MicrosoftMicrosoft Entra

    Entra Domain Services

    Managed Active Directory domain services in Azure — no domain controllers to run.

    Microsoft Entra Domain Services provides managed Active Directory domain services — domain join, group policy, LDAP, and Kerberos/NTLM authentication — in Azure, without deploying, managing, or patching domain controllers. It lets legacy applications that need traditional AD run in the cloud. Faltrox designs, deploys, and operates it as managed cloud directory services.

    Overview

    What Entra Domain Services is

    Many applications still depend on traditional Active Directory capabilities — domain join, group policy, LDAP, Kerberos — that Entra ID does not provide directly, and running domain controllers in the cloud is operational overhead. Microsoft Entra Domain Services solves this by providing those capabilities as a managed service in Azure.

    It offers managed domain services — domain join, group policy, LDAP, and Kerberos/NTLM authentication — that are compatible with traditional Active Directory, without you deploying, managing, patching, or securing domain controllers. It integrates with Entra ID so identities sync automatically, letting legacy and lift-and-shift applications run in Azure with the AD capabilities they need. Faltrox designs, deploys, and operates it as managed cloud directory services.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Legacy Applications

    Runs legacy apps that need traditional AD capabilities in Azure.

    02

    Lift-and-Shift Workloads

    Supports lift-and-shift workloads that depend on domain services.

    03

    Kerberos/NTLM & LDAP

    Provides Kerberos/NTLM authentication and LDAP without domain controllers.

    04

    Group Policy & Domain Join

    Domain join and group policy for Azure-based machines.

    05

    Fully Managed

    No domain controllers to deploy, manage, patch, or secure.

    06

    Entra ID Sync

    Identities sync automatically from Entra ID.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Enable

      Managed domain services are enabled in Azure — no domain controllers to deploy.

    2. 02

      Sync

      Identities and groups sync automatically from Entra ID into the managed domain.

    3. 03

      Join

      Azure-based machines domain-join and receive group policy from the managed domain.

    4. 04

      Authenticate

      Applications authenticate via Kerberos/NTLM and LDAP against the managed domain.

    5. 05

      Operate

      Faltrox designs, deploys, and operates it as managed cloud directory services.

    Capabilities

    Key capabilities

    Managed Domain Services

    Domain join, group policy, LDAP, and Kerberos/NTLM as a managed service in Azure.

    No Domain Controllers

    No domain controllers to deploy, manage, patch, or secure.

    AD Compatibility

    Compatible with traditional Active Directory for legacy applications.

    Entra ID Integration

    Identities and groups sync automatically from Entra ID.

    Lift-and-Shift Support

    Lets legacy and lift-and-shift apps run in Azure with the AD capabilities they need.

    LDAP & Kerberos/NTLM

    Provides LDAP and Kerberos/NTLM authentication for compatible apps.

    Group Policy

    Applies group policy to Azure-based domain-joined machines.

    High Availability

    Managed, highly available domain services in Azure.

    Works with

    Part of the platform

    Microsoft products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Microsoft Entra Domain Services for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What does Entra Domain Services provide that Entra ID doesn’t?

    Traditional Active Directory capabilities — domain join, group policy, LDAP, and Kerberos/NTLM authentication — that legacy applications depend on and Entra ID does not provide directly. It gives those capabilities as a managed service in Azure, so legacy apps can run in the cloud.

    02Do we have to run domain controllers?

    No — that is the point. It provides managed domain services without you deploying, managing, patching, or securing domain controllers, removing that operational overhead while still giving applications the AD capabilities they need.

    03How does it stay in sync with our identities?

    Identities and groups sync automatically from Entra ID into the managed domain, so the managed domain reflects your directory without separate management. Faltrox configures that integration.

    04What’s the main use case?

    Lift-and-shift and legacy applications that need traditional AD — domain join, group policy, LDAP, Kerberos — to run in Azure. It lets those apps move to the cloud without re-architecting them or standing up domain controllers.

    05How does Faltrox operate it?

    We design and deploy the managed domain, configure the Entra ID sync and group policy, and operate it — delivering managed cloud directory services so your legacy and lift-and-shift apps run securely in Azure.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us