Solving AD-Synced Identity Containment Challenge – ThreatDefence
Skip to content

Solving AD-Synced Identity Containment Challenge

Cybersecurity

Anton Guzhevskiy
Anton Guzhevskiy July 23, 2026 6 min read
Principal Product Researcher

Containing a compromised identity is not always as simple as disabling the user in Microsoft Entra ID.

In hybrid Microsoft environments, many Entra ID users are synchronised from on-premises Active Directory. In this model, Active Directory remains the source of authority for the account. If the user is disabled only in Entra ID, directory synchronisation may later overwrite the change and restore the account state from Active Directory.

At the same time, disabling the account only in Active Directory may not immediately terminate existing Microsoft 365 access. An attacker may still have active cloud sessions or valid refresh tokens that allow continued access for a period of time.

This creates two common containment gaps:

  • A cloud-only containment action may not persist for AD-synced users.
  • An AD-only containment action may not immediately terminate existing cloud sessions.

ThreatDefence addresses this by supporting identity containment across both Active Directory and Microsoft Entra ID for hybrid Microsoft environments.

How It Works

ThreatDefence uses the ThreatDefence Endpoint Agent to support on-premises Active Directory containment.

When authorised, the agent can communicate with the on-premises Active Directory environment to disable or re-enable AD user accounts. This allows ThreatDefence to perform containment at the source of authority for AD-synchronised identities.

When the SOC confirms that an identity is compromised or high-risk, ThreatDefence checks whether the account is cloud-only or AD-synced.

For AD-synced users, ThreatDefence SOC can perform a two-part containment action:

  1. Revoke active sessions and refresh tokens in Microsoft Entra ID.
  2. Disable the user account in on-premises Active Directory.

This helps stop active Microsoft 365 access while also preventing the account from being re-enabled in the cloud by directory synchronisation.

Why Both Actions Are Needed

For hybrid identities, cloud and on-premises containment solve different parts of the problem. Revoking sessions and refresh tokens in Entra ID helps terminate existing Microsoft 365 and cloud application access. This is important when an attacker already has an active browser session, access token, or refresh token.

Disabling the account in Active Directory prevents further on-premises authentication and ensures the disabled account state is synchronised back into Entra ID.

Together, these actions provide stronger containment than either cloud-only or AD-only response.

How to Activate On-Premises AD Containment

To enable on-premises Active Directory containment, customers must authorise this action in the containment section of the ThreatDefence SOC Operations Manual.

The ThreatDefence Endpoint Agent must also be installed on a domain controller or another approved server with the required access to perform the authorised Active Directory containment action.

Once enabled, the SOC can use this capability during confirmed or approved identity containment scenarios, in line with the agreed operations manual and customer authorisation.

Sign Up for ThreatDefence Updates

Get insider access to ThreatDefence tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy