Join our Newsletter — 33% off our NHI Course

Should organisations manage on-premises AD and Microsoft Entra ID together?

Yes, if identity governance is expected to be consistent across both directories. Separate tools or separate processes can work, but only if they preserve a single view of privilege, change review, and delegated administration. The key test is whether control evidence remains coherent across both environments.

When should you manage both directories as one governance problem?

On-premises AD and microsoft entra id should be managed together when the same people, groups, administrative roles, or service paths can influence access in both places. In hybrid estates, the practical issue is not directory ownership alone, but whether privilege, delegation, and change review stay aligned as identities move between domains. If those controls drift apart, governance becomes inconsistent fast.

That usually means treating the pair as one access ecosystem for policy, review, and evidence, even if separate operational teams still run parts of the stack. The question is less “one tool or two” and more whether a single control model can describe who has authority, how it changes, and where that authority is visible.

In hybrid identity, the most important connections are often AD and Entra ID hardening principles such as tiering, delegation, privileged groups, and hybrid trust paths. If those relationships are not governed together, a control that looks strong in one directory can be undermined by a weaker path in the other.

What actually has to stay consistent across AD and Entra ID?

The first thing that must stay coherent is privilege. A group, role, or delegated admin path in one directory should not create hidden authority in the other without being reflected in the review process. The second is lifecycle, because joiner, mover, leaver, and exception handling need to produce the same security outcome regardless of which directory hosts the effective control.

That is why hybrid governance depends on a single view of delegated administration and privileged change. If the teams that approve, grant, and revoke access are different, they still need a shared rule set and a shared record of who can change what. Otherwise, one directory becomes the shadow authority for the other.

Hybrid environments also need careful treatment of authentication and trust paths, especially where federation, sync, or token-based access bridges the two sides. The Entra ID actor token flaw is a reminder that weaknesses in cloud identity paths can have tenant-wide impact, so the review model should include both the on-premises control plane and the cloud control plane.

Where separate tooling is acceptable, and where it usually fails

Separate tools can work when they are clearly partitioned and still feed a single governance outcome. For example, one team may operate AD administration and another may operate entra id, but both must report into the same privilege inventory, exception handling, and recertification cadence. The model fails when “separate” becomes “unrelated.”

That failure usually shows up in three places: orphaned privileged access, inconsistent delegation, and blind spots in evidence. In hybrid estates, the real risk is not only overprivilege, but also the inability to answer a basic audit question: who can still make security-relevant changes, from where, and under what approval trail?

Attackers also benefit when the directories are managed as disconnected systems. Bridging controls, token trust, and admin role mappings can create paths that are not obvious if each directory is reviewed in isolation. A practical example is tenant-hijack risk in Entra ID, where cloud-side compromise can bypass the assumptions made by an on-premises-only review process.

Risk and Threat Considerations

Hybrid directory governance creates concentration risk, because a weakness in one control plane can propagate into the other through sync, federation, or delegated administration. The biggest exposure is usually not a single bad account, but inconsistent privilege visibility that lets excessive access persist across both environments.

Failure mechanism: The organisation reviews AD and Entra ID through separate change, access, or audit processes, so the effective privilege set is never reconciled into one authoritative view. Attackers and insiders can exploit that gap through role drift, delegated admin abuse, token-based access, or stale privileged assignments.

Impact: Control evidence becomes fragmented, privilege revocation becomes slower and less reliable, and a compromise in one directory can translate into broader administrative reach than the local team expects. That raises both breach impact and audit failure risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Hybrid AD and Entra ID governance depends on consistent account lifecycle control.
AC-6 — Least Privilege The question is about preserving a single view of privilege across both environments.
IA-2 — Identification and Authentication (Organizational Users) AD and Entra ID together must preserve coherent authentication and identity assurance.
Recommendation — Centralize account lifecycle reviews across both directories and reconcile access changes promptly. Enforce least privilege across both directories using one consolidated privilege model. Align organizational authentication controls so both directories enforce the same trust assumptions.
ISO/IEC 27001:2022 A.5.15 — Access control The topic centers on consistent access governance across hybrid directories.
A.8.2 — Privileged access rights Hybrid administration hinges on controlling privileged rights coherently across both systems.
Recommendation — Define and apply access rules consistently across on-premises AD and Entra ID. Track, approve, and review privileged rights in both directories under one governance process.

Practitioner Guidance

What to prioritise: Build one privilege inventory and one delegated-administration record for both directories, even if operations remain split. If a role, group, or admin path changes access in either environment, it should appear in the same review and recertification workflow.

What to verify: Confirm that your evidence can answer three questions without manual stitching: who has privileged authority, where that authority is effective, and what approval or review supported it. If you cannot produce that answer quickly, the governance model is too fragmented for hybrid identity.

Common mistake: Treating AD administration and Entra ID administration as parallel but independent problems. In practice, hybrid identity only behaves well when change control, privilege review, and exception handling are designed around the combined blast radius.

Practitioner takeaway: Manage the directories separately only at the operational layer; manage them together at the governance layer, or you will lose coherent privilege evidence exactly where hybrid identity is most exposed.