Quest Software’s FedRAMP High certified offering for Quest Identity Defense and Quest Identity Recovery is more than a compliance achievement. It provides federal agencies, regulated industries, and other security-conscious organizations with a high-assurance cloud foundation for protecting and recovering Microsoft Entra ID as part of a broader hybrid identity resilience strategy.
Across Microsoft Entra ID and on-premises Active Directory, Quest has long helped organizations identify and govern their most critical identity assets, protect them against unauthorized change, and recover the identity control plane when defenses are overcome.
The FedRAMP High certification – FedRAMP’s highest certification class – adds another layer of Quest’s trusted protection for organizations, giving CISOs further peace of mind as identity security has become top of mind with the explosion of AI-driven cyber threats.
Identity as the new control plane
In most organizations, identity has become the control plane for infrastructure, applications, and data. It spans Active Directory forests and Group Policy, Microsoft Entra ID tenants and cloud applications, and the human and non-human identities that connect them.
Together, these systems form the identity control plane: the directories, privileged identities, policies, administrative systems, and recovery capabilities that determine who, or what, can access organizational resources, and who has the authority to change those decisions.
That makes identity foundational to Zero Trust. It also makes the identity control plane a high-value target for attackers.
An attack may begin with an ordinary account, endpoint, or application, but the attackers’ objective is often to gain control over identity itself to undermine every downstream access decision. This happens once attackers have broken in and changed privileged groups, administrative roles, authentication policies, Group Policy, or service accounts.
Identity threat detection and response (ITDR), combined with strong governance, proactive protection, and tested recovery, is therefore central to cyber resilience.
FedRAMP High: assurance for the identity control plane
Identity security platforms operate close to some of an organization’s most consequential systems. They may analyze privileged relationships, process sensitive telemetry, protect critical directory objects, or maintain the backups required to restore trusted identity configurations.
Organizations should therefore evaluate more than product capabilities. They should understand how the service is architected and operated, where information is processed, how administrative access and changes are controlled, and whether the supporting security controls have been independently assessed.
FedRAMP provides a standardized government-wide approach to assessing the security and continuous monitoring of cloud services. Quest’s two products offered at the highest certification level operate within Microsoft Azure Government, aligning it with the sovereign Microsoft cloud environment used by many public sector customers.
No certification guarantees that every customer environment will be secure. FedRAMP High does, however, provide independently assessed evidence that the underlying cloud service has been engineered and operated for environments where the consequences of compromised confidentiality, integrity, or availability could be severe.
For a platform operating close to the identity control plane, that FedRAMP High assurance matters.
Finding and governing Tier Zero and privileged identity assets
Logging alone is not enough. Organizations must first identify the assets whose compromise could give an attacker control over identity itself.
In Active Directory, these are commonly described as Tier Zero assets. They include domain controllers, highly privileged accounts and groups, critical administrative computers, forest and domain configuration, the schema, and key Group Policy Objects.
Microsoft Entra ID has equivalent privileged assets, including tenant-level roles, privileged users and groups, enterprise applications, service principals, workload identities, and Conditional Access policies.
Quest Identity Defense helps organizations discover these critical assets across Active Directory and Entra ID. It surfaces exposure paths, identifies risky configurations, monitors critical objects for drift, and brings identity activity into a common security view.
This gives defenders a prioritized map of the identity control plane so they can concentrate governance, monitoring, and protection where compromise would have the greatest impact.
Shields Up: active protection for crown-jewel assets
Identifying critical assets is necessary, but visibility alone does not stop an attacker from changing them.
Quest’s dynamic Shields Up containment applies highly restrictive protections to selected Tier Zero Active Directory objects. It can prevent unauthorized or accidental changes to assets such as domain controllers, privileged groups, critical computers, and key Group Policy Objects.
Because Shields Up is scoped to protected objects, it can contain high-risk identity changes without requiring organizations to broadly disable identity services while an investigation proceeds.
This can disrupt persistence and privilege-escalation techniques, limit lateral movement, reduce blast radius, and preserve trusted identity configurations during an incident.
Shields Up can be activated tactically during an attack. For selected assets, organizations may also choose to enable its protections continuously as a proactive defense.
The best recovery is the one an organization never needs to perform. Preventing a consequential Tier Zero change can be more effective than detecting it afterward and attempting to reverse the damage.
Recovering the hybrid identity control plane
Prevention and containment reduce risk, but organizations must still prepare for malicious changes, accidental deletions, corruption, ransomware, and other events that overcome their defenses.
Recovery must reflect the reality that most Microsoft identity environments are hybrid.
Quest Identity Recovery provides backup, comparison, and recovery for Microsoft Entra ID. It helps organizations determine what changed, compare the current tenant with a known earlier state, and restore identity objects, attributes, policies, and relationships.
Quest Recovery Manager for Active Directory Disaster Recovery Edition (RMAD DRE) provides granular Active Directory recovery and orchestrated recovery from forest-wide disasters. It supports the restoration of domain controllers, directory services, and the broader Active Directory forest.
Together, Identity Recovery and RMAD DRE provide coordinated recovery capabilities across the hybrid identity control plane. Each solution operates where the relevant component resides: Identity Recovery protects Entra ID in the cloud, while RMAD DRE protects on-premises Active Directory.
This allows organizations to re-establish trusted relationships between cloud and on-premises identity, restore the identity services on which applications and operations depend, remove unauthorized privileges and persistence, and validate that the environment has returned to a known-good state.
Detection tells an organization that trust may have been compromised. Protection limits how much trust an attacker can destroy. Recovery establishes a trusted identity state.
Hybrid identity is mission-critical infrastructure
Federal agencies, defense organizations, and regulated industries depend on Microsoft identity technologies to control access to mission-critical systems. In these environments, identity is operational infrastructure.
Few of these organizations are purely cloud-native. Their identity control planes span Entra ID, Active Directory forests, factories, operational technology networks, remote facilities, and tactical systems. Some operate with intermittent connectivity. Others must remain locally operational because cloud access cannot be treated as an absolute prerequisite.
For example, a manufacturing facility may depend on Active Directory for operator workstations, maintenance systems, jump servers, service accounts, and vendor access. A deployed environment may require local authentication and administration when connectivity is constrained.
Compromise of identity infrastructure in either environment can become an operational event rather than merely an IT incident.
FedRAMP High certification adds independently assessed assurance to the cloud component of that strategy. Quest’s broader portfolio extends identity governance, protection, auditing, and recovery across the complete hybrid environment, supporting customers’ identity systems where they are.
Raising the standard for the identity control plane
Quest’s FedRAMP High certification establishes a new level of assurance for the cloud services used to secure and recover Microsoft Entra ID.
Combined with Quest’s Active Directory governance, protection, auditing, and disaster-recovery capabilities, it supports a broader objective: making the complete hybrid identity control plane more resilient.
Organizations must know which identities and systems control trust. They must govern privileged access, prevent unauthorized changes where possible, contain attacks while they are underway, and maintain a tested path to recovery when defenses are overcome.
Zero Trust is only as trustworthy as the identity control plane beneath it.
That control plane must be visible, governed, protected, and recoverable. And the platforms used to secure it must be worthy of the same trust.
