They miss a large part of the attack path. A review that stops at on-premises AD can overlook cloud permissions, guest access, application consent, and authentication weaknesses that attackers use to pivot into or out of the directory. In practice, that leaves gaps in detection and remediation, especially when privileged identity controls are inconsistent across both environments.
Why a hybrid identity review must cover both AD and Entra ID
A hybrid identity environment is one directory security surface, even if it is split across an on-premises forest and a cloud identity plane. A review that only inspects AD usually sees legacy group membership, domain trusts, and local privilege paths, but it misses cloud-native permissions and the authentication and consent layer that often decide whether an attacker can move laterally, persist, or re-enter the environment.
That gap matters because the attack path is rarely confined to one directory. A compromise can start with a weak on-premises account, then pivot through federation, stale application consent, guest collaboration, or mis-scoped cloud roles. The inverse is also true: a cloud foothold can be used to influence or accelerate access back into the enterprise directory if the two sides are not reviewed together.
Entra ID also changes the shape of the review. You are not only checking who has a group in AD, you are checking whether cloud permissions, conditional access, app registrations, enterprise applications, delegated consent, and external users are producing access that never appears in a domain-only assessment. That is why hybrid identity reviews need to cover both directory planes as a connected control system, not as two separate inventories. For practical guidance on the non-human side of that control system, see Ultimate Guide to NHIs and Top 10 NHI Issues.
What teams usually miss when they stop at on-premises AD
The most common blind spots are cloud permissions, guest access, application consent, and authentication policy drift. Those are not side issues. They are often the points where an attacker can convert a valid but low-friction foothold into durable access, especially when cloud roles, legacy AD groups, and administrator workflows are not aligned.
- Cloud roles and directory-wide permissions that never exist in AD.
- Guests, cross-tenant users, and collaboration paths that bypass traditional joiner-mover-leaver checks.
- Application consent and service principal permissions that create silent access paths.
- Authentication controls in Entra ID that differ from on-premises MFA, password policy, or sign-in monitoring.
Because these controls operate differently, a clean AD report can give a false sense of completeness. A team may conclude that privileged access is tightly managed when, in reality, the same person or app has effective control through an Entra role, consent grant, or token-based path. The result is inconsistent remediation, because the issue is discovered only after the directory review is considered “done.”
For evidence-driven context on how missed identity pathways turn into real compromise, the 52 NHI Breaches Analysis is a useful companion, and the broader attack-path lesson is reinforced by Storm-2949 Azure Breach and Microsoft Entra ID Flaw.
How to make the review materially complete
The review should start with the access paths that connect the two environments: federation, synchronization, privileged role assignment, guest governance, and application authentication. That is where gaps usually hide, because the control owner, audit trail, and remediation owner can differ between AD and Entra ID even when the identity belongs to the same user, app, or administrator.
What to verify: confirm that every privileged identity is assessed in both planes, that cloud roles are mapped back to business ownership, and that application consent is reviewed alongside group membership and admin rights. If a control exists only in one environment, treat that as a finding, not a convenience.
Decision rule: if an identity can authenticate to cloud resources, administer applications, or grant access without appearing in the on-premises review, the review is incomplete. Use the combined result to drive remediation, not the AD report alone.
For implementation alignment, pair directory review with authoritative control guidance from OWASP Non-Human Identity Top 10 and NIST Cybersecurity Framework 2.0, and use Cloud Compliance Pulse 2025 to anchor governance, audit, and access review expectations across the hybrid estate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Visibility and Discovery | Hybrid reviews must cover cloud and non-human access paths to avoid blind spots. |
| NHI-03 — Secrets and Credential Management | Authentication weaknesses and token paths can create hybrid pivot opportunities. | |
| NHI-06 — Privilege and Authorization | Cloud roles and app permissions materially affect hybrid privilege exposure. | |
| Recommendation — Inventory every identity and access path across AD and Entra ID. Review and rotate credentials, tokens, and consented access in both planes. Apply least privilege consistently across directory, app, and cloud roles. | ||
| NIST CSF 2.0 | GV.OC-03 — Cybersecurity Risk Management Strategy | A hybrid identity review defines scope for enterprise access risk management. |
| PR.AA-01 — Identity Management, Authentication, and Access Control | The issue is missing authentication and access paths across both environments. | |
| DE.CM-01 — Monitoring and Log Data | Gaps in detection occur when cloud sign-in and consent events are excluded. | |
| Recommendation — Scope identity reviews to include both on-premises and cloud control planes. Verify authentication and access controls across AD and Entra ID together. Collect and review sign-in, role, and consent telemetry from both directories. | ||
| CIS Controls v8 | 6 — Access Control Management | Hybrid access reviews must include authorization and privileged access in both systems. |
| 5 — Account Management | Guest and synced account governance is central to hybrid identity completeness. | |
| Recommendation — Review and remove unused or excessive access across AD and Entra ID. Maintain authoritative account inventories for both on-premises and cloud identities. | ||
| NIST Zero Trust (SP 800-207) | SC-1 — Zero Trust Architecture | Hybrid identity is a trust-boundary problem requiring continuous verification across control planes. |
| Recommendation — Treat each directory and token issuance point as a separate trust decision. | ||
| NIST SP 800-63 | 3 — Authenticator Assurance and Lifecycle | Hybrid reviews depend on consistent authenticator policy and lifecycle management. |
| Recommendation — Align authenticator assurance and recovery controls across AD and Entra ID. | ||
Practitioner Guidance
What to prioritise: start with the identities that can bridge environments, especially privileged users, cloud administrators, synced accounts, and apps with tenant-wide permissions. Those are the paths most likely to hide a high-impact gap if you only inspect AD.
What to measure: track how many access grants, admin roles, and consented applications are visible in Entra ID but absent from the AD-focused review. A non-zero mismatch is the signal that the hybrid review design needs correction, not just cleaner reporting.
Common mistake: treating Entra ID as a downstream implementation detail of AD. In practice, cloud authentication and authorization frequently create independent exposure, so a directory review that ignores them misses both attacker paths and remediation targets.
Practitioner takeaway: A hybrid identity review is only defensible when it tests the full trust chain, because attackers need only one unmanaged path between AD and Entra ID to turn a partial review into a real control failure.
Related resources from NHI Mgmt Group
- How should security teams assess hybrid identity environments across AD, Entra ID, and Okta?
- How should federal IAM teams assess hybrid identity posture across GCC High and on-premises AD?
- How should security teams implement IAM resilience for Microsoft Entra ID in hybrid identity environments?
- How should teams govern hybrid Active Directory and Entra ID at the same time?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org