What an AD/Entra Hybrid Audit Actually Looks For & Why Most Teams Fail the First One
What an AD/Entra Hybrid Audit Actually Looks For & Why Most Teams Fail the First One
Oct 2, 2026
Most AD cleanup processes stop at the domain boundary, but hybrid audits don’t. Here’s what auditors actually check across Active Directory and Entra ID, and the gaps that trip up teams in their first review.
Ask a few IT teams how they handle offboarding and you’ll hear the same answer: disable the account in Active Directory, close the ticket, and move on.
Then an auditor pulls the Entra ID inventory and finds that account still enabled and still assigned to the application role it had on day one. The sync missed the change, no alert fired because none was configured, and both directories reported a healthy account. They just disagreed about its state.
I hear versions of this from teams that were confident, right up until their first hybrid audit, that their identity hygiene was covered.
“We have AD hygiene covered” isn’t the same claim as “we’ll pass a hybrid audit”
Most teams have some version of an AD cleanup process: quarterly stale-account reviews, privileged group audits, and password policy checks. It’s a real process, and it usually works…for Active Directory.
Most published AD security advice is aimed at hardening it against attackers by patching, tiering admin accounts, and closing off delegation paths. Those are useful things to do, but they don’t answer the question an auditor is really asking. They’re not testing whether your directory would survive an attack. They’re testing whether your identity data holds up as evidence when someone reviews it after the fact.
The problem is scope. That process is almost always scoped to on-premises AD because that’s where the tooling, ownership, and institutional habit all live. But auditors scope their reviews differently: to the identity as it exists and functions everywhere it’s usable. In a hybrid Microsoft environment, that includes the synced Entra ID side, too.
That’s the gap between what security teams assume gets checked and what an auditor actually pulls:
- What teams assume gets checked: AD account hygiene, password policy compliance, and privileged AD group membership.
- What auditors actually pull: all of that, plus sync state and lag, permission drift between the two directories, a change history for the sync configuration itself, and any privilege that exists in Entra with no on-prem equivalent to review against. The frameworks back that up, too: SOC 2’s logical access criteria (CC6.1–CC6.3) and ISO 27001:2022’s access-control controls (A.5.15, A.5.18, and A.8.2 on privileged access) both require access to be reviewed as it stands, not as one system reports it, which is exactly the AD-only blind spot most teams carry into a hybrid review.
Teams pass the AD half of that list and get surprised by the Entra half because they’re running an AD-era hygiene process against a hybrid-era environment, not because they’re being sloppy.
The five things an auditor pulls in week one
- Sync lag and drift: The account is disabled in AD but remains privileged in Entra because sync hasn’t run, ran incompletely, or silently excludes a scope it was never configured to cover. Auditors ask for a diff, not a snapshot, and most teams have never generated one. No vendor or analyst publishes an aggregate rate for how often this happens because nobody is measuring the gap you’re being asked to close. The diff is the only way to find out where you stand.
- A change history for the sync configuration itself: You need to know who changed sync scope or filtering rules and when. This matters because it’s a documented pivot point in real incidents rather than just an audit checkbox. Microsoft’s own August 2025 writeup on the Storm-0501 ransomware group describes exactly this: the actors compromised an unmonitored Entra Connect Sync server, extracted the Directory Synchronization Account’s credentials, then reset the target user’s on-premises password, which Entra Connect Sync then dutifully, legitimately propagated to the cloud identity, handing them a synced Global Administrator account that had never been enrolled in MFA. The sync mechanism did exactly what it was built to do, but on behalf of an attacker who’d found the one server nobody was watching. If your sync configuration and its administrative credentials have no change log, you can’t rule that scenario out, and neither can an auditor. It’s not an isolated pattern either; the joint CISA/FBI/RCMP/ASD/NCSC-UK advisory on the Scattered Spider group documents the same underlying move across multiple victims: a helpdesk-driven credential or MFA reset used to pivot into privileged cloud roles through the hybrid sync path.
- Cloud-only privilege with no on-prem equivalent: Roles or group memberships assigned directly in Entra that never touch AD are invisible to any review process still centered on AD. These are as easy to create by accident as they are to forget entirely.
- The sync/service account’s own privilege: The account running your Connect Sync or Cloud Sync process often carries more standing privilege than any human account in the environment, and it’s usually the one examined least in a routine AD review, because it doesn’t look like a “user.”
- An evidence trail spanning both sides, not just current state: Auditors want to see who changed what and when, across both directories. Most teams can produce a clean current-state report, but far fewer can produce one that actually spans the boundary between AD and Entra.
Who owns the gap?
AD is usually owned by an infrastructure or identity team, and Entra is owned by a cloud or M365 team. That ownership split, not any tooling gap, is the problem. Audit prep inherits the split by default, meaning each team can show up to a clean report, but only for their half.
Rather than addressing that gap, native tooling reinforces it. The Active Directory Administrative Center shows AD cleanly, and the Entra admin center shows Entra cleanly. Neither one shows what happens between them because neither one is responsible for it.
The audit fails because your directory has two halves and nobody owns the gap between them, not because your directory is dirty.
What to check this week
You don’t need to wait for an audit notice to find out where you stand. Before your next review:
- Pull your sync error logs: not just the success/failure summary, but whether any job has partial or silent failures baked into its “success” status.
- Diff privileged group membership between AD and Entra directly, rather than reviewing each side independently.
- Inventory your sync and service account privilege the same way you’d inventory a human admin account.
- Confirm change-history retention exists and is comparable on both sides, not just current state, but history.
- Check for cloud-only role assignments that have no AD-side equivalent to compare against.
None of these require new tooling to start, but they do require someone to run the comparison across both directories instead of reviewing each one in isolation.
Where that leaves you
A hybrid AD/Entra audit tests something genuinely different from an AD audit, so it’s not just a harder version of the same thing. Most teams still walk in with an AD-only checklist, and that’s why the first audit tends to surface findings nobody saw coming.
Netwrix Directory Manager won’t flag that sync gap for you, but it can help you do most of the manual reconciliation work above, so you don’t have to stitch it together by hand. It gives you a single place to see group lifecycle, ownership, and admin activity across AD, Entra ID, and Google Workspace, along with a built-in audit trail of admin actions. And that gives you a head start on the evidence an auditor will ask for.
Share on
Learn More
About the author
Dave Miles
David Miles is an Expert Product Manager at Netwrix, leading product strategy for Netwrix Directory Manager (NDM) within the company’s Identity and Access Management portfolio.
With more than two decades of experience in identity and cybersecurity, David brings a practical perspective on the challenges organizations face in managing identities, securing access, and reducing risk across complex enterprise environments.
Throughout his career, David has worked at the intersection of technology, security, and product strategy, holding senior roles at Arctic Wolf, One Identity, Dell, and Quest Software. His experience spans product leadership, software engineering, customer engagement, and go-to-market, giving him a broad perspective on both the technical and business challenges of enterprise identity security.
David regularly works with customers and technology teams around the world to understand emerging identity challenges and translate them into practical product strategies and solutions.
He is based in Somerset, UK.
Learn more on this subject
System logs: how to differentiate between an AI agent and a human hacker
Netwrix Auditor named to two 2026 Capterra Shortlists
NIST CSF 2.0: What's new in the Cybersecurity Framework
Privileged Access Management solutions market: 2026 guide
Data Privacy Laws by State: Different Approaches to Privacy Protection