Running Windows, Mac and Google in One Business Without Picking a Side

A mixed fleet is a business running more than one desktop platform and more than one productivity suite at the same time, most commonly Windows with Microsoft 365 alongside Macs and Google Workspace. Almost every Melbourne business over about thirty staff is one, whether anyone planned it or not. The design team bought Macs, the accounts team runs Windows because the practice software demands it, and the founder set up Google Workspace in 2016 and never looked back.

Most providers respond to this by proposing a migration. That is usually a sales position rather than a technical one. A mixed fleet is entirely runnable, but only if you are honest about which layer must be unified and which layers should be left alone.

Identity is the only thing you genuinely must unify

Everything else in a mixed environment can be tolerated. Two identity stores cannot.

The moment a person exists as a separate account in Microsoft 365, in Google Workspace and again in Apple’s ecosystem, you have three joiner processes, three leaver processes and three places to enforce multi-factor authentication. When someone resigns on a Friday afternoon, the account you forget is the one that gets used. This is the single most common failure we see in businesses that grew into a mixed fleet rather than designing one.

Unified identity does not mean one vendor. It means one authoritative directory that every other system trusts, and one onboarding and offboarding checklist that closes every door at once.

Make Entra ID the anchor and Google the relying party

If you are running both suites, the direction of federation is not a matter of taste. It is determined by what the two vendors actually support.

Microsoft publishes a first-party integration for using Microsoft Entra ID as the identity provider for Google Workspace, listed in the Entra gallery as the Google Cloud / G Suite Connector by Microsoft, with SCIM provisioning alongside it. Google documents the other half from its side, confirming that Workspace supports single sign-on from third-party identity providers over both SAML and OIDC, and ships a pre-built Microsoft Entra OIDC profile.

The reverse is not a supported architecture. Microsoft’s Google federation feature is scoped to business-to-business guest users, and Microsoft states plainly that it no longer performs validation testing of independent identity providers for compatibility with Entra ID. Anyone proposing Google Workspace as the primary identity provider for a Microsoft 365 tenancy is proposing something neither vendor documents.

One caveat worth writing into your runbook: Google restricts single sign-on for super administrators, and super admins signing in to the admin console must use their Google password rather than federated credentials. Keep at least one break-glass Google super admin outside single sign-on, store the credential properly, and test it. If you skip this, read what happens when you are locked out of your Google Workspace admin account before you find out the hard way.

Apple will federate with one identity provider, not two

Apple Business, the portal formerly known as Apple Business Manager, can federate with Google Workspace, with Microsoft Entra ID, or with a generic provider over OIDC or SCIM. Apple’s documentation is explicit that you can link to one of these at a time, not several.

That single sentence settles a lot of architectural arguments. If your Macs and iPhones are going to draw their Managed Apple Accounts from a directory, you must choose which directory, and in a Microsoft-anchored environment that is Entra ID.

There is a second trap here that catches people badly. Before Apple will federate a domain it must be verified and captured, and turning on Domain Capture gives every staff member with a personal Apple Account on your company domain a fixed thirty days to move their personal data off it. Apple states the date cannot be extended and that turning on Domain Capture cannot be undone. Staff with a decade of personal photos and App Store purchases attached to a work email address will not take this well if it lands unannounced. Communicate before you press the button, not after. The full sequence is covered in the guide to Apple Business, the portal formerly called Apple Business Manager.

Device management does not consolidate, and that is fine

Identity converges. Device management does not, and chasing a single pane of glass here usually costs more than it saves.

Windows provisioning through Autopilot, macOS enrolment through Apple’s Automated Device Enrolment, and Chrome or Android enrolment through the Google admin console are three genuinely different pipelines with three different trust models. One console can hold all three records, but the underlying work is still platform-specific. What matters is that every device is enrolled in something, that the something reports compliance back to your identity provider, and that nothing is unmanaged.

If you already pay for Microsoft 365 Business Premium or E3, you already own Intune, and Intune will manage Macs. Whether it manages them well enough is a real question with a real answer, covered in what Intune can and cannot do on a Mac and in the head-to-head on Jamf and Intune compared honestly. The practical mechanics of enrolling and managing a Mac fleet are a separate discipline again, and it is the one most generalist providers quietly skip. We have written separately about why most Melbourne MSPs cannot support Macs properly, because the gap is structural rather than a matter of effort.

On the Google side, the equivalent baseline work is in the Google Workspace admin console settings that matter, and the day-to-day device story sits alongside your broader approach to mobile device management.

Running both suites costs more than two subscriptions

The licence line is the visible cost. It is rarely the largest one.

Only one system can own your mail. Your domain has one set of MX records. Google documents split delivery and dual delivery as the two ways to run a second mail platform alongside Gmail, and in both cases the second system receives forwarded copies rather than authoritative delivery. You pay for two mail platforms and get one authoritative mailbox store, plus permanent complexity in SPF, DKIM and DMARC alignment on forwarded messages.

Storage entitlements do not travel. Google’s pooled storage is pooled within Google. Microsoft’s mailbox and OneDrive quotas are entitlements within Microsoft. Buying more of one never offsets the other, and staff will keep the same files in both, so you pay twice to store the same bytes. Neither vendor is backing that data up for you either, which is the subject of Google is not backing up your Workspace data.

Policy parity requires an edition uplift on both sides. Conditional Access on the Microsoft side requires Entra ID P1, which is included in Microsoft 365 Business Premium and E3. The nearest Google equivalent, Context-Aware Access, is restricted to the Enterprise, Education and Frontline editions or to Cloud Identity Premium, and Google states that users without a supported edition are simply not subject to Context-Aware Access policies at all. That Google-side uplift is the cost most businesses miss, because it is not a security add-on you buy for a handful of people. It is an edition change across every user.

We are not going to publish a dollar figure here, because the honest answer depends on your exact mix of editions. What we will say is that the second suite is almost never as cheap as the second subscription line suggests.

Your security baseline does not translate across platforms

This is where mixed fleets quietly fail audits and cyber insurance questionnaires.

The Essential Eight is the framework Australian businesses are measured against, and read closely it is shaped around Microsoft products. The current maturity model, last updated in November 2023, contains no mention of macOS, Apple, iOS, Chrome or Google anywhere in the document. One of the eight strategies is restrict Microsoft Office macros, and at Maturity Level Two and above it requires blocking macros from making Win32 API calls, which is Windows-only by definition. Application control at Maturity Level Two and above requires implementing Microsoft’s recommended application blocklist. User application hardening names Internet Explorer 11 and PowerShell logging.

ASD’s own hardening library reflects the same shape. It publishes hardening guides for Windows 10, Windows 11 and Linux workstations. There is no enterprise macOS hardening publication at all, and the only Apple configuration guide covers iOS 14. Its Blueprint for Secure Cloud is described by ASD as having a current focus on Microsoft 365, with no Google Workspace equivalent.

None of that means a Mac fleet cannot be secured to an equivalent standard. It means the equivalence has to be argued and documented rather than assumed, using the model’s own allowance for vendor hardening guidance and its exceptions process. Do that work before an assessor asks, not during. The detail sits in mapping the Essential Eight onto macOS and whether you can meet the Essential Eight on Google Workspace, and the underlying platform hardening in hardening Google Workspace.

One more thing worth knowing if you are planning a multi-year uplift: ASD ran a consultation on the evolution of the Essential Eight that closed on 12 July 2026, proposing a new Essentials series with the current guidance becoming a chapter called Essentials for enterprise IT. ASD says existing adopters can expect strong alignment with their current controls. Build your roadmap anyway, but build it knowing the framework is being rewritten.

When consolidating actually is the right call

Sometimes the migration everyone keeps proposing is correct. The honest triggers are these.

Consolidate when the duplication is at the identity layer and cannot be federated away. Consolidate when a compliance obligation or a client security review requires a single enforceable policy set and you cannot demonstrate equivalence on the second platform. Consolidate when the second suite is used by fewer people than it costs to administer properly. Consolidate when the business is being sold or is acquiring, because two suites double the integration work later.

Do not consolidate because one platform is unfamiliar to your provider. That is their problem to fix, not yours to pay for.

If you do decide to move, move deliberately. The comparison itself is covered where we have already compared the two suites feature by feature, and the actual migration mechanics, including what breaks in shared drives and calendar delegation, are in the mechanics of moving off Google Workspace. If you have inherited an environment and cannot even establish who owns what, start with inheriting a Workspace tenancy nobody documented.

What a properly run mixed fleet looks like

One authoritative directory. Every other platform federated to it, including Apple. Every device enrolled in a management service appropriate to its platform, reporting compliance back to that directory. One documented joiner and leaver process that touches every system. A written, defensible mapping of your security baseline onto each platform, including the parts where the framework does not fit and you have documented an equivalent control instead. And a hardware lifecycle that does not depend on who happened to buy the laptop, which is the subject of buying, redeploying and disposing of Apple hardware.

That is achievable at 30 staff and at 200. What it requires is a provider who is competent on all three platforms rather than one who tolerates two of them: someone who works with Apple’s business deployment programmes for enrolment and device management, runs Entra ID and Intune as daily work rather than as an escalation, and can open the Google Admin console and tell you what is wrong with it.

TechAssist has run Windows, Mac and Google environments side by side for Melbourne businesses for over 20 years, with 13 certified specialists across the team. We are a Microsoft partner and a Jamf partner, and on the Apple side we are a member of the Apple Consultants Network, Apple’s programme of independent technology partners specialising in Apple solutions for small and medium-sized businesses. That combination is the point rather than the decoration. A provider holding partnerships on both sides of an argument has no commercial reason to steer the answer, and the only honest test of neutrality is whether they ever recommend the option that earns them less. We do that regularly, and you will find us doing it in the posts linked above. If you want a straight assessment of whether your mixed fleet should be unified or simply run properly, call 1300 028 324 or get in touch at https://techassist.au/contact/. We will tell you which of the two it is, including when the answer is that you do not need to change anything.

Microsoft Entra ID is Microsoft’s cloud identity and access management service — the system that decides who can sign in to your Microsoft 365 tenant and what they can reach once they do. It is the new name for Azure Active Directory, renamed in 2023. The technology underneath did not change; the label did.

If you run a business on Microsoft 365, you already use Entra ID every day, whether you know the name or not. Every login to Outlook, Teams, SharePoint and OneDrive is authenticated by it. It is also, increasingly, the single most important security control you own. This post explains what it actually is, what the licensing tiers unlock, and why identity has quietly become the perimeter you most need to defend.

The rename: Azure AD became Microsoft Entra ID in 2023

In July 2023, Microsoft renamed Azure Active Directory to Microsoft Entra ID. The product, the APIs, the sign-in URLs, the licences — all of it kept working. Service plan names like “Azure Active Directory Premium P1” were rebadged as “Microsoft Entra ID P1”, but your existing subscriptions carried across without action. Microsoft folded the identity product into a broader family called Microsoft Entra, which also covers Entra Permissions Management, Entra Verified ID and Entra Internet Access.

One point of confusion worth clearing up: Entra ID is not the same thing as the on-premises Active Directory you might run on a Windows Server domain controller. On-prem AD (the one with domains, organisational units and Group Policy) still exists and still carries the Active Directory name. Entra ID is the cloud directory behind Microsoft 365. Many businesses run both and synchronise between them using Entra Connect. So when someone says “we got rid of AD”, ask which one they mean — they almost certainly still have Entra ID.

What Microsoft Entra ID actually is

At its core, Entra ID is a directory and an authentication engine. It holds the identities for your organisation and brokers access to applications. Strip away the marketing and there are a few building blocks worth understanding.

Users and groups

Every staff member has a user object — their account, their email, their licence assignments, their sign-in history. Groups bundle users together so you can assign licences, app access and policies in bulk rather than one person at a time. Security groups control access; Microsoft 365 groups also create a shared mailbox, calendar and SharePoint site. Getting your group structure right early saves a lot of pain later, because almost everything else hangs off it.

App registrations and single sign-on

Entra ID is also where third-party applications connect to your tenant. When you sign in to Xero, Canva or a line-of-business app using your Microsoft account, that app is registered against Entra ID and trusts it to verify who you are. This is single sign-on (SSO): one identity, one set of credentials, one place to enforce policy. SSO is not just convenient — it is a security win, because it means staff are not inventing weak passwords across a dozen separate logins, and you can cut access to everything by disabling one account when someone leaves.

Conditional Access and MFA

This is where Entra ID stops being plumbing and becomes a genuine security tool. Multi-factor authentication (MFA) requires a second proof of identity — typically an approval in the Microsoft Authenticator app — on top of the password. Conditional Access is the policy engine that decides when to demand it. You can require MFA for all users, block sign-ins from outside Australia, force a compliant device for admin accounts, or step up authentication when a login looks risky.

We have written a full walkthrough on Conditional Access policies in Microsoft 365, so we will not repeat it all here. The short version: Conditional Access is the difference between MFA being a blanket annoyance and being a targeted, risk-aware control. It is the single highest-value thing most Melbourne SMEs can turn on.

Security defaults versus Conditional Access

Microsoft offers two ways to enforce baseline identity security, and the distinction matters.

Security defaults are a free, all-or-nothing switch available to every tenant. Turn them on and Microsoft enforces MFA for all users, requires it for admins, and blocks legacy authentication protocols that bypass MFA entirely. For a very small business with no internal IT, security defaults are far better than nothing and should be enabled if you have nothing else.

The catch is that they are rigid. You cannot exclude a service account, you cannot vary policy by location or device, and you cannot tune the risk thresholds. The moment you need that flexibility — and most businesses do once they grow past a handful of staff — you move to Conditional Access, which requires Entra ID P1 or higher. You cannot run both at once: enabling Conditional Access means switching security defaults off.

ControlSecurity defaultsConditional Access
CostFree, all tenantsRequires Entra ID P1+
MFA enforcementAll users, no exceptionsTargeted by user, group, app, location
Block legacy authYesYes, configurable
Device and location rulesNoYes
Risk-based policiesNoYes (with P2)
Best forMicro-businesses, no ITAny SME that has grown past a few staff

Entra ID P1 and P2 licensing

Most of the security value lives behind paid licences. Entra ID comes in a free tier (bundled with any Microsoft 365 subscription), plus two paid plans: P1 and P2. P1 is included in Microsoft 365 Business Premium, which is the plan we steer most clients towards. P2 is included in the larger enterprise E5 suites or can be bought as an add-on.

What P1 unlocks

P1 is the workhorse tier. It gives you Conditional Access, self-service password reset that writes back to on-prem AD, group-based licence assignment, and the ability to enforce device compliance. For the overwhelming majority of Melbourne SMEs, P1 — via Business Premium — is the right baseline.

What P2 adds

P2 includes everything in P1 and layers on the more advanced controls:

  • Identity Protection — machine-learning detection of risky sign-ins and compromised accounts, feeding risk signals into Conditional Access so you can automatically force a password reset or block a suspicious login.
  • Privileged Identity Management (PIM) — just-in-time, time-limited access to admin roles. Instead of leaving five people as permanent Global Administrators, they request elevation when needed, it expires automatically, and every activation is logged and approvable.
  • Access reviews — scheduled recertification so access does not quietly accumulate over years.

PIM alone is a strong reason for any business with multiple administrators to consider P2. Standing admin rights are one of the most common findings we see in security assessments.

Why identity is the new perimeter for SMEs

The old model of security assumed a hard outer wall — a firewall at the office, with everything inside it trusted. That model died when work moved to the cloud and to homes across the metro. Your data now lives in Microsoft 365, accessed from laptops, phones and home networks that your firewall never sees. The only thing standing between an attacker and your email, files and finance system is whether they can prove they are an authorised user. That proof is identity, and Entra ID is where it is enforced.

This is why attackers no longer bother breaking through walls — they log in. Credential theft, phishing and token replay are the dominant intrusion methods against Australian SMEs precisely because a valid login bypasses everything else. The Australian Cyber Security Centre (ACSC) puts multi-factor authentication front and centre in its guidance for exactly this reason.

A real-world shape of the problem: a manufacturing business in Dandenong we work with had MFA switched on for office staff but had quietly left it off for a shared accounts-payable mailbox, because “it was easier”. That mailbox was the one an attacker phished, and from it they sat reading invoice threads for a fortnight before attempting a payment redirection. Nothing was breached at the network layer. The gap was an identity exception nobody had reviewed. Conditional Access with no carve-outs, plus PIM on the admin accounts, would have closed it.

How Entra ID maps to the Essential Eight

The Essential Eight is the ACSC’s baseline of eight mitigation strategies, and two of them are pure identity controls that Entra ID delivers directly.

Multi-factor authentication is one of the eight outright. Entra ID with Conditional Access is the standard way Australian businesses meet it for Microsoft 365 and connected apps. Restrict administrative privileges is another, and this is where PIM earns its keep — just-in-time elevation and access reviews are precisely what the maturity levels ask for as you move up from Maturity Level One. Entra ID also contributes to the broader picture through sign-in logging and audit trails that support detection and response.

If Essential Eight alignment is on your radar — and for any business touching government contracts or cyber insurance it should be — Entra ID configuration is a large part of the work. Our Essential Eight compliance service treats identity hardening as the first thing to fix, because it is the cheapest, fastest control with the largest blast-radius reduction.

Getting it right

Entra ID ships with sane-ish defaults, but “switched on” and “configured properly” are different things. The common failures we see across Melbourne tenants are predictable: MFA with too many exclusions, legacy authentication still enabled, no Conditional Access despite paying for P1, Global Administrator handed out like sweets, and break-glass accounts that either do not exist or are not protected. Each of these is a quiet open door.

TechAssist is a Melbourne-based MSP, founded in 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma. We run Microsoft 365 and Entra ID hardening as standard onboarding for managed clients, because identity is the control that prevents the largest category of incidents we are called to clean up. Per-user fixed monthly pricing means this work is in scope, not a surprise invoice.

Frequently asked questions

Is Microsoft Entra ID free?

There is a free tier bundled with every Microsoft 365 subscription, which covers basic users, groups and SSO. The security controls most businesses need — Conditional Access (P1), and Identity Protection and PIM (P2) — require paid licences. P1 is included in Microsoft 365 Business Premium, which is what we recommend for most SMEs.

Do I still need on-premises Active Directory?

It depends. Many businesses have moved entirely to the cloud and run Entra ID alone. Others keep on-prem AD for legacy applications or file servers and synchronise it to Entra ID with Entra Connect. There is no requirement to keep on-prem AD if nothing depends on it, and removing it can simplify management considerably.

What happened to my Azure AD settings after the rename?

Nothing broke. The rename in 2023 was cosmetic at the product level — your policies, users, app registrations and licences all carried across. The portal now refers to Microsoft Entra ID and some menus moved, but no reconfiguration was required.

Should I use security defaults or Conditional Access?

If you have no internal IT and no Entra ID P1 licences, enable security defaults today — it is far better than nothing. Once you have P1 (via Business Premium) and need to handle service accounts, location rules or device compliance, move to Conditional Access. You cannot run both simultaneously.

Talk to us about identity

Identity is the control most worth getting right and the one most commonly left half-configured. If you are not sure what your tenant is actually enforcing, our Microsoft 365 and cybersecurity teams can audit your Entra ID setup, close the gaps and align it to the Essential Eight. Get in touch and we will tell you plainly where you stand.

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon — just a clear-eyed look at where you stand and what's possible.