Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesHard

A company uses a third-party CI/CD pipeline, hosted outside of Azure, to deploy applications to an Azure Kubernetes Service (AKS) cluster. The pipeline needs to authenticate to Azure AD to obtain tokens for deploying resources and managing the AKS cluster. The security team wants to eliminate the need for long-lived client secrets or certificates for this external pipeline. The solution should leverage modern authentication practices. Which Azure AD feature should be configured?

  1. ASystem-assigned Managed Identity on the CI/CD server
  2. BAzure AD Application Registration with certificate credentials
  3. CWorkload Identity Federation
  4. DAzure AD Application Registration with client secret
Show answer & explanation

Correct answer: C. Workload Identity Federation

Workload Identity Federation allows external workloads (like a third-party CI/CD pipeline) to authenticate to Azure AD and access Azure resources without needing to manage client secrets or certificates. It achieves this by exchanging tokens issued by the external identity provider for Azure AD tokens.

Why the other options are wrong

  • A. System-assigned managed identities are tied to Azure resources; they cannot be directly assigned to an external, third-party CI/CD server running outside Azure.
  • B. Certificate credentials are more secure than client secrets but still require certificate management and rotation, which Workload Identity Federation aims to eliminate.
  • D. Client secrets are long-lived and require rotation, which the scenario explicitly wants to avoid.

Workload Identity Federation

An Azure AD feature that enables external workloads (e.g., CI/CD pipelines, on-premises applications) to authenticate to Azure AD without managing client secrets or certificates.

  • Eliminates the need for long-lived credentials.
  • Relies on tokens issued by external identity providers.
  • Enhances security posture for external integrations.

Memory trick: Federation's the bridge, no secrets to hide, external to Azure, on a secure tide.

More Implement and manage workload identities questions