Join our Newsletter — 33% off our NHI Course
Home› FAQ› Architecture & Implementation› What breaks in practice when organisations rely on…
Architecture & Implementation

What breaks in practice when organisations rely on AD-only approaches for modern web, device, and app access?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Architecture & Implementation

AD-only approaches break when teams need seamless web SSO, mobile access, device trust, or modern provisioning across cloud apps. The result is usually extra add-ons, fragmented policy enforcement, and more manual work to bridge the gap. That increases operational complexity and leaves access governance dependent on inconsistent legacy controls rather than one coherent identity layer.

Where AD-only access models stop matching modern work

AD-only designs were built around a world where the directory, the network boundary, and the primary application estate were tightly coupled. Modern access is not. Web SSO, SaaS, mobile devices, cloud apps, and cross-environment provisioning all depend on policy decisions that happen outside classic on-prem directory assumptions, so teams end up stitching together extra identity layers instead of enforcing one coherent access model. That is why the gap shows up as friction, not just missing features.

The practical break is usually not a single outage. It is the accumulation of workarounds: federation for web access, separate controls for device posture, ad hoc sync for user provisioning, and manual exceptions for apps that cannot speak legacy directory protocols cleanly. The more the organisation extends access beyond the original AD boundary, the more policy, trust, and lifecycle decisions become fragmented across tools rather than consistently evaluated in one place.

That fragmentation matters because access governance is only as strong as the weakest control plane. If one system decides who can sign in, another decides whether the device is trusted, and a third decides whether the app account exists, the organisation no longer has a single place to verify entitlement, revoke access, or explain why an identity still has reach.

For a broader NHI and identity-lifecycle view of why fragmented access and overprivilege become hard to contain, see Ultimate Guide to NHIs and its section on key challenges and risks.

What breaks operationally in web, mobile, device, and app flows

Web SSO is usually the first pressure point. AD can remain part of the trust chain, but modern browsers, federation services, and SaaS platforms often require tokens, claims, conditional access, and session policies that AD alone does not express natively. Without that layer, organisations end up creating brittle bridges that work for a subset of apps and fail for newer ones that expect cloud-native identity controls.

Mobile access exposes another mismatch. A directory can hold the user record, but it does not by itself verify device posture, enrollment state, or whether the session should be constrained by risk signals. That is why teams typically need additional policy engines and device-management integrations when they want reliable access from unmanaged or partially managed endpoints.

Provisioning is where the operational cost becomes obvious. In a modern environment, access changes are not just account creation and deletion. They include app entitlements, group membership, role assignment, device trust state, and lifecycle transitions across SaaS and cloud services. When AD remains the only control anchor, those other changes are handled manually or through bespoke sync jobs, which slows onboarding, delays deprovisioning, and increases the chance of access drift.

Useful reference points for these control gaps are OWASP Non-Human Identity Top 10 for lifecycle and privilege issues, NIST SP 800-207 Zero Trust Architecture for policy-driven access decisions, and CIS Controls v8 for account and access hygiene.

Why the gap becomes a governance problem, not just a compatibility problem

AD-only approaches create a false sense of consistency because the directory still looks like the central source of truth. In practice, cloud apps, devices, tokens, and delegated admin paths create parallel trust relationships that are governed elsewhere. That makes access reviews harder, revocation slower, and exception handling more error-prone, especially when teams rely on legacy controls to cover modern entitlements.

The other hidden issue is operational scale. The more applications and devices depend on manual bridging, the more identity administrators become the control plane for everyday business change. That increases queue time for legitimate access requests and increases the chance that urgent changes are approved without full validation. Over time, the organisation pays for this with more tickets, more exceptions, and weaker audit evidence.

For governance-heavy environments, the lesson is to treat AD as one component of identity infrastructure, not the whole model. Modern access works best when directory data, device trust, application authorization, and lifecycle automation are coordinated so that policy is enforced close to the resource, not only at the directory boundary.

Practitioner Guidance: Define which access decisions remain directory-backed and which must be delegated to federation, device, or app policy. If a control cannot answer “should this user and this device access this app now?”, it is not sufficient as the primary decision point.

What to verify: Check whether onboarding, offboarding, and access reviews produce the same result across web, mobile, and SaaS paths. If users can still reach apps after AD changes are made, the real control plane is somewhere else and needs explicit governance.

Common mistake: Treating sync jobs and add-on tools as if they restore a coherent identity layer. They usually preserve connectivity, but they do not automatically restore consistent authorization, device trust, or revocation behaviour.

Practitioner takeaway: The real test is not whether AD can still authenticate something, but whether the organisation can enforce and prove the full access decision across every modern entry point.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-1 — Organisational ContextAD-only breakage changes how identity services support business access.
PR.AA-01 — Identity Management, Authentication, and Access ControlThe issue is fundamentally about modern authentication and access control beyond AD.
PR.PS-03 — Configuration ManagementLegacy-only access often forces compensating integrations and inconsistent policy enforcement.
Recommendation — Align identity architecture to the organisation’s actual web, device, and cloud access needs. Use modern identity controls that cover SSO, device trust, and app access consistently. Standardise access-policy configuration across directory, federation, and cloud services.
NIST Zero Trust (SP 800-207)PL-2 — Policy EnforcementModern access requires policy decisions at multiple enforcement points, not only AD.
ID-1 — Identity ManagementThe question centers on identity sources that cannot by themselves govern modern access flows.
Recommendation — Place access enforcement where the resource and session conditions can actually be evaluated. Treat AD as one identity source within a broader zero trust identity plane.
CIS Controls v85.2 — Account Inventory and ControlAD-only approaches often leave cloud and app accounts outside consistent inventory and control.
6.3 — Access Rights ManagementFragmented identity layers make entitlement review and revocation inconsistent.
Recommendation — Maintain a complete inventory of user, device, and application accounts across all platforms. Review and revoke access rights across directory, SaaS, and device systems on one cadence.
OWASP Non-Human Identity Top 10NHI-01 — NHI Discovery and InventoryModern access estates include machine and service identities alongside human users.
Recommendation — Inventory non-human identities that AD-only workflows fail to govern.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org