Entra Domain Services
Managed Active Directory domain services in Azure — no domain controllers to run.
Microsoft Entra Domain Services provides managed Active Directory domain services — domain join, group policy, LDAP, and Kerberos/NTLM authentication — in Azure, without deploying, managing, or patching domain controllers. It lets legacy applications that need traditional AD run in the cloud. Faltrox designs, deploys, and operates it as managed cloud directory services.
Overview
What Entra Domain Services is
Many applications still depend on traditional Active Directory capabilities — domain join, group policy, LDAP, Kerberos — that Entra ID does not provide directly, and running domain controllers in the cloud is operational overhead. Microsoft Entra Domain Services solves this by providing those capabilities as a managed service in Azure.
It offers managed domain services — domain join, group policy, LDAP, and Kerberos/NTLM authentication — that are compatible with traditional Active Directory, without you deploying, managing, patching, or securing domain controllers. It integrates with Entra ID so identities sync automatically, letting legacy and lift-and-shift applications run in Azure with the AD capabilities they need. Faltrox designs, deploys, and operates it as managed cloud directory services.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Legacy Applications
Runs legacy apps that need traditional AD capabilities in Azure.
Lift-and-Shift Workloads
Supports lift-and-shift workloads that depend on domain services.
Kerberos/NTLM & LDAP
Provides Kerberos/NTLM authentication and LDAP without domain controllers.
Group Policy & Domain Join
Domain join and group policy for Azure-based machines.
Fully Managed
No domain controllers to deploy, manage, patch, or secure.
Entra ID Sync
Identities sync automatically from Entra ID.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Enable
Managed domain services are enabled in Azure — no domain controllers to deploy.
- 02
Sync
Identities and groups sync automatically from Entra ID into the managed domain.
- 03
Join
Azure-based machines domain-join and receive group policy from the managed domain.
- 04
Authenticate
Applications authenticate via Kerberos/NTLM and LDAP against the managed domain.
- 05
Operate
Faltrox designs, deploys, and operates it as managed cloud directory services.
Capabilities
Key capabilities
Managed Domain Services
Domain join, group policy, LDAP, and Kerberos/NTLM as a managed service in Azure.
No Domain Controllers
No domain controllers to deploy, manage, patch, or secure.
AD Compatibility
Compatible with traditional Active Directory for legacy applications.
Entra ID Integration
Identities and groups sync automatically from Entra ID.
Lift-and-Shift Support
Lets legacy and lift-and-shift apps run in Azure with the AD capabilities they need.
LDAP & Kerberos/NTLM
Provides LDAP and Kerberos/NTLM authentication for compatible apps.
Group Policy
Applies group policy to Azure-based domain-joined machines.
High Availability
Managed, highly available domain services in Azure.
Works with
Part of the platform
Microsoft products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Microsoft Entra Domain Services for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What does Entra Domain Services provide that Entra ID doesn’t?
Traditional Active Directory capabilities — domain join, group policy, LDAP, and Kerberos/NTLM authentication — that legacy applications depend on and Entra ID does not provide directly. It gives those capabilities as a managed service in Azure, so legacy apps can run in the cloud.
02Do we have to run domain controllers?
No — that is the point. It provides managed domain services without you deploying, managing, patching, or securing domain controllers, removing that operational overhead while still giving applications the AD capabilities they need.
03How does it stay in sync with our identities?
Identities and groups sync automatically from Entra ID into the managed domain, so the managed domain reflects your directory without separate management. Faltrox configures that integration.
04What’s the main use case?
Lift-and-shift and legacy applications that need traditional AD — domain join, group policy, LDAP, Kerberos — to run in Azure. It lets those apps move to the cloud without re-architecting them or standing up domain controllers.
05How does Faltrox operate it?
We design and deploy the managed domain, configure the Entra ID sync and group policy, and operate it — delivering managed cloud directory services so your legacy and lift-and-shift apps run securely in Azure.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us