TL;DR: Identity teams must treat directory risk, certificate paths, and governance workflow speed as one control plane, not separate projects, as Netwrix’s on-demand session outlines roadmap changes for Active Directory, Entra ID, PingCastle, and AD CS, focusing on real-time identity attack detection, posture management, governance, and a redesigned risk assessment experience, according to Netwrix.
Editorial analysis by NHI Mgmt Group, based on content published by Netwrix: “Identity security roadmap: Reduce risk and stop identity-based attacks”.
Key questions
Q: How should security teams prevent unwanted persistence in Active Directory and Entra ID?
A: Security teams should tie identity removal to lifecycle events, not just login disablement.
Q: Why do posture management and governance need to work together for identity security?
A: Because posture tells you what is exposed, while governance tells you whether the access or trust should exist at all.
Practitioner guidance
- Map identity attack paths across directory and certificate trust Inventory the Active Directory and Entra ID relationships that create reusable trust, especially where AD CS, delegation, or legacy group structures can extend access beyond their intended scope.
- Unify posture findings with remediation ownership Connect identity risk findings to named owners, review cadence, and closure criteria so posture management produces action instead of static reporting.
- Bring AD CS into identity governance reviews Treat certificate issuance, trust paths, and revocation as part of identity governance so certificate-driven authentication is reviewed alongside account and role changes.
Bottom line: Identity security in Active Directory and Entra ID now spans attack paths, governance workflows, posture management, and certificate trust.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity security is moving from visibility to executable governance. A roadmap that links real-time detection, posture management, and certificate-path reduction reflects a broader shift in the market: identity teams now need control loops, not just reports. The old model of periodic review cannot keep pace with attack paths that span Active Directory, Entra ID, and AD CS. Practitioners should treat identity risk as a workflow problem as much as a tooling problem.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
A question worth separating out:
Q: How can IAM teams decide whether a roadmap feature will reduce real risk?
A: Look for whether the feature changes a control decision, not just the dashboard. A useful capability shortens the path from finding to action across access, certificates, or governance state. If it cannot show which identity condition changed and who must act, it is unlikely to lower attack potential.
👉 Read our full editorial: Identity security roadmap: what changes for AD and Entra ID
Identity security is moving from visibility to executable governance. A roadmap that links real-time detection, posture management, and certificate-path reduction reflects a broader shift in the market: identity teams now need control loops, not just reports. The old model of periodic review cannot keep pace with attack paths that span Active Directory, Entra ID, and AD CS. Practitioners should treat identity risk as a workflow problem as much as a tooling problem.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
A question worth separating out:
Q: How can IAM teams decide whether a roadmap feature will reduce real risk?
A: Look for whether the feature changes a control decision, not just the dashboard. A useful capability shortens the path from finding to action across access, certificates, or governance state. If it cannot show which identity condition changed and who must act, it is unlikely to lower attack potential.
👉 Read our full editorial: Identity security roadmap: what changes for AD and Entra ID
Identity risk is now a control-plane problem, not a product-silo problem. The article’s framing is correct in that Active Directory, Entra ID, governance, and certificate trust are all part of the same attack surface. When those functions are managed separately, security teams lose the ability to see how a directory weakness becomes an attack path. The practitioner conclusion is that identity security programmes need shared risk language across directory, governance, and certificate operations.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How can identity teams tell whether their assessment workflow is actually working?
A: Look for shorter time from finding to decision, clear ownership of identity risks, and visible closure of the path that created the exposure. If assessments only produce reports, the workflow is not reducing identity risk.
👉 Read our full editorial: Identity security roadmap: what changes for AD and Entra ID