---
title: "Where should identity live, and who gets to decide? | Authentication Insights"
description: "The decision around where identity should live is not just a debate about cloud vs. on-prem. It's a question of control, sovereignty, and the tradeoffs we're willing to make (or not). Read this issue of the Authentication Insights Newsletter to learn more."
locale: "en"
updated_at: "2026-09-18T14:46:57.441Z"
canonical: "https://www.isdecisions.com/en/authentication-insights/where-should-identity-live-and-who-gets-to-decide-"
---

# Where should identity live, and who gets to decide?

The Authentication Insights Newsletter

Hello,

Welcome to the latest edition of **[The Authentication Insights Newsletter](/authentication-insights/)**, where we share practical perspectives on identity and authentication in on-premises and hybrid Active Directory environments.

**Today, we're raising a question that many security teams are asking: where should identity live? Who gets to decide, and why?**

It's not just a debate about cloud vs. on-prem. It's a question of control, sovereignty, and the tradeoffs we're willing (or not) to make.

### **If AI is going local, why not identity?**

At a recent lunch with media leaders, Sam Altman made a passing comment that stuck:

*In the not-so-distant future, AI will run locally on devices rather than in the cloud.*

The drivers? Data security and privacy.

That probably sounds familiar if you work in a highly regulated environment, or if you've ever had to justify architectural decisions to compliance teams.

Of course, AI and identity workloads aren't the same. But the shift is worth paying attention to.

As the implications of cloud-first adoption become clearer, more teams are rethinking what truly belongs in the cloud, and what doesn't.

**If even AI, with its intense computing needs, finds value in local control, shouldn't identity have that option too?**

### **Identity is where sovereignty begins**

Identity is a critical layer in the security stack. It's the control point for everything else.

And yet, in the rush to modernize, we're expected to extend, or offload, that control to the cloud.

For many, the tradeoff makes sense. But for others, especially those in tightly regulated sectors, giving up control over identity data isn't just complex. It's simply not an option.

Sovereignty matters. It means knowing, and deciding, who has access to what, when, and from where. On your terms, not your vendor's.

### **Asking the obvious question**

So, what about the continued push to move identity to the cloud?

There's no denying the value in cloud-native tools: agility, scale, innovation. But there are familiar warning signs, too:

- **Identity sprawl** across tenants, apps, and providers
- **Expanded attack surface** from broader cloud exposure
- **Reduced visibility and control**** **for teams managing primarily on-prem environments

The momentum is massive. The incentives are clear.

But the risks, particularly around data sovereignty, identity sprawl, and attack surface, are just as real.

Too often, the solutions that help bridge these gaps come with an enterprise price tag (whether that's a third-party IAM platform, an Entra P2 license, or both) or an outsized operational burden (like maintaining GPOs at scale).

Raising a hand to ask "Does this actually make sense for us?" doesn't make you outdated. It means you're a careful steward of your environment.

### **Making the right identity choice for your team**

The real question isn't *what the market is doing.* It's: where should **your** critical identity data live?

There *is* a choice, and it's a strategic one.

- For many organizations, hybrid identity is the only realistic model
- For some, full cloud may be the right fit (especially where flexibility trumps control)
- For others, on-prem remains essential, with added identity security layered on top

What matters is finding the right balance.

Here's what a modern "middle path" might look like:

- Active Directory remains your authoritative identity source
- You layer in strong access controls (MFA, SSO, contextual policies)
- You extend on-prem authentication securely to cloud services like Microsoft 365

The future isn't all cloud or all on-prem. At least, not for everyone. It's whatever hybrid blend gives you the control you need, now and for whatever comes next.

### **Insights and practical tips**

Thinking through your hybrid identity strategy? These reads can help:

- **[Q&A: Keeping security simple](/blog/news/safetydetectives-interview)**
- **[The hybrid AD identity challenge](/blog/mfa/hybrid-identity-extend-on-premise-active-directory-identity-to-entra-id)**
- **[On-premises MFA for Microsoft 365](/blog/mfa/microsoft-365-mfa-simplify-on-premise-management)**

Until next time,

The Authentication Insights Team
