Skip to content
Blog · Jul 8, 2026 · 2 min read

Monitoring Identity Across Active Directory and Microsoft Entra ID

Monitoring Identity Across Active Directory and Microsoft Entra ID

Most organizations now run identity in two places at once. Active Directory still holds the on-premises estate, and Microsoft Entra ID handles cloud sign-in. Attackers treat the two as one system. Monitoring often does not.

The seam is the weak point

Hybrid identity creates a join between directories, and the join is where visibility drops. An account escalated on-premises can inherit cloud access nobody reviewed it for. A sign-in from an unusual location means little by itself, and means a great deal if the same account changed a privileged group membership an hour earlier.

Teams watching only one side see half of that sequence, usually the less alarming half.

What to watch on the directory side

Changes to privileged group membership deserve the most attention, particularly Domain Admins and any group that grants administrative rights indirectly. Account creation and reactivation matter, as do changes to password and lockout policy pushed through Group Policy. Failed logon patterns are worth keeping even after they resolve, because they establish what normal looks like for a service account.

What to watch in the cloud

Sign-in activity is the obvious one, though location and device are the useful fields rather than the raw count. Role assignments in Entra ID change quietly and rarely get reviewed after the fact. Changes to conditional access affect every user at once, which makes them worth alerting on rather than reporting monthly.

Correlation is what makes either side useful

A single event is rarely conclusive. Sequences are. An account added to a privileged group, then a sign-in from a new location, then access to a file share that account has never opened, is a pattern worth interrupting. None of those events would justify a phone call on its own.

Getting to that view means collecting both directories onto one timeline in a common format, and keeping it long enough to be useful during an investigation rather than only during the week it happened.

Where LT AuditorMP® fits

LT AuditorMP® monitors Active Directory user and group changes, Windows logon activity, Azure sign-in activity and Entra ID, and runs user and group vulnerability assessments against the directory. It correlates that activity with file and system events, so the sequence above reads as one story instead of three unrelated entries.

Request a demo or start a free trial to see it against your own directory.

All posts

Secure your network. Prove it.

Start a free assessment