Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium
A security team wants to enforce a policy that all certificates used by Azure AD application registrations for authentication must have a maximum validity period of one year. After this period, the certificates should automatically expire, forcing a rotation. Which Azure AD feature allows administrators to define and enforce such a policy for workload identities?
- AAzure AD Conditional Access policy.
- BAzure AD Identity Protection policy.
- CAzure AD Access Reviews.
- DCredentialLifetimePolicy.
Show answer & explanationAnswer & explanation
Correct answer: D. CredentialLifetimePolicy.
The CredentialLifetimePolicy in Azure AD allows administrators to define the lifetime of secrets and certificates for service principals and application registrations. This directly addresses the requirement for enforcing a maximum validity period for certificates.
Why the other options are wrong
- A. Conditional Access policies control access based on conditions, not credential lifetimes.
- B. Identity Protection focuses on risk detection for users, not certificate validity for applications.
- C. Access Reviews manage the periodic review of access assignments, not the validity period of credentials themselves.
CredentialLifetimePolicy
An Azure AD policy that allows administrators to specify the lifetime of secrets and certificates for application registrations and service principals, enforcing rotation schedules.
- Applies to secrets and certificates.
- Can be set at the tenant or service principal level.
- Enforces rotation and reduces risk from compromised credentials.
Memory trick: CredentialLifetimePolicy: Time's up for secrets, policy sets the clock.