TL;DR: Legacy on-premises identity and device tools create visibility gaps, VPN friction, and siloed controls that slow hybrid work and complicate AI adoption, according to JumpCloud. A cloud-native, unified access model shifts the conversation from tool sprawl to identity governance and Zero Trust execution.
Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “Breaking Free from Microsoft: Embracing a Modern Workplace”.
Key questions
Q: Why do legacy identity stacks create more risk in AI-first environments?
A: Legacy stacks fragment authentication, device management, and authorization, so teams cannot see the full context of an access decision.
Q: Why do VPN-bound access models create so much friction in modern workplaces?
A: They force users, devices, and applications through a control path designed for perimeter-era networks rather than session-based cloud access.
Q: How can teams tell whether identity modernization is working?
A: Look for fewer manual exceptions, more complete audit trails, and faster closure of access lifecycle actions.
Practitioner guidance
- Map identity and device control fragmentation Inventory where directory services, device management, and collaboration access are managed separately, then identify which access decisions rely on implicit trust in the network or location.
- Remove location-based access assumptions Replace VPN-first and office-bound access patterns with policies that evaluate user identity, device posture, and session context before granting access.
- Treat lift-and-shift as a governance risk Do not count cloud hosting as identity modernisation unless the access model, control ownership, and enforcement path are also redesigned for cloud operations.
Bottom line: Legacy identity architecture becomes a bottleneck when organisations try to support AI-first work on top of location-bound access assumptions.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Legacy identity sprawl is now a governance problem, not just an infrastructure problem. The article shows that forced boundaries, VPN dependence, and siloed directories do more than create friction. They weaken the organization’s ability to answer basic access questions across human users, devices, and AI-assisted workflows. That is a structural issue for IAM and Zero Trust programmes, not merely an IT inconvenience. Practitioners should treat fragmented identity control as an operating risk.
A few things that frame the scale:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to The 2026 Infrastructure Identity Survey.
- Another 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to The 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What is the difference between cloud migration and identity modernization?
A: Cloud migration moves infrastructure. Identity modernization changes how access, device posture, and collaboration are governed. If the old control assumptions remain in place, the organisation only relocates the problem. Modernization is successful when the control model becomes simpler, more observable, and easier to enforce across hybrid work.
👉 Read our full editorial: Legacy identity stacks are the bottleneck in AI-first workplaces
Legacy identity architecture becomes the bottleneck when work is no longer location-bound. The article is really about governance lag, not just infrastructure age. Identity and access models that assume a fixed office, a trusted network, and a known endpoint cannot keep pace with hybrid work or AI-enabled workflows. The practitioner conclusion is that modernisation is an identity programme decision, not an IT refresh exercise.
A question worth separating out:
Q: What is the difference between cloud hosting and identity transformation?
A: Cloud hosting changes where systems run, while identity transformation changes how access is governed, enforced, and observed. A lifted workload can still carry the same directories, approval chains, and network assumptions, so the security model may remain legacy even when the infrastructure is not.
👉 Read our full editorial: Legacy identity stacks are the bottleneck in AI-first workplaces