<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Entra ID - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/entra-id/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/entra-id/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Tue, 31 Mar 2026 08:59:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Entra ID - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/entra-id/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Overview of Active Directory security tools – version 2026 </title>
		<link>https://www.riskinsight-wavestone.com/en/2026/03/overview-of-active-directory-security-tools-version-2026/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/03/overview-of-active-directory-security-tools-version-2026/#respond</comments>
		
		<dc:creator><![CDATA[Benoît Marion]]></dc:creator>
		<pubDate>Tue, 31 Mar 2026 08:59:36 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Active directory]]></category>
		<category><![CDATA[AD Backup & Recovery]]></category>
		<category><![CDATA[AD Discovery]]></category>
		<category><![CDATA[Entra ID]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[security tools]]></category>
		<category><![CDATA[Vulnerability Discovery]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=29578</guid>

					<description><![CDATA[<p>  In 2026, Active Directory remains at the heart of the now hybrid identity infrastructure of most large companies and is still widely used as an on-premises identity provider, even when organisations migrate to the cloud.  Wavestone incident response teams note that 38% of attacks begin with...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/03/overview-of-active-directory-security-tools-version-2026/">Overview of Active Directory security tools – version 2026 </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">In 2026, Active Directory remains at the heart of the now hybrid identity infrastructure</span></b><span data-contrast="auto"> of most large companies and is still widely used as an on-premises identity provider, even when organisations migrate to the cloud.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Wavestone incident response teams note that</span><b><span data-contrast="auto"> 38% of attacks begin with identity compromise </span></b><span data-contrast="auto">(vs. 20% in 2024).</span><b><span data-contrast="auto"> </span></b><span data-contrast="auto">More broadly,</span><b><span data-contrast="auto"> attackers frequently exploit on-premises identities to move laterally into cloud environments </span></b><span data-contrast="auto">(Microsoft Digital Defence Report 2025 [1]).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">In a context where the </span><b><span data-contrast="auto">hybridisation of identities increases an already vast attack surface</span></b><span data-contrast="auto">, companies must be able to understand the challenges and equip themselves effectively.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Through this </span><b><span data-contrast="auto">new 2026 overview of Active Directory security tools</span></b><span data-contrast="auto">, we offer you:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol style="text-align: justify;">
<li><b><span data-contrast="auto">An updated map of Active Directory security tools</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">An overview of major market trends</span></b><span data-contrast="auto"> (consolidation, transition to platforms, cloud hybridisation)</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Feedback on operational implementation challenges</span></b><span data-contrast="auto"> and key success factors</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ol>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><span data-contrast="none">An overview of AD 2026 security tools, which has been further enhanced </span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">By analysing the market, we have identified four main use cases for these tools:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol style="text-align: justify;">
<li><b><span data-contrast="auto">Analysis and audit</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Hardening and maintaining security </span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Detection</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Response and reconstruction</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ol>
<p> </p>
<p style="text-align: justify;"><span data-contrast="auto">A listing of publishers and tools offering features that meet one or more of these four use cases was conducted. It was designed to be as comprehensive as possible, including tools from the best-known and most widely used players on the market as well as those from lesser-known players, proprietary tools and open-source tools, tools with a wide range of features and tools offering a more limited set of features. All relevant tools were thus included in a list, with various information for each one (reputation, description of the tool and use cases covered, hosting, etc.).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">The following overview selected a number of publishers from this list, for the functional coverage they offer and their large use within organisations.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">The Microsoft Entra ID logo is added to tools that offer the possibility of integrating it into their operations in addition to on-premises AD coverage. This is a strong trend in the market.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p> </p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-29566" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1.png" alt="" width="1582" height="890" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1.png 1582w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1-768x432.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1-1536x864.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1-800x450.png 800w" sizes="(max-width: 1582px) 100vw, 1582px" /></span></p>
<h2> </h2>
<h2 style="text-align: justify;"><span data-contrast="none">1. A dynamic market undergoing consolidation</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<p> </p>
<p style="text-align: justify;"><span data-contrast="auto">The Active Directory market has undergone several changes since 2022, with different major transactions. The </span><b><span data-contrast="auto">aim is most often for publishers to complement their offering </span></b><span data-contrast="auto">or to cover a new need for Active Directory security.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Among other things, we can note :</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><strong>Acquisition of PingCastle by Netwrix [2] :</strong><span data-contrast="auto"><strong> </strong>PingCastle, renowned for its expertise in AD security auditing, strengthens Netwrix&#8217;s offering. This acquisition enables Netwrix to expand its portfolio with a lightweight, quick-to-deploy tool that is popular with technical teams, while reaffirming its commitment to providing a unified platform covering the entire AD security lifecycle.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><strong>Acquisition of Attivo by SentinelOne [3] :</strong><span data-contrast="auto"> Attivo, a specialist in identity security and lateral movement detection, strengthens SentinelOne&#8217;s offering by integrating advanced AD protection capabilities into a unified platform combining EDR, XDR and identity security.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><strong>Acquisition of BrainWave by Radiant Logic [4] :</strong><span data-contrast="auto"> Radiant Logic strengthens identity and governance analysis capabilities. By combining BrainWave&#8217;s detailed rights mapping with Radiant Logic&#8217;s identity federation, the offering becomes more comprehensive in addressing AD challenges.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><strong>Integration of Stealthbits by Netwrix [5] :</strong><span data-contrast="auto"><strong> </strong>By merging with Stealthbits, Netwrix has integrated historical Active Directory auditing and detection components (StealthAUDIT, StealthDEFEND, etc.), strengthening its offering in the protection of identities and sensitive data and moving towards a unified platform focused on AD security.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">2. From specific tools to centralised platforms</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">In 2022, our overview of Active Directory security tools mentioned </span><i><span data-contrast="auto">“specialised tools, each addressing part of the equation.” </span></i><span data-contrast="auto">[6]. In 2026, we are seeing the emergence of </span><b><span data-contrast="auto">centralised platforms</span></b><span data-contrast="auto"> capable of covering several needs around Active Directory and, often, Entra ID. This dynamic is </span><b><span data-contrast="auto">primarily driven by publishers</span></b><span data-contrast="auto"> seeking to broaden their value proposition and differentiate themselves with comprehensive platforms rather than specialised tools offering specific features.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">Some publishers build their platforms through successive acquisitions</span></b><span data-contrast="auto">, such as Netwrix (AD auditing, data protection, vulnerability discovery, PingCastle, etc.) or SentinelOne (EDR/XDR enhanced by Attivo on identity), while </span><b><span data-contrast="auto">others are gradually enhancing their existing offerings </span></b><span data-contrast="auto">to provide modular suites, whether they are administration/monitoring tools such as ManageEngine ADAudit Plus or Quest Change Auditor, which add AD auditing, hardening and detection components across the entire Active Directory ecosystem.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">The promises made by publishers are clear:</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Centralisation of data</span></b><span data-contrast="auto"> (accounts, groups, rights, security events)</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1253,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[720,1253,3684,6300],&quot;469777927&quot;:[0,0,0,0],&quot;469777928&quot;:[0,8,1,1]}"> </span></li>
<li><b><span data-contrast="auto">Unified view of attack paths</span></b><span data-contrast="auto"> between AD and Entra ID</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1253,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[720,1253,3684,6300],&quot;469777927&quot;:[0,0,0,0],&quot;469777928&quot;:[0,8,1,1]}"> </span></li>
<li><b><span data-contrast="auto">Simplified management</span></b><span data-contrast="auto"> for security, infrastructure and IAM teams via consolidated consoles and dashboards</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1253,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[720,1253,3684,6300],&quot;469777927&quot;:[0,0,0,0],&quot;469777928&quot;:[0,8,1,1]}"> </span></li>
</ul>
<p style="text-align: justify;"><b><span data-contrast="auto">From the customer&#8217;s point of view, the benefits are obvious, but the reality may be more nuanced:</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<ul>
<li><span data-contrast="auto">Consolidation can reduce the number of tools and simplify integrations, but </span><b><span data-contrast="auto">it does not eliminate the need for AD expertise or specialised tools </span></b><span data-contrast="auto">(e.g. for post-incident reconstruction).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1253,&quot;469777462&quot;:[720,1253,3684,6300],&quot;469777927&quot;:[0,0,0,0],&quot;469777928&quot;:[0,8,1,1]}"> </span></li>
<li><span data-contrast="auto">Environments often remain </span><b><span data-contrast="auto">multi-vendor</span></b><span data-contrast="auto">, with a mix of global platforms (XDR, CNAPP, Identity Security) and targeted AD tools, particularly in large groups or organisations that are already heavily equipped.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1253,&quot;469777462&quot;:[720,1253,3684,6300],&quot;469777927&quot;:[0,0,0,0],&quot;469777928&quot;:[0,8,1,1]}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">In this context, the challenge is not simply to “choose a platform”, but rather to </span><b><span data-contrast="auto">put together a coherent whole</span></b><span data-contrast="auto">, ensuring that:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:708,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<ul>
<li><span data-contrast="auto">The AD/Entra ID scope is well covered throughout the entire lifecycle (prevention, detection, response, reconstruction).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></li>
<li><span data-contrast="auto">The tools can feed </span><b><span data-contrast="auto">existing processes</span></b><span data-contrast="auto"> (SOC, crisis management, PRA, IAM).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></li>
<li><span data-contrast="auto">Dependence on a single publisher is assessed and controlled.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">3. Cloud hybridisation</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">With the rise of Entra ID and SaaS applications, identity hybridisation has become the norm: AD accounts and groups are synchronised to the cloud, and the same credentials are used to access on-premises and cloud resources. Numerous recent incidents show that attackers are exploiting these hybrid architectures to pivot between AD and Entra ID, taking advantage of poor configurations or weak alignment between the two worlds. [7]</span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:533}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">This translates into several concrete needs:</span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:533}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Joint supervision</span></b><span data-contrast="auto"> of AD and Entra ID: ability to correlate signals from the on-premises directory (changes, anomalies, lateral movement attempts) and the cloud (Entra ID Protection signals, connection anomalies, conditional access, etc.). </span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></li>
<li><b><span data-contrast="auto">Security policy alignment</span></b><span data-contrast="auto">: hardening of AD (configuration, delegation, privileged accounts) in line with conditional access policies, MFA and Zero Trust requirements. </span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></li>
<li><b><span data-contrast="auto">Hybrid reconstruction capabilities</span></b><span data-contrast="auto">: in the event of AD compromise, reconstruction and restoration must integrate Entra ID dependencies (synchronisation, service accounts, applications) to avoid side effects on the cloud, and vice versa.</span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></li>
</ul>
<p style="text-align: justify;"><b><span data-contrast="auto">Publisher are gradually positioning themselves on this hybridisation. </span></b><span data-contrast="auto">Some are expanding their AD audit engines to include Entra ID (on-premises to cloud) and offer a unified view of identity vulnerabilities: Netwrix Auditor now allows Entra ID to be monitored in parallel with Active Directory with a single view of hybrid threats. Tenable Identity Exposure extends its exposure indicators to specific Entra ID risks, and Semperis Directory Services Protector correlates AD and Entra ID changes in a single console to reduce the hybrid attack surface.</span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:533}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Other tools start in the cloud (Entra ID, SaaS) and move down to on-premises AD (cloud to on-premises), using a hybrid identity threat detection and response approach: Microsoft Defender for Identity provides a consolidated inventory of AD and Entra ID identities and new detection capabilities on hybrid components (Entra Connect, AD FS, etc.), while CrowdStrike Falcon Identity Threat Protection analyses hybrid accounts present in both AD and Entra ID/Azure AD.</span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></p>
<h1 style="text-align: justify;"><span data-contrast="none">Operational implementation still has room for improvement</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p> </p>
<p style="text-align: justify;"><span data-contrast="auto">The Active Directory security market is seeing growing and structured adoption of sophisticated tools. In many organisations, functional coverage is now adequate, or even advanced, across the various aspects of AD security (auditing, hardening, detection, backup).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">However, technological maturity contrasts with operational implementation that is still incomplete. AD disaster recovery plans (DRPs) often remain theoretical, untested, or disconnected from the backup and reconstruction tools deployed. Regular reviews (of privileges, delegations, approval relationships) are still rarely industrialised: they often depend on a few experts, with a limited level of automation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">The effectiveness of implementation is also impacted by the constant evolution of the ecosystem, between the platformisation of tools and the hybridisation of identities. The challenge for the coming years will therefore be to align tools (both existing and future) with robust, documented and tested processes:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol>
<li><b><span data-contrast="auto">Clarify responsibilities</span></b><span data-contrast="auto"> between infrastructure, IAM, security and SOC teams,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Formalise and automate recurring controls </span></b><span data-contrast="auto">(rights reviews, configuration validation, restoration tests).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ol>
<p style="text-align: justify;"><span data-contrast="auto">Only then will investments in Active Directory security tools, both on-premises and in the cloud, enable true resilience to be achieved.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></p>
<h1><span data-contrast="none">Methodology overview</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p> </p>
<p style="text-align: justify;"><span data-contrast="auto">We have identified four main categories for grouping tools:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h3><span data-contrast="none">Analysis and audit:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<ul>
<li><b><span data-contrast="auto">Account and Privilege</span></b><span data-contrast="auto">: Inventory of accounts, groups and associated rights to detect excessive or non-compliant privileges.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">AD Discovery</span></b><span data-contrast="auto">: Exploration of the AD structure (OUs, GPOs, objects) to deduce the architecture, relationships and dependencies.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Vulnerability Discovery</span></b><span data-contrast="auto">: Identification of security vulnerabilities (configuration, obsolete accounts, weak passwords, etc.).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Attack Path Discovery</span></b><span data-contrast="auto">: Modelling potential attack paths to privileged accounts.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<h3><span data-contrast="none">Hardening and management:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<ul>
<li><b><span data-contrast="auto">Password Management</span></b><span data-contrast="auto">: Management of password policies, synchronisation, password auditing (strength, reuse, compromise, etc.).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Rights &amp; Privilege Management</span></b><span data-contrast="auto">: Delegation, access control, role and permission management.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">GPOs Management</span></b><span data-contrast="auto">: Creation, analysis, modification of group policy objects.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Change Management</span></b><span data-contrast="auto">: Change tracking, traceability, change management and migration tools.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<h3><span data-contrast="none">Monitoring:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<ul>
<li><b><span data-contrast="auto">Threat Detection</span></b><span data-contrast="auto">: Proactive detection of suspicious behaviour, privilege escalation, lateral movement.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Security Incident Detection: </span></b><span data-contrast="auto">Identification of security incidents, real-time alerts, event correlation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><span data-contrast="none">Backup and Recovery:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">AD Backup &amp; Recovery</span></b><span data-contrast="auto">: Partial or complete backup of AD objects, rapid disaster recovery.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Investigation &amp; Forensics</span></b><span data-contrast="auto">: Post-incident analysis, traceability of malicious actions, evidence collection.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1619}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">For each of the tools classified, a badge (Microsoft Entra ID logo) is added when the tool offers the possibility of integrating Microsoft Entra ID into its operation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"> </span></p>
<h1>Conclusion</h1>
<p> </p>
<p style="text-align: justify;"><span data-contrast="auto">The 2026 overview is based on an analysis of 180 tools, compared to 150 in 2022. It was constructed using a similar approach to that of 2002. It is based on a listing of tools on the market. On this basis, and in line with recurring themes in Active Directory security, a categorisation has been established to facilitate reading.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">The list of tools mentioned is not intended to be exhaustive, as the list of tools that can contribute directly or indirectly to Active Directory security is vast. This overview is therefore a summary of the main existing tools, particularly those that Wavestone consultants encounter most often in large organisations (considered, studied, tested or deployed).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p> </p>
<h1 style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}">References</span></h1>
<p style="text-align: justify;"><span data-contrast="none">[1] </span><a href="https://www.microsoft.com/en-us/corporate-responsibility/cybersecurity/microsoft-digital-defense-report-2025/"><span data-contrast="none">Microsoft Digital Defense Report 2025 | Microsoft</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[2] </span><a href="https://netwrix.com/en/resources/news/netwrix-acquires-pingcastle/"><span data-contrast="none">Netwrix Acquires PingCastle | Netwrix</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[3] </span><a href="https://investors.sentinelone.com/press-releases/news-details/2022/SentinelOne-Completes-Acquisition-of-Attivo-Networks/default.aspx?utm_source=chatgpt.com"><span data-contrast="none">SentinelOne, Inc. &#8211; SentinelOne Completes Acquisition of Attivo Networks</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[4] </span><a href="https://www.radiantlogic.com/news/radiant-logic-signs-definitive-agreement-to-acquire-brainwave-grc/?utm_source=chatgpt.com"><span data-contrast="none">Radiant Logic Signs Definitive Agreement to Acquire Brainwave GRC &#8211; Radiant Logic | Unify, Observe, and Act on ALL Identity Data</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[5] </span><a href="https://netwrix.com/fr/resources/news/netwrix-stealthbits-merge-to-address-demand-for-data-protection/"><span data-contrast="none">Netwrix annonce sa fusion avec Stealthbits | Netwrix</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[6] </span><a href="https://www.riskinsight-wavestone.com/en/2022/05/active-directory-security-tools-radar/"><span data-contrast="none">Radar des outils pour renforcer la sécurité d’Active Directory &#8211; RiskInsight</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[7] </span><span data-contrast="none">Microsoft Incident Response lessons on preventing cloud identity compromise | Microsoft Security Blog</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/03/overview-of-active-directory-security-tools-version-2026/">Overview of Active Directory security tools – version 2026 </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/03/overview-of-active-directory-security-tools-version-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Resilience Entra ID</title>
		<link>https://www.riskinsight-wavestone.com/en/2025/07/resilience-entra-id/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2025/07/resilience-entra-id/#respond</comments>
		
		<dc:creator><![CDATA[Pierre LALIN]]></dc:creator>
		<pubDate>Thu, 03 Jul 2025 08:42:03 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[Active directory]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cyber resilience]]></category>
		<category><![CDATA[Entra ID]]></category>
		<category><![CDATA[risk management strategy & governance]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=26544</guid>

					<description><![CDATA[<p>Entra ID (formally known as Azure AD) is an Identity and Access Management solution. Through a Cloud-based directory, administrators provision and manage the lifecycle of various identities from Users, Applications to Devices. Unlike Microsoft Active Directory, Entra ID extends its...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/07/resilience-entra-id/">Resilience Entra ID</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">Entra ID (formally known as Azure AD) is an Identity and Access Management solution. Through a Cloud-based directory, administrators provision and manage the lifecycle of various identities from Users, Applications to Devices. Unlike Microsoft Active Directory, Entra ID extends its authentication and authorization capabilities beyond the company&#8217;s network to cover SaaS applications, on-premises and Cloud workloads using either company-owned devices or BYOD. These new features and connections are achieved thanks to web-based protocols like SAML and simplified identity structure (AD forest vs Entra ID tenant).</p>
<p style="text-align: justify;">In this article, we will expose the cyber-resilience challenge of Entra ID, explain why native features are incomplete and present the result of a PoC conducted on an open-source tool, Microsoft 365 DSC, to backup and recover Entra ID’s data.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">The challenge of cyber-resilience in managed Cloud services</h2>
<p> </p>
<p style="text-align: justify;">With Entra ID, the directory management strategy is in line with the Cloud paradigm. It means that the various network, storage, computer, OS and application layers are handled by Microsoft, leaving the customer to focus solely on his identity data.</p>
<p><img decoding="async" class="aligncenter wp-image-26527 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/07/Diapositive1.jpg" alt="" width="1280" height="720" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/07/Diapositive1.jpg 1280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/07/Diapositive1-340x191.jpg 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/07/Diapositive1-69x39.jpg 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/07/Diapositive1-768x432.jpg 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/07/Diapositive1-800x450.jpg 800w" sizes="(max-width: 1280px) 100vw, 1280px" /></p>
<p style="text-align: justify;">This fundamental difference has an impact on the resiliency of the service. Indeed, the creation of snapshots to back up the integrality of the system, which is a common practice on AD, is not native on a managed service such as Entra ID. Thus, in order to face a disaster recovery scenario linked to malicious activities, we can only rely on native Microsoft functionalities: the identity lifecycle model, RBAC administration model and import/export capabilities.</p>
<p> </p>
<h2 style="text-align: justify;">The incomplete soft delete model</h2>
<p> </p>
<p style="text-align: justify;">To ensure resilience, Cloud services are widely using a soft delete mechanism. Its main purpose is to recover data in the event of an accidental deletion. For example, in Azure Recovery Service Vault, the soft delete is the last safeguard in the event of intentional or unintentional deletion of the vault. Combined with immutability parameters, the vault cannot be erased regardless of admin permissions.</p>
<p style="text-align: justify;">In Entra ID, the concept of soft delete exists but is insufficient to ensure data resilience for two reasons. On the one hand, there is neither role distinction between soft-delete and hard-delete nor Recovery role, i.e. the permissions required to delete an object are sufficient to allow for permanent deletion. On the other hand, the life cycle of objects in Entra ID (create, manage, delete) is governed by the same role:</p>
<ul>
<li>The role User Administrator can both create and hard-delete a user</li>
<li>The role Cloud Application Administrator can register an application, configure all aspects of the application and hard-delete the application</li>
<li>The role Cloud Device Administrator can add a device, configure all aspects of the device and unregister a device</li>
</ul>
<h2> </h2>
<h2 style="text-align: justify;">The impact of a deletion on Entra ID</h2>
<p> </p>
<p style="text-align: justify;">This design makes the User Administrator, Privileged Authentication Administrator, Cloud Application Administrator, Application Administrator, Cloud Device Administrator, Intune Administrator and Windows 365 Administrator roles all the more critical, as their compromise can lead to the permanent loss of identity data. The impact of such a deletion can be a loss of access to applications and data, a loss of permissions, and an inability to administrate.</p>
<p style="text-align: justify;">Although the deletion of hybrid users synchronized with an on-premise AD is reversible, information such as role assignment will be lost, threatening the rights and access model. This is not the case for Cloud identities, which are generally part of the Control Plane. As part of the Enterprise Access Model, the Control Plane includes the most sensitive access, leading to a global compromise of an Information System.</p>
<p style="text-align: justify;">In a disaster recovery scenario, some assets are more critical than others and should be backed up as a priority. These include:</p>
<ul>
<li>Control Plane users, groups and roles assigned</li>
<li>Enterprise Applications (service principals) with critical permissions over Azure or Microsoft 365</li>
<li>Administrative workstations</li>
</ul>
<h2> </h2>
<h2 style="text-align: justify;">Comparison of backup open-source methods</h2>
<p> </p>
<p style="text-align: justify;">To reduce the likelihood of Entra ID malicious data loss risk, the implementation of a backup solution seems essential, at least for the Control Plane in order to maintain control over your Information System and rebuild. We have therefore analyzed 3 open-source methods for ensuring data backup:</p>
<ul style="text-align: justify;">
<li><strong>Microsoft Graph PowerShell</strong>: this is the PowerShell library for Microsoft Graph APIs. You can build your own script(s) to export and import Entra ID objects attributes that fit with organization needs</li>
<li><strong>Microsoft Entra Exporter</strong>: this is a PowerShell module that export a local copy of some Entra ID attributes (Users, Applications, Service Principals, Roles, etc.) into JSON file</li>
<li><strong>Microsoft 365 Desired State Configuration (DSC)</strong>: this is a PowerShell module for declarative configuration, deployment and management of Microsoft 365 services</li>
</ul>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Backing up Entra ID objects with Microsoft 365 DSC</h2>
<p> </p>
<p style="text-align: justify;">In this part, we will explain how we tested the open-source solution Microsoft 365 DSC and share the results and conclusions we got.</p>
<p style="text-align: justify;">Our PoC</p>
<p style="text-align: justify;">Microsoft 365 DSC enables the management of the configuration and state of Microsoft 365 services following a declarative approach. By defining the desired state rather than specific steps, it simplifies the management of complex cloud configurations and ensures consistency across the environment.</p>
<p style="text-align: justify;">In the context of a PoC, the test population deployed in our test tenant is as follows:</p>
<ul style="text-align: justify;">
<li>30 Cloud Only Users (randomly generated by Microsoft as part of the test’s tenant creation process)</li>
<li>10 Security Groups (randomly assigned to Users)</li>
</ul>
<p style="text-align: justify;">The purpose of this PoC is to identify the benefits and limitations of the solution through a series of tested and documented uses cases:</p>
<table>
<tbody>
<tr>
<td style="text-align: center;" colspan="3" width="623">
<p><strong>Users</strong></p>
</td>
</tr>
<tr>
<td style="text-align: center;" colspan="2" width="365">
<p><strong>Use cases</strong></p>
</td>
<td style="text-align: center;" width="257">
<p><strong>Findings</strong></p>
</td>
</tr>
<tr>
<td width="161">
<p><strong>What happens if we delete a user and then restore a backup?</strong></p>
</td>
<td width="204">
<p>Does the user return with all the data that was attached to them?</p>
<p>Does their password come back, or do they have a new password?</p>
<p>Do their information return or not?</p>
</td>
<td width="257">
<p>Not all the attributes related to deleted users are retrieved. However, their password is replaced with a default password. In case of inconsistency, a non-blocking error occurs in the script, preventing the user from being set with attributes that point to non-existent object.</p>
<p>If the user has the “Ensure” attribute set to “Absent”, then they will not be retrieved.</p>
</td>
</tr>
<tr>
<td width="161">
<p><strong>What happens if a user is deactivated but, in the backup, they are active?</strong></p>
</td>
<td width="204">
<p>Do they get reactivated?</p>
</td>
<td rowspan="2" width="257">
<p>We cannot know the state of users (active or deactivated) from the backup.</p>
<p>Depending on the situation, we can set the “Ensure” parameter to “Absent” or “Present” to ensure consistency between our tenant state and our export.</p>
<p>When set to “Absent”, the user will be considered as deactivated and not be deployed during the restoration process. When set to “Present”, the user will be considered as active and be deployed during the restoration process.</p>
<p>If we attempt to recover a user marked as &#8216;Absent&#8217; and they do not exist on Entra ID, we simply get a confirmation of their non-existence.</p>
</td>
</tr>
<tr>
<td width="161">
<p><strong>What happens if a user is active but, in the backup, they are deactivated?</strong></p>
</td>
<td width="204">
<p>Do they get deactivated?</p>
</td>
</tr>
<tr>
<td width="161">
<p><strong>What happens if we add a user, and the backup doesn&#8217;t contain this new user?</strong></p>
</td>
<td width="204">
<p>Does the user get deleted?</p>
<p>Do their data remain intact?</p>
</td>
<td width="257">
<p>There is no impact observed on the new user.</p>
</td>
</tr>
<tr>
<td width="161">
<p><strong>What happens if we make a backup without changing the user?</strong></p>
</td>
<td width="204">
<p>If nothing changed, what happens?</p>
<p>If only an attribute of the user (like a group) was deleted, what happens?</p>
<p>If an attribute of the user (like a group) was added, what happens?</p>
<p>If an attribute was modified (like a password), what happens?</p>
<p>If a group they belonged to was deleted, what happens?</p>
<p>What happens with the licenses assigned to a user if a backup is made before the modification?</p>
<p>What happens if we modify a user’s role before making the backup?</p>
</td>
<td width="257">
<p>Because the username is used to associate attributes with the user, if it changes, the user cannot be found from the backup (unless it is also changed there).</p>
<p>The attributes from the backup overwrite the existing ones. Everything else remains untouched. Therefore, if an attribute is not included in the snapshot, it will stay as it was.</p>
</td>
</tr>
</tbody>
</table>
<p style="text-align: justify;"> </p>
<table>
<tbody>
<tr>
<td style="text-align: center;" colspan="3" width="623">
<p><strong>Groups</strong></p>
</td>
</tr>
<tr>
<td style="text-align: center;" colspan="2" width="365">
<p><strong>Use cases</strong></p>
</td>
<td style="text-align: center;" width="257">
<p><strong>Findings</strong></p>
</td>
</tr>
<tr>
<td width="161">
<p><strong>What happens if I delete a group and then restore a backup?</strong></p>
</td>
<td width="204">
<p>Does the group return with all the data that was attached to it?</p>
<p>Are the members of this group reintegrated?</p>
<p>Does the snapshot save who belongs to which group?</p>
<p>Are all groups saved in the snapshot?</p>
<p>Does the snapshot save the rights within the group?</p>
</td>
<td width="257">
<p>Only the security groups and Microsoft 365 groups with the right confidentiality label are backed-up.</p>
<p>The snapshot contains the members of the group and the owner but does not save the rights within the group.</p>
<p>It is necessary to redo the snapshot as the newly created group no longer has the same ID as the previous one. It won’t be recognized by the snapshot which will consider that the group does not exist.</p>
</td>
</tr>
<tr>
<td width="161">
<p><strong>What happens if I back up a group that already exists but has modified attributes?</strong></p>
</td>
<td width="204">
<p>What happens if the name has changed?</p>
<p>What happens if a user has left the group after the snapshot?</p>
<p>What happens if there are new users after the snapshot?</p>
</td>
<td width="257">
<p>The backup overwrites the old attributes except for the name.</p>
</td>
</tr>
<tr>
<td width="161">
<p><strong>What happens if a group exists in the tenant but not in the backup?</strong></p>
</td>
<td width="204">
<p>Does it get deleted or impacted after restoration?</p>
</td>
<td width="257">
<p>There is no impact observed apart from the information defined in the configuration file.</p>
</td>
</tr>
</tbody>
</table>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">The process required configuring a service account with the right permissions (<em>User.ReadWrite.All,</em> <em>Group.ReadWrite.All</em>) in Entra ID to interact with Microsoft Graph API for data export and import.</p>
<p style="text-align: justify;">These permissions enabled the service account to retrieve the necessary configuration and data from Entra ID and later re-import it.</p>
<p style="text-align: justify;">Result of the PoC Microsoft 365 DSC</p>
<p style="text-align: justify;">As a result of these tests, we were able to gather conclusive information on the solution’s benefits and limitations. On the positive side:</p>
<ul>
<li><strong>Granular Configuration Selection: </strong>The solution allows precise targeting of configurations for backup, enabling users to select specific settings.</li>
<li><strong>Recovery without deletion: </strong>During recovery, current users and groups are retained, preventing accidental deletion.</li>
<li><strong>Overwrite of Outdated Attributes: </strong>Backed-up attributes replace the old ones.</li>
<li><strong>Language of the Data Storage: </strong>Data is stored in JSON format, making it easy to manipulate and modify backup files.</li>
<li><strong>Automation Capabilities: </strong>Once the necessary tools are installed, the solution is easy to automate.</li>
<li><strong>Monitoring and Alerts: </strong>Microsoft 365 DSC can be used to monitor data consistency and receive alerts in the event of suspicious changes</li>
<li><strong>Snapshot Versions management: </strong>It enables easy maintenance and administration of multiple snapshot versions</li>
<li><strong>Detailed Logging Functionality: </strong>It offers the possibility to generate highly detailed logs, providing records of all operations for enhanced oversight.</li>
</ul>
<p style="text-align: justify;">Despite these advantages, the study revealed several limitations:</p>
<ul>
<li><strong>Incomplete Data in Backup: </strong>The backup process does not capture all attributes, leading to potential loss of important information.</li>
<li><strong>Backup Size Limit: </strong>The backup size is capped at 11MB, which may be insufficient for larger configurations or datasets.</li>
<li><strong>Deactivation Status Not Captured: </strong>Snapshots do not store deactivation statuses for users, potentially re-enabling disabled users during recovery.</li>
<li><strong>Unencrypted Data and Credentials: </strong>Security concerns arise from data and credentials being stored unencrypted, posing risks to sensitive information.</li>
<li><strong>Object IDs’ Loss: </strong>During imports, object IDs are lost, causing recreated objects to have new IDs, which can lead to duplicate entries in subsequent imports.</li>
<li><strong>Privileged Service Principal: </strong>The service principal involved has elevated privileges, increasing the risk of security vulnerabilities if not properly managed.</li>
</ul>
<p style="text-align: justify;">It is important to note that this tool does not really support “restoration” as it is possible to re-create objects, but it does not ensure service restoration and continuity. The reason being that it currently cannot restore links between new ID objects and applications, which is an issue native to Entra ID.</p>
<p style="text-align: justify;">Our opinion about Microsoft 365 DSC</p>
<p style="text-align: justify;">Microsoft 365 DSC is a great tool when it comes to basic uses and documentation as it is simple to use and to deploy on test environments. It is also quite efficient as a monitoring tool thanks to its version control and detailed logs. However, it is not adapted to large environments because of the limited scalability, the poor user experience and security issues related to configurations and credentials. It can also lead to inconsistencies or duplication as object IDs that can be referenced elsewhere are unrecoverable.</p>
<p style="text-align: justify;">Additional solutions may be required such as scripting for handling configuration files and ensuring the consistency of the modifications, as well as well-defined encryption and backup processes. Therefore, we recommend always carefully evaluating the specific needs, planning additional developments and mainly using the solution for supervision and testing purposes.</p>
<p style="text-align: justify;">Given the limitations of Microsoft&#8217;s open-source tools, it could be worthwhile to explore what third-party vendors, such as Semperis or Quest who are pure players on the subject, have to offer. These alternatives might address some of the challenges related to scalability, reliability and security, providing options that better suit larger environments. It is important to remain open to these possibilities and evaluate them based on the specific requirements of your organization.</p>
<p style="text-align: justify;"> </p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/07/resilience-entra-id/">Resilience Entra ID</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2025/07/resilience-entra-id/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
