Last updated: April 29, 2026
Hybrid AD environments — on-prem AD synchronized with Entra ID via Entra Connect, possibly federated through ADFS — combine the attack surfaces of both. Attackers move between on-prem and cloud planes via the connection points: Entra Connect server, ADFS, seamless SSO computer object, password hash sync. This module covers the hybrid attack patterns and the controls that limit lateral pivot in 2026.
The hybrid identity architectures
- Cloud-only — accounts native in Entra ID; no on-prem AD. Increasingly common for new orgs
- Synchronized identity — Entra Connect syncs user objects + password hash to Entra ID. Single identity used both
- Federated identity — sign-in delegated from Entra ID to on-prem ADFS; ADFS authenticates against AD
- Pass-through authentication (PTA) — Entra ID forwards auth requests to lightweight agents on-prem that validate against AD
Each model has distinct compromise paths.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.