Product

Microsoft Entra Workload ID

Track documentation and Message Center changes for Microsoft Entra Workload ID.

Microsoft Learn documentation ↗

Latest Microsoft Entra Workload ID changes

Workload Identities Github Immutable Subjects

Microsoft identity platform

Replace `<application-object-id>` with the object ID of your app registration. Create one credential for each subject the workflow presents, such as a different branch or environment.

Workload Identity Federation

Developer

- GitHub Actions. First, configure a trust relationship between your [user-assigned managed identity](workload-identity-federation-create-trust-user-assigned-managed-identity.md) or [application](workload-identity-federation-create-trust.md) in Microsoft Entr…

Configure Domain Controllers

Security

- The Service Principal Names (SPNs) of the private apps you want to protect. You add these SPNs in the policy for Private Access Sensors that are installed on the DCs.

Create an Azure app identity (PowerShell)

Authentication

Describes how to use Azure PowerShell to create a Microsoft Entra application and service principal, and grant it access to resources through role-based access control. It shows how to authenticate application with a certificate.

Managed Identity Libraries

Authentication

Get to know the client libraries that you can use to authenticate your apps using managed identities for Azure resources.

Overview

Fundamentals

An overview of the managed identities for Azure resources.

Sensitive operations report workbook

Monitoring

Learn how to use the sensitive operations report workbook in Microsoft Entra ID to explore suspicious app and service principal activity.

Configure Workload Identity Sap Successfactors Provisioning

Provisioning

2. **SAP Cloud Identity Service exchanges the JWT for an access token.** The signed JWT is presented to SAP Cloud Identity Service, which is trusted by SAP SuccessFactors. SAP Cloud Identity Service validates the JWT against the trust rules you configure in t…

Workload identities

Fundamentals

Understand the concepts and supported scenarios for using workload identity in Microsoft Entra.

Managed Identities Status

General

| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|

Conditional Access Users Groups

Fundamentals

A workload identity is an identity that allows an application or service principal access to resources, sometimes in the context of a user. Conditional Access policies can be applied to single tenant service principals registered in your tenant. Non-Microsoft…

Workload Identity

Conditional Access

> In directories without appropriate licenses, existing Conditional Access policies for workload identities continue to function, but can't be modified. For more information, see [Microsoft Entra Workload ID](https://www.microsoft.com/security/business/identi…

Configurable Token Lifetimes

Fundamentals

- **Managed identities**: Configuring token lifetimes for [managed identity service principals](~/identity/managed-identities-azure-resources/overview.md) isn't supported.

Plan Conditional Access

Conditional Access

- Which users, groups, directory roles, or workload identities are included in or excluded from the policy?

Mandatory Multifactor Authentication

Fundamentals

Some customers apply Conditional Access policies to user-based service accounts. You can reclaim the user-based license, and add a [workload identities](~/workload-id/workload-identities-overview.md) license to apply [Conditional Access for workload identitie…

Workload Identity

Conditional Access

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Scope Supported Objects Limitations

General

An app role assignment records when a user, group, or service principal is assigned an app role for an app. All properties of app role assignment are in scope. View all app role assignment details and properties in the [Microsoft Graph appRoleAssignment resou…

What Is Entra

Fundamentals

**For example**, GitHub Actions need a workload identity to access Azure subscriptions to automate, customize, and execute software development workflows.

Qs Configure Portal Windows Vmss

General

- Using the Azure portal, give an Azure virtual machine scale set managed identity [access to another Azure resource](~/identity/managed-identities-azure-resources/grant-managed-identity-resource-access-azure-portal.md).

Managed Identities Status

General

| Azure Container Apps | [Managed identities in Azure Container Apps](/azure/container-apps/managed-identity) |

Workload Identity Federation

Security

Learn how workload identify federation enables secure access to Microsoft Entra protected resources from external software workloads without managing secrets.

21836

Security

If administrators assign privileged roles to workload identities, such as service principals or managed identities, the tenant can be exposed to significant risk if those identities are compromised. Threat actors who gain access to a privileged workload ident…

Alert Service Principal

Developer

2. Now delete the old application and object using the following PowerShell cmdlets:

Managed Identities Status

General

| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|

Grant Managed Identity Resource Access Azure Portal

Fundamentals

The steps outlined below show how you grant access to a service using Azure RBAC. Check specific service documentation on how to grant access; for example, check [Azure Data Explorer](/azure/data-explorer/data-explorer-overview) for instructions. Some Azure s…

Manage User Assigned Managed Identities Azure Cli

General

Deleting a user-assigned managed identity won't remove the reference from any resource it was assigned to. Remove those from the resource itself. For example, for a VM or virtual machine scale set, use the `az vm/vmss identity remove` command.

Managed Identity Regional Move

General

1. Copy user-assigned managed identity assigned permissions. You can list [Azure role assignments](/azure/role-based-access-control/role-assignments-list-powershell) but that may not be enough depending on how permissions were granted to the user-assigned man…

Overview

Fundamentals

At a high level, there are two types of identities: human and machine/non-human identities. Machine / non-human identities consist of device and workload identities. In Microsoft Entra, workload identities are applications, service principals, and managed ide…

Managed Identities Faq

General

You can find the list of resources that have a system-assigned managed identity by using the following Azure CLI Command:

Configure Managed Identities Isolation Scope

Fundamentals

- Read the [Isolation scope for user-assigned managed identities](managed-identities-isolation-scope.md) concept article to understand the benefits and implications.

Retire Service Principal Less Authentication

Authentication

Microsoft Entra ID will block authentication for all non-Microsoft multitenant applications that don't have a service principal in the tenant where they're authenticating. This scenario is also known as service principal-less authentication. This behavior has…

Create an Azure app identity (PowerShell)

Authentication

Describes how to use Azure PowerShell to create a Microsoft Entra application and service principal, and grant it access to resources through role-based access control. It shows how to authenticate application with a certificate.

Workload Identity Federation Config App Trust Managed Identity

Developer

The audience value must be set to one of the following values:<br/> &#8226; **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>&#8226; **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>&#8226; **Entra ID China operated by 21Vi…

Workload Identity Federation Config App Trust Managed Identity

Microsoft identity platform

- *issuer*, *subject* are the key pieces of information needed to set up the trust relationship. When the Azure workload requests Microsoft identity platform to exchange the managed identity token for an Entra app access token, the *issuer* and *subject* valu…

Service Principal Table

Authentication

Reference table that maps application IDs to applications and their service principal usage from the sign-in logs.

Workbook Sensitive Operations Report

Monitoring

Learn how to use the sensitive operations report workbook in Microsoft Entra ID to explore suspicious app and service principal activity.

Copilot Security Entra Investigate Risky Apps

Fundamentals

Jason starts his assessment and signs in to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) or the Microsoft Entra admin center. In order to view application and service principal details, he signs in as at least a [Security Reader](/entr…

Attribute Assignment Administrator

Security

Users with this role can assign and remove custom security attribute keys and values for supported Microsoft Entra objects such as users, service principals, and devices.

Managed identity sign-in logs

Fundamentals

Learn about the type of information captured in the managed identity sign-in logs in Microsoft Entra monitoring and health.

Directory Writers

General

This is a [privileged role](../privileged-roles-permissions.md). Users in this role can read and update basic information of users, groups, and service principals.

Overview

Fundamentals

- A service principal of a special type is created in Microsoft Entra ID for the identity. The service principal is tied to the lifecycle of that Azure resource. When the Azure resource is deleted, Azure automatically deletes the service principal for you.

Retire Service Principal Less Authentication

Authentication

This change to service principal-less authentication will make client service principal a requirement for all applications in order to improve our "Security by default" ([See authentication behaviors](/graph/api/resources/authenticationbehaviors?view=graph-re…

Service principal sign-in logs

Fundamentals

Learn about the activity captured in the service principal sign-in logs in Microsoft Entra monitoring and health.

Workload Identity Federation Config App Trust Managed Identity

Developer

The audience value must be set to one of the following values:<br/> &#8226; **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>&#8226; **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>&#8226; **Entra ID China operated by 21Vi…