By LeadThem Consulting · April 22, 2026
Quest published a piece this week worth reading for anyone responsible for identity in a hybrid estate: https://blog.quest.com/the-approach-to-comprehensive-identity-security-has-been-broken-for-years/
The argument is one LeadThem Consulting has watched play out across hundreds of Active Directory, Entra ID, and Microsoft 365 migrations: identity security has been treated as three disconnected problems. Detection lives with the SOC. Recovery lives with the AD team. Migration lives with whichever integrator is handling the current M&A cycle. Each discipline has its own tooling, its own runbooks, and its own assumptions about what "secure" means.
The cost of that split shows up at the worst possible moment,during an incident, during a cutover, during the week a newly acquired domain has to be folded into the parent forest. Attackers do not respect the org chart, and neither does a broken trust.
After eighteen-plus years as a Quest partner, the LeadThem Consulting architects' view is straightforward: unified identity security is not a product story, it is an operating posture. Detection informs recovery. Recovery informs migration design. Migration design determines what you will actually be able to detect next quarter.
What separates the organizations that will navigate the next wave of identity incidents from those that will struggle? It often comes down to whether they have stopped running detection, recovery, and migration as parallel, disconnected tracks. How are forward-thinking firms breaking down those silos today?
#IdentitySecurity#ActiveDirectory#EntraID#HybridIdentity#MicrosoftSecurity
