Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesHard

A company uses Azure DevOps for its CI/CD pipelines. These pipelines need to frequently update Azure resource configurations, including deploying new Azure Functions and modifying Azure Key Vault access policies. The security team wants to ensure that the CI/CD pipelines authenticate to Azure AD using a method that eliminates the need for manually managed secrets or certificates, and also allows for fine-grained, temporary elevation of privileges when performing sensitive operations.

  1. AImplement Workload Identity Federation with a service principal and integrate with Azure AD Privileged Identity Management (PIM).
  2. BStore Azure AD administrator credentials as secure variables in Azure DevOps.
  3. CUse a system-assigned managed identity for the Azure DevOps agent.
  4. DConfigure the Azure DevOps service connection to use a Service Principal with a client secret.
Show answer & explanation

Correct answer: A. Implement Workload Identity Federation with a service principal and integrate with Azure AD Privileged Identity Management (PIM).

Workload Identity Federation allows the CI/CD pipeline (e.g., Azure DevOps) to authenticate to Azure AD without secrets, using federated credentials. Integrating this with Azure AD PIM enables just-in-time access for the service principal, providing temporary elevated privileges only when sensitive operations are performed, meeting the requirement for fine-grained, temporary privilege elevation.

Why the other options are wrong

  • B. Storing administrator credentials in secure variables, even if encrypted, is not a secure or recommended practice for workload identities and doesn't offer temporary privilege elevation.
  • C. Azure DevOps agents (if self-hosted on Azure VMs) can use system-assigned managed identities, but this doesn't directly support the CI/CD pipeline's authentication to Azure AD for cross-resource deployments, nor does it inherently provide temporary privilege elevation.
  • D. Using a Service Principal with a client secret still requires manual secret management and rotation, which the security team wants to eliminate.

Workload Identity Federation with PIM

A solution combining Workload Identity Federation (secret-less authentication for workloads) with Azure AD Privileged Identity Management (PIM) to enable just-in-time, time-bound access for service principals. This allows CI/CD pipelines or other workloads to authenticate without managing secrets and gain elevated privileges only when needed.

  • Eliminates the need for client secrets/certificates for workload authentication.
  • PIM provides just-in-time (JIT) and time-bound access to Azure AD roles.
  • Ideal for CI/CD pipelines requiring temporary elevated access to Azure resources.

Memory trick: FEDERATE for NO secrets, PIM for JIT powers.

More Implement and manage workload identities questions