Yes. In hybrid estates, reviewing only one directory creates a false sense of closure because access can persist through other identity planes and application roles. A complete programme should certify the full entitlement chain, otherwise the review boundary becomes the risk boundary.
Why Hybrid Directory Review Has to Span Both Planes
In a hybrid Microsoft estate, Azure AD and on-premises Active Directory are not separate truth sources, they are linked control planes. A review that stops at one directory misses the way access can survive through synchronized accounts, delegated administration, group nesting, application roles, and other entitlement paths that still resolve to real access.
The practical question is not whether both systems are identical, but whether the review boundary matches the actual entitlement chain. If the answer is no, the review is incomplete even when each directory looks clean on its own.
That is why hybrid review should follow the path of effective access, not the convenience of a single admin console. The relevant unit is the permission that can still be exercised, whether it originates in cloud-native identity, on-prem directory objects, or an application authorization layer that inherits from both.
Where Partial Review Creates False Closure
Partial review fails when administrators treat directory visibility as equivalent to access visibility. A disabled user in one system may still have active rights through a synced account, a stale group membership, a nested administrative role, or an application assignment that was never reconciled back to the directory layer. Active Directory and Entra ID Hardening Guide is useful here because the same hybrid paths that need hardening are the ones a review must be able to traverse end to end.
It also fails when teams assume cloud review and domain review can be scheduled independently without overlap. In practice, the risk sits in the handoff points: directory sync, privileged group design, service accounts, delegation, and identity-linked application access. If one layer is reviewed without the other, the residual access can be invisible to the team doing the certification.
The problem is compounded by application roles and privileged access paths that sit outside both core directories. A valid access review has to account for what the identity can do after authentication, not just whether the account object itself appears correct.
What a Complete Review Should Actually Cover
A complete hybrid review should certify the full entitlement chain, including the account source, group inheritance, directory synchronization effects, privileged roles, and application-level permissions that depend on those identities. It should also distinguish between direct assignment and inherited access, because inherited access is where many false negatives hide.
- Review the originating account in on-prem AD and the cloud identity it maps to.
- Trace synchronized groups, delegated admin roles, and nested group membership.
- Check privileged roles separately from ordinary access, especially where elevation is time-bound or brokered.
- Include application roles and service-linked permissions that are not obvious from the directory object alone.
- Validate that removed access is removed in every plane, not just in the system being audited.
This is also where hybrid identity hardening and access governance meet. AD and Entra ID hardening becomes the operational backdrop for a review process that must understand tiering, delegation, and the blast radius created by shared trust paths. Microsoft verified publisher OAuth phishing 2022 also shows why application consent and role-based access cannot be treated as separate from directory review when persistent access can be established outside the directory itself.
For control design, a hybrid review is strongest when it is event-driven as well as calendar-driven. New sync connectors, changes to privileged groups, application consent, and directory trust changes should all trigger a fresh entitlement check rather than waiting for the next annual certification cycle.
Risk and Threat Considerations
Hybrid estates create a control gap when teams assume that one clean directory means clean access. The resulting risk is hidden privilege persistence, where an account or app keeps effective access through the other directory, inherited group paths, or an application role that was not part of the review boundary. Microsoft Storm-0558 key breach 2023 is a reminder that identity trust failures can turn into broad downstream access when token or key validation assumptions break.
Failure mechanism: The review scope is narrower than the effective authorization path, so stale entitlements, synced objects, delegated trust, or app permissions remain live after the “review” appears complete.
Impact: Organisations can miss dormant but usable access, understate privilege exposure, and leave a compromised or overprivileged identity with a path to sensitive systems, mailboxes, or administrative functions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Hybrid review is fundamentally about account and entitlement lifecycle across both directories. |
| AC-6 — Least Privilege | The question centers on excess access that survives through inherited or alternate entitlement paths. | |
| IA-5 — Authenticator Management | Hybrid identity review depends on credential and authenticator state across directory boundaries. | |
| Recommendation — Review accounts and associated access across both identity planes before certifying closure. Revalidate least-privilege access across synced groups, roles, and application assignments. Check authenticator and credential lifecycle wherever either directory can still confer access. | ||
| NIST CSF 2.0 | ID.AM-01 — Identities and credentials are inventoried | A complete review needs an inventory of identities and credentials across both directories. |
| PR.AA-05 — Access permissions are managed | The issue is whether permissions are reviewed across all planes that can grant effective access. | |
| Recommendation — Maintain a unified inventory of identities, credentials, and linked entitlements across the estate. Manage and certify permissions end to end, including inherited and synchronized access paths. | ||
Practitioner Guidance
What to verify: Verify the identity source, the synced representation, and every inherited entitlement before signing off a hybrid review. If the access path cannot be traced from on-prem object to cloud object to application permission, the review is not complete.
Decision rule: If an identity can authenticate in one plane but still exercise meaningful access in another, treat the review as incomplete until both planes are reconciled and the entitlement chain is certified.
Practitioner takeaway: The safest hybrid review boundary is the path of actual authorization, not the boundary of a single directory platform.
Related resources from NHI Mgmt Group
- What breaks when organisations try to use Azure AD as a complete replacement for on-prem Active Directory?
- When should organisations pair Azure AD with on-prem Active Directory instead of using Azure AD alone?
- How do organisations operationalise NHI ownership at scale?
- When should organisations treat an NHI as a high-priority risk?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org