Guided transformations
Identity migrations and transitions planned to reduce operational impact and access risk.
Analytics preferences
I use GA4 only for aggregated traffic and CTA analytics, without advertising purposes.
Identity Architecture
I work as a Senior Identity Consultant at Impresoft 4ward and focus on identity architecture in complex scenarios: tenant-to-tenant migrations, M&A integration, IAM modernization, PIM governance, and hybrid transformations across Microsoft ecosystems, including Active Directory (AD) and on-premise/on premise environments.
Special focus
Migrations, mergers, separation scenarios, hybrid estates, and governance hardening need clear architecture decisions and disciplined execution.
My contribution spans strategy, execution governance, and post go-live operational stabilization, with specific focus on IAM, PIM, Active Directory, and privileged identity in on-premise and hybrid contexts.
About
I work as a Senior Identity Consultant at Impresoft 4ward and focus on identity architecture in transformation scenarios where operational continuity, governance, and access control must stay solid during complex change.
My core scope covers IAM, PIM, Active Directory, and hybrid Microsoft environments, with practical focus on migrations, M&A integrations, and post go-live stabilization.
Personal profile: https://www.mattiagrandi.it
View full profileExpertise
On the home page you get a visual summary of my core areas; the dedicated page contains the full detail.
Identity migrations and transitions planned to reduce operational impact and access risk.
Design of IAM models, privileged access, and controls that stay sustainable after go-live.
Operational focus on Entra ID, PIM, Active Directory, and enterprise hybrid scenarios.
Case Studies
Personal identity projects focused on practical architecture outcomes, operational resilience, and measurable security improvements.
Context
Construction scaffolding manufacturer with around 100 employees including office staff, engineers, technicians and installers. Office PCs were disconnected from the production environment and managed independently.
Challenge
Design and deploy a structured Active Directory environment, centralize authentication, connect every department and introduce consistent governance for users, groups and shared resources.
Outcome
Delivered a modern domain infrastructure with standardized policies, centralized management, secure access control and a scalable foundation for future growth.
Context
Furniture retailer with four stores and around 50 employees using local email services and unmanaged Windows devices.
Challenge
Provision a new Microsoft 365 tenant, select the appropriate Business Premium licensing, migrate mailboxes, configure Microsoft Entra ID, enroll devices into Intune and introduce basic endpoint management with minimal business disruption.
Outcome
Migration completed in approximately one month, including planning, pilot, mailbox migration, device onboarding and user training. The company gained secure cloud email, centralized identity management and modern device administration.
Context
Regional professional services organization with approximately 120 users working across headquarters and remote offices, with inconsistent sign-in policies and uneven account protection.
Challenge
Implement secure Single Sign-On, enforce MFA for all high-risk and admin sign-ins, and introduce Conditional Access policies by user risk, device compliance and location, without blocking daily operations.
Outcome
Delivered a phased security baseline with SSO coverage on critical apps, MFA enforcement on privileged paths, and Conditional Access guardrails that reduced risky sign-ins while keeping user friction low.
Field Guides
How-tos, real-world troubleshooting, and field notes from identity architecture programs.
Practical guide to GPO Security Filtering and Delegation in Active Directory: how to separate targeting from administration to avoid audit, hardening, and governance mistakes.
Protected Users in Active Directory is a hardening control for human admin accounts: learn what it blocks, how adminCount works, and how to roll it out without lockout.
Practical Active Directory lab: can a legacy RC4-only service account issue AES Kerberos tickets after a pwdLastSet toggle and msDS-SupportedEncryptionTypes change, without a password reset?
Contact
I share content, field experience, and practical guidance to help clarify complex identity scenarios. You can reach out on LinkedIn or email for technical deep-dives and discussion.
Mattia Grandi on LinkedIn
Professional profile, technical content, and identity-focused updates.
Send me an email
For technical questions, clarifications, and deeper discussion on published content.
PayPal
Support the project on PayPal
If these technical resources help your daily work, you can support future publications with an optional donation.