The Identity Blueprint

Ernie Prescott

Enterprise identity and access management isn't a product you buy — it's a program you build. The Identity Blueprint covers the full spectrum: seven-phase IAM frameworks, zero trust architecture, JIT access, FIDO2 passkeys, identity governance, and the operational models that hold up at enterprise scale. Built for practitioners who are past the basics. Hosted by Ernie and Josée.

  1. 4d ago

    Secure Your Infrastructure Without Service Accounts

    For twenty years, every server and every application in your environment had a password somewhere — a service account, a computer account — managed by a human who was supposed to rotate it on schedule and usually didn't. That model quietly became obsolete the moment infrastructure started spinning up and disappearing in minutes instead of living for years, and most organizations are still running critical systems on it anyway. In this episode, Ernie and Josée trace how managed identities eliminate that problem entirely — no password exists anywhere, for anyone, ever, closing off an entire category of attack rather than just hardening it. Then we turn to the harder question: what do you do with the legacy application that still expects Active Directory to exist? We walk through both real architectural paths available today — Microsoft's Entra Domain Services, which recreates the legacy directory in the cloud, and the identity-aware gateway approach from Okta, Ping, and Keycloak, which modernizes access at the front door instead. Each is built for a different priority, and we lay out exactly how each one actually works under the hood. You'll leave knowing exactly how to eliminate static service accounts for good, and which of the two legitimate paths forward actually fits what your organization needs most. If you're the one deciding how legacy applications survive a cloud migration, this episode is not optional. Connect with Ernie Prescott on LinkedIn at linkedin.com/in/ernieprescott

    Secure Your Infrastructure Without Service Accounts
  2. Sep 1

    Day One of an M&A. Okta and Ping, Bloodhounds Sniffing Out Hidden Risk.

    You just merged networks with a company that might already be compromised — and they can't tell you, because they don't know either. That's day one. Not a checklist item. A live, unknown risk sitting inside a network you now own. Then it gets worse: the person responsible for deciding who keeps access is a manager staring at a list of strangers, with zero context, under pressure to not break payroll. So they approve everything. That's how a breach nobody caught turns into a breach nobody's watching. In this episode, Ernie and Josée cover how Okta and Ping are actually built to survive that exact failure. Okta doesn't leave the judgment call to a confused manager — access gets bundled into pre-built packages so nobody's approving two hundred individual permissions blind. Ping goes further and contains the blast radius at the data level, filtering what someone can actually see down to the individual field, so legitimate access doesn't mean seeing everything. And when the acquired company genuinely doesn't know what it's hiding, we walk the exact forensic playbook for finding it yourself — financial records, DNS anomalies, TLS handshakes. You'll leave knowing exactly where the real exposure hides in an Okta or Ping integration, and how each platform actually contains it once you find it. If you're responsible for securing an integration like this, this episode is not optional. Connect with Ernie Prescott on LinkedIn at linkedin.com/in/ernieprescott

    Day One of an M&A. Okta and Ping, Bloodhounds Sniffing Out Hidden Risk.

About

Enterprise identity and access management isn't a product you buy — it's a program you build. The Identity Blueprint covers the full spectrum: seven-phase IAM frameworks, zero trust architecture, JIT access, FIDO2 passkeys, identity governance, and the operational models that hold up at enterprise scale. Built for practitioners who are past the basics. Hosted by Ernie and Josée.