Industry: Wealth Management / Financial Services Region: North Carolina, Georgia, Tennessee & Raleigh, United States Engagement Model: White-label delivery for an MSP partner Core Services: Hybrid identity architecture, Single Sign-On, MFA, compliance reporting

Quick Summary

A wealth management firm managing over $2.8B in assets and operating under strict SEC and FINRA oversight was running on a legacy identity setup that simply hadn’t kept pace with the cloud. Every one of their 320 employees had two separate identities — one on-prem, one cloud-only — with no true SSO, inconsistent MFA, and audit reporting that ate up 80+ hours every cycle.

TechMonarch was engaged through the firm’s MSP partner to design and roll out a full hybrid identity architecture with zero business disruption. The results: password reset tickets dropped 78% in the first month, audit reporting time fell from 80+ hours to under one hour, and onboarding went from roughly two hours to about 20 minutes.


Meet the Client

This client is a wealth management firm with offices across the Southeast, managing more than $2.8 billion in assets for a workforce of about 320 employees — all operating under the kind of regulatory scrutiny that comes with SEC and FINRA oversight.

As the firm adopted Microsoft 365, a cloud CRM, and a growing stack of SaaS platforms, their legacy on-prem Active Directory started showing its age. It simply wasn’t built for modern authentication, and the gap between “on-prem identity” and “cloud identity” was quietly turning into a security and compliance problem.

(Note: client details have been anonymized at the customer’s request. This is a real engagement delivered through one of TechMonarch’s MSP partners.)

The Challenge: Two Identities, Zero Visibility, and 80-Hour Audits

Here’s what was actually happening under the hood:

Every user had two identities. One on-prem AD account, one cloud-only Microsoft 365 account — with separate passwords for each. That meant confused users, and a steady stream of password reset tickets clogging up the helpdesk.

Onboarding and offboarding were a manual scramble. IT had to touch 8–9 separate systems for every new hire or departure, with real risk of missed deprovisioning when someone left the firm — a genuine security exposure in a regulated industry.

There was no real Single Sign-On. Microsoft 365, Salesforce, and core financial applications each required their own login. No unified experience, no centralized control.

MFA coverage was inconsistent. It was enforced in the cloud but not for on-prem access — leaving a gap that any security-conscious regulator would flag immediately.

Mobile device management was effectively broken, since there was no Azure AD identity to build it on.

Compliance reporting was brutal. Because logs were fragmented across systems, pulling together what auditors needed took more than 80 hours every single cycle.

Taken together, this wasn’t just an inconvenience — it was growing security and regulatory risk with no centralized identity visibility to manage it. The firm’s MSP partner brought in TechMonarch to design and implement a secure hybrid identity solution, with one non-negotiable: zero business disruption.

The Solution: A Full Hybrid Identity Architecture Built on Azure AD Connect

We designed and implemented a complete hybrid identity architecture centered on Azure AD Connect, unifying identity, enabling true SSO and MFA, and giving the firm real compliance visibility for the first time.

Key design components included:

  • Azure AD Connect with Password Hash Synchronization (PHS)
  • Password writeback and self-service password reset (SSPR)
  • Group and device synchronization
  • Hybrid Azure AD Join
  • Conditional Access and MFA policies
  • Azure AD–based SSO across all major SaaS applications
  • Azure AD Application Proxy for secure on-prem app access
  • Group-based Microsoft 365 licensing
  • Centralized auditing and reporting

Phase 1: Assessment & Planning

We audited all 320 users, 450+ groups, and the existing Microsoft 365 tenant, identified the authentication methods in use across every SaaS platform, and mapped compliance and audit requirements against the target architecture.

Phase 2: Architecture & Security Design

We selected Password Hash Synchronization for its resilience and performance, then designed SSO, MFA, Conditional Access, Hybrid Join, and a least-privilege access model. Just as important, we planned secure account matching upfront to avoid duplicating cloud users during sync.

Phase 3: Environment Preparation

We deployed a dedicated Server 2022 Azure AD Connect VM, cleaned up AD attributes using IdFix, standardized UPNs, verified domains in Azure AD, and prepared licensing and pilot security groups.

Phase 4: Pilot Deployment

The IT team and a group of selected users went first. We enabled synchronized identities, SSPR with writeback, Hybrid Azure AD Join, and SSO to Microsoft 365 and Salesforce — then monitored for two weeks. Zero critical issues.

Phase 5: Phased Organization Rollout

Headquarters rolled out first, followed by the satellite offices. Every user was converted to a synchronized identity, with continuous sync health monitoring and close helpdesk coordination throughout.

Phase 6: Advanced Security & Automation

Once the core rollout was stable, we layered in the harder security controls: enforcing MFA and Conditional Access policies, blocking legacy authentication outright, deploying Application Proxy for secure on-prem access, automating group-based licensing, and activating Azure AD Identity Protection and Privileged Identity Management (PIM).

Phase 7: Monitoring, Documentation & Handover

We enabled Azure AD Connect Health, built out audit dashboards and compliance reports, and delivered full runbooks, disaster recovery procedures, and admin training to the MSP’s team.

The Results

  • 78% reduction in password reset tickets in the first month
  • 12–15 helpdesk hours saved per week
  • True Single Sign-On across Microsoft 365, Salesforce, and core financial systems
  • Intelligent MFA enforcement with device-based and location-based policies
  • Audit reporting time cut from 80+ hours to under 1 hour
  • Onboarding time reduced from ~2 hours to ~20 minutes
  • Instant, reliable offboarding across every cloud and on-prem system
  • Fully functional Intune-based mobile device management
  • ~$18K in annual cost savings from reduced MSP support and admin workload

Beyond the metrics, the firm now has a genuinely secure foundation for continued cloud adoption — and, just as importantly, a much easier story to tell their regulators.

Why the MSP Chose TechMonarch

The firm’s MSP partner selected TechMonarch for our deep expertise in hybrid identity for regulated industries, a strong grasp of FINRA, SEC, and audit controls, and a security-first architecture built on least-privilege access and layered controls.

Delivered white-label, the engagement let the MSP retain full ownership of the client relationship while leaning on our Microsoft 365 identity expertise behind the scenes. We ran a low-risk, phased rollout with real pilot testing before touching the wider organization, and we kept a heavy focus on user experience — not just technical success.

Complete documentation and structured knowledge transfer meant the MSP’s team could confidently own the environment going forward, including the audit and compliance reporting processes that used to take 80+ hours per cycle.


Frequently Asked Questions

What is hybrid identity, and why does it matter for financial services firms? Hybrid identity connects an organization’s on-premise Active Directory with cloud services like Microsoft 365 through tools like Azure AD Connect, giving users a single identity and password across both environments. For regulated firms, it also centralizes the authentication logs and access controls that auditors need to review.

How much can Single Sign-On reduce helpdesk workload? In this engagement, implementing SSO and self-service password reset with writeback cut password reset tickets by 78% in the first month and saved the helpdesk 12–15 hours per week.

How do you implement hybrid identity without disrupting a live financial services organization? Through a phased rollout: starting with an IT and pilot user group, monitoring for issues before expanding further, then rolling out by office location with continuous sync health monitoring and helpdesk support at every stage.

Can hybrid identity projects like this be delivered white-label for an MSP’s clients? Yes — this entire engagement was delivered white-label, with TechMonarch handling the design and technical implementation while the MSP retained full ownership of the client relationship.


Planning a hybrid identity project for one of your clients? TechMonarch delivers white-label hybrid identity, cloud, and security solutions for MSPs across the United States. Let’s talk.