AzureCIO BriefingsRetrospectives

CIO Brief: Hybrid Identity Means On-Prem Flaws Become Cloud Flaws

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2020, written in 2026 with the benefit of hindsight.

The short version: In 2020, a flaw called Zerologon let attackers take over a company's core identity system — Active Directory — in seconds, without a password. Because most companies connect that system to Microsoft 365, an on-premises flaw can become a cloud breach.

Why hybrid identity matters to leadership

Most mid-sized organizations still run Active Directory on their own servers and synchronize it to Microsoft's cloud. That makes sign-in convenient, but it ties the security of your cloud to the security of older on-premises systems. A weakness in either can compromise both.

The business impact

  • Company-wide compromise if Active Directory falls.
  • Cloud exposure through synchronized accounts and identity servers.
  • Long recovery — rebuilding identity infrastructure takes weeks.

Questions to ask your team

  • How quickly are critical patches applied to our domain controllers?
  • Are we monitoring Active Directory for attacks?
  • Which cloud administrator accounts are synchronized from on-premises, and could an on-prem attacker take them over?
  • Do we have a plan to reduce our dependence on on-premises identity?

What good looks like

Domain controllers patched within days, monitored continuously, cloud administrators using cloud-only accounts, and a roadmap to reduce on-premises identity dependencies.

The decision

Ask for confirmation that no cloud administrator account is synchronized from on-premises Active Directory. It's a simple separation that limits how far an on-prem breach can reach.

zerologon impactZerologon2020

More on this story