Higher ed’s revolving door swings open for security risk

Every year, higher education hits the same beats. New students show up in the fall, ready to begin their undergraduate career. Staff and faculty come and go on their own timelines, some tenured for decades and others moving on after a single semester. Every spring, graduates ring in a new chapter, crossing the stage after years of hard-won achievements. Then there’s visiting researchers and affiliated partners, collaborating all throughout the academic year.

Behind each of those individuals sits a digital identity that's supposed to follow the same lifecycle: created when someone arrives, adjusted as their role changes and shut off the moment they leave. This last step often ends up more an ideal than a constant, and it's just one symptom of a much bigger identity problem in the “eclectic environment” of higher ed.

One Identity global strategist Robert Kraczek, bringing years of hands-on work on Active Directory (AD) in higher education and other industries, and over a decade working with One Identity solutions, explored this complexity in a recent on-demand session. He detailed what happens when identity sprawl goes unmanaged and what buttons up gaps.

Higher ed's identity sprawl is a bigger risk than most industries face

Institutions running Microsoft systems can't simply migrate to the cloud and walk away from on-premises AD. Tenured faculty run their own departments, students turn over constantly, alumni need lingering access and external partners cycle in and out. That mix produces a wider attack surface than most industries carry.

Security agencies across the Five Eyes alliance, including the CISA and NSA, already flag AD as the top target for attackers, whether a lone actor or a state-sponsored hacker, and Verizon's Data Breach Investigations Report data shows roughly a fifth of breaches start with compromised credentials, most often tied to AD.

The "hybrid gap" is where the real damage happens

Disabling an account in AD means nothing if the corresponding Entra ID account is still live. This disconnect is where many breaches take root, a point driven home with the real-world example Rob shared. An AD account at a university got turned off, but the Entra ID account kept running, disconnected and retaining access to Microsoft apps like Teams and OneDrive.

The resulting breach wasn’t caught for six months, leaving 47,000 exposed student records and $2.3 million in penalty fees in its wake. Other typical use cases show how a single compromised student account from a phishing attack, coupled with a disconnected AD/Entra ID environment, can escalate to global admin access in a mere matter of weeks. Unified governance would have prevented it.

Managing AD and Entra ID as one system

Active Roles by One Identity was positioned as a simple yet integral management layer spanning both AD and Entra ID. It's meant to augment existing identity governance and administration (IGA) or privileged access management (PAM) tools rather than replace them.

The core of it is a single, unified console, least privilege delegation, built-in audit trails and workflow automation that turns manual, error-prone onboarding and offboarding into something repeatable and documented.

The results speak for themselves

Two customer results stood out. One institution's automated workflow approvals meant a FERPA audit passed on the first try. Another reduced orphan accounts from 400 to zero in six months.

No university has a truly clean Microsoft environment. Most inherit years of abandoned accounts and groups nobody knows what to do with and hesitate to turn off. Fortunately, that cleanup is exactly what surfaces once governance is unified.

ROI will look different depending on where you sit

Rather than a single number, return on investment (ROI) splits across three lenses:

  • Tactical/technical - time and manual effort saved administering accounts across dozens of domains

  • Organizational - audit-finding and helpdesk savings

  • Overall – the combined effect of both, weighted by whatever your institution prioritizes

Maybe you’re the admin doing the work, or perhaps the leader justifying the investment. In any case, the value shows up, manifesting in different forms depending on who's asking.

Implementation is fast to start, slow to perfect

Connecting AD domains and Entra ID tenants can happen within the first few days of deployment. Designing a least privilege model and cleaning up years of duplication takes longer though, and that timeline depends entirely on how messy the existing environment is and your goals. It's also worth noting Active Roles by One Identity is deployed on-prem, virtualized or through the AWS/Microsoft marketplaces.

Hybrid, “eclectic” AD environments are difficult to manage but aren’t going away in higher ed, and neither is the risk of managing them in isolation. The institutions that come out ahead are the ones ready to treat AD and Entra ID as one governed system instead of two loosely connected ones.

Watch Rob’s full session here.

Blog Post CTA Image

Anonymous
Related Content