They often treat them as compatibility layers instead of high-value trust infrastructure. AD FS, NTLM, and LDAP may be old, but they still help decide whether identity assertions are accepted. That makes them security-critical, especially when modern controls are deployed around them but not through them.
Why This Matters for Security Teams
AD FS and legacy protocols are not harmless compatibility layers. They sit in the trust path that decides whether assertions, tickets, and directory lookups are accepted, which means weaknesses there can invalidate otherwise strong controls at the edge. Security teams often harden cloud apps, MFA, and endpoint policy while leaving older trust brokers and authentication protocols under-monitored. That gap is visible in real incidents, including the Schneider Electric credentials breach, where identity infrastructure became part of the attack path rather than just a background service.
The mistake is to treat AD FS, NTLM, and LDAP as legacy exceptions instead of as active security control points. If they issue or validate identity signals, they can be abused to replay, relay, or amplify trust. Current guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls supports strong control over authentication, logging, and privileged access, but those controls must be applied through the legacy path, not just around it. In practice, many security teams discover the risk only after a legacy protocol has already been used to turn a small foothold into domain-level trust.
How It Works in Practice
AD FS and older protocols still matter because they often perform the final trust decision. AD FS can mint or relay assertions that downstream services accept, while NTLM and LDAP can provide the authentication and directory validation used by servers, service accounts, and administrative tools. Attackers know that if they can influence those checks, they may bypass modern controls that never inspect the legacy exchange directly. The result is a trust mismatch: modern identity governance on top, older authentication semantics underneath.
Security teams should map every legacy trust dependency, then decide where control needs to move. A practical approach includes:
- Reducing reliance on NTLM where modern Kerberos, certificate-based auth, or federated methods are available.
- Hardening AD FS claims rules, signing certificates, token lifetimes, and administrative access.
- Logging and alerting on directory binds, federation events, and authentication failures, not only successful logons.
- Restricting where legacy protocols can be used, especially for service accounts and admin workflows.
- Testing for relay, downgrade, and token abuse paths as part of routine validation.
This is also where identity governance intersects with NHI controls. Service accounts, API connectors, and automation often depend on LDAP or federation artifacts that were issued long ago and rarely reviewed. NHI Mgmt Group’s Ultimate Guide to NHIs shows how long-lived credentials and excessive privilege remain common failure modes, and that pattern becomes more dangerous when a legacy trust broker can accept them without modern challenge. The operational answer is to treat legacy auth as a tier-0 dependency and align it with controls in NIST SP 800-53 Rev 5 Security and Privacy Controls. These controls tend to break down in hybrid directories with multiple forests and federated partners because trust paths become indirect and difficult to validate end to end.
Common Variations and Edge Cases
Tighter protocol restrictions often increase operational overhead, requiring organisations to balance security gains against application breakage and legacy dependency risk. That tradeoff is especially sharp in environments with old ERP systems, OT-adjacent tools, print services, or vendor-managed integrations that still rely on NTLM or LDAP binds. Best practice is evolving, but there is no universal standard for replacing every legacy protocol at once, so teams should prioritize risk-based containment over disruptive elimination.
AD FS edge cases also matter. Some organisations still use it only for a narrow set of claims transformations, while others rely on it as a full federation hub across cloud and on-prem estates. In the first case, the safer move may be to reduce scope and monitor the remaining assertion flow. In the second, a full review of signing keys, token issuance policy, MFA enforcement, and administrative separation is warranted. The same logic applies to legacy protocol exceptions: if an exception exists for one application, it can become the easiest lateral movement path for many others. The Schneider Electric credentials breach is a reminder that identity infrastructure failures are often discovered through compromise, not policy review. Current guidance suggests tracking every exception as a formal risk acceptance item, then retiring it with a date and owner rather than letting it persist indefinitely.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Legacy auth paths often expose long-lived non-human credentials. |
| NIST CSF 2.0 | PR.AC-1 | Trust decisions in AD FS and legacy protocols are access control functions. |
| NIST Zero Trust (SP 800-207) | SC-7 | Legacy protocols undermine trust segmentation if left broadly reachable. |
| NIST AI RMF | GOVERN | Legacy identity infrastructure needs accountable oversight and risk ownership. |
| OWASP Agentic AI Top 10 | A2 | Autonomous systems amplify legacy trust abuse when they inherit old protocols. |
Inventory legacy NHI-dependent services and replace static credentials with short-lived, monitored alternatives.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on July 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org