Call For Paper - Presentations

Welcome to Hybrid Hell - Breaking Entrpise Identity beyond Active Directory
2026-09-10 , Großer Saal

Enterprise identity has fundamentally changed.

Large organisations no longer rely on a single identity system. Instead, Active Directory, Microsoft Entra ID, Azure, Microsoft 365, SaaS applications, identity synchronisation, third-party identity providers and cross-tenant trust relationships have evolved into a single interconnected identity architecture.

Unfortunately, attackers don’t think in terms of “on-premises” or “cloud.” They follow trust relationships.

While organisations often assess Active Directory and cloud environments separately, the most valuable attack paths increasingly exist between them. Hybrid identity, multi-forests, multiple Entra ID tenants, synchronisation services, service principals, managed identities and delegated administration all contribute to an enterprise identity attack surface that is significantly larger, and far less understood, than many organisations realise.

This session explores enterprise identity architecture from an attacker’s perspective. Rather than focusing on individual attack techniques, it examines how identity systems interact, where trust boundaries actually exist, and how seemingly isolated weaknesses can be chained together across on-premises and cloud environments.

Attendees will leave with a practical approach to identifying enterprise identity attack paths, defining realistic assessment scopes, and understanding why the biggest identity risks often exist in the connections between systems,not the systems themselves.


Enterprise identity is no longer defined by a single directory service. Modern organisations operate complex identity architectures spanning Active Directory, Microsoft Entra ID, Azure, Microsoft 365, SaaS platforms, synchronisation services, multiple identity providers and increasingly multiple business units, subsidiaries and cloud tenants. Every integration introduces new trust relationships. Every trust relationship introduces new attack paths.

This session approaches enterprise identity from the perspective that matters most during an assessment: the attacker’s.

Rather than presenting a catalogue of Active Directory or Entra ID attack techniques, the talk focuses on how modern enterprise identity is constructed, why traditional assessment methodologies frequently fail to capture the complete attack surface, and how attackers move across identity boundaries by abusing trust instead of exploiting individual technologies.

Using realistic enterprise architectures, practical demonstrations and real-world attack scenarios, the session examines common challenges encountered during offensive security engagements, including hybrid identity deployments, synchronisation, multi-forest environments, multiple Entra ID tenants, delegated administration, identity trust relationships and assessment scoping. The audience will see how architectural decisions influence attack paths, why trust relationships become the true security boundary, and how weaknesses in one part of the identity architecture can create unexpected consequences elsewhere.

The presentation concludes with a practical framework for mapping enterprise identity architecture from an attacker’s perspective, enabling security teams to define more realistic assessment scopes, prioritise the trust relationships that matter most, and better understand how identity has become one of the largest and least visible enterprise attack surfaces.

Key takeaways

  • Understand how enterprise identity has evolved beyond a single directory service.
  • Learn why attackers focus on trust relationships rather than technology boundaries.
  • Identify common architectural patterns that expand the enterprise identity attack surface.
  • Recognise the challenges of scoping and assessing complex hybrid identity environments.
  • Apply an attacker-focused methodology for analysing enterprise identity architecture and prioritising risk.

Georg Heise is a Senior Offensive Security Consultant and security researcher at Lufthansa Industry Solutions, specialising in enterprise offensive security, identity security and AI-driven security research. His work focuses on helping large organisations understand and assess complex enterprise environments, ranging from Active Directory and Microsoft Entra ID to modern AI systems and autonomous security agents.

Alongside his role at Lufthansa Industry Solutions, Georg serves as a strategic advisor to the shareholders of an international logistics and holding group, advising on information security, digitalisation and technology strategy across a diverse portfolio of companies. This combination of hands-on offensive security and strategic advisory work provides a unique perspective on the challenges faced by large enterprise environments.

Over the past decade, Georg has led and contributed to hundreds of security assessments, including Active Directory, cloud, web application and Red Team engagements for Fortune 500 companies, government organisations and operators of critical infrastructure. His current research focuses on enterprise identity architecture, AI-assisted offensive security and autonomous security agents. He regularly shares his research through conference talks, technical publications and open-source projects.

Born in Germany with Australian roots, Georg studied, worked and completed two university degrees in Australia before returning to Europe. His goal is to bridge the gap between enterprise offensive security and the next generation of AI-powered security tooling, helping organisations prepare for an attacker that is becoming increasingly autonomous.