What does modern AD authentication look like?
The Authentication Insights Newsletter
Hello,
Welcome back to Authentication Insights, where we share practical perspectives on identity and authentication in on-premises and hybrid Active Directory environments.
Last time we looked at why you need visibility to know if your AD hardening and authentication policies are working. We talked about how hybrid identity makes visibility harder and creates security gaps.
Which raises the question: can you modernize AD identity security without migrating? That’s a good question, but not the root issue, which is: can you choose? The options should be strong enough for the decision to be yours.
Between a binary and a hard place
Microsoft’s move away from legacy authentication technologies such as NTLM is prompting AD teams to reassess their authentication architecture. Microsoft Entra ID provides capabilities such as Conditional Access and risk-based authentication. For organizations that continue to rely on AD, the challenge is how to strengthen authentication across their existing systems without adding unnecessary complexity.
For many organizations, Entra is the right and most simple direction. For others, legacy systems and dependencies run deep. A lot of critical systems or legacy apps don’t have a SaaS equivalent. Or maybe they do, but migrating to it is a heavy lift of its own.
This keeps many environments hybrid, now and for the foreseeable future. The question is whether that’s a choice or a default.
Tech debt and complexity
Most AD defenses fail because of a lapse in fundamentals: a missing control, a misconfiguration, a deprecated protocol. Too much complexity makes it hard to keep your fundamentals sharp. A web builds up over time, across trust relationships no one has reviewed in years, policy hierarchies that contradict each other, old machine identities, and outdated permissions that were never removed.
As Jen Easterly, former CISA director and CEO of RSAC, frequently explains, cybersecurity failures often reflect a software quality problem. When a system is too complex, it’s hard to understand. And if it’s hard to understand, it’s harder to secure. No additional security control fixes that.
Friction as a security problem
When security is hard, users find a way around it. MFA fatigue approvals, password reuse across systems, and shared Windows sessions are all predictable responses to friction, not user error.
It’s easy to point at this as a people problem, but it’s a design and security problem. Security that people need to work around is less likely to work as intended.
Simple security is better security
The way forward isn’t always a full migration. For many, the future will remain hybrid. What matters is to choose the path that meets your security and operational requirements with the least unnecessary complexity.
That’s also the best way to ensure you can answer these questions about your environment:
Who has access?
Under what conditions?
What changed?
Why did it change?
Can we recover quickly?
You can defend Active Directory. But you need to keep it simple.
Modern, secure controls around access and authentication that work for your users and for your environment are what keep the choice yours.
Insights and practical tips
[Webinar] What pentesters fix first: 5 AD hardening wins | October 14, 2026 | 11am EDT/5pm CEST: Spencer Alessi, senior penetration tester and Microsoft MVP, shares how to make your environment harder to attack. Register now
Until next time,
The Authentication Insights Team