Digital transformation has accelerated the growth of identities - and with it the expansion of the enterprise attack surface. Today’s organisations rely on an increasingly diverse set of human and non-human identities originating from many sources: Entra ID for SaaS, federated domains created through mergers and acquisitions, partner and supplier ecosystems, service accounts, API integrations, IoT devices, workloads, automation tools, and increasingly autonomous AI agents operating across cloud and on-prem environments. Every optimisation or digitalisation initiative introduces additional actors that must be consistently authenticated and authorised.
But identity proliferation doesn’t just introduce complexity. When applications directly rely on external identity providers - whether from SaaS platforms, multi‑cloud setups, partner ecosystems, or post‑merger domains - trust begins to spread far beyond its intended boundary. This increases blast radius whenever a credential is compromised or a provider is misconfigured.
In this session, I demonstrate how OAuth Token Exchange offers a standards‑based pattern to decouple identity origin from trust enforcement. By issuing context‑aware, boundary‑scoped tokens, organisations can enforce identity consistently and reduce risk across internal domains - regardless of where the identity was created.
Key Message
The architectural approach applies equally to on‑prem systems, multi‑cloud deployments, and federated organisations.
Call to Action
We cannot control where identities are created — but we can control how, where, and under what conditions trust is applied.
If identity enforcement still lives inside your applications, you are scaling complexity and risk. Let’s talk about how to centralise trust - not vulnerabilities.