Authenticationthat holds up inproduction.

I design and deliver authentication, authorization and SSO on Microsoft Entra ID and Azure AD B2C, built to keep up as the company grows. For finer-grained permissions, down to individual resources, I use OpenFGA. I have worked with .NET for 17 years and with Azure since 2010.

id_tokensample

header

{ "alg": "EdDSA", "typ": "JWT", "kid": "edgarus-sample" }

payload

{"iss": "https://edgarus.eu","sub": "przemyslaw-gawdzik","name": "Przemysław Gawdzik","role": "Senior Identity Management Engineer","scp": "entra-id azure-ad-b2c oauth2 oidc dotnet","azure_since": 2010,"dotnet_years": 17,"degree": "Engineer (inż.) — computer networks and distributed systems"}

signature · EdDSA

2CWrWFritK0T6EMRuNhlPgha6T0TDJ6QgOl0feVIE3NGDrCM-Jj5Hekd7SDteOc5k_Ix4qw9UVZbZ8qZU9gAAw

signature verifiedsignature check failed

Przemysław Gawdzik

Senior Identity Management Engineer · Entra ID · Azure AD B2C · .NET

I design and build identity solutions on Azure, including CIAM systems. I cover the whole solution: from architecture, code and automation to infrastructure and running production.

I also develop open-source projects as Edgarus79, in the edgarus-labs organisation. I hold an engineer’s degree (inż.) in computer networks and distributed systems from WSPA in Lublin.

Got something to build or fix? The form at the bottom of this page goes straight to my inbox.

  1. 2022 – 2024Senior .NET Developer / Cloud Infrastructure ConsultantPredica (now SoftwareOne)
  2. 2019 – 2022Senior Software Developer / ConsultantCloudTeam
  3. 2011 – 2019Software Developer / ConsultantAction Centrum Edukacyjne
  4. 2010 – 2011Windows Azure Trainer / Consultant / DeveloperABC Data Centrum Edukacyjne

Open source.
Licensed under MIT and LGPL.

A few projects I maintain in the open. Code, issues and releases live in the repositories, so that is where things are current.

What I do
day to day.

In practice these areas overlap: backend, access and deployment. The homelab is where I test new things before I use them in a real project.

Authentication and access.

I work on how users sign in, what they are allowed to do and how applications talk to each other. Day to day that means Microsoft Entra ID, External ID, Azure AD B2C, OAuth 2.0 and OpenID Connect, with SSO and MFA where they make sense. In OpenFGA I describe permissions as relationships between users and resources.

  • Entra ID
  • Azure AD B2C
  • OAuth 2.0
  • OIDC
  • OpenFGA
  • CIAM

Secure .NET applications.

Identity does not end with Entra ID configuration. I also build the applications themselves in C# and ASP.NET Core — APIs that validate identity, enforce authorization, and handle business logic and integrations. I apply DDD, TDD and SOLID to keep the code readable, well tested, and easy to evolve and maintain.

  • C#
  • ASP.NET Core
  • Authorization
  • DDD
  • TDD

From code to production.

Azure, containers and CI/CD, so that a deployment is boring and repeatable. Infrastructure lives in code and configuration in the repository. After a release I read the logs, metrics and traces, because I want to know what is really happening.

  • Azure
  • CI/CD
  • Containers
  • OpenTelemetry

Room to experiment.

In my homelab I test networking, security and automation before I use them in a project.

  • Homelab
  • Security
  • Networking
  • Automation

How I test.

Tests are there to catch bugs,
not to earn a percentage.

I aim for tests that catch regressions: a test has to fail when behaviour breaks, including the odd cases. A test that passes while the code is wrong protects nothing.

Unit tests.

Rules, calculations and edge cases, in isolation.

Integration tests.

Whether the API, the database and authentication work together.

End-to-end tests.

The key user journeys from start to finish, including when something goes wrong.

How I work.

The problem first.

Before I pick a tool, I ask what has to work, who will use it and who will maintain it.

Small steps.

I prefer changes that are easy to review and test. Smaller releases are also easier to fix.

Maintenance in mind.

Readable code, useful logs and written-down decisions. The next person to open this is often me.

Got something
to build?

All fields are required.

5 to 5000 characters.

This site uses no cookies or analytics and keeps nothing in your browser for good. When you switch language, it remembers where you were reading for up to 30 seconds, so the other version opens at the same place.

Cloudflare Turnstile checks the form for spam in the background. By sending a message, you acknowledge Cloudflare’s Turnstile Privacy Addendum.

Data processing details

I use your name, email address and message only to reply to you. The message reaches me through Resend. I do not profile, sell or use this data for marketing.

Prefer LinkedIn? Message me here ↗