Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesHard

A security auditor has identified that an Azure AD application registration used by a critical application has a client secret that expires in over two years. The auditor recommends enforcing a maximum client secret lifetime of 180 days for all application registrations. What should you configure in Azure AD to meet this requirement for all *new* and *existing* application registrations?

  1. ADefine an Azure AD service principal policy for credential lifetime.
  2. BImplement a custom Azure Automation runbook to check and rotate secrets.
  3. CCreate an Azure AD Conditional Access policy targeting application registrations.
  4. DConfigure an Azure AD custom security attribute for client secret expiration.
Show answer & explanation

Correct answer: A. Define an Azure AD service principal policy for credential lifetime.

Azure AD service principal policies (specifically, the 'CredentialLifetimePolicy') allow you to define rules for the lifetime of secrets or certificates on service principals (which are created for application registrations). You can apply these policies to specific service principals or to the entire tenant to enforce a maximum secret lifetime for all new and existing application registrations, directly addressing the requirement.

Why the other options are wrong

  • B. While a custom runbook could *check* and *rotate* secrets, it doesn't *enforce* a maximum lifetime policy at the Azure AD level for new secrets or prevent longer-lived secrets from being created initially.
  • C. Conditional Access policies primarily control user access based on conditions; they do not manage application client secret lifetimes.
  • D. Custom security attributes are for categorizing and authorizing resources, not for enforcing technical policies like secret lifetime.

Azure AD CredentialLifetimePolicy

A type of Azure AD policy that allows administrators to define the maximum lifetime for client secrets and certificates used by service principals (application registrations).

  • Enforces secret/certificate lifetime limits.
  • Can be applied tenant-wide or to specific service principals.
  • Helps comply with security audit requirements for credential rotation.
  • Managed via Azure AD PowerShell or Microsoft Graph API.

Memory trick: Policy Prevents Prolonged Passwords.

More Implement and manage workload identities questions