The directory at the centre of this lender had been extended, patched and worked around for twenty years, and the institution had outgrown it. Nobody could say with confidence who held administrative rights, or what would break if a permission were withdrawn. A set of legacy IBM terminal applications, still in daily use on the lending desk, depended on it in ways that had never been written down.
A clean domain, with administration held apart
We rebuilt the directory on a new forest under a tiered administration model. Control of the directory and the servers now sits with dedicated, tightly held accounts; the accounts staff use each day cannot touch it. Their working access, to the lending systems and the transaction data included, carried on unchanged.
Sign-in that holds even when a password leaks
Staff authenticate with a hardware key and a known device before anything else is considered. The shared local passwords and the older sign-in protocols that had built up for compatibility were traced and switched off one at a time, each one checked for what still depended on it before it went.
The terminal applications moved last, and carefully
The IBM terminal applications could not be re-engineered, so the work was shaped around them. Their dependencies were mapped first, the old domain stayed live as a fallback throughout, and each application was proven against the new environment before its predecessor was retired.
The lender now holds a written, current account of who can administer what, the evidence sits behind it, and the cutover cost the business no scheduled downtime at all.
