Abstract
Federated identity has quietly become the default way large organisations run their infrastructure: an on-premises Active Directory (AD) domain on one side, a Microsoft Entra ID tenant on the other, and a synchronisation layer stitching the two together [4]. Directory sync makes access management easier for administrators, but it also creates a blind spot exactly where the two authorisation models meet. Years of nested groups, delegated rights, and one-off provisioning decisions leave behind Access Control List (ACL) misconfigurations that nobody remembers granting [5], [9], and once one of those misconfigurations sits on an account that happens to be synchronised to the cloud, an on-premises problem quietly becomes a cloud problem too. This paper describes HYBRID-SHIELD, a prototype built to trace these cross-domain paths with graph theory rather than manual review. It parses on-premises and cloud directory snapshots into a single directed multigraph using NetworkX, persists that graph in Neo4j for querying, and searches it for transitive kill chains — the HybridSyncPivot chain documented in this paper is one example — that connect a low-privilege on-premises account to a high-privilege cloud role [4], [7]. A CVSS-inspired scoring routine then ranks how severe a discovered path is, and, unlike most of the diagnostic tools reviewed for this work, the framework does not stop at the report: it generates a PowerShell script to revoke the specific access control entry (ACE) responsible and re-runs the traversal to confirm the fix actually worked. In our dual-boundary test environment, revoking a single User-Force-Change-Password ACE cut the attacker off entirely (d(u,v) = ∞) and brought the cumulative path-risk score down from 30.5 to 0.0 on a 40.0-point scale. It should be said plainly that this result comes from one controlled testbed and is meant to demonstrate feasibility rather than a generalisable performance claim; the scope and limitations are laid out in Section 8.
Index Terms — Active Directory, Microsoft Entra ID, attack graphs, graph theory, access control lists, privilege escalation, NetworkX, Neo4j, automated remediation, hybrid identity.