A strong approach is to treat the directory as the control plane for authentication, authorisation, and device management, not just a user list. Keep a single, cloud-based source of truth for users, devices, and applications, then extend existing LDAP or Active Directory only where migration needs it. This reduces fragmentation, supports consistent policy enforcement, and makes access decisions easier to govern.
What changes when the directory becomes the control plane?
Modernising directory management is not mainly a data migration project. It is a shift in how organisations define and enforce trust, because authentication, authorisation, and device trust increasingly depend on the directory rather than sitting beside it. The practical goal is to make the directory authoritative for policy and access decisions, while reducing duplicated user stores and brittle sync logic.
A cloud-based directory works best when it is treated as the system of record for who or what can access resources, then connected to legacy directories only as a transitional dependency. That approach preserves policy continuity, avoids parallel sources of truth, and makes it easier to apply consistent lifecycle controls across users, devices, and applications.
How to combine cloud identity with legacy LDAP or Active Directory
The common mistake is to lift and shift the old directory model into the cloud without changing the operating model. A better pattern is to centralise identity governance in the cloud directory and use LDAP or Active Directory extension points only where applications, endpoints, or migration sequencing still require them. That preserves compatibility without making legacy infrastructure the long-term control plane.
This is where IAM and IGA Basics is useful as a reference for the relationship between authentication, authorisation, provisioning, and access review. It also helps to align the directory with Active Directory and Entra ID Hardening Guide when hybrid identity still exists, because privileged groups, delegation, and tiering remain exposed during the transition.
For cloud-native access paths, the directory should also be able to represent non-human access cleanly. Cloud Workload Identity Guide is relevant here because workload identities, temporary credentials, and federated access should be governed alongside human users rather than managed as a separate exception process.
What good modern directory management looks like in practice
Modernisation should improve three outcomes at once: policy consistency, lifecycle control, and device trust. The directory should know not only the user, but also the device posture or trust state that the policy depends on. That makes it possible to enforce conditional access, access reviews, and revocation from one place instead of across scattered admin consoles.
Device management is part of this model, not an adjacent function. When the directory is the control plane, joining a device, revoking a device, or checking device compliance becomes part of access governance. A strong implementation keeps enrolment, authentication, and device trust aligned so that stale accounts, stale devices, and stale permissions do not drift apart.
Where identity posture becomes important, Identity Security Posture Management (ISPM) Guide provides a useful way to think about stale accounts, standing privilege, and configuration drift as measurable conditions. For organisations running deeper hybrid estates, Machine Identity, PKI and Certificate Lifecycle Guide is also relevant because certificates and trust anchors often become part of device and workload authentication as directories move cloudward.
At the architecture level, this is a control-plane problem, not just a directory product choice. If policy decisions still depend on manual exceptions, disconnected groups, or local account sprawl, the cloud directory will only mirror old fragmentation in a newer interface.
Risk and Threat Considerations
When directory management is fragmented, the biggest risk is inconsistent trust. A weak hybrid design can leave legacy accounts, sync paths, privileged groups, or device trust states active long after the organisation believes migration is complete. That creates an attack surface where compromise of one identity system can be reused across others.
Failure mechanism: stale synchronisation rules, over-privileged admin roles, and inconsistent device trust checks can let attackers move from one identity boundary into another, especially during hybrid migration or long coexistence periods.
Impact: organisations can end up with hidden standing access, unreliable revocation, and broader blast radius if a directory, sync account, or management plane is compromised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Cloud directory modernisation centralises user authentication and access decisions. |
| IA-9 — Identification and Authentication (Service and System Accounts) | The answer includes workload and application identities alongside human users. | |
| IA-5 — Authenticator Management | Directory modernisation depends on credential lifecycle, rotation, and revocation consistency. | |
| Recommendation — Centralise user authentication in the authoritative directory and retire duplicate account stores. Apply separate controls for service and workload identities instead of folding them into user processes. Govern credential lifecycle centrally so revocation and rotation work across cloud and legacy paths. | ||
| NIST Zero Trust (SP 800-207) | PR.AA-01 — Identity and Access Management | The subject is about using the directory as the policy and access control plane. |
| Recommendation — Use the directory as the identity authority that drives policy decisions and access enforcement. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Directory modernisation is fundamentally about consistent access governance across cloud and legacy systems. |
| Recommendation — Define and enforce access rules from one authoritative directory model. | ||
| CSA Cloud Controls Matrix | IAM — Identity & Access Management | Cloud directory migration directly concerns cloud identity governance and policy enforcement. |
| Recommendation — Align cloud directory design with central identity governance, lifecycle, and privileged access controls. | ||
Practitioner Guidance
What to prioritise: define the cloud directory as the authoritative control plane first, then map every remaining LDAP or Active Directory dependency to a specific migration reason, owner, and retirement path. If a legacy dependency cannot be retired, it should be treated as an exception with explicit governance rather than a permanent default.
What to verify: verify that user, device, and application records resolve to one policy source, that privileged roles are tightly bounded, and that revocation actually removes access across cloud and legacy paths. If a control only works after a manual sync, it is not yet a reliable control-plane function.
What good looks like: access decisions are made from a single identity state, device trust is visible to policy, and migration does not create duplicate administrators or parallel group hierarchies. The objective is not to eliminate every legacy directory overnight, but to prevent it from remaining the place where trust is implicitly decided.
Practitioner takeaway: modernisation succeeds when the directory becomes the place where access is governed, not merely where identities are stored, and every remaining legacy dependency is reduced to a controlled transition artifact.
Related resources from NHI Mgmt Group
- How should organisations approach IoT device management when they want one platform to cover devices, connectivity, and cloud control?
- Why do server identity environments need better visibility when organisations move toward cloud-based control planes?
- What do security teams get wrong when they treat privileged account management as one control instead of separate account, user, and identity problems?
- How should organisations approach identity management when moving Office 365 to the cloud without keeping Active Directory?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org