I’ve spent twenty years building identity systems — from Active Directory in Windows Server, through Azure AD, to Microsoft Entra. Over that time, I owned successive layers of the identity stack: device identity (Hybrid Azure AD Join was my idea), hybrid and cloud authentication for hundreds of millions of users, the authorization platform, and most recently Entra ID Governance, whose core services my teams took from incubation to launch — including its first AI Copilot.
This blog exists because of transitions. It started when devices became a new class of identity and the model didn’t know what to do with them — the AAD Join, Hybrid Join, and Windows Hello for Business posts here documented that architecture while it was still settling, and I’m told they’re still doing useful work a decade later. The same kind of transition is happening now with AI agents, so I’m writing again: the new series on identity architecture for the agentic era starts with Your Agents Don’t Have an Authentication Problem. They Have an Authorization Problem. There’s working code too — an open-source reference identity broker for agents at github.com/JairoACadena/agentic-broker-lab.
The goal hasn’t changed in ten years: reference material, written down before the confusion peaks.
Outside the identity world, I’m the founder of Cadena Core Group, my family’s firm — where among other things we’re building our home in the Arizona desert like a software project, and where the next generation of Cadenas ships their own work.
You can find me on LinkedIn or at jairo@cadenacoregroup.com. Everything here reflects my personal views, not those of any employer — past, present, or future.
This blog looks like it has a lot of the info I have been looking for. but it is hard to find. It would be very helpful if this info was publicized in the main EMS/Azure AD sites.
LikeLiked by 1 person