Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A security auditor has identified that an Azure AD application registration used by a critical line-of-business application has a client secret configured to expire in 10 years. The company's security policy dictates that all application secrets must be rotated at least every 90 days. You need to enforce this policy for all future and existing application registrations that use client secrets.

  1. AImplement a custom Azure Automation script to rotate secrets every 90 days.
  2. BManually update the client secret expiration for each application registration.
  3. CConfigure an Azure AD CredentialLifetimePolicy.
  4. DUse Azure Key Vault to manage and rotate the client secrets.
Show answer & explanation

Correct answer: C. Configure an Azure AD CredentialLifetimePolicy.

An Azure AD CredentialLifetimePolicy allows administrators to define and enforce credential lifetime policies for service principals (application registrations) within their tenant. This policy can specify maximum lifetimes for passwords and certificates, ensuring compliance with rotation requirements.

Why the other options are wrong

  • A. A custom script could rotate secrets, but it doesn't enforce a policy or prevent new secrets from being created with long lifetimes.
  • B. Manually updating secrets is not scalable or enforceable as a policy for all applications.
  • D. Azure Key Vault manages secrets, but it doesn't directly enforce a maximum lifetime policy on Azure AD application registration client secrets themselves.

Azure AD CredentialLifetimePolicy

A policy in Azure Active Directory that allows administrators to control the lifetime of credentials (passwords and certificates) for service principals and application objects.

  • Enforces maximum credential lifetimes.
  • Applies to service principals and application objects.
  • Can be set at the tenant level or applied to specific service principals.

Memory trick: Policy controls the PASSWORD clock.

More Implement and manage workload identities questions