Summary
This post challenges a widely held assumption, that keeping legacy Active Directory running alongside Entra ID is a safe, neutral choice. It argues that AD, left in place mainly to support legacy applications or antivirus policy enforcement, has become a disproportionate security liability. The piece walks through why AD lacks native modern authentication protections such as enforced MFA, why patching cycles for Microsoft's identity infrastructure consistently lag behind disclosed vulnerabilities, and why syncing AD to Entra ID improves visibility without closing the underlying gaps. It draws on Sophos research showing attackers reach an AD server in a median of 3.4 hours after initial access, explains the practical damage an attacker can do once inside a domain, raises AD backup and recoverability as a separate but related risk, and includes a direct quote from CommSec CTO Barry Rooney pressing readers to treat identity strategy as a deliberate decision rather than an inherited default. It closes with a two-step recommendation: an Active Directory penetration test to establish real exposure, followed by a Microsoft Identity Assessment to map the wider AD and Entra ID relationship.
For years, Active Directory was the backbone of enterprise IT. Every user, every device, every permission ran through it. Then the shift to the cloud began, and most organisations layered Entra ID on top, syncing identities so staff could log into Microsoft 365 and cloud applications with the same credentials they always used. The result, for many companies, is that they are now running two identity systems side by side: the legacy on-premises AD they built their network on, and the cloud-based Entra ID they adopted to keep pace with everything else. That raises an uncomfortable question. Do you still need the original one, or has it quietly become just another way in for an attacker?
The stakes of getting this wrong are not theoretical. Sophos found that once an attacker gains a foothold inside a network, they reach the Active Directory server in a median time of just 3.4 hours, and that identity-related weaknesses, stolen credentials, brute-force attempts, and weak passwords now drive more breaches than software exploits do. Whatever role legacy AD still plays in your environment, it is one of the fastest routes an attacker has to full control.
Why Do Companies Still Run Legacy Active Directory?
Nobody keeps legacy Active Directory running out of nostalgia. There is usually a specific reason it has not been switched off. Certain line-of-business applications were built to authenticate directly against on-premises AD and were never rearchitected for cloud identity. Antivirus and endpoint management tools in some environments still depend on AD to push policies and group memberships to devices. Print services, file shares, and older infrastructure may all be tied to it in ways that are inconvenient, expensive, or simply forgotten about to unpick.
None of these reasons are unreasonable on their own. The problem is that they accumulate, and each one becomes a justification to leave a legacy system running indefinitely, long after the organisation’s actual centre of gravity has moved to the cloud.
Is Active Directory Still Secure in 2026?
Here is the uncomfortable detail many IT teams overlook. Active Directory, on its own, was never built with modern authentication protections at its core. Multi-factor authentication is not enforced natively at the AD level the way it is in Entra ID. In practice, this means MFA can be absent, weakly applied, or effectively turned off for on-premises authentication, even in organisations that assume they are fully protected because MFA is switched on for their cloud applications.
That gap matters enormously, and it sits alongside a second problem: the pace at which AD-related vulnerabilities are being found and fixed. Microsoft’s identity platform has faced maximum-severity vulnerabilities in recent months, including a flaw rated a perfect ten for severity, and researchers have previously flagged issues that could have been catastrophic had they been discovered by attackers first. Yet patching cycles consistently lag behind disclosure. Many organisations take weeks or months to apply critical updates across their identity infrastructure, and legacy on-premises AD servers, often lower on the patching priority list than customer-facing systems, are frequently the slowest of all to be brought up to date. Attackers know this and factor the delay into their planning.
Combine that with everything covered in AD’s long history of weaknesses, weak password policies, excessive standing privileges, unconstrained delegation, legacy protocols like NTLM still quietly enabled, and legacy AD stops looking like a harmless leftover. It starts looking like the softest target in the environment.
Does Syncing AD to Entra ID Make It Secure?
Many organisations sync their on-premises AD to Entra ID specifically so that authentication events, sign-in attempts, and anomalies get surfaced through Azure’s monitoring and conditional access policies. This is a sensible step. It brings visibility to activity that would otherwise sit invisible on a local domain controller.
But synchronisation is not the same as protection. It extends Entra ID’s visibility into AD activity, it does not retrofit AD with the security model Entra ID was actually built around. If an attacker compromises a domain controller directly, or exploits a misconfiguration that never touches the cloud sync path at all, that activity can still go unnoticed for far longer than anyone assumes. This is compounded by a problem Sophos has raised directly: log retention on firewalls and other appliances can be as short as twenty-four hours to seven days. Given a median breach-to-AD time of 3.4 hours, that retention window can close before anyone has a chance to investigate. Sync gives you a window into AD. It does not close the gaps inside it, and it does not guarantee you will have the evidence left to understand an incident after the fact.
Active Directory vs Entra ID: What Is the Difference?
You may notice references here to both Active Directory and Entra ID. This is not two different products. In 2023, Microsoft rebranded Azure Active Directory, its cloud-based identity and access management service, as Microsoft Entra ID. The change was largely about clarity and positioning, separating the cloud identity platform from the on-premises Active Directory Domain Services that many organisations still run on local servers.
The distinction matters for how you think about risk. On-premises Active Directory remains vulnerable to the misconfigurations covered in this post: excessive privileges, unconstrained delegation, and legacy protocols. Entra ID, as the cloud counterpart, carries its own exposure through conditional access gaps, token theft, and recently disclosed critical vulnerabilities. Most mid-sized and enterprise organisations run a hybrid setup, syncing on-premises AD with Entra ID. A weakness in either half can become a route into the other.
What Can a Hacker Do if They Access Active Directory?
This is where the stakes become clear. Active Directory is not just one system among many, it is the system that everything else in a Windows environment trusts. If an attacker compromises a domain controller or gains sufficient privilege inside AD, the consequences are not contained to one server or one account.
They can create new administrator accounts that look entirely legitimate. They can reset the password of any user in the domain, including yours. They can push malicious Group Policy Objects to every machine on the network at once, a technique Sophos has documented being used to disable firewalls, security software, and logging agents at scale. They can extract every password hash stored in the domain, giving them the means to impersonate any user for as long as those credentials remain valid. If your antivirus, your file shares, and your line-of-business applications all still trust AD, an attacker who owns AD effectively owns all of them too. This is what “keys to the kingdom” actually means in practice, not a figure of speech, but a single compromised system with the authority to grant an attacker anything else it controls.
Is Your Active Directory Backed Up?
There is a separate question worth asking alongside all of this: is your Active Directory actually backed up, and could you rebuild it if it were destroyed or encrypted in an attack? Ransomware groups increasingly target domain controllers directly, because destroying or corrupting AD does not just cause disruption, it can take down authentication for the entire organisation at once. A backup strategy for AD needs to account for this specifically, not simply assume that general server backups cover it.
A Question Worth Asking Directly
“Every organisation running legacy AD alongside Entra ID needs to ask itself a hard question,” says Barry Rooney, CTO at CommSec. “Is Active Directory still serving a genuine purpose, or has it just become another attack path you no longer actually need? Too many businesses keep it running by default rather than by decision, and that is exactly the kind of gap attackers are counting on. Identity strategy cannot be an afterthought. It has to be reviewed as deliberately as any other part of the security estate.”
Should You Keep, Secure, or Retire Active Directory?
For some organisations, the honest answer is yes, for now, because a specific legacy application or piece of infrastructure genuinely still depends on it. For others, the more honest answer is that AD has been kept running by inertia rather than necessity, and the risk it now represents outweighs the convenience it once provided.
Either way, the decision should be a deliberate one, not a default. That means identifying exactly what still relies on AD, testing whether MFA and modern protections are genuinely enforced at the AD level, confirming AD is properly backed up and recoverable, and building a realistic plan to migrate remaining dependencies to Entra ID where possible. Microsoft’s own guidance on mitigating critical threats to Active Directory makes the same basic point: strong passwords, enforced MFA, minimal standing privilege, and retired legacy protocols address the majority of real-world risk. What should not happen is legacy AD sitting untouched simply because nobody has had the time to ask whether it still needs to be there.
The practical starting point is a penetration test focused specifically on your Active Directory environment. Rather than assuming where the gaps are, a pen test shows you exactly how an attacker could move through your domain today, whether that is through excessive privilege, unconstrained delegation, weak service account passwords, or legacy protocols still quietly enabled. It gives you a concrete, evidenced picture of your actual exposure, rather than a theoretical one.
From there, a Microsoft Identity Assessment builds out the wider picture, reviewing how AD and Entra ID work together, where authentication policies differ between the two, and where hybrid identity configuration is creating gaps that neither system fully covers on its own. Together, the two give you both the attacker’s view of your current AD environment and a clear path towards resolving the dependencies keeping it in place.
Frequently Asked Questions
Is Active Directory still relevant in 2026?
Active Directory remains in use across many organisations, usually to support legacy applications, antivirus policy enforcement, or infrastructure not yet migrated to the cloud. However, it lacks native modern authentication protections such as enforced MFA, making it a higher-risk component than Entra ID if left unmanaged.
What is the difference between Active Directory and Entra ID?
Active Directory is an on-premises identity and access management system. Entra ID, formerly Azure Active Directory, is Microsoft’s cloud-based equivalent. Many organisations run both in a hybrid configuration, syncing identities between the two.
Can a hacker do more damage through Active Directory than Entra ID?
Active Directory often carries more legacy misconfigurations, such as unconstrained delegation, excessive privileges, and outdated protocols like NTLM, which can give an attacker broader and faster access once inside the domain.
How do you know if your Active Directory is a security risk?
A penetration test focused specifically on Active Directory is the most direct way to identify real, exploitable weaknesses, rather than assuming your environment is secure based on cloud protections alone.
Should we migrate fully from Active Directory to Entra ID?
For many organisations, yes, though the decision depends on which legacy applications or services still require on-premises authentication. A Microsoft Identity Assessment can clarify what is safe to migrate and what still needs AD in place.
