Two tenants: corporate and CIAM. The alternative — one tenant with customers as guests or B2C users — was rejected because the blast radius of a customer-facing misconfiguration would then include workforce administrative roles.
The cost is real and stated: two Conditional Access estates, two policy pipelines, and B2B configuration for partner staff who need corporate resources. That cost buys a boundary a reviewer can verify in one screen.
Workload identity is a first-class identity class, not an afterthought attached to applications. 3,400 workload identities outnumber administrators by eighteen to one, and they are governed with owners, reviews and expiry like any other principal.
Rules that hold everywhere
No human identity is created by hand. Employees and contractors arrive from Workday; a contractor without a sponsor and an expiry date cannot be created at all.
Every workload identity has an owning group, never an owning person, so an engineer leaving does not orphan a running integration.
Guests are reviewed every 90 days and inherit nothing by default: a guest gains access only through an access package with an explicit sponsor.
The visible debt
170 service principals still hold client secrets because their target systems cannot federate. Tracked as a named burn-down with an owner per principal, not accepted as steady state.
Two permanent break-glass accounts. Reduced from six; two is the floor, because one is a single point of failure during an incident.
AD DS remains for Kerberos-dependent applications. Retiring it is a separate programme, and until then Cloud Sync is a dependency with its own failure mode (view 27).