The most practical approach is to keep AD where it still works, then layer in cloud IAM, strong authentication, and endpoint controls that close perimeter gaps. Modernisation should preserve existing identities and group structures while extending policy enforcement to cloud apps and non-Windows devices. The goal is not replacement for its own sake, but tighter trust decisions across a hybrid estate.
Keep Active Directory, but reduce its trust boundary
The strongest modernisation pattern is usually evolutionary, not a wholesale directory replacement. Keep Active Directory for the identities, groups, and applications that still depend on it, but stop treating it as the trust anchor for everything. The practical zero trust move is to narrow where AD is authoritative, then add stronger authentication, conditional access, device posture, and policy enforcement around it.
That means preserving existing group structure and legacy dependencies while shifting high-risk access decisions to controls that evaluate user, device, location, and application context at the time of access. In a hybrid estate, this is often more resilient than migration because it avoids breaking line-of-business dependencies while still reducing implicit trust.
For directory-specific hardening and hybrid identity planning, the Active Directory and Entra ID Hardening Guide is a useful companion for the control choices that sit around the directory rather than inside it.
What Zero Trust changes in practice for AD
Zero Trust does not require AD to disappear, but it does require AD to stop being treated as a blanket permission source. The key shift is from static network trust to continuous verification and least-privilege access decisions. In practice, that means stronger sign-in controls, tighter admin boundaries, and policy enforcement for cloud apps and non-Windows endpoints that AD alone cannot secure well.
Modernisation usually works best when organisations separate three layers: identity source, authentication, and authorisation. AD may remain the source of record for some identities, but cloud IAM or federated policy can become the enforcement layer for application access. That lets you keep the directory while modernising how access is granted, rechecked, and revoked.
For workload and service-to-service trust models, the Guide to SPIFFE and SPIRE shows how non-user identities can move toward stronger, short-lived, verifiable trust without depending on legacy directory assumptions.
The operating model that usually succeeds
The best path is to modernise by control plane, not by wholesale identity cutover. Start with privileged access, internet-facing apps, and remote access, because those are the areas where weak trust assumptions hurt most. Then extend toward workload access, SaaS integrations, and non-Windows devices once the core policy and authentication model is stable.
AD should be treated as one part of a broader identity fabric. That usually means stronger MFA, device compliance checks, role scoping, tiered admin separation, and removal of stale or overexposed accounts before broadening policy enforcement. A clean migration target is less important than having a consistent decision model for who or what can access which resource under which conditions.
Where machine and service identities are part of the hybrid estate, the NHI Lifecycle Management Guide is helpful because modernisation often fails when non-human credentials, rotation, and offboarding are left behind during broader Zero Trust work.
Risk and Threat Considerations
Keeping AD in place is practical, but the risk is carrying forward implicit trust, long-lived privileges, and brittle dependencies into a Zero Trust programme. If organisations modernise only the front door and leave legacy admin paths, service accounts, or flat network assumptions unchanged, attackers still have high-value routes to credential theft, lateral movement, and privilege escalation.
Failure mechanism: Legacy authentication flows, excessive group membership, and unmanaged service credentials preserve standing access and make it easy for a compromised account or endpoint to pivot across on-premises and cloud resources.
Impact: The estate may look “partly modernised” while the real blast radius remains large, especially where AD still anchors privileged access, application trust, or hybrid federation decisions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST Zero Trust (SP 800-207) | PR.AA-05 — Authenticator Management and Identity Verification | Zero Trust modernization hinges on stronger authentication and verified access decisions. |
| Recommendation — Apply continuous verification and least privilege before granting access to hybrid resources. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | AD modernization centers on stronger user authentication across hybrid access paths. |
| IA-5 — Authenticator Management | Modernisation requires better credential lifecycle, rotation, and control of AD-linked authenticators. | |
| Recommendation — Strengthen organizational user authentication before extending trust to cloud and remote access. Control authenticator lifecycle and rotation for all AD-dependent access paths. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The topic is fundamentally about tightening who can access what during hybrid modernisation. |
| A.8.5 — Secure authentication | Safer modernisation depends on stronger authentication than legacy directory trust alone. | |
| Recommendation — Define and enforce access rules that narrow AD-derived trust across the estate. Upgrade authentication strength for users and admins before broadening cloud access. | ||
Practitioner Guidance
What to prioritise: Modernise the access decision points first, not the directory itself. If an app or admin path can still succeed without device trust, MFA strength, or conditional policy, it should be treated as the higher-risk migration candidate.
What to verify: Confirm which systems truly depend on AD as a source of identity versus which only depend on it for convenience. That distinction determines whether you need federation, policy overlay, application refactoring, or simple hardening.
Practitioner takeaway: The goal is not to replace AD everywhere, but to make it impossible for AD alone to confer broad trust; Zero Trust succeeds when access is continuously evaluated, not when the directory is merely renamed.
Related resources from NHI Mgmt Group
- Why do Active Directory service accounts complicate zero trust programs?
- What breaks when organisations try to run Zero Trust without full certificate visibility?
- What happens when organisations try to clean up Active Directory without full visibility?
- What happens when organisations deploy zero trust segmentation around a fast-growing network without a full rebuild?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org