For Secure Identity and Access Management, Hybrid Organisations Require a Strong Hybrid Authentication System

Your cloud identity is protected. What about everything you haven't moved to the cloud yet?
That question tends to land uncomfortably, because most security teams can answer the first half instantly and stall on the second. Entra ID is locked down. Conditional access is tuned. The cloud apps are behind phishing-resistant factors. And then there is the rest of the estate: the legacy line-of-business application nobody wants to touch, the Windows sign-in on the domain-joined machines, the certificate-based access that predates the current team. Strong authentication across the board is the actual goal, and it is the part most programmes quietly leave half-finished.
The Gap Most Phishing-Resistance Conversations Skip
Phishing resistance has become shorthand for one thing: securing the cloud identity provider. It makes sense: that is where the marketing energy goes, where the vendor demos point, and where the newest controls live.
But cloud IdPs are not the whole environment. Authentication via legacy applications, on-prem systems like Microsoft Exchange’s MFA, and PKI-based access frequently sit outside that coverage entirely. They authenticate via older protocols, separate directories, or mechanisms that were never designed to interface with a modern conditional access policy.
The result is a boundary. Inside it, strong, modern authentication; outside it, whatever was there before. Attackers do not respect that boundary. They look for the weakest reachable credential, and a hybrid estate usually offers one. Sophos’ 2026 Active Adversary report found that 67% of major data breaches were related to compromised identity, while their The State of Ransomware 2026 research found that 79% of ransomware attacks started with an identity-based approach. Malicious actors are evidently finding and exploiting those vulnerabilities with concerning levels of success.
What Is the Strongest Authentication Method?
The strongest authentication method available today is phishing-resistant, passwordless, and certificate-backed. In practice, that means factors bound to the device and the user in a way that cannot be replayed, intercepted, or handed over on a convincing fake login page: FIDO2 security keys, smart cards, and certificate-based credentials.
The distinction from standard multi-factor authentication matters. A one-time passcode or a push prompt still relies on a shared secret or a human decision, and both can be phished. A user can be tricked into typing a code into an attacker-controlled site, or fatigued into approving a prompt they did not initiate.
Phishing-resistant factors remove that failure mode. The credential is cryptographically tied to the legitimate service, so there is nothing useful for an attacker to capture. That is the ideal worth aiming for, and the bar worth applying everywhere - not just to the cloud front door.
Why a Fragmented Approach Leaves Real Exposure
Most enterprises do not have one authentication problem. They have three or four: cloud apps, legacy on-prem systems, Windows sign-in, and certificate-based access. When each is handled by a different tool, or not handled consistently at all, the gaps compound.
The exposure shows up in three ways:
- Inconsistent policy enforcement. A strong policy on cloud apps means little if the same identity can reach a legacy system through a weaker access point.
- Weaker audit visibility. Fragmented tooling means fragmented logs. Proving who accessed what, and how they authenticated, becomes a complex stitching exercise across systems.
- More administrative overhead. Every additional tool is another set of policies, another lifecycle to manage, another place for drift, and associated insecurities to creep in.
Windows MFA is the clearest example. Desktop and server sign-in is one of the most valuable surfaces in the estate, and it is routinely left inconsistent: protected in some places and untouched in others. The human element remains the dominant factor in breaches - the Verizon 2026 Data Breach Investigations Report found it was a component of 62% of breaches - which is precisely why credential and sign-in surfaces cannot be left uneven. Find more detail on this topic in our Managing Authentication in Your Organisation blog, but the short version is that inconsistency is the primary vulnerability.
What "One Access Layer Across Environments" Means in Practice
The alternative to four separate tools is a single access layer. Consistent strong authentication and passwordless access, applied the same way whether the system is cloud, legacy, or on-premises.
Rather than asking each application to solve authentication in its own way, the access layer sits across them and enforces one policy. A user gets the same phishing-resistant experience signing into a modern SaaS app, a legacy on-prem system, or their Windows desktop. Administrators manage one set of rules. Auditors get one coherent record.
This is the mechanism Pointsharp is built around: extending modern, passwordless, phishing-resistant authentication to the environments that cloud-only tools leave behind, so hybrid estates stop being a patchwork.
A security posture assessment is the fastest way to see how many separate authentication paths your estate actually runs today, and which of them sit outside your strongest controls.
Where PKI Fits
For organisations with certificate-based access requirements, public key infrastructure is often already doing quiet, essential work. Smart cards issued to staff, credentials stored in hardware security modules, machine and device certificates: these are strong, well-established forms of authentication.
PKI earns its place because the credential lives in hardware and cannot easily be copied or phished. The challenge is rarely the certificates themselves. It is bringing PKI-based access under the same policy and visibility as everything else, rather than treating it as a separate entity. A single access layer is where certificate-based access and modern passwordless factors stop being two different conversations.
What Are the Best Practices for Identity and Access Management (IAM)?
The practices that hold up across hybrid estates are consistent rather than clever:
- Consolidate to a single access layer. Fewer tools, one arena to define and enforce policy.
- Enforce consistent policy across environments. Cloud, legacy, on-prem, and Windows sign-in should meet the same standard, not whatever each supports by default.
- Prioritise phishing resistance. Move credentials toward passwordless and certificate-backed factors wherever possible.
- Maintain audit visibility. One coherent record of who authenticated, how, and to what.
Taken individually, these practices might not seem exotic. Their implementation, however, remains challenging because most estates grew organically, one tool at a time. Bringing them together is exactly the kind of problem The Kernel works through with security teams as a specialist partner rather than simply a retailer.
Get a Clear Picture of Where Your Authentication Coverage Has Gaps
A protected cloud identity is not the same as a protected organisation. The systems outside that coverage are where the real questions sit.
A security posture assessment gives you a clear picture of where your authentication coverage has gaps: across cloud, legacy, Windows sign-in, and certificate-based access. That is the fundamental starting point for a single, strong, hybrid authentication system.
FAQ
- What is identity and access management?
Identity and access management (IAM) is the set of policies, processes, and technologies an organisation uses to ensure the right people and devices can access the right resources, and no one else can. It covers how identities are created and managed, how users authenticate, and how access is granted, monitored, and revoked across every system, cloud and on-prem alike. - What is the difference between standard MFA and phishing-resistant authentication?
Standard MFA adds a second factor such as a one-time passcode or push notification, both of which rely on a shared secret or a human decision and can be intercepted or socially engineered on a fake login page. Phishing-resistant authentication uses factors cryptographically bound to the legitimate service and device, such as FIDO2 keys, smart cards, and certificate-based credentials, so there is nothing an attacker can replay or capture. - What is PKI-based authentication and when is it used?
PKI-based authentication uses public key infrastructure to verify identity through digital certificates rather than passwords. The credential is typically held in hardware, such as a smart card or a hardware security module, which makes it very difficult to copy or phish. It is commonly used where strong assurance is required for staff access, device identity, or machine-to-machine authentication, and in regulated environments with certificate-based access requirements. - What is a single access layer?
A single access layer is one consistent authentication and access control point that sits across all environments - cloud, legacy, and on-premises - rather than each application handling authentication separately. It lets an organisation enforce one policy, deliver one user experience, and maintain one audit trail, closing the gaps that appear when different systems are secured by different tools. - Why do hybrid organisations need consistent authentication across environments?
Attackers target the weakest reachable credential, so protecting cloud identity while leaving legacy systems, Windows sign-in, or certificate-based access on weaker controls simply moves the exposure rather than removing it. Consistent authentication across every environment closes those gaps, simplifies policy enforcement and auditing, and reduces the administrative overhead of managing multiple disconnected tools. - Can on-premises Microsoft Exchange MFA security be improved?
On-premises systems, including legacy applications and infrastructure that predate modern cloud identity platforms, can be brought under consistent, phishing-resistant authentication by extending a single access layer across the whole estate rather than leaving each system to handle authentication in its own way. This closes the gap between cloud and on-prem environments, ensuring the same strong policy and audit visibility apply everywhere.
Want these in your inbox?
We publish practical, vendor-neutral writing on identity, authentication, and security operations in the region. No spam, no hard sell.

