Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium
A company uses a third-party CI/CD pipeline, hosted outside of Azure, to deploy application updates to Azure Kubernetes Service (AKS). The pipeline needs to authenticate to Azure AD to obtain tokens to manage AKS resources. The security team wants to avoid storing any long-lived Azure credentials (like client secrets) in the CI/CD system. Which feature should you implement?
- AConfigure an Azure AD application registration with a certificate and upload the certificate to the CI/CD system.
- BImplement Workload Identity Federation for the Azure AD application registration.
- CUse a system-assigned managed identity for the CI/CD pipeline.
- DCreate an Azure AD application registration and use a client secret stored in the CI/CD system.
Show answer & explanationAnswer & explanation
Correct answer: B. Implement Workload Identity Federation for the Azure AD application registration.
Workload Identity Federation allows external workloads (like a third-party CI/CD system) to authenticate to Azure AD using credentials issued by their own identity provider (e.g., GitHub Actions, GitLab, AWS). This eliminates the need to manage secrets in Azure AD for the external system.
Why the other options are wrong
- A. While more secure than client secrets, this still involves managing a certificate (a credential) within the CI/CD system, which Workload Identity Federation aims to avoid entirely.
- C. System-assigned managed identities are for Azure resources, not for external CI/CD pipelines.
- D. This option explicitly stores long-lived credentials, which the security team wants to avoid.
Workload Identity Federation
A feature that allows external identity providers (like GitHub Actions, AWS) to issue tokens that Azure AD trusts, enabling external workloads to authenticate to Azure AD without storing client secrets or certificates.
- Eliminates the need for client secrets or certificates for external workloads.
- Azure AD trusts tokens from specified external identity providers.
- Enhances security by reducing credential exposure.
- Commonly used with CI/CD pipelines hosted outside Azure.
Memory trick: Federation lets external friends join the Azure party without needing a secret handshake.