Identity Architecture

Mattia Grandi: experience and deep-dives in complex identity change without losing operational control.

I work as a Senior Identity Consultant at Impresoft 4ward and focus on identity architecture in complex scenarios: tenant-to-tenant migrations, M&A integration, IAM modernization, PIM governance, and hybrid transformations across Microsoft ecosystems, including Active Directory (AD) and on-premise/on premise environments.

Tenant-to-tenant migrationsM&A identity integrationHybrid IAM and Privileged IdentityActive Directory (AD), Entra ID, PIM, ADFS
Prefer to review expertise first

Special focus

Programs where identity is business-critical, not just technical.

Migrations, mergers, separation scenarios, hybrid estates, and governance hardening need clear architecture decisions and disciplined execution.

My contribution spans strategy, execution governance, and post go-live operational stabilization, with specific focus on IAM, PIM, Active Directory, and privileged identity in on-premise and hybrid contexts.

  • Identity strategy with delivery depth
  • Strong Microsoft ecosystem specialization
  • Focus on risk, continuity, and governance

Selected certifications

About

Identity programs shaped around risk, continuity, and execution.

I work as a Senior Identity Consultant at Impresoft 4ward and focus on identity architecture in transformation scenarios where operational continuity, governance, and access control must stay solid during complex change.

My core scope covers IAM, PIM, Active Directory, and hybrid Microsoft environments, with practical focus on migrations, M&A integrations, and post go-live stabilization.

Personal profile: https://www.mattiagrandi.it

View full profile

Expertise

Architecture themes and delivery areas.

On the home page you get a visual summary of my core areas; the dedicated page contains the full detail.

Guided transformations

Identity migrations and transitions planned to reduce operational impact and access risk.

Architecture and governance

Design of IAM models, privileged access, and controls that stay sustainable after go-live.

Microsoft platforms

Operational focus on Entra ID, PIM, Active Directory, and enterprise hybrid scenarios.

Case Studies

Selected personal projects

Personal identity projects focused on practical architecture outcomes, operational resilience, and measurable security improvements.

Centralized Active Directory infrastructure for a construction company

Context

Construction scaffolding manufacturer with around 100 employees including office staff, engineers, technicians and installers. Office PCs were disconnected from the production environment and managed independently.

Challenge

Design and deploy a structured Active Directory environment, centralize authentication, connect every department and introduce consistent governance for users, groups and shared resources.

Outcome

Delivered a modern domain infrastructure with standardized policies, centralized management, secure access control and a scalable foundation for future growth.

Microsoft 365 migration for a multi-store furniture retailer

Context

Furniture retailer with four stores and around 50 employees using local email services and unmanaged Windows devices.

Challenge

Provision a new Microsoft 365 tenant, select the appropriate Business Premium licensing, migrate mailboxes, configure Microsoft Entra ID, enroll devices into Intune and introduce basic endpoint management with minimal business disruption.

Outcome

Migration completed in approximately one month, including planning, pilot, mailbox migration, device onboarding and user training. The company gained secure cloud email, centralized identity management and modern device administration.

Identity security hardening with SSO, MFA and Conditional Access

Context

Regional professional services organization with approximately 120 users working across headquarters and remote offices, with inconsistent sign-in policies and uneven account protection.

Challenge

Implement secure Single Sign-On, enforce MFA for all high-risk and admin sign-ins, and introduce Conditional Access policies by user risk, device compliance and location, without blocking daily operations.

Outcome

Delivered a phased security baseline with SSO coverage on critical apps, MFA enforcement on privileged paths, and Conditional Access guardrails that reduced risky sign-ins while keeping user friction low.

Field Guides

Notes from the field

How-tos, real-world troubleshooting, and field notes from identity architecture programs.

Active DirectoryDelegation

GPO Security Filtering vs Delegation in Active Directory: critical differences for audits and hardening

Practical guide to GPO Security Filtering and Delegation in Active Directory: how to separate targeting from administration to avoid audit, hardening, and governance mistakes.

Read
Active DirectoryDomain Controllers

Protected Users in Active Directory: what it is, limits, adminCount, and rollout without lockout

Protected Users in Active Directory is a hardening control for human admin accounts: learn what it blocks, how adminCount works, and how to roll it out without lockout.

Read
Active DirectoryDomain Controllers

Active Directory RC4 remediation: service accounts from RC4 to AES without password reset

Practical Active Directory lab: can a legacy RC4-only service account issue AES Kerberos tickets after a pwdLastSet toggle and msDS-SupportedEncryptionTypes change, without a password reset?

Read

Contact

If you have questions on IAM, PIM, or Active Directory, this is a place for clear technical discussion.

I share content, field experience, and practical guidance to help clarify complex identity scenarios. You can reach out on LinkedIn or email for technical deep-dives and discussion.

LinkedIn