Organisations should decide based on workload mix, device diversity, and how much on premises complexity they can sustain. If most access is for Windows only systems, AD may remain useful. If teams need consistent control across cloud apps, macOS, Linux, and third party services, a cloud directory platform can reduce add ons, licensing sprawl, and admin overhead while improving access consistency.
Why this is really a directory architecture decision
The choice is less about “old versus new” and more about which directory model best matches your operating environment. active directory remains a strong fit where Windows authentication, legacy applications, group policy, and domain-joined devices still do real work. A cloud directory platform is usually better when identity needs to be consistent across SaaS, mobile, and mixed operating systems, with less dependence on on premises plumbing.
The practical question is whether your directory is acting as a local Windows control plane or as a broader access platform. If the latter, the platform has to handle modern authentication, lifecycle changes, app integration, and admin overhead without creating parallel silos. That is why many teams now treat NHI lifecycle management as part of the decision, because directory sprawl often becomes lifecycle sprawl.
When a cloud directory wins, the benefit is usually operational consistency rather than a dramatic security uplift on day one. When AD wins, the benefit is usually compatibility and control for a Windows-centric estate. The wrong answer is trying to force one directory to behave like both without clear boundaries.
What to evaluate before you keep both or migrate
Start with workload mix. If most privileged access, device trust, and user sign-in still depend on domain services, keeping AD may reduce disruption. If users increasingly authenticate to cloud services, third-party applications, macOS endpoints, and remote-first workflows, a cloud directory can simplify policy enforcement and reduce the number of bolt-on tools needed to maintain parity.
Then assess device diversity and operating model. Mixed fleets are where directory friction becomes visible: conditional access, join state, app launch paths, and admin workflows can diverge quickly. A cloud directory tends to help when you need the same identity policy to apply across multiple device types and locations. AD tends to help when the environment is still anchored in Windows administration patterns and local network dependencies.
Finally, measure the cost of complexity itself. The decision is often driven by how much duplication you can sustain across licensing, synchronization, conditional rules, and identity administration. If you are already maintaining multiple control planes to compensate for AD limitations, the migration case becomes stronger. If your on premises estate is stable and deeply integrated, the migration cost can outweigh the simplification benefit.
A useful reference point is the NIST Cybersecurity Framework 2.0, which helps teams organise this decision around governance, protection, detection, and recovery rather than brand preference.
How to avoid an identity split that creates more work
The main failure mode is a hybrid setup that preserves AD for legacy dependencies while introducing a cloud directory for everything else, but without a clear authority boundary. That can lead to duplicate users, mismatched group logic, inconsistent access reviews, and different rules for password, MFA, and privileged access. At that point, you have not simplified identity, you have just redistributed the complexity.
Another common issue is assuming the cloud directory removes the need for strong governance. It does not. It changes where the control plane sits, but you still need clear ownership for provisioning, deprovisioning, app integration, and exception handling. If those responsibilities are split across teams without a single operating model, the result is usually drift rather than clarity.
This is why the governance and risk side of the decision matters as much as the technical fit. The best migration plans preserve authoritative source data, reduce account duplication, and keep the number of identity systems that can independently grant access as low as possible.
Risk and Threat Considerations
The biggest risk in either direction is identity inconsistency. If AD and a cloud directory both influence access without clean authority boundaries, attackers and administrators alike can exploit the gaps, stale accounts, overprivileged groups, and forgotten synchronization paths.
Failure mechanism: Parallel identity stores create drift in group membership, account lifecycle, and access revocation, which can leave an access path active long after the business believes it has been removed.
Impact: The result is unnecessary exposure, slower offboarding, weaker auditability, and a larger blast radius if one directory tier is compromised or misconfigured.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Directory choice is a risk and architecture trade-off across identity control planes. |
| ID.AM-02 — Software, Data, and External Systems Are Inventoried | The decision depends on inventorying apps, devices, and external services that rely on directory services. | |
| Recommendation — Align the directory decision to a documented risk appetite and target operating model. Inventory identity dependencies before choosing a directory strategy. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Directory migration changes provisioning, deprovisioning, and account authority. |
| IA-5 — Authenticator Management | The choice affects how credentials, tokens, and authentication methods are managed across environments. | |
| Recommendation — Centralise account lifecycle ownership and deprovisioning controls. Standardise authenticator lifecycle and rotation across the chosen directory. | ||
| ISO/IEC 27001:2022 | A.5.9 — Inventory of information and other associated assets | You need an inventory of systems and dependencies before moving directory authority. |
| A.5.15 — Access control | The decision directly affects how access is governed across platforms and operating systems. | |
| Recommendation — Map all identity-dependent assets and integrations before migration. Define one consistent access model across the directory estate. | ||
Practitioner Guidance
What to prioritise: Decide first which system is authoritative for user lifecycle and application access, then make the other system subordinate. A migration fails when teams try to preserve equal authority in both places.
What to verify: Check whether your core applications, device management, and privileged access workflows can tolerate the target directory as the source of truth. If they cannot, keep AD longer or phase the change by workload class rather than by calendar date.
Practitioner takeaway: Treat this as an operating model decision, not a product swap. The right answer is the directory that lets you reduce identity duplication, keep governance coherent, and support the mix of systems you actually run.
Related resources from NHI Mgmt Group
- How should organisations decide between cloud-based MFA and on-premises MFA for Active Directory environments?
- What is the difference between keeping Active Directory as the authentication store and moving to a cloud identity provider?
- How should organisations approach identity management when moving Office 365 to the cloud without keeping Active Directory?
- Why do organisations keep Active Directory even after moving heavily to the cloud?