18 June 2026

When landing zones argue with identity

Pretty account diagrams collapse when identity is treated as a later ticket. Federation gaps, leftover local admins, and mismatched group claims show up the week before wave one.

During Cloud Architecture Planning we force an identity session early. Map who authenticates today, which systems still use local accounts, and what break-glass looks like if the IdP hiccups during cutover. Those answers constrain network and logging choices more than brand preference for a cloud console colour scheme.

If security needs a stronger model than the migration timeline allows, say so in the decision log. Delaying a wave is cheaper than inventing temporary exceptions that become permanent.

Teams in Taiwan often juggle vendors and regional compliance notes; write those constraints beside the identity diagram so nobody “simplifies” them out of the next revision.

← Back to field notes