Workload Identities Federated Credential Mutable Subjects
"audiences": ["api://AzureADTokenExchange"]
Track documentation and Message Center changes for Microsoft Entra Workload ID.
Microsoft Learn documentation ↗"audiences": ["api://AzureADTokenExchange"]
Replace `<application-object-id>` with the object ID of your app registration. Create one credential for each subject the workflow presents, such as a different branch or environment.
Learn how to migrate a Microsoft Entra federated identity credential for GitHub Actions from a mutable subject to GitHub's immutable subject format.
Learn how mutable OIDC subject claims expose Microsoft Entra federated identity credentials to subject recycling, and how immutable claims reduce the risk.
- GitHub Actions. First, configure a trust relationship between your [user-assigned managed identity](workload-identity-federation-create-trust-user-assigned-managed-identity.md) or [application](workload-identity-federation-create-trust.md) in Microsoft Entr…
Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.
Learn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.
Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.
Learn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.
- The Service Principal Names (SPNs) of the private apps you want to protect. You add these SPNs in the policy for Private Access Sensors that are installed on the DCs.
Learn how to configure an application to trust a managed identity in Microsoft Entra ID.
Configure app management policies in Microsoft Entra ID to set restrictions on how apps and service principals in your tenant can be configured. Secure your environment with step‑by‑step guidance.
Learn how to replace basic authentication with short-lived, federated OpenID Connect tokens for Microsoft Entra provisioning to SAP SuccessFactors.
Describes how to use Azure PowerShell to create a Microsoft Entra application and service principal, and grant it access to resources through role-based access control. It shows how to authenticate application with a certificate.
Reference table that maps application IDs to applications and their service principal usage from the sign-in logs.
Learn about Microsoft Entra Workload ID Flexible federated identity credentials and its capabilities.
Use new audit log properties to understand why a new service principal was added to your tenant.
A Microsoft Entra documentation page was updated: How to use managed identities for Azure resources on an Azure VM to acquire an access token .
A Microsoft Entra documentation page was updated: How to use managed identities for Azure resources on an Azure VM with Azure SDKs .
Get to know the client libraries that you can use to authenticate your apps using managed identities for Azure resources.
Create a new Microsoft Entra app and service principal to manage access to resources with role-based access control in Azure Resource Manager.
Learn how to troubleshoot service principal configuration alerts for Microsoft Entra Domain Services
Learn how to use the sensitive operations report workbook in Microsoft Entra ID to explore suspicious app and service principal activity.
Learn how to set up a Flexible Federated identity credential in the Azure portal or Microsoft Graph Explorer.
Learn how to access Azure Storage from a web app in Azure App Service using managed identities. Simplify security and avoid managing secrets.
In this tutorial, you learn how to access data in Microsoft Graph from a web app running in Azure App Service using managed identities.
Learn why a Microsoft Entra service principal was created in your tenant and who or what triggered the event through new properties that have been added audit log activity.
Step-by-step instructions for viewing the Azure resources that are associated with a user-assigned managed identity
Important considerations and restrictions for creating a federated identity credential on an app.
1. Under **Assignments**, select **Users or workload identities**.
2. **SAP Cloud Identity Service exchanges the JWT for an access token.** The signed JWT is presented to SAP Cloud Identity Service, which is trusted by SAP SuccessFactors. SAP Cloud Identity Service validates the JWT against the trust rules you configure in t…
Understand the concepts and supported scenarios for using workload identity in Microsoft Entra.
author: kenwith
Documentation for the Azure Policy that can be used to assign managed identities to Azure resources.
| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|
Microsoft Entra ID will enable App Instance Lock by default for new applications starting June 2026, protecting sensitive properties from unauthorized changes outside the home tenant. Existing apps are unaffected. Admins can disable the lock if needed. Review and update automati…
A workload identity is an identity that allows an application or service principal access to resources, sometimes in the context of a user. Conditional Access policies can be applied to single tenant service principals registered in your tenant. Non-Microsoft…
> In directories without appropriate licenses, existing Conditional Access policies for workload identities continue to function, but can't be modified. For more information, see [Microsoft Entra Workload ID](https://www.microsoft.com/security/business/identi…
- **Managed identities**: Configuring token lifetimes for [managed identity service principals](~/identity/managed-identities-azure-resources/overview.md) isn't supported.
- Which users, groups, directory roles, or workload identities are included in or excluded from the policy?
Some customers apply Conditional Access policies to user-based service accounts. You can reclaim the user-based license, and add a [workload identities](~/workload-id/workload-identities-overview.md) license to apply [Conditional Access for workload identitie…
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
An app role assignment records when a user, group, or service principal is assigned an app role for an app. All properties of app role assignment are in scope. View all app role assignment details and properties in the [Microsoft Graph appRoleAssignment resou…
Learn how to enable continuous access evaluation for workload identities to enforce Conditional Access policies and instantly revoke tokens.
**For example**, GitHub Actions need a workload identity to access Azure subscriptions to automate, customize, and execute software development workflows.
- Using the Azure portal, give an Azure virtual machine scale set managed identity [access to another Azure resource](~/identity/managed-identities-azure-resources/grant-managed-identity-resource-access-azure-portal.md).
Step-by-step instructions for configuring managed identities for Azure resources on a virtual machine scale set using the Azure portal.
Step-by-step instructions for configuring system and user-assigned managed identities on an Azure VMs.
An overview how developers can use managed identities for Azure resources.
A tutorial that walks you through the process of using a system-assigned managed identity on a virtual machine (VM) to access Azure Resource Manager.
Learn how to use managed identities with Windows VMs using the Azure portal, CLI, PowerShell, Azure Resource Manager template
Step-by-step instructions and examples for using an Azure VM-managed identities for Azure resources service principal for script client sign-in and resource access.
Step-by-step instructions for viewing the Azure resources that are associated with a user-assigned managed identity
Step-by-step instructions for viewing the service principal of a managed identity.
| Azure Container Apps | [Managed identities in Azure Container Apps](/azure/container-apps/managed-identity) |
Learn how workload identify federation enables secure access to Microsoft Entra protected resources from external software workloads without managing secrets.
If administrators assign privileged roles to workload identities, such as service principals or managed identities, the tenant can be exposed to significant risk if those identities are compromised. Threat actors who gain access to a privileged workload ident…
2. Now delete the old application and object using the following PowerShell cmdlets:
| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|
Creation of federated identity credentials is currently **not supported** on user-assigned managed identities created in the following regions:
A Microsoft Entra documentation page was updated: Managed Identity Libraries.
A Microsoft Entra documentation page was updated: Howto Create Service Principal Portal.
Learn about the mitigation steps tenant administrators should perform for the retirement of service principal-less authentication.
Learn how to include or exclude users, groups, and workload identities in Conditional Access policies for secure and flexible access management.
A Microsoft Entra documentation page was updated: Assign App Role Managed Identity.
- If you're unfamiliar with managed identities for Azure resources, see [Managed identity for Azure resources overview](./overview.md).
- If you're unfamiliar with managed identities for Azure resources, see [Managed identity for Azure resources overview](./overview.md).
The steps outlined below show how you grant access to a service using Azure RBAC. Check specific service documentation on how to grant access; for example, check [Azure Data Explorer](/azure/data-explorer/data-explorer-overview) for instructions. Some Azure s…
A Microsoft Entra documentation page was updated: How Manage User Assigned Managed Identities.
Deleting a user-assigned managed identity won't remove the reference from any resource it was assigned to. Remove those from the resource itself. For example, for a VM or virtual machine scale set, use the `az vm/vmss identity remove` command.
Step-by-step instructions on using PowerShell to assign a managed identity access to an Azure resource or another resource.
1. Copy user-assigned managed identity assigned permissions. You can list [Azure role assignments](/azure/role-based-access-control/role-assignments-list-powershell) but that may not be enough depending on how permissions were granted to the user-assigned man…
At a high level, there are two types of identities: human and machine/non-human identities. Machine / non-human identities consist of device and workload identities. In Microsoft Entra, workload identities are applications, service principals, and managed ide…
Create a new Microsoft Entra app and service principal to manage access to resources with role-based access control in Azure Resource Manager.
Learn how to access Azure Storage from a web app in Azure App Service using managed identities. Simplify security and avoid managing secrets.
In this tutorial, you learn how to access data in Microsoft Graph from a web app running in Azure App Service using managed identities.
You can find the list of resources that have a system-assigned managed identity by using the following Azure CLI Command:
Configure Conditional Access user assignments in Microsoft Entra ID. Target specific users, groups, directory roles, and workload identities while avoiding administrator lockout with proper exclusions.
Learn how to configure isolation scope for user-assigned managed identities to improve security and resilience.
- Read the [Isolation scope for user-assigned managed identities](managed-identities-isolation-scope.md) concept article to understand the benefits and implications.
A Microsoft Entra documentation page was updated: Enable Managed Identities Regional Isolation.
Learn about isolation scope for user-assigned managed identities and how it improves security and resilience.
Microsoft Entra ID will block authentication for all non-Microsoft multitenant applications that don't have a service principal in the tenant where they're authenticating. This scenario is also known as service principal-less authentication. This behavior has…
Describes how to use Azure PowerShell to create a Microsoft Entra application and service principal, and grant it access to resources through role-based access control. It shows how to authenticate application with a certificate.
Learn how to access Azure Storage from a web app in Azure App Service using managed identities. Simplify security and avoid managing secrets.
In this tutorial, you learn how to access data in Microsoft Graph from a web app running in Azure App Service using managed identities.
The audience value must be set to one of the following values:<br/> • **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>• **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>• **Entra ID China operated by 21Vi…
- *issuer*, *subject* are the key pieces of information needed to set up the trust relationship. When the Azure workload requests Microsoft identity platform to exchange the managed identity token for an Entra app access token, the *issuer* and *subject* valu…
Learn how the Microsoft Entra recommendation to renew expiring service principal credentials work and why it's important.
Reference table that maps application IDs to applications and their service principal usage from the sign-in logs.
Learn how to use the sensitive operations report workbook in Microsoft Entra ID to explore suspicious app and service principal activity.
Jason starts his assessment and signs in to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) or the Microsoft Entra admin center. In order to view application and service principal details, he signs in as at least a [Security Reader](/entr…
Users with this role can assign and remove custom security attribute keys and values for supported Microsoft Entra objects such as users, service principals, and devices.
author: barclayn
Learn about the type of information captured in the managed identity sign-in logs in Microsoft Entra monitoring and health.
This is a [privileged role](../privileged-roles-permissions.md). Users in this role can read and update basic information of users, groups, and service principals.
In addition to human and device identities, workload identities such as applications, services, and containers require authentication and authorization policies.
- A service principal of a special type is created in Microsoft Entra ID for the identity. The service principal is tied to the lifecycle of that Azure resource. When the Azure resource is deleted, Azure automatically deletes the service principal for you.
This change to service principal-less authentication will make client service principal a requirement for all applications in order to improve our "Security by default" ([See authentication behaviors](/graph/api/resources/authenticationbehaviors?view=graph-re…
Learn about the activity captured in the service principal sign-in logs in Microsoft Entra monitoring and health.
The audience value must be set to one of the following values:<br/> • **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>• **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>• **Entra ID China operated by 21Vi…