"Active Directory (AD) and Entra ID are at the center of how many organizations manage access to critical systems, applications, and data."
Identity — the new perimeter
The cybersecurity paradigm has shifted: the perimeter is no longer the network; it is identity. Active Directory and Entra ID sit at the control plane that ties endpoints, cloud workloads, and infrastructure together, which is why attackers focus on the directory rather than a single host. AD remains the primary identity store for about 90 percent of businesses worldwide, and compromising the directory can grant an attacker access to an entire environment rather than an individual system.
The pattern in major incidents is consistent. Rather than relying first on endpoint malware, adversaries exploit identity material — stolen or forged credentials and tokens — to move through environments. The source notes that attackers who specialize in AD often possess a deeper understanding of its architecture than the teams responsible for defending it, widening the gap between offense and defense.
The visibility problem in government agencies
Visibility, the report warns, is the central problem: what security teams cannot see they cannot fix. This dynamic is acute in the public sector. Many government IT environments depend on legacy systems with unpatched vulnerabilities and misconfigurations. Agencies frequently built identity and access management programs incrementally, producing disconnected legacy systems, operational blind spots, and governance gaps.
The consequence is cumulative: every “temporary” permission, exception, and legacy service account adds weight to an environment, and the more fragmented the infrastructure, the more misconfigurations accumulate. In short, treating identity stores as stable infrastructure—something that only changes when it breaks—creates a widening gap between assumed posture and the reality that audits, assessments, or attackers eventually reveal.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildPurple Knight and the role of independent measurement
To move from assumption to evidence, the source highlights independent assessment tools as a practical starting point. It cites Purple Knight, a free assessment tool from Semperis, which scans hybrid Active Directory, Entra ID, and Okta environments for indicators of exposure and indicators of compromise. Purple Knight provides assessment scores and prioritized guidance to identify and remediate weaknesses.
The tool earned a specific endorsement in the international security community: Purple Knight was cited as a recommended tool in the Five Eyes joint advisory, Detecting and Mitigating Active Directory Compromises, which was co-authored by the U.S. National Security Agency, CISA, and partner agencies. That citation frames the scanner as an accepted diagnostic instrument rather than a silver bullet.
A scan is a diagnostic baseline, not a panacea
The source stresses that a scan is a starting point. It describes a scan as a diagnostic baseline — useful for moving from belief to evidence — but not a complete defense. Scanning does not replace a comprehensive security strategy and still requires ongoing governance, continuous monitoring, and active remediation to close the gaps it identifies.
Put another way: identity infrastructure must be treated as a dynamic attack surface. That demands continuous, objective measurement rather than treating the environment as secure because it has not yet failed.
What this means for technologists, policymakers, and enterprises
- Technologists and security teams: Measure continuously and translate assessment scores into prioritized remediation. Relying on assumed stability in AD or Entra ID invites accumulation of permissions, legacy accounts, and misconfigurations.
- Policymakers and regulators: Acknowledge that public sector environments often contain disconnected legacy systems and governance gaps; policy and funding choices that support centralized identity governance and remediation programs address the operational blind spots the source describes.
- Affected enterprises and procurement leaders: Use independent assessment tools — such as Purple Knight, which scans hybrid AD, Entra ID, and Okta environments and was recommended in the Five Eyes advisory — as part of a baseline diagnostic, then invest in the governance and remediation those diagnostics require.
A concrete next step
The central, unavoidable point from the source is blunt: the organizations best positioned to defend identity infrastructure in the coming years will not necessarily be those with the biggest budgets, but those willing to measure their true exposure and act on what measurement reveals. Scans can expose where identity controls are weakest; governance, monitoring, and remediation close the gaps. That combination — measurement plus follow-through — is the practical path the source presents for shifting identity from an assumed safe haven to a defended, accountable control plane.




