Hybrid Directory Orchestration: Phishing Resistant Authentication with Active Directory and Entra ID
Date: 2026-08-10
Author: Versasec

Migrating enterprise identities to the cloud is rarely a simple “flip of a switch.” Most established organizations operate in a hybrid reality: relying on legacy on-premise Microsoft Active Directory (AD) for legacy applications, while aggressively adopting Microsoft Entra ID (formerly Azure AD) for modern cloud access.
The challenge? Securing both environments simultaneously without forcing users to juggle multiple identities or driving IT support tickets through the roof.
Historically, securing identities in these directories meant creating separate credentials, relying on insecure workarounds, or dealing with fragmented credential management systems. With the release of vSEC:CMS 7.4, Versasec has solved this pain point through Frictionless Hybrid Directory Orchestration.
The Friction of Hybrid Identity
When an organization wants to issue both traditional PKI certificates (for Windows desktop logon, VPNs, or S/MIME) and FIDO2 device-bound passkeys (for Entra ID passwordless access), the process often splits into two separate workflows and worse different management systems.
Administrators are forced to manage the PKI lifecycle on-premise and separately enable the user for FIDO2 passkey registration in Entra. This results in:
- Identity Duplication: Maintaining separate user profiles for on-premise and cloud access.
- Logistical Nightmares: Tracking which user has which hardware token across disjointed systems.
- Security Gaps: Inconsistent revocation processes when an employee leaves or a token is lost
Streamlining with vSEC:CMS 7.4
With the new capabilities in vSEC:CMS 7.4, organizations can unify their credential issuance under a single pane of glass.
You can now use your primary Active Directory account as the foundational identity to issue both PKI certificates and FIDO2 passkeys on a single hardware device (like a YubiKey or Thales eToken or smart card), while securely connecting directly to your Azure Entra ID tenant.
How Hybrid Directory Orchestration Benefits Your Enterprise:
- Single Pane of Glass Management: Manage the entire lifecycle of both PKI and FIDO2 credentials side-by-side. Enroll, update, and revoke access across both AD and Entra ID simultaneously.
- No Duplicate Accounts: By using the AD account as the base, vSEC:CMS ensures a 1:1 mapping between the user’s physical token, their local domain access, and their cloud identity.
- Instant Passwordless Enablement: When you issue a credential in vSEC:CMS, it can simultaneously register FIDO2 Passkeys in Entra ID (and other IdPs), granting users immediate, passwordless access to their Microsoft 365 environment alongside domain and VPN access.
- Instant Authentication with vSEC:CMS Identity: For non-Microsoft web applications, the newly introduced vSEC:CMS Identity authentication server allows those same FIDO2 passkeys to be used for OIDC authentication, fully integrated into your on-premise or hybrid infrastructure.
A Phishing-Resistant Future, Anchored in Your Current Infrastructure
By leveraging Versasec’s credential management orchestration, you can seamlessly combine your legacy infrastructure with Entra ID, closing security gaps and delivering a frictionless, passwordless experience to your workforce.
Want to see how hybrid orchestration works in practice? Schedule a call with a Versasec identity expert.
vSEC:CMS
Our product suite provides all the software tools to administrate and manage credentials in a secure and convenient way.
Schedule a Strategic Call
Versasec provides enterprise credential management to accelerate phishing-resistant MFA. Our solutions enable customers to securely authenticate, issue and manage user credentials more cost effectively. Schedule a 1:1 Strategic Call With Our Identity Experts.
Job Openings
We are always looking for new exceptional persons to join our team! Find out more about our job openings.
