This blog has been quiet for a while, but I know many of you still land here — the AAD Join, Hybrid Join, and Windows Hello for Business posts keep finding readers a decade after I wrote them. I still hear from engineers using them to explain hybrid join trade-offs to customers today. That’s the best compliment technical writing can get, and it’s also why I’m writing this note.
Those posts existed because of a specific moment: a new class of identity — devices — had arrived, and the existing identity model didn’t know what to do with it. There was confusion, half-right guidance everywhere, and a real need for someone to write down how the architecture actually worked. Then the model settled: devices got first-class identities, attestation gave us roots of trust, and Conditional Access got built on top. What felt novel became infrastructure.
It’s happening again — faster, and with higher stakes. This time the new class of identity is AI agents: non-deterministic actors that authenticate once and then act continuously, chain tools, spawn sub-agents, and hold credentials in places no human session ever did. The old model — verify at login, trust the token until it expires — breaks in ways that will feel very familiar to anyone who lived the device transition.
So I’ve started writing again, with the same goal as before: reference material, written before the confusion peaks.
The new series lives on LinkedIn, starting here:
Your Agents Don’t Have an Authentication Problem. They Have an Authorization Problem.
It covers why bearer tokens are the wrong artifact for agents, the credential properties that replace them (brokered, just-in-time, task-scoped, time-bound, attributable), delegation chains, what to do about legacy apps, and an honest read on where the standards actually are — WIMSE, SPIFFE, token exchange, CAEP.
If the device identity posts helped you back then, I think this series will feel familiar: same discipline, new actors.
You can follow along on LinkedIn or at cadenacoregroup.com, where I now advise on identity and access architecture for the agentic era.
Thanks for still being here after all these years.
— Jairo