Retail & Hospitality
Directory Modernization
Scalable identity and device infrastructure for a fast-growing global beauty brand
The Challenge
Identity sprawl and aging infrastructure ahead of rapid growth
A fast-growing global beauty and personal care brand had scaled its headcount and international footprint faster than its IT foundation could support. The company ran on a single on-premises Active Directory domain controller with no redundancy, a hybrid-join configuration Microsoft had already begun deprecating, and inconsistent security group hygiene. Devices only received policy updates when connected to VPN, and there was no unified platform for managing them.
With a workforce split across corporate offices, remote staff, and a significant BYOD population, the company needed a clear-eyed assessment of its options — and an execution partner who could carry out a multi-year modernization without slowing down a business moving this fast.
The Solution
JumpCloud as the identity backbone, with a phased device and application rollout
Macktez began with a focused, fixed-scope discovery engagement: reviewing the existing Active Directory and sync architecture, auditing SaaS applications for single sign-on readiness, meeting with stakeholders across the organization, and evaluating the security implications of the company's BYOD culture. That discovery produced a clear recommendation — modernize the identity layer around JumpCloud, a cloud-based, cross-platform directory built for a hybrid Mac and Windows environment.
From there, the engagement expanded in phases over several years:
- Deployed JumpCloud as the organization's central identity provider, federating Microsoft and other business-critical platforms under a single directory
- Stood up a co-managed NinjaOne tenant for remote monitoring and device management, deployed via JumpCloud across the Mac and Windows fleet, with the internal IT team trained to run it directly
- Executed a full Windows hardware refresh — evaluating the existing fleet, shipping pre-configured standardized replacement workstations directly to employees in phased waves, and refurbishing or retiring machines based on age and condition
- Audited 21 business-critical SaaS applications — including Adobe, Dropbox, Greenhouse, NetSuite, SAP Concur, and Zoom — for native single sign-on support, mapping a largely cost-free integration path for most of them
- Ran an initial assessment of the internal help desk's ticketing workflows, SLAs, and self-service resources, then reallocated the remaining budget toward higher-impact priorities within the engagement
Outcomes
What we delivered.
- A single cloud-based directory now governs identity and device policy, replacing a single point of failure on-prem domain controller
- Identity management now spans more than 750 users, with over 570 workstations under active device management
- Multi-factor authentication enforced across all JumpCloud-federated access points
- A modernized, standardized Windows fleet with a clear replacement and retirement policy going forward
- An ongoing, multi-year co-managed relationship, with Macktez available for new integrations, ad hoc support, and periodic account and device audits
Centralize Logins
Still running identity out of a single, aging domain controller?
We modernize directories with single sign-on, MFA, and phased device rollouts, so growth doesn't outpace your infrastructure. Let's review how your identity setup works today.
Let's TalkRelated
To modernize your own directory with single sign-on and clean onboarding, these services are where to begin:
For the concepts behind this modernization, see our University guides on directory services, MFA, and least privilege:
More identity and device work in action: