Microsoft's on-premises Active Directory (AD) and Microsoft Entra ID continue to be the leading Identity and Access Management (IAM) solutions for enterprises worldwide. Over time, these IAM platforms have become central to security concerns for both attackers and defenders, as their compromise can grant control over an entire corporate network. Recognized as tier-1 assets, blue teams implement multiple mechanisms to monitor and thwart attack operations. Meanwhile, attackers deploy various Operational Security (OPSEC) techniques to evade detection by these defenses. However, even with OPSEC measures in place, detection by blue teams remains a possibility. This presentation will examine real-world attack paths that abuse techniques from on-premises Active Directory to Microsoft Entra ID, demonstrating the significant impact they can have. We will explore OPSEC methodologies employed to avoid blue team detection and ensure operational success. Lastly, we will introduce detection strategies and practical applications from the blue teams’ perspective, emphasizing the importance of understanding and helping the red team to execute OPSEC precisely.