Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium
A security auditor has identified that an Azure AD application registration used by a critical line-of-business application has a client secret with an expiration date 5 years in the future. The auditor recommends enforcing a maximum secret lifetime of 1 year for all workload identities. Which Azure AD feature should you use to implement this policy for the application registration?
- AAzure Policy
- BAzure AD CredentialLifetimePolicy
- CAzure AD PIM (Privileged Identity Management)
- DConditional Access Policy
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD CredentialLifetimePolicy
Azure AD CredentialLifetimePolicy allows administrators to set specific restrictions on the lifetime of secrets and certificates for service principals (which are created from application registrations). This policy can enforce a maximum lifetime, ensuring secrets are rotated regularly.
Why the other options are wrong
- A. Azure Policy can enforce rules for Azure resources, but it doesn't directly manage the lifetime of Azure AD application registration credentials.
- C. PIM manages just-in-time access for privileged roles, not the lifetime of application credentials.
- D. Conditional Access policies control *when and how* users or applications can access resources, not the lifetime of their credentials.
Azure AD CredentialLifetimePolicy
A policy type in Azure AD that allows administrators to set custom lifetimes for application and service principal credentials (secrets and certificates).
- Applies to application registrations and their associated service principals.
- Can define maximum secret/certificate lifetimes.
- Helps enforce security best practices for credential rotation.
- Configured using Azure AD PowerShell or Microsoft Graph API.
Memory trick: Credential Lifetime Policy: Time's up for old secrets!