Back to Field Notes
Identity & Access/Field Note

Directory Services Modernization — Beyond the AD Era

AD is not dead. It is just no longer the right center of gravity. The migration is multi-year and worth doing.

Author

Yusuf Ahmed

Principal Engineer, Platform Security

Published

March 19, 2026

Read

10 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01Active Directory remains the heart of most enterprise identity despite years of cloud-first investment. Modernization (cloud IdP as center of gravity, AD reduced to authoritative-for-Windows) is multi-year but increasingly the right program.
  • 02End-state target: cloud IdP as authentication source for all SaaS and modern web apps, AD reduced to Windows authentication and legacy directory needs, AD trust to cloud IdP (not the reverse), group memberships that matter live in cloud IdP, service accounts modernized to managed identity wherever feasible.
  • 03Migration sequence: start greenfield SaaS (cloud IdP only, no AD federation), move existing SaaS in waves prioritized by user population, migrate Windows authentication selectively (Entra Join for new devices, hybrid for existing). AD cleanup is the long tail and the most painful step — schedule it last.
  • 04AD security in the meantime: treat it as the Tier-0 asset it is. Tiered administration, separate workstations for AD admins, no internet browsing from AD admin sessions, ITDR coverage for AD-specific attacks. Vulnerabilities have been documented for a decade; discipline is what is missing.

Active Directory remains the heart of most enterprise identity, despite years of cloud-first investment. Modernization — moving the center of gravity to a cloud-native IdP and reducing AD to authoritative-for-Windows — is a multi-year program but increasingly the right one.

The end-state target

  • 01Cloud IdP as the source of authentication for all SaaS and modern web apps
  • 02AD reduced to Windows authentication and legacy directory needs
  • 03AD trust to cloud IdP, not the reverse
  • 04Group memberships that matter live in the cloud IdP
  • 05Service accounts modernized to managed identity wherever feasible

The migration sequence

Start with greenfield SaaS — onboarding to the cloud IdP only, no AD federation. Move existing SaaS in waves, prioritized by user population. Migrate Windows authentication selectively (Azure AD Join for new devices, hybrid for existing). The AD cleanup is the long tail and the most painful step — schedule it last.

AD security in the meantime

While AD is still in use, treat it as the Tier-0 asset it is. Tiered administration model, separate workstations for AD admins, no internet browsing from AD admin sessions, ITDR coverage for AD-specific attacks. The vulnerabilities have been documented for a decade; the discipline is what is missing.

#Active Directory#Modernization#Identity

/WRITTEN_BY

Yusuf Ahmed

Principal Engineer, Platform Security · Alexa Cybersecurity