Academy

Module 7 · Hybrid AD & ADFS Attack Surface 🔒

Manish Garg
Manish Garg Associate CISSP · RingSafe
April 22, 2026
4 min read

Hybrid AD environments — on-prem AD synchronized with Entra ID via Entra Connect, possibly federated through ADFS — combine the attack surfaces of both. Attackers move between on-prem and cloud planes via the connection points: Entra Connect server, ADFS, seamless SSO computer object, password hash sync. This module covers the hybrid attack patterns and the controls that limit lateral pivot in 2026.

The hybrid identity architectures

  1. Cloud-only — accounts native in Entra ID; no on-prem AD. Increasingly common for new orgs
  2. Synchronized identity — Entra Connect syncs user objects + password hash to Entra ID. Single identity used both
  3. Federated identity — sign-in delegated from Entra ID to on-prem ADFS; ADFS authenticates against AD
  4. Pass-through authentication (PTA) — Entra ID forwards auth requests to lightweight agents on-prem that validate against AD

Each model has distinct compromise paths.

Entra Connect server — the crown jewel

The Entra Connect server has, by default:

🔐 Advanced Module · Pro Tier

Continue reading with Pro tier (₹4,999/year)

You've read 25% of this module. Unlock the remaining deep-dive, quiz, and every other Advanced/Expert module.

136+ modulesAll levels up to this tier
20-question quizzesUnlimited retries with explanations
Completion certificatesShareable on LinkedIn
6 more sections locked below