TL;DR: Hybrid identity began as a cloud transition mechanism, but it is increasingly out of step with workforce IAM that now starts and operates in the cloud, especially as organisations adopt passwordless authentication, OAuth 2.0, OpenID Connect, and agentic AI governance, according to HYPR. The real question is no longer whether hybrid can support the past, but whether it still fits the operating model of the next decade.
NHIMG editorial — based on content published by HYPR: Rethink Hybrid Identity: It Is Not the Destination
By the numbers:
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
- Only 5.7% of organisations have full visibility into their service accounts.
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
Questions worth separating out
Q: How should IAM teams decide when hybrid identity should be retired?
A: Retirement should be driven by whether hybrid still solves an actual dependency or only preserves legacy habits.
Q: Why do legacy applications keep hybrid identity in place longer than necessary?
A: Legacy applications usually keep hybrid in place because teams treat one dependency as a reason to preserve the whole model.
Q: What are the signs that hybrid identity has become an operating constraint?
A: The clearest sign is when access architecture is being shaped by old directory limitations rather than current work patterns.
Practitioner guidance
- Audit hybrid dependencies by application class Map which applications still require Active Directory, LDAP, Kerberos, or other legacy dependencies, then separate true exceptions from cases where the directory is merely convenient.
- Reframe VPN from default access to legacy exception Identify where VPNs still exist to extend network reach when the business only needs application access.
- Separate identity ownership from sync mechanics Decide where workforce identities should be mastered going forward, then stop using synchronization as evidence that the legacy directory should remain the authoritative long-term source for all users.
What's in the full article
HYPR's full blog post covers the operational detail this post intentionally leaves for the source:
- The full argument for replacing VPN-era access assumptions with identity-centric private access
- The article's discussion of OAuth 2.0, OpenID Connect, and FIDO-based migration paths
- The reasoning behind decoupling workforce identity from legacy directories and sync layers
- The section on how AI-assisted development may reduce the effort needed to modernise legacy authentication logic
👉 Read HYPR's analysis of why hybrid identity is no longer the end state for workforce IAM →
Hybrid identity and workforce IAM: are legacy constraints still necessary?
Explore further
Hybrid identity is a transition architecture, not an end-state. Enterprises adopted it to bridge on-premises directories and cloud services, but the operational need that created it has changed. When most workforce activity now happens in SaaS, cloud collaboration, and cloud-hosted systems, treating hybrid as permanent creates governance drag and architectural inertia. The implication is that IAM roadmaps should distinguish compatibility from strategy.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which shows how quickly identity governance breaks when asset ownership is unclear.
A question worth separating out:
Q: How can organisations reduce directory dependence without breaking workforce access?
A: Start by separating true application exceptions from the general identity model, then migrate the general case first. Use identity-centric private access for remote connectivity, adopt modern authentication standards, and keep synchronization only where it is still required for specific legacy systems.
👉 Read our full editorial: Hybrid identity is becoming a legacy constraint for workforce IAM