Where should identity live, and who gets to decide?
The Authentication Insights Newsletter
Hello,
Welcome to the latest edition of The Authentication Insights Newsletter, where we share practical perspectives on identity and authentication in on-premises and hybrid Active Directory environments.
Today, we're raising a question that many security teams are asking: where should identity live? Who gets to decide, and why?
It's not just a debate about cloud vs. on-prem. It's a question of control, sovereignty, and the tradeoffs we're willing (or not) to make.
At a recent lunch with media leaders, Sam Altman made a passing comment that stuck:
In the not-so-distant future, AI will run locally on devices rather than in the cloud.
The drivers? Data security and privacy.
That probably sounds familiar if you work in a highly regulated environment, or if you've ever had to justify architectural decisions to compliance teams.
Of course, AI and identity workloads aren't the same. But the shift is worth paying attention to.
As the implications of cloud-first adoption become clearer, more teams are rethinking what truly belongs in the cloud, and what doesn't.
If even AI, with its intense computing needs, finds value in local control, shouldn't identity have that option too?
Identity is a critical layer in the security stack. It's the control point for everything else.
And yet, in the rush to modernize, we're expected to extend, or offload, that control to the cloud.
For many, the tradeoff makes sense. But for others, especially those in tightly regulated sectors, giving up control over identity data isn't just complex. It's simply not an option.
Sovereignty matters. It means knowing, and deciding, who has access to what, when, and from where. On your terms, not your vendor's.
So, what about the continued push to move identity to the cloud?
There's no denying the value in cloud-native tools: agility, scale, innovation. But there are familiar warning signs, too:
Identity sprawl across tenants, apps, and providers
Expanded attack surface from broader cloud exposure
Reduced visibility and control for teams managing primarily on-prem environments
The momentum is massive. The incentives are clear.
But the risks, particularly around data sovereignty, identity sprawl, and attack surface, are just as real.
Too often, the solutions that help bridge these gaps come with an enterprise price tag (whether that's a third-party IAM platform, an Entra P2 license, or both) or an outsized operational burden (like maintaining GPOs at scale).
Raising a hand to ask "Does this actually make sense for us?" doesn't make you outdated. It means you're a careful steward of your environment.
The real question isn't what the market is doing. It's: where should your critical identity data live?
There is a choice, and it's a strategic one.
For many organizations, hybrid identity is the only realistic model
For some, full cloud may be the right fit (especially where flexibility trumps control)
For others, on-prem remains essential, with added identity security layered on top
What matters is finding the right balance.
Here's what a modern "middle path" might look like:
Active Directory remains your authoritative identity source
You layer in strong access controls (MFA, SSO, contextual policies)
You extend on-prem authentication securely to cloud services like Microsoft 365
The future isn't all cloud or all on-prem. At least, not for everyone. It's whatever hybrid blend gives you the control you need, now and for whatever comes next.
Thinking through your hybrid identity strategy? These reads can help:
Until next time,
The Authentication Insights Team