Appreciate that. So this is Hybrid Identity, Liminal Space or Permanent Fixture. I figure coming over to a country where English is not primary language, we'll use big English words like liminal that even English-speaking people in the US don't understand, right? So just starting off here, defining liminal, right? So this is from some online dictionary here, right? It's between or belonging to two different places, states, you know, things like this, right? And so from a visual perspective, a lot of times, right, if we're talking about liminal spaces, it's things like hallways, right?
Like design, like visualization, right? And it's supposed to evoke these sorts of feelings here, right? So here's like a hallway, you know, and then here's another hallway, right? And especially when there's no, you know, people in these things, right? It kind of evokes a certain thing.
You know, here's a hotel, right? So, you know, these liminal spaces you can also look at essentially as, you know, it's no longer, right?
We're not, you know, in the room we were in and not yet, right? We're not yet to where we're going, which, you know, might be a different room with, you know, maybe a more interesting talk, right? So we're in this liminal space here, right? Now you may say, that's great. What does this have to do with, you know, anything identity related?
You know, I think if we're Active Directory shops, right? The Active Directory is the no longer, right? Microsoft is like Active Directory's dead, right? We're not using it anymore. Go to the cloud, et cetera, right? But for most organizations, unless you're a startup, right? Nobody's really in Entra by itself yet, right? So we're in this sort of hybrid identity space that enterprises have been in now for, you know, 10, 15 plus years, depending on, you know, when organizations went to Azure and Office 365 and all this, right?
And the liminal space for a lot of these orgs, you know, kind of looks like this, right? Where you want to run the exit, it's not very nice, right?
And so, you know, there's a lot of challenges within here though. So we have two identity providers.
And again, this isn't like a revelation, but the thing that we see with a lot of organizations is that this is very difficult to manage, right? Orgs don't even know how to secure Active Directory, right? Now you want them to also have to go manage and secure Entra, right?
And, you know, within this, again, we have, you know, twice the user objects, but, you know, it's not just copies, right? There's attributes, there's things out in Entra that aren't in Active Directory and, you know, potentially sometimes, you know, the opposite, right? And this is complex for a lot of enterprise IAM people to manage, right? For groups, again, we have groups in Active Directory. We sync out to the cloud, but we also have M365 groups. All these are the cloud native things, right? That are specific to Entra. And group management in itself, right?
Sprawl, what groups are being used, the whole lifecycle around them. Again, it's hard enough in Active Directory, let alone essentially replicating this out to, you know, another identity provider.
You know, and again, same with devices, right? In BYOD, it's all this stuff that is not necessarily new, but it still feels foreign in a way to a lot of people that manage these identity systems, right? And the complexity just sort of compounds here, right? We've got two platforms to learn and manage and, you know, maintain and two platforms to secure, right?
And so, some of us, right, we're a security company and we see a lot of Active Directory, you know, breaches, a lot of less than stellar, you know, security postures around AD. And same with Entra now as we work with enterprises here, right?
And so, you know, even though we're a security company and this is not a pitch for us, but the thing is a lot of customers ask us, right, like how do we get rid of Active Directory, right? Have a lot of AD people, you know, but we want to move to Entra, right? We don't want this liminal space that we're in. And unfortunately, it's not as easy as, you know, some people may think. And there's a lot of blockers here and this is what we're going to sort of dive into a bit.
So, you know, timely the other week, Mero Fernando who's a PM at Microsoft, a lot of people might be familiar with, right? He actually asked on LinkedIn this question that's, you know, basically asking, you know, what is your organization's text? It's a bit small here. Identity endgame for 2030 and beyond, right? Basically asking are we going to go, you know, fully to the cloud? Are you going to be hybrid identity? Still Active Directory or just AD, right? You have no intentions of moving to Entra.
And, you know, I thought the results from his sort of non-scientific study here were promising, right, where you have about 56% or you do have 56% of respondees here saying that they're going to be cloud native, you know, in 2030, you know, or beyond. And then 37%, right, the rest of the majority saying that they're going to stay as hybrid.
But, you know, I think here the focus is really that beyond part of things, right? Because when we're asked about, well, how do I get rid of Active Directory now, right, orgs are saying how do I get rid of it this year or next year? How do I start these things, right?
And, you know, this is why migration is currently difficult for organizations, right? So, you know, right now, and this is something I've noodled on quite a bit because, you know, even though we do a lot of AD stuff, want to try to give customers a path to Entra, but there's really not a good path for, you know, agile user migration to cloud native, right? We've got 100,000 user objects, right? How do we move them in chunks, right, out to Entra so that they're no longer in Active Directory? And there really isn't a way to do this, right?
We don't have a good way to break that relationship between a single user object or a select group of user objects in Active Directory and Entra. And there's some hacky things you can do, right? You can sort of delete the user, you know, you can remove them out of sync and then they'll get deleted in Entra and you go restore them. But if you want an actual path that's supported, you know, by Microsoft, if something goes wrong, they tell you not to do that, right?
So, right now, the only thing that we actually can do, right, is just break this relationship between Active Directory and Entra, right? You can go run a command, sort of disconnect these two systems.
But again, if we have 100,000 users, right, most orgs are not going to have the appetite for that sort of risk, even if it's 10,000, 5,000, 1,000 users, right? So, with groups, right again, right now, groups, it's a real rip and replace sort of thing.
Now, if you're a Microsoft customer, right, you might know things on a roadmap and whatnot. But if we're talking about what's available GA today, right, on paper, they'll tell you, we'll just go, you know, do this stuff. But the reality is, right, for groups, right, we end up doing this rip and replace.
So, you've got all these groups in Active Directory, right, that were synchronized X years ago out to Entra, and we've assigned them to things in Azure and 365, and they're used for claims and, you know, all our SaaS applications, and that's great. But there's no way to sort of, you know, flip the source of authority on this group right now, right?
So, the answer is effectively to have to copy this group, right, copy its membership, find out where it exists out in all these things, and go assign it out there, right, and then get rid of that Active Directory group. And, you know, this isn't really tenable if you're talking about 100,000, 10,000 groups out there, right?
And so, devices also, right, the other sort of big component here is it's really a long road to go Entra ID join. Now, you know, I used to work at Microsoft, and, you know, when I was there, some of the Intune PMs, no offense to them, would just say, well, just, you know, reimage all the devices.
Like, sure, you know, we've got nothing else to do. We'll just go reimage all our Windows devices, right, so that they'll just be Entra joined. And really, it ends up being that lifecycle of the device, right, at this point. And they've sort of acknowledged, right, that the migration from, you know, hybrid joined devices to Entra joined devices is really based on, you know, how long that device is going to live in the organization, which, again, right, if it's three years, five years, right, for that device, that's five years before that user, their device is going to go Entra joined.
This, though, I would say is probably the furthest along that, you know, we are from, you know, users, groups, and devices, sort of the big three things out there, right, in moving to the cloud works pretty well, but it definitely is that time-based thing.
Right, so also when we're talking about, you know, applications and the authentication within apps, right, it's still an uphill battle to modernize this stuff, right, and so, you know, not saying this is a one-to-one translation of, you know, Kerberos to OpenID Connect or NTLM to SAML, whatnot, right, but sort of the three big things that we tend to see still used in organizations, right, there's apps out there, right, that still are using Windows integrated OAuth, right, Kerberos, they still have high dependencies on LDAP, and there are some sort of bridges out there, right, that can sort of, you know, gap things or, you know, allow you to use Entra, right, and bridge things back to Active Directory, but they still actually require AD, right, so there's Entra App Proxy, still requires Active Directory, right, it's essentially translating things to Kerberos, so on the app, you know, modernization is a thing that takes years and years for organizations to accomplish, right, and that's even if they can modernize these apps, right, some of these things could be 20-something years old, they're still running, and again, the organization, right, the business doesn't find a need to prioritize getting rid of these things, right, and also Active Directory, again, this kind of leads into it's not just identity, right, so, you know, what about all the servers, right, all servers, big Windows infrastructure, what's everyone use for managing these things, right, it's group policy, right, group policy is and has been the thing forever, even if you're primarily an identity person, right, if you manage AD, you're likely dealing with group policy, right, and so, again, there's some answers out there, but they don't actually really fit that well, right, so there's desired state config, and this has been around now for actually a good long while, and there's been some iterations on it, but it has gaps, and even some people that, you know, are very familiar with desired state config would say it's not a replacement for group policy, right, and then there's Intune, right, so there's some things you can do with Windows Server and Intune, which, again, is great, but, you know, you go ask, you know, Intune, you know, PMs, well, can't we just add Windows Server in fully and have all the policies essentially out there, and, you know, so far it's still like the answer is no, right, so Intune's a bit iffy, and there's Azure policy, right, but this is very cloud specific, you've got to be an Azure customer, and again, Azure policy doesn't cover all the bases of group policy, so right now we've got a group policy sort of replacement here with three different systems that don't actually fully cover what we were doing in Active Directory, right, and beyond that, if you have a big Active Directory or a big Windows Server estate, I should say, right, also how do we connect to these things, right, so you can intra-join Server 2022, Server 2025, but the experience from an admin perspective, again, is not easy, if you've ever tried to RDP to an intra-join device, it can be a bit of a headache, right, and then what about WinRM and other sort of remote management tools for these devices, and there's intra-domain services, which, again, you know, it's cool and great, but a lot of organizations are like, well, if I already had Active Directory, why am I going to move to another Active Directory to try to get rid of my Active Directory, right, it doesn't really make any sense, and there is some security benefit, right, because intra-domain services, you don't have domain admin out there, but overall, a lot of the reasons why orgs are keeping their current Active Directory, right, they're not really going to gain anything from moving to a service that's basically managed Active Directory for you out there, so.
Right, and so the answer a lot of times, sometimes from Microsoft and just, you know, folks out there is, right, the just refactor the application, which I kind of already touched on this, right, but it's just so easy, right, to take your thousand applications, you know, whatever the number might be that depend on Active Directory, that use Kerberos for authentication, and just, you know, refactor them to, right, use OpenID Connect or SAML, right, some of these things might have support for it, some of them may not, right, but again, a lot of organizations don't see this as a priority, right, it's in the big picture of things from a business perspective, refactoring all the apps to get rid of AD is not the biggest challenge most orgs have, and usually it doesn't tend to be a thing that they focus on unless they've had some sort of Active Directory breach, right, and then everyone's sort of scrambling to try to, you know, get rid of the security pain point there.
Right, so, you know, are we stuck with hybrid identity?
You know, I think it depends, and sort of going back to, you know, what Merrill was asking here, I think if we look at a timeline, so, you know, for a good long time, right, organizations have wanted to move to Entra, right, move to Azure AD, again, you can find going back 2015, even sort of earlier, right, organizations have the appetite to get rid of Active Directory, and I don't see that, you know, changing anytime soon, right, but, you know, this is my personal opinion, but based on things that you see out there, I don't think the maturity of offerings from Microsoft, right, is really going to be there for the next five years, right, to really help organizations kind of go down this path, this journey, right, so, you know, a bit of a spoiler, I was actually going to give this talk last year at EIC, and then I ended up getting COVID at Identiverse, and then come here, but aside from sprucing this deck up, right, the story really hasn't changed, which I think is a bit, you know, telling that over a year, right, there isn't really anything new, right, this wasn't sort of spoiled by any great advancements by Microsoft, and, you know, again, I think there's things coming, but it's just going to take time, right, and once we have those offerings, right, unless you're really an early adopter, right, orgs aren't just going to be jumping on things, right, we still struggle with organizations, you know, running Server 2012, 2016, 2019, right, because they don't want to upgrade to Server 2022, 2025 for things like Active Directory, well, they're certainly not going to be right on the front of things there saying let's, you know, just dump all that and go to Entra, right, so I think the reality is here that we're still going to see at least another decade of organizations sticking with Active Directory before, you know, anyone really starts to have an appetite, those, you know, offerings to sort of switch the record of authority, source of authority of objects in AD right out to Entra is really going to be in a place where we can sort of say, yep, like, it's a place where most orgs can move off Active Directory and on to Entra, so, and speed around that a little bit, so have a few minutes left here if there's any questions, but thank you.
Do we have questions from the audience? All right, I would have a question. Sure. Are there any best practices that you would like to share with us that help unify, let's say, governance across hybrid environments?
Oh, I mean, I think organizations have such a challenge with governance in Active Directory, right, that, you know, if you look at a lot of IGA systems, it's a lot of IGA systems, you know, if you look at a lot of IGA systems, it's all, I think, specific to the tools you're using, right, you know, but Active Directory still tend to see a lot of orgs out there who are still home rolling, like governance solutions, right, they're still doing IGA with, you know, scripts, you know, forms, things like that, and they're not really mature in that space, the hybrid piece just really complicates it, right, because if you go look out in the cloud and write the lack of governance out there, if you go ask most orgs, like, do you know where groups are assigned in, you know, Azure, out in Office 365, SharePoint, stuff like that, they'll tell you that they have no idea.
So I think it's a mix of tools, but also actually making this stuff a bit of a priority, so I'd give the sort of consultant non-answer answer to you there, so. It depends.
Okay, perfect, yeah. And you raised the question, will this be, will we stay in this liminal space, or will hybrid identity be the permanent fixture, the fixture?
What's, let's say, what's your one sentence answer to that? The non-consultant answer.
Yeah, I think we'll move off of Active Directory, but I don't think it will be in the time that Microsoft wants us to think. I picture most orgs having AD for another 15, 20 years, so.
Yeah, I think so, also, yeah. That's because of legacy structures, the, let's say, life cycle of developments within organization can be quite long, depending on the complexity of the organization, so, yeah. Thank you so much. Thank you.