Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A company is redesigning its CI/CD pipeline. The pipeline runs on self-hosted GitHub Actions runners outside of Azure and needs to deploy resources to an Azure subscription. The security team wants to eliminate the use of long-lived secrets (like service principal client secrets) and ensure that GitHub Actions can authenticate to Azure securely and with minimal credential management. Which Azure AD feature should you implement?

  1. AAzure AD Privileged Identity Management (PIM).
  2. BWorkload identity federation.
  3. CAzure AD Connect Health.
  4. DAzure AD Conditional Access policies.
Show answer & explanation

Correct answer: B. Workload identity federation.

Workload identity federation allows external identity providers, like GitHub, to authenticate to Azure AD without needing client secrets. It establishes a trust relationship based on OpenID Connect (OIDC) tokens issued by the external provider.

Why the other options are wrong

  • A. PIM manages just-in-time access for human users and roles, not for programmatic CI/CD authentication.
  • C. Azure AD Connect Health monitors sync services and doesn't address CI/CD authentication.
  • D. Conditional Access policies control access based on conditions but don't solve the problem of secret management for CI/CD.

Workload Identity Federation

An Azure AD feature that enables external identity providers (e.g., GitHub, AWS) to authenticate directly to Azure Active Directory using OpenID Connect (OIDC) tokens, eliminating the need for long-lived secrets.

  • Uses OpenID Connect (OIDC) for trust.
  • Eliminates the need for client secrets.
  • Enhances security for CI/CD pipelines and external workloads.

Memory trick: Federation: Trust external ID, without a secret, Azure's identity is free.

More Implement and manage workload identities questions