually make sense:

  • OU structure, organized by location with functional sub-OUs: Corporate (Grand Rapids), Ohio Facility, Indiana Facility, a dedicated Service Accounts OU, and a Disabled Objects OU
  • Group Policy, consolidated from 120+ down to 18 core GPOs covering baseline security, location-based policies, role-based user policies, and application-specific policies
  • A role-based security model using the AGDLP framework
  • Six new Server 2022 domain controllers (two per location), fully standardized
  • Azure AD Connect for hybrid identity, setting the foundation for future SSO and zero-trust initiatives

Phase 3: Cleanup & Preparation

Before touching production, we ran a full cleanup: disabling and quarantining orphaned users, consolidating duplicate accounts, rebuilding the service account inventory, eliminating generic shared accounts, removing stale DNS records and orphaned SIDs, and auditing file-share permissions department by department with actual data owners.

This gave us a genuinely clean baseline before a single production object moved.

Phase 4: New Domain Deployment

We built the new domain in parallel with the old one still running — fully patched and monitored Server 2022 DCs, a pre-built clean OU and GPO structure, RBAC security groups already created, and Azure AD Connect configured and tested.

Phase 5: Migration Execution

Using Quest Migration Manager with SID History, we migrated in controlled waves over six weeks:

  1. Wave 1: IT and pilot users
  2. Wave 2: Grand Rapids (≈400 users)
  3. Wave 3: Ohio (≈250 users)
  4. Wave 4: Indiana (≈200 users)
  5. Wave 5: Servers and service accounts

Every wave came with structured communication, authentication validation, application testing, and immediate hypercare support — nobody was left figuring things out on their own.

Phase 6: Legacy Domain Decommissioning

After two weeks of read-only validation, we removed the trusts, demoted the old domain controllers, fully decommissioned the legacy forests, and archived final compliance snapshots for the record.

Phase 7: Optimization & Knowledge Transfer

Post-migration, we put ongoing safeguards in place: automated inactive account cleanup, privilege escalation monitoring, GPO change tracking, and group membership auditing.

We also delivered complete documentation — AD architecture and replication design, a full GPO catalog, the RBAC security model, AD disaster recovery procedures, and daily operations SOPs — followed by structured knowledge transfer sessions with the MSP partner’s operations team.

The Results

  • Onboarding time cut from 3–4 days to ~30 minutes
  • Logon times improved from 5–7 minutes to under 30 seconds
  • User accounts reduced from 2,400+ to under 1,100
  • Domain Admins reduced from 27 members to 4, fully documented
  • Zero authentication outages since migration
  • ~60% reduction in AD-related operational workload
  • Significant licensing cost savings from eliminating 1,300+ unused accounts

Beyond the numbers, the new single-domain environment eliminated the trust complexity that had been silently causing outages for years, improved the outcome of subsequent security audits, and gave the organization a genuinely future-ready identity foundation for SSO and zero-trust initiatives.

Why the MSP Chose TechMonarch

The client’s MSP partner brought in TechMonarch for our experience with large-scale, multi-forest AD consolidations, a risk-controlled phased methodology, and the ability to preserve user access throughout the process using SID history and controlled cutovers.

Because the engagement was delivered white-label, the MSP retained full ownership of the client relationship while leaning on our deep network administration expertise behind the scenes. We insisted on pre-migration cleanup rather than a straight lift-and-shift, which meant the environment wasn’t just relocated — it was actually rebuilt.

Thorough documentation and structured knowledge transfer meant the MSP’s team could run the new environment confidently long after we closed the project — including the security and compliance reporting processes that had tripped up two prior audits.


Frequently Asked Questions

How do you consolidate multiple Active Directory forests without disrupting operations? By migrating in controlled waves rather than all at once. In this engagement, users were moved in five sequenced waves over six weeks using SID History to preserve access, with authentication validation and hypercare support built into every wave.

Why did this manufacturing company have over 2,400 AD accounts for 850 employees? The excess came from years of acquisitions — duplicate accounts, orphaned users, undocumented service accounts, and generic shared logins that had never been cleaned up across three merged environments.

What causes slow logon times in a legacy Active Directory environment? Conflicting or bloated Group Policy Objects, inconsistent domain controller versions, and unresolved replication issues are common culprits. In this case, consolidating 120+ GPOs down to 18 core policies and standardizing domain controllers cut logon times from 5–7 minutes to under 30 seconds.

Can an AD consolidation project like this be delivered white-label for an MSP’s clients? Yes — this entire engagement was delivered white-label, with TechMonarch handling the technical delivery while the MSP retained full ownership of the client relationship.


Planning a complex Active Directory project for one of your clients? TechMonarch delivers AD design, consolidation, and optimization projects for MSP partners across the United States through a white-label engagement model. Let’s talk.