How to Move a Small Business from Local AD to Microsoft 365 and Intune
For small businesses, running a local Active Directory (AD) server often becomes unnecessary once everything shifts to the cloud. With Microsoft 365 (O365), Microsoft Entra ID (Azure AD), and Intune, you can manage users and devices without on-premises infrastructure.
Here’s a step-by-step guide on how to set this up and avoid common pitfalls.
Step 1: Prepare Your Environment
- Verify that you have Microsoft 365 Business Premium or licenses that include Intune.
- Assign the Intune licenses to your users in the Microsoft 365 admin center.
- In the Intune admin center, go to:
Devices > Enroll devices > Automatic Enrollment.- Enable MDM user scope for all (or specific) users.
- This ensures devices automatically enroll into Intune when they join Entra ID.
Step 2: Join Windows 11 Devices to Entra ID
- On each Windows 11 computer, go to:
Settings > Accounts > Access work or school > Connect. - Sign in with the user’s Microsoft 365 account.
- The device will join Entra ID. If automatic MDM enrollment is enabled, it should also register in Intune.
Step 3: Enroll Existing Devices
If the device doesn’t show up in Intune:
- Install the Company Portal app from the Microsoft Store.
- Sign in with the user’s Microsoft 365 account.
- Follow the prompts to register and enroll the device.
👉 This is the recommended way to enroll already-joined or BYOD devices.
Step 4: When to Reset a Device
Sometimes Intune enrollment won’t trigger properly on existing machines. In those cases:
- Back up user data.
- Reset the device (wipe and reinstall).
- Join the device fresh to Entra ID.
A clean reset often avoids lingering policies or enrollment errors.
Step 5: Future Devices
Once the setup is complete:
- New Windows devices that are joined to Entra ID will automatically enroll in Intune.
- This gives you centralized management, compliance policies, and app deployment out of the box.
Extra Resources
- Microsoft Docs: Automatic enrollment
- YouTube tutorials on Intune setup
- Community forums like Reddit’s r/Intune for troubleshooting tips.
Final Thoughts
Migrating a small business from local AD to cloud-based Microsoft 365 is very doable. The key is to:
- Enable automatic MDM enrollment.
- Use the Company Portal app for existing devices.
- Reset devices if enrollment issues persist.
Once configured, Intune and Entra ID provide a simple, secure, and scalable solution for managing your business devices without on-prem servers.

