Module 7 · Hybrid AD & ADFS Attack Surface

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Apr 22, 2026
4 min read
Read as

Last updated: April 29, 2026

Entra Connect crown jewel, ADFS Golden SAML, PHS attacks, on-prem ↔ cloud lateral movement, Tier 0 isolation.

Hybrid AD environments — on-prem AD synchronized with Entra ID via Entra Connect, possibly federated through ADFS — combine the attack surfaces of both. Attackers move between on-prem and cloud planes via the connection points: Entra Connect server, ADFS, seamless SSO computer object, password hash sync. This module covers the hybrid attack patterns and the controls that limit lateral pivot in 2026.

The hybrid identity architectures

  1. Cloud-only — accounts native in Entra ID; no on-prem AD. Increasingly common for new orgs
  2. Synchronized identity — Entra Connect syncs user objects + password hash to Entra ID. Single identity used both
  3. Federated identity — sign-in delegated from Entra ID to on-prem ADFS; ADFS authenticates against AD
  4. Pass-through authentication (PTA) — Entra ID forwards auth requests to lightweight agents on-prem that validate against AD

Each model has distinct compromise paths.

Want this for your team?

Custom team training + practitioner advisory

Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.

Book team training call Replies in 4 working hrs · India-only · Senior consultants