Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesHard
A company uses a third-party CI/CD pipeline running outside of Azure to deploy applications to Azure App Services. The CI/CD pipeline needs to authenticate to Azure AD to obtain tokens for deploying code and managing App Service configurations. You want to implement a solution that allows the external CI/CD system to authenticate without storing long-lived secrets in its configuration. Which Azure AD feature should you use?
- AManaged Identity for Azure resources.
- BClient secret for an Azure AD application registration.
- CWorkload Identity Federation for an Azure AD application registration.
- DPrivate Endpoint for Azure App Services.
Show answer & explanationAnswer & explanation
Correct answer: C. Workload Identity Federation for an Azure AD application registration.
Workload Identity Federation allows an Azure AD application registration to trust tokens issued by an external identity provider (like a CI/CD system). This enables the external system to exchange its own short-lived tokens for Azure AD tokens, eliminating the need to store long-lived client secrets or certificates in the CI/CD environment.
Why the other options are wrong
- A. Managed Identities are for Azure resources to authenticate to Azure AD; they cannot be directly used by external, non-Azure CI/CD systems.
- B. Using a client secret would require storing a long-lived secret in the CI/CD pipeline, which the question explicitly aims to avoid.
- D. Private Endpoints secure network access to Azure services; they are not an authentication mechanism for workload identities.
Workload Identity Federation
An Azure AD feature that allows an application registration to exchange tokens issued by an external identity provider (like GitHub Actions, GitLab, AWS) for Azure AD access tokens, without managing secrets.
- Eliminates client secrets/certificates for external workloads.
- Relies on trust relationships with external identity providers.
- Enhances security by using short-lived tokens.
- Configured on an Azure AD application registration.
Memory trick: Federation Frees Foreign Friends From Fiddly Secrets.