Common signs include reliance on on premises AD for core access, extra tooling needed for device management, separate subscriptions to cover external identities, and conditional access that does not extend cleanly across all devices and resources. Those gaps usually show up as fragmented administration, inconsistent policy enforcement, and continued dependence on legacy infrastructure that should have been retired.
Modernisation breaks when Entra ID becomes a front door, not the control plane
The clearest warning sign is that Entra ID P1 is present, but the organisation still behaves as if identity lives in several separate systems. If access decisions, device posture, and external-user handling are split across on-premises directories, add-on tooling, and legacy exceptions, the platform is being used for login coverage rather than for unified control.
That usually means modernisation is partial. You may still authenticate through Entra, but the real policy authority remains elsewhere, so administration fragments and the intended reduction in legacy dependency never materialises.
A useful way to judge the situation is whether the directory is actually driving policy outcomes across users, devices, applications, and external identities. If not, P1 is acting as a compatibility layer instead of a control plane.
Fragmented administration is usually the first operational symptom
When modernisation is working, administrators should not need multiple places to define access logic for the same population. A failing setup shows up as duplicated groups, separate workflows for internal and external access, and device management steps that only exist because one platform cannot express the policy cleanly.
That fragmentation matters because it creates drift. Teams start making local exceptions to keep work moving, and those exceptions become the real access model. Over time, the environment looks cloud-ready on paper while still relying on legacy conventions to function.
Another strong signal is policy inconsistency. If conditional access behaves differently depending on device type, resource, or user population, then the organisation has not achieved a stable policy layer. Modern access control should be predictable enough that administrators can explain the rule once and see it apply everywhere it is meant to apply.
Legacy dependency shows up when retirement never happens
Modernisation is failing when the environment still depends on on-premises AD for core access decisions that should have moved into the cloud identity layer. The same concern applies when external identities require a separate subscription or an alternative path just to be managed cleanly.
That pattern often indicates the organisation has not removed old trust anchors, only wrapped new ones around them. If the legacy system remains required for day-to-day access administration, then the migration is incomplete even if the user experience appears modern.
The practical test is whether the old platform can be retired without breaking access, device control, or guest-user administration. If retirement would expose gaps, the controls were never fully modernised.
Risk and Threat Considerations
Fragmented access control increases the chance of inconsistent enforcement, shadow exceptions, and stale privilege paths. It also keeps older trust relationships alive, which can widen the blast radius if one directory, policy path, or administrative workflow is compromised.
Failure mechanism: access decisions are split between modern and legacy systems, so policy changes, revocations, and device checks do not propagate uniformly. That creates control gaps that attackers and insiders can exploit, and it makes it harder to prove that access is actually governed end to end.
Impact: the organisation keeps paying the cost of modern identity tooling while retaining the exposure of legacy dependency, including inconsistent access enforcement, harder audits, and a slower path to decommissioning older infrastructure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Modern access modernisation hinges on consistent account lifecycle governance across systems. |
| AC-6 — Least Privilege | Fragmented policy enforcement often masks excessive or inconsistent access rights. | |
| IA-2 — Identification and Authentication (Organizational Users) | The question is about whether modern identity controls are replacing legacy access paths for users. | |
| Recommendation — Centralise account lifecycle control and remove duplicate access workflows across legacy and cloud systems. Apply least-privilege rules uniformly across users, devices, and external identities. Verify that user authentication and access decisions are enforced through the intended identity control plane. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The issue is whether access control is coherent across all resources and identity populations. |
| Recommendation — Define one access-control model that applies consistently across legacy and cloud environments. | ||
Practitioner Guidance
What to verify: confirm whether one policy layer governs internal users, external identities, and managed devices without requiring separate control planes or duplicate exceptions. If the answer depends on manual coordination, the modernisation effort is not yet complete.
What practitioners underestimate: a successful sign-in experience can hide weak access architecture. The question is not whether Entra authenticates users, but whether it is the system of record for access decisions across the full population and resource set.
Practitioner takeaway: treat fragmented administration as the key diagnostic, because if access logic still depends on legacy systems or special-case tooling, the organisation has modernised the login path more than the control model.
Related resources from NHI Mgmt Group
- What are the signs that Exchange Online PowerShell access is failing because of identity or session control issues?
- What are the signs that time-based access control is failing?
- What are the signs that an IAM or IGA program is failing to keep access under control?
- What are the signs that an LLM deployment is failing its access-control and leak-prevention checks?