The Identity Blueprint
Enterprise identity and access management isn't a product you buy — it's a program you build. The Identity Blueprint covers the full spectrum: seven-phase IAM frameworks, zero trust architecture, JIT access, FIDO2 passkeys, identity governance, and the operational models that hold up at enterprise scale. Built for practitioners who are past the basics. Hosted by Ernie and Josée.
The Identity Blueprint
The Cloud Quietly Fired Active Directory
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
This episode gives you a working, accurate model of hybrid identity in 2026: where authority actually lives, how it's protected end to end, and exactly where your remaining legacy footprint still needs attention. No guessing, no assumptions — just the real architecture, so you can defend it properly.
In this episode, Ernie and Josée open Season Two — Beyond the Domain — by tracing exactly how an identity gets created today, why the industry built a one-way valve to stop a single compromised on-prem account from climbing into the cloud, and why even cloud-forward enterprises still carry what the industry calls the "ugly 20 percent" — the slice of infrastructure that isn't migrating.
You'll leave knowing whether your organization's hybrid state is a deliberate, secured architecture or an assumption nobody's tested lately — and exactly what to check first.
If you're an identity architect or security lead responsible for that boundary, this episode is not optional.
Connect with Ernie Prescott on LinkedIn at linkedin.com/in/ernieprescott
Welcome back to the Identity Blueprint. I'm Ernie, joined by Jose. Season one built the blueprint for modern identity architecture. Season two, beyond the domain, puts it to the test. Starting with the question a lot of architects still argue about. Is Active Directory still your source of truth? Or did the cloud already take that job? We trace how an identity actually gets created in 2026, why the industry built a one-way valve to stop local breaches from climbing into the cloud. And why even cloud forward enterprises get stuck on what we call the ugly 20%. If you're running hybrid and wondering whether that's a phase or a permanent state, this one's for you. Let's get into it.
SPEAKER_01Imagine a hacker breaches a single undersecured laptop in, you know, a forgotten branch office of a Fortune 500 company.
SPEAKER_00Right. Just a random office somewhere.
SPEAKER_01Yeah. Ten years ago, that exact scenario meant the entire global network of that company was just, well, doomed within hours.
SPEAKER_00Oh, absolutely doomed.
SPEAKER_01Yeah. The hacker would use that laptop to find a local server, hijack an administrator account, and basically ride that access straight up into the company's cloud, just stealing everything.
SPEAKER_00Aaron Powell Taking the literal keys to the kingdom.
SPEAKER_01Trevor Burrus Exactly. But today, that same hacker hits an impenetrable brick wall. I mean, they get the laptop and uh they get absolutely nowhere else.
SPEAKER_00Nowhere.
SPEAKER_01So welcome to this deep dive. You rely on massive enterprises every single day to protect your personal data, your finances, um, your communications.
SPEAKER_00Yeah, pretty much everything.
SPEAKER_01Right. So today we are looking at the 2026 architecture blueprints, some vendor guides, and industry playbooks to understand exactly how these companies are building that brick wall.
SPEAKER_00Aaron Powell It's a fascinating shift to look at.
SPEAKER_01It really is. The mission for you today is to understand the core of modern enterprise security by identifying the true source of truth for digital identity.
SPEAKER_00Aaron Powell Right, the real foundation. Aaron Powell Yeah.
SPEAKER_01So the fundamental question we're answering is whether on-premises Active Directory, you know, the local network servers that have run businesses for decades, is still the primary identity king, or if cloud identity has definitively taken over that throne. Like, is Active Directory the rotary phone of the enterprise, or is it still the main switchboard everybody relies on?
SPEAKER_00Aaron Powell I mean, it is the defining architectural question of this decade, honestly. Oh, absolutely. Because for a very long time, the prevailing wisdom in IT was that the ground like the physical servers inside your office building was the safest place for your identity to live.
SPEAKER_01Aaron Powell Right. Because you could physically see it.
SPEAKER_00Aaron Powell Exactly. And the cloud was just, well, an extension of that. But the sources we are looking at today show a complete inversion of that logic. Trevor Burrus, Jr.
SPEAKER_01A total 180.
SPEAKER_00Trevor Burrus, Jr.: A total 180, yeah. Trevor Burrus, to understand what the actual source of truth is in 2026, we have to look at the Genesis point.
SPEAKER_01Trevor Burrus, Jr.: Meaning where the account starts. Aaron Powell Right.
SPEAKER_00The birth of a digital identity. We have to look at how an employee account is created today versus um the legacy method. Aaron Powell Okay.
SPEAKER_01Let's unpack the old way first, just so we have a baseline.
SPEAKER_00Sure.
SPEAKER_01Historically, Active Directory was kind of the sun that the entire corporate solar system orbited around.
SPEAKER_00Aaron Powell Oh, without a doubt.
SPEAKER_01Like if you wanted to access a file server or send an email or even just log into your desktop workstation, Active Directory was the system in the basement checking your ID.
SPEAKER_00Aaron Powell Yeah, the ultimate bouncer.
SPEAKER_01Trevor Burrus, Jr. Right. So in that era, when a company hired a new employee, how did they actually get an account?
SPEAKER_00Aaron Powell Well, it was a very ground-heavy process. The human resources department would enter the new hire's information into their HR system. Okay. And from there, that data would flow down to the IT department who would manually, or maybe via some internal scripting, populate that employee into the local on-premises active directory. Trevor Burrus, Jr.
SPEAKER_01So they punch it right into the physical server.
SPEAKER_00Aaron Powell Exactly. That local server was the absolute genesis point. Your digital identity was physically born on the ground.
SPEAKER_01Aaron Powell And what about the cloud?
SPEAKER_00Aaron Powell Well, only after the account was created locally would a synchronization engine take a copy of that identity and push it up to the cloud.
SPEAKER_01Oh, okay.
SPEAKER_00Yeah. And this allowed the user to access online email or you know early cloud applications. But architecturally, Active Directory was the boss. The cloud was strictly a downstream consumer.
SPEAKER_01So the cloud was basically just taking orders from the server sitting in the basement.
SPEAKER_00Pretty much, yeah.
SPEAKER_01It just assumed that whatever the local server said was absolute truth.
SPEAKER_00Precisely. But based on the 2026 consensus across all the deployment playbooks we reviewed, that architecture is dead.
SPEAKER_01It's just completely gone.
SPEAKER_00Completely. The primary account has definitively moved. It is no longer born in on-premises Active Directory. Wow. Cloud identity has absolutely taken over as the primary identity control plane.
SPEAKER_01Okay, so walk us through what that actually looks like mechanically today. I mean, if I get hired by a massive enterprise tomorrow morning, where does my digital identity come from?
SPEAKER_00We call it the HR provisioning flip. Flip. Right. Today, when HR enters your data, they don't set it to the local basement server at all.
SPEAKER_01Aaron Powell Really? They just skip it.
SPEAKER_00They completely skip it. The HR systems are configured to provision the employee directly into the cloud first. Oh wow. Yeah. They push your identity straight into a modern cloud platform like Microsoft's Enter ID, which acts as the primary identity bouncer for the enterprise now.
SPEAKER_01Aaron Powell And how are they actually connecting those systems?
SPEAKER_00Aaron Powell They do this using inbound provisioning and standard APIs, commonly known as SCIM APIs.
SPEAKER_01It's SE APIs.
SPEAKER_00Right, which essentially just act as a universal pipeline language between HR and the cloud. So your identity is born in the cloud. The ground server doesn't even know you exist yet.
SPEAKER_01Aaron Powell That is wild. Why did the industry flip the script on this? I mean, if the old way worked, why go through the massive headache of completely replumbing how user accounts are created.
SPEAKER_00Aaron Powell Because of where the actual work is taking place now?
SPEAKER_01Right.
SPEAKER_00I mean, think about a typical workday today. Right. The vast majority of business workloads, the communications, the Sauce applications like Salesforce or Workday, the data storage, it almost entirely lives in the cloud.
SPEAKER_01Aaron Powell True. Nobody is saving things to a local desktop folder anymore.
SPEAKER_00Aaron Powell Exactly. So from a logical standpoint, it simply makes sense for the identity to be born where the work is actually being done.
SPEAKER_01Yeah, that makes sense.
SPEAKER_00If 99% of what a user interacts with is a cloud-based service, generating their identity on a local server and then constantly syncing it upward is incredibly inefficient.
SPEAKER_01It's like printing out a digital PDF document just so you can physically scan it back into an email.
SPEAKER_00Yes. That is a perfect analogy.
SPEAKER_01You are taking a completely unnecessary detour through the physical world.
SPEAKER_00And that detour isn't just inefficient. Um, it introduces extreme architectural fragility.
SPEAKER_01Okay, but let me push back on this architecture though.
SPEAKER_00Sure.
SPEAKER_01If the cloud is the primary control plane now, right? And the local network is subordinate to it, doesn't that introduce a terrifying new vulnerability? Well, let's go back to the scenario I mentioned at the start of the deep dive. We have a malicious actor, they manage to breach the local office network. Maybe someone clicked a bad link in a branch office.
SPEAKER_00Okay, right.
SPEAKER_01If the ground is still physically connected to the cloud to sync data back and forth, doesn't a local breach leave the front door to the cloud wide open?
SPEAKER_00You've just described the exact nightmare scenario that forced modern architecture to evolve in the first place.
SPEAKER_01Oh, really?
SPEAKER_00Yeah. In the old model where the cloud trusted the ground implicitly, a compromise on the ground absolutely poisoned the cloud. The mechanism attackers use for this is called upward lateral movement.
SPEAKER_01Okay, let's define lateral movement for a second, just so we are totally clear on the mechanics for everyone.
SPEAKER_00Sure. Lateral movement is when an attacker gets a tiny low-level foothold in a network and they use it to pivot.
SPEAKER_01Like climbing a ladder.
SPEAKER_00Exactly. So they compromise that single branch office laptop, right? Then they scrape the memory of that laptop to find the credentials of an IT support person who logged into it earlier. Yeah. Then they use those credentials to access a local server. They scrape that server to find a local administrator's credentials. They're moving sideways and upwards, gathering more and more powerful accounts. And historically, once they got the big one, once they compromised the local on-premises Active Directory, it was game over. They owned everything.
SPEAKER_01Because they could just take any local account, granted, maximum privileges, and just wait for that synchronization engine to push those privileges up to the cloud.
SPEAKER_00Exactly.
SPEAKER_01They just ride the synchronization elevator straight up to the penthouse.
SPEAKER_00And because the cloud assumed the local server was the source of truth, it accepted those elevated privileges without question.
SPEAKER_01Wow, just let them write in.
SPEAKER_00Right in. The attacker suddenly had global administrator rights in the cloud environment, meaning they could access the CEO's emails, download corporate databases, or just shut down the company's entire infrastructure.
SPEAKER_01Aaron Powell So how does a modern 2026 architecture actually stop that? Because if the cloud on the ground still have to communicate for the business to function, how do you block that upward lateral movement?
SPEAKER_00Aaron Powell By establishing a strict physical and logical security separation.
SPEAKER_01A separation.
SPEAKER_00Platforms like Intra ID now intentionally block on-premises Active Directory from modifying privileged cloud accounts.
SPEAKER_01Oh, they just block it entirely. Trevor Burrus, Jr.
SPEAKER_00It is a hard-coded logic gate. If a request comes in to change the password or the permissions of a cloud administrator, the cloud checks where that request originated.
SPEAKER_01And if it came from the basement?
SPEAKER_00If it originated from the local network, the cloud simply drops the request. It refuses to accept the modification.
SPEAKER_01Aaron Powell So if we look at this through an analogy, for years the local active directory was like a universal master key for a massive corporate campus. Yes. It could open the lobby, the main owns closets, and the executive suites. And management finally realizes this is incredibly dangerous. Super dangerous. So they changed the locks on the CEO suite and the server room, which represent the cloud administrators here. That old master key from the ground can still open the regular offices, but if you try to use it on the CEO's door, it's useless. The cloud holds the only keys to its own kingdom.
SPEAKER_00Exactly. Let's take that master key analogy a bit further, actually, because in a digital network, we have to look at the communication flow.
SPEAKER_01Okay.
SPEAKER_00It's less about a changed lock and more about a one-way security valve.
SPEAKER_01Oh, one-way valve. Okay.
SPEAKER_00The cloud is perfectly capable of sending instructions down to the ground. But that valve aggressively snaps shut if the ground tries to send administrative instructions up to the cloud.
SPEAKER_01So nothing goes up.
SPEAKER_00Nothing privileged goes up. The cloud strictly governs its own privileged roles. This guarantees that a local network compromise, even a total takeover of the legacy on-premises servers, cannot be used to pivot and take over the cloud environment.
SPEAKER_01This means the cloud fundamentally no longer trusts the ground.
SPEAKER_00Exactly. In modern security, implicit trust is entirely eliminated. Wow. You do not trust a digital signal just because it comes from inside your own corporate office building. Every single signal is evaluated independently.
SPEAKER_01You know, this shift toward cloud-first identities, strict separation, and zero implicit trust, it makes total sense for a company that was founded like three years ago.
SPEAKER_00Oh, for sure.
SPEAKER_01If you are a nimble software startup, of course you build everything natively in the cloud. You probably don't even own a physical server. Trevor Burrus, Jr.
SPEAKER_00Just laptops and coffee shop Wi-Fi.
SPEAKER_01Right. But what does this mean for massive established enterprises? I'm talking about the airlines, the banks, the global manufacturers.
SPEAKER_00The organizations with immense technical debt. Trevor Burrus, Jr.
SPEAKER_01Right. These organizations were founded 30 or 40 years ago. Their foundational directory is deeply entrenched on premises. They have spent decades and millions of dollars building their entire digital foundation on Active Directory or IBM, LDAP, or some similar infrastructure.
SPEAKER_00It's everywhere.
SPEAKER_01It is literally wired into every factory floor and every legacy application they own. For these giants, are cloud identities just a theoretical best practice, or do they actually need to make this move too?
SPEAKER_00The vendor guides and the architectural blueprints we looked at are absolutely definitive on this. And they say Yes, established enterprises must transition their primary identity control plane to the cloud.
SPEAKER_01No exceptions.
SPEAKER_00None. This is not just a luxury for startups. The security benefits, specifically that protection against upward lateral movement we just talked about, along with the scalability, they make it mandatory for survival. Wow. However, there is a crucial caveat here. They do not need to rip out their legacy directories overnight.
SPEAKER_01Okay. I have to challenge that logic.
SPEAKER_00Go for it.
SPEAKER_01If the cloud is so much safer and eliminates this massive vulnerability of implicit trust, why wouldn't you just rip the band-aid off?
SPEAKER_00It sounds tempting.
SPEAKER_01Right. Isn't maintaining both systems like a massive modern cloud environment and an aging massive on-premises environment, essentially just paying two mortgages for no reason?
SPEAKER_00Aaron Powell On paper, yeah, it looks exactly like paying two mortgages. But you have to understand the mechanics of how deeply intertwined these legacy systems are. Okay. If an IT director tried to rip out Active Directory overnight in a Fortune 500 manufacturing company, they wouldn't just cause an IT outage. They would fundamentally break the physical business.
SPEAKER_01Aaron Powell Break the business how? Break it mechanically for me.
SPEAKER_00Trevor Burrus, all right. Imagine a massive automotive assembly line.
SPEAKER_01Okay.
SPEAKER_00There are thousands of internal applications, robotic manufacturing systems, and localized internal tools that were hard-coded over the last 20 years. Trevor Burrus, Jr.
SPEAKER_01And they all rely on that old server.
SPEAKER_00Trevor Burrus Right. The code in those systems was written to look for one specific thing: an on-premises Active Directory server at a specific IP address on the local network.
SPEAKER_01Oh man.
SPEAKER_00If you turn that server off, those robotic systems literally go blind. They can't authenticate. Production lines physically stop moving. Local payroll systems fail to process checks.
SPEAKER_01Everything just dies.
SPEAKER_00The business grinds to an absolute halt. So instead of ripping the band-aid off and destroying the company, the industry standard approach is to adopt a hybrid identity model.
SPEAKER_01A hybrid model, meaning they are forced to marry the old world and the new world.
SPEAKER_00Exactly.
SPEAKER_01But how does that actually function in practice without creating a massive security loophole?
SPEAKER_00So in the hybrid approach, the cloud assumes the role of the primary security boundary. The cloud becomes the only front door to the business. And it enforces modern zero trust controls that those legacy directories simply cannot natively support.
SPEAKER_01Because the old directories, like Active Directory, were built in the 1990s. Right. They were built for a world where everyone was sitting at a physical desk inside a physically secure building. They basically just check if your password is correct.
SPEAKER_00Exactly. Active Directory wasn't built to evaluate the context of a login. It doesn't know how to ask, you know, is this login attempt coming from a known safe laptop? Or is it coming from a compromised network halfway across the world at 3 a.m.?
SPEAKER_01It just blindly accepts the password.
SPEAKER_00Yes. But the cloud can ask those contextual questions in milliseconds. The cloud enforces what we call risk-based conditional access.
SPEAKER_01Risk-based conditional access.
SPEAKER_00It evaluates your physical location, the health and compliance status of your specific device, and your real-time behavior.
SPEAKER_01And if anything looks weird.
SPEAKER_00If anything looks suspicious, it demands phishing resistant multi-factor authentication, like a physical security key or a biometric scan. The legacy systems simply lack the plumbing to do any of that. So the cloud acts as the intelligent shield.
SPEAKER_01So the cloud is this high-tech shield at the front door.
SPEAKER_00Right.
SPEAKER_01But we still have these ancient, fragile applications sitting behind it on the local network. Applications that don't understand what a cloud token or a biometric scan even is. So how do they actually talk to each other?
SPEAKER_00This is where the engineering gets really clever. They use specific bridging tools, typically called application proxies or secure gateways.
SPEAKER_01Application proxies.
SPEAKER_00Right. These tools sit directly between the modern cloud and the legacy ground. They allow users to securely access those older on-premises applications without changing a single line of code and how those old apps currently work.
SPEAKER_01Wait, how does that translation actually work? Because they are speaking two completely different digital languages, right?
SPEAKER_00Yeah, they are. Mechanically, it works like a highly secure translator. Let's say you are working from home and you need to access a 20-year-old internal HR site.
SPEAKER_01Okay. Pretty common scenario.
SPEAKER_00Right. You log into the cloud front door, the cloud evaluates your device, checks your biometrics, and says, okay, you are safe.
SPEAKER_01Right.
SPEAKER_00The cloud then hands your computer a modern digital token. You take that token and present it to the application proxy.
SPEAKER_01And the proxy is the bridge.
SPEAKER_00Exactly. The proxy verifies the token is valid, and then it turns around to the local network and translates that modern token into a legacy Kerberos ticket.
SPEAKER_01Kerberos ticket.
SPEAKER_00Yeah, which is basically the old authentication language the local network understands. The proxy hands that ticket to the ancient HR app.
SPEAKER_01So the app is totally fooled.
SPEAKER_00Completely. The legacy app thinks it's just talking to a standard user on the local network. It has no idea the cloud is even involved. The traffic is rigorously verified and routed by the cloud, but the old app gets to stay in its comfort zone.
SPEAKER_01Man, it's like placing a state-of-the-art biometric security checkpoint at the entrance of a historic 19th-century building.
SPEAKER_00That is a great way to picture it.
SPEAKER_01Yeah, you don't have to renovate the historic rooms. You don't have to replace the antique doors inside. But you enforce absolute modern security at the street level before anyone is even allowed to walk into the lobby.
SPEAKER_00Exactly. And while that checkpoint is running, keeping everything safe, the organization engages in gradual modernization.
SPEAKER_01Because they don't want to stay hybrid forever.
SPEAKER_00No, they don't stay in this hybrid state willingly if they can help it. They slowly, meticulously transfer the source of authority for users from the on-premises directory to the cloud over time.
SPEAKER_01Just chipping away at it.
SPEAKER_00Right. They update or replace dependencies app by app, user by user, phasing out the old servers without disrupting daily operations.
SPEAKER_01Okay, so it sounds incredibly elegant in theory. A seamless transition where nobody even notices the engine is being swapped out while the car is driving down the highway?
SPEAKER_00In theory, yes.
SPEAKER_01But if this gradual phaseout is the industry standard, why are so many massive enterprises permanently stuck halfway through the transition? I mean, I talk to IT professionals all the time who say they are seemingly unable to ever fully cut the cord and turn off that old server in the basement.
SPEAKER_00What's fascinating here is that the architectural blueprints we reviewed actually acknowledge this exact reality. They have a specific name for it.
SPEAKER_01What do they call it?
SPEAKER_00They call it the ugly 20% problem.
SPEAKER_01The ugly 20%, what exactly lives in that remaining 20%?
SPEAKER_00Well, it is the harsh reality of enterprise IT. You can migrate 80% of your workforce, your standard email, and your modern Saws apps to the cloud relatively easily.
SPEAKER_01Sure, that's the modern stuff.
SPEAKER_00That's the low-hanging fruit. But then you hit the bottom of the barrel. The ugly 20% consists of highly customized legacy ERP systems, enterprise resource planning systems.
SPEAKER_01All right.
SPEAKER_00These are the massive software monoliths that run the entire supply chain, manage factory inventory, and handle corporate accounting.
SPEAKER_01Systems that took like a decade to implement in the first place.
SPEAKER_00Exactly. You also have 30-year-old mainframes that process millions of financial transactions a day. And you have specific exchange hybrid dependencies, which basically means the company's email routing is so deeply tangled between old local servers and the cloud that untangling it is a monumental engineering feat.
SPEAKER_01Aaron Powell That sounded like a nightmare.
SPEAKER_00It is. These deeply embedded systems have historically forced Active Directory to remain the source of truth because they simply cannot function without it. And rewriting them would cost tens of millions of dollars.
SPEAKER_01So it's not that the cloud itself isn't technically capable of handling them, it's that the old apps stubbornly refuse to let go of the ground.
SPEAKER_00And this reveals the core obstacle to full cloud migration in 2026. It is rarely a technical limitation of the cloud. The cloud identity platforms are robust enough to handle almost anything. Right. The real obstacle is extreme operational risk aversion around a very small set of incredibly critical dependencies.
SPEAKER_01I see. It's a human problem, not a code problem. It's fear.
SPEAKER_00100% fear.
SPEAKER_01Like if you have an obsolete, dusty VCR hooked up to your brand new 8K smart TV, and you only keep it there because you have exactly one irreplaceable family tape that you are absolutely terrified of digitizing. Right. You know the VCR is ancient, you know it's a terrible way to watch video, but the fear of accidentally destroying that one tape keeps the old machine plugged in forever.
SPEAKER_00That professional fear is very real and very justified in enterprise IT.
SPEAKER_01I bet.
SPEAKER_00No IT director wants to be the person who finally unplugs the last Active Directory server only to accidentally stop the mainframe from processing the entire company's payroll on a Friday afternoon.
SPEAKER_01That's a resume generating event right there.
SPEAKER_00Exactly. The career risk is just too high. So they maintain the bridge, they keep the hybrid motto running indefinitely.
SPEAKER_01Well, to summarize this deep dive for you, the architectural mindset of the enterprise has completely shifted. The cloud is now the definitive primary identity control plane, with employee identities being borne directly into systems like Intra ID rather than local servers. And the days of the on-premises network dictating security are entirely over, with strict separations and one-way valves in place to prevent local breaches from moving upward and infecting cloud administration.
SPEAKER_00Precisely.
SPEAKER_01However, due to the intense operational fears surrounding that ugly 20% of legacy dependencies, like the mainframes and massive ERPs, the hybrid model remains the sticky, persistent reality for established enterprises. They are forced to maintain the old world to keep the business running, ultimately treating on-premises Active Directory as a localized dependency rather than the Supreme Authority.
SPEAKER_00That's a wrap on the cloud quietly fired Active Directory. The takeaway the cloud already owns identity. It's operational fear around a shrinking pile of legacy dependencies that's keeping the domain controller plugged in. Next episode, we asked the harder question. Once you've handed over the keys, can you actually take them back? That's you can fire Active Directory, can you take the keys back? Find the show notes and connect with Ernie on LinkedIn. Link in the description. If this is useful, subscribe so you don't miss it. Until next time.