Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / Windows 11 Is Quietly Mandating Enterprise Cloud-Only Identity
Transcript
- Lucas: So here we are in June 2026, and Microsoft has been quietly hard-coding a requirement into Windows 11 Enterprise that I think a lot of IT departments are still not taking seriously enough: cloud-only identity. Luna: By cloud-only, you mean they're essentially phasing out on-premises Active Directory for new feature access? Lucas: Exactly. It's not that your on-prem domain controller stops working tomorrow. But Microsoft has started tying specific Windows 11 Enterprise features — we're talking about Windows Hello for Business, passwordless authentication, some of the new zero-trust network access controls — to being exclusively in Azure AD, now called Entra ID. If you're still running hybrid, those features simply aren't available. Luna: And this isn't hypothetical. I believe Microsoft announced back in 2025 that new feature releases in Windows 11 would require cloud authentication for certain capabilities. Lucas: Right. The official documentation from Microsoft says that starting with Windows 11 version 24H2, which is already rolling out, the 'cloud trust' authentication model for Windows Hello for Business requires the device to be Entra ID joined. Not hybrid. Not domain-joined with Azure AD sync. Pure cloud. Luna: That's a huge shift. A lot of mid-size and large enterprises have been running hybrid for years — they sync their on-prem AD to Azure AD and call it a day. Lucas: Yeah, and that's exactly the scenario that's now being squeezed. According to Gartner's 2025 survey, about 40 percent of Fortune 500 companies still have a hybrid identity setup. That's four hundred of the largest companies in the world, still running some form of on-prem directory alongside cloud sync. And Microsoft is essentially saying: you have a couple of years, maybe less, to make the full move. Luna: So what's the actual timeline? Because I know deprecations in enterprise IT tend to be slow — but this feels faster than usual. Lucas: It is faster. Microsoft has already stopped selling new on-premises Active Directory Federation Services — AD FS — licenses. The existing AD FS support ends in 2027. And they've announced that future Windows 11 feature updates will increasingly require Entra id only join. I'd say by the end of 2027, if you're not on cloud-only identity, you'll be running a version of Windows 11 that's missing major security and productivity features. Luna: Let me push back a little. Some IT admins I've talked to say they can't move to cloud-only because they have legacy apps that require on-prem LDAP or Kerberos authentication. What's Microsoft's answer to that? Lucas: That's the real tension point. Microsoft's answer is 'use Entra ID Domain Services' — which is basically a managed domain controller in the cloud — or migrate those apps to support modern authentication. But that's not a trivial lift. If you have a custom internal app that was written in 2008 and only talks to a local domain controller, you're looking at a rewrite or a third-party identity bridge. Luna: So the cost isn't just the migration of user accounts — it's the application compatibility layer. Lucas: Exactly. And Microsoft knows this. That's why they're doing it gradually — they don't want to break everything at once. But the direction is unmistakable. And if you look at the Windows 11 Enterprise baseline security profiles that became mandatory last year, they already assume cloud-only for several settings. For example, the requirement to use Windows Hello for Business for passwordless sign-in — that only works fully if the device is Entra ID joined. Luna: Let's talk about the hidden cost here. A lot of orgs have spent years building out sync rules, password hash sync, seamless SSO — all the hybrid infrastructure. Now they have to dismantle that and rebuild in the cloud. Lucas: And the tooling is still maturing. Microsoft's migration tools — like the Azure AD Connect sync engine — are being deprecated in favor of the new 'Microsoft Entra Connect Sync' but the migration path isn't one-click. For large orgs with thousands of group policies, legacy GPOs that tie into on-prem AD won't directly translate to cloud-only. You end up rebuilding policies in Intune or using Group Policy Analytics. Luna: That's a lot of IT hours. And IT budgets are tight right now. Lucas: They are. Which is why this is the kind of thing that sneaks up on you. You think, 'We'll get to it next quarter.' But next quarter becomes next year, and suddenly you're on a version of Windows 11 that can't enable the latest security features. And in a regulatory environment where breach liability is increasing, that's a real risk. Luna: So what should an IT leader do today, in June 2026? What's the first step? Lucas: Audit your current identity setup. Find out how many of your devices are hybrid-joined versus cloud-only. Check which Windows 11 features you're using or planning to use that require cloud-only. Then inventory your legacy apps — which ones can't move to modern auth? That gives you the migration scope. And then start piloting cloud-only with a small group of users. Luna: And for those legacy apps, what's the stopgap? Is there a way to buy time? Lucas: You can use a third-party identity provider like Okta or Ping that bridges to Entra ID, but that's an added cost. Or you can keep a small on-prem footprint for those specific apps while moving everything else to cloud-only. Microsoft calls that 'minimal hybrid' — not ideal, but workable for a transition period. Luna: It feels like Microsoft is forcing the pace here. I mean, they want everyone on their cloud because it's more profitable for them, but also because the security model is better. Lucas: That's the tension, right? On one hand, cloud-only identity genuinely improves security — no more on-prem AD servers exposed to ransomware, no more Kerberos ticket attacks. On the other hand, it's a forced migration that costs time and money. And Microsoft gets more recurring revenue from Entra ID Premium licenses than from on-prem CALs. Luna: There's also a human factor. IT admins who have been managing on-prem AD for twenty years are going to have to upskill. The cloud-identity skill set is different. Lucas: Absolutely. And that's another hidden cost. Training, certification, maybe hiring new talent. But the reality is: Windows 11 Enterprise is the future, and that future is cloud-only identity. The sooner you start, the more control you have over the timeline. Luna: It's worth noting that for smaller organizations, this is actually easier. If you're already fully cloud with Microsoft 365, you're probably already Entra ID joined and don't have this problem. Lucas: Exactly. This is really a problem for the mid-market and enterprise — the ones with legacy infrastructure. And that's where the pain is concentrated. Lucas: I want to step back for a second. We talk about these forced migrations a lot on this show, and I think it's important to say: this show exists because we believe in helping IT pros navigate these changes without the hype. We deliberately don't run ads on these episodes — no sponsors, no pressure to sell you anything. If you find that valuable and want to support that choice, you can go to buy me a coffee dot com slash fexingo. It's a simple way to keep the conversation going. Luna: Yeah, and I think that's especially relevant today — because if you're an IT leader trying to plan a cloud identity migration, the last thing you need is more vendor marketing. You need clear, independent analysis. Lucas: Right. So back to the timeline. If you haven't started your cloud-only identity migration by now, you're already behind. But there's still a window. The key is to move deliberately, app by app, pilot group by pilot group. Don't try to do a big bang migration. Luna: And what about the user experience? Users are used to single sign-on with their on-prem credentials. If you move to cloud-only, will they notice? Lucas: If you do it right, they shouldn't notice much. Windows Hello with biometrics or PIN is actually faster than typing a password. And with seamless SSO, they sign in once and that's it. The bigger change is for IT — how you manage devices, how you apply policies, how you troubleshoot authentication issues. Luna: One thing I think our listeners would want to know: are there any industry verticals where this is harder? Like healthcare or finance? Lucas: Healthcare and finance both have heavy compliance requirements — HIPAA, PCI DSS — and many of those regulations still assume on-prem control. However, both are moving to cloud under strict controls. Microsoft has compliance certifications for Entra ID, so it's not that you can't do it, it's that you need to document the controls. That adds overhead but isn't a blocker. Luna: So the real blocker is cultural and skill-based, not technical. Lucas: Exactly. And that's why this is such an important topic for the show. Windows 11 Enterprise is not just an OS update — it's a re-architecture of how identity works. And if you're not preparing for that, you'll be scrambling in 2027.