Microsoft Entra Workload ID
Developer

Workload Identity Federation Config App Trust Managed Identity

In brief

The documentation changes the example `-Subject` value in the `New-AzADAppFederatedCredential` command.

What Entra admins need to know

Administrators using the example should use the updated subject value.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

The audience value must be set to one of the following values:
Entra ID Global Service: api://AzureADTokenExchange
Entra ID for US Government: api://AzureADTokenExchangeUSGov
Entra ID China operated by 21Vianet: api://AzureADTokenExchangeChina

New-AzADAppFederatedCredential -ApplicationObjectId $appObjectId -Audience api://AzureADTokenExchange -Issuer 'https://login.microsoftonline.com/{tenantID}/v2.0' -Name 'MyMsiFic' -Subject '00001111-aaaa-2222-bbbb-3333cccc4444aaaabbbb-0000-cccc-1111-dddd2222eeee'
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…