Workload Identities Federated Credential Mutable Subjects
"audiences": ["api://AzureADTokenExchange"]
Daily.Entra.NewsTrack documentation and Message Center changes for Microsoft Entra Workload ID.
Microsoft Learn documentation ↗"audiences": ["api://AzureADTokenExchange"]
Replace `<application-object-id>` with the object ID of your app registration. Create one credential for each subject the workflow presents, such as a different branch or environment.
Learn how to migrate a Microsoft Entra federated identity credential for GitHub Actions from a mutable subject to GitHub's immutable subject format.
Learn how mutable OIDC subject claims expose Microsoft Entra federated identity credentials to subject recycling, and how immutable claims reduce the risk.
- GitHub Actions. First, configure a trust relationship between your [user-assigned managed identity](workload-identity-federation-create-trust-user-assigned-managed-identity.md) or [application](workload-identity-federation-create-trust.md) in Microsoft Entra ID and a GitHub repo in the [Microsoft Entra admin center](https://entra.microsoft.com) or using Microsoft Graph. Then [configure a GitHub Actions workflow](/azure/developer/github/connect-from-azure) to get an access token from Microsoft identity provider and access Azure resources.
Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.
Learn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.
Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.
Learn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.
- The Service Principal Names (SPNs) of the private apps you want to protect. You add these SPNs in the policy for Private Access Sensors that are installed on the DCs.
Learn how to configure an application to trust a managed identity in Microsoft Entra ID.
Configure app management policies in Microsoft Entra ID to set restrictions on how apps and service principals in your tenant can be configured. Secure your environment with step‑by‑step guidance.
Learn how to replace basic authentication with short-lived, federated OpenID Connect tokens for Microsoft Entra provisioning to SAP SuccessFactors.
Describes how to use Azure PowerShell to create a Microsoft Entra application and service principal, and grant it access to resources through role-based access control. It shows how to authenticate application with a certificate.
Reference table that maps application IDs to applications and their service principal usage from the sign-in logs.
Learn about Microsoft Entra Workload ID Flexible federated identity credentials and its capabilities.
Use new audit log properties to understand why a new service principal was added to your tenant.
A Microsoft Entra documentation page was updated: How to use managed identities for Azure resources on an Azure VM to acquire an access token .
A Microsoft Entra documentation page was updated: How to use managed identities for Azure resources on an Azure VM with Azure SDKs .
Get to know the client libraries that you can use to authenticate your apps using managed identities for Azure resources.
Create a new Microsoft Entra app and service principal to manage access to resources with role-based access control in Azure Resource Manager.
Learn how to troubleshoot service principal configuration alerts for Microsoft Entra Domain Services
Learn how to use the sensitive operations report workbook in Microsoft Entra ID to explore suspicious app and service principal activity.
Learn how to set up a Flexible Federated identity credential in the Azure portal or Microsoft Graph Explorer.
Learn how to access Azure Storage from a web app in Azure App Service using managed identities. Simplify security and avoid managing secrets.
In this tutorial, you learn how to access data in Microsoft Graph from a web app running in Azure App Service using managed identities.
Learn why a Microsoft Entra service principal was created in your tenant and who or what triggered the event through new properties that have been added audit log activity.
Step-by-step instructions for viewing the Azure resources that are associated with a user-assigned managed identity
Important considerations and restrictions for creating a federated identity credential on an app.
1. Under **Assignments**, select **Users or workload identities**.
2. **SAP Cloud Identity Service exchanges the JWT for an access token.** The signed JWT is presented to SAP Cloud Identity Service, which is trusted by SAP SuccessFactors. SAP Cloud Identity Service validates the JWT against the trust rules you configure in the SAP Cloud Identity Service admin console and returns a short-lived access token that can only be used to query the SAP SuccessFactors OData API.
Understand the concepts and supported scenarios for using workload identity in Microsoft Entra.
author: kenwith
Documentation for the Azure Policy that can be used to assign managed identities to Azure resources.
| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|
Microsoft Entra ID will enable App Instance Lock by default for new applications starting June 2026, protecting sensitive properties from unauthorized changes outside the home tenant. Existing apps are unaffected. Admins can disable the lock if needed. Review and update automation or scripts accordingly before rollout.
A workload identity is an identity that allows an application or service principal access to resources, sometimes in the context of a user. Conditional Access policies can be applied to single tenant service principals registered in your tenant. Non-Microsoft SaaS and multitenant apps are out of scope. Managed identities aren't covered by policy.
> In directories without appropriate licenses, existing Conditional Access policies for workload identities continue to function, but can't be modified. For more information, see [Microsoft Entra Workload ID](https://www.microsoft.com/security/business/identity-access/microsoft-entra-workload-identities#office-StandaloneSKU-k3hubfz).
- **Managed identities**: Configuring token lifetimes for [managed identity service principals](~/identity/managed-identities-azure-resources/overview.md) isn't supported.
- Which users, groups, directory roles, or workload identities are included in or excluded from the policy?
Some customers apply Conditional Access policies to user-based service accounts. You can reclaim the user-based license, and add a [workload identities](~/workload-id/workload-identities-overview.md) license to apply [Conditional Access for workload identities](~/identity/conditional-access/workload-identity.md).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
An app role assignment records when a user, group, or service principal is assigned an app role for an app. All properties of app role assignment are in scope. View all app role assignment details and properties in the [Microsoft Graph appRoleAssignment resource type](/graph/api/resources/approleassignment).
Learn how to enable continuous access evaluation for workload identities to enforce Conditional Access policies and instantly revoke tokens.
**For example**, GitHub Actions need a workload identity to access Azure subscriptions to automate, customize, and execute software development workflows.
- Using the Azure portal, give an Azure virtual machine scale set managed identity [access to another Azure resource](~/identity/managed-identities-azure-resources/grant-managed-identity-resource-access-azure-portal.md).
Step-by-step instructions for configuring managed identities for Azure resources on a virtual machine scale set using the Azure portal.
Step-by-step instructions for configuring system and user-assigned managed identities on an Azure VMs.
An overview how developers can use managed identities for Azure resources.
A tutorial that walks you through the process of using a system-assigned managed identity on a virtual machine (VM) to access Azure Resource Manager.
Learn how to use managed identities with Windows VMs using the Azure portal, CLI, PowerShell, Azure Resource Manager template
Step-by-step instructions and examples for using an Azure VM-managed identities for Azure resources service principal for script client sign-in and resource access.
Step-by-step instructions for viewing the Azure resources that are associated with a user-assigned managed identity
Step-by-step instructions for viewing the service principal of a managed identity.
| Azure Container Apps | [Managed identities in Azure Container Apps](/azure/container-apps/managed-identity) |
Learn how workload identify federation enables secure access to Microsoft Entra protected resources from external software workloads without managing secrets.
If administrators assign privileged roles to workload identities, such as service principals or managed identities, the tenant can be exposed to significant risk if those identities are compromised. Threat actors who gain access to a privileged workload identity can perform reconnaissance to enumerate resources, escalate privileges, and manipulate or exfiltrate sensitive data. The attack chain typically begins with credential theft or abuse of a vulnerable application. Next step is privilege escalation through the assigned role, lateral movement across cloud resources, and finally persistence via other role assignments or credential updates. Workload identities are often used in automation and might not be monitored as closely as user accounts. Compromise can then go undetected, allowing threat actors to maintain access and control over critical resources. Workload identities aren't subject to user-centric protections like MFA, making least-privilege assignment and regular review essential.
2. Now delete the old application and object using the following PowerShell cmdlets:
| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|
Creation of federated identity credentials is currently **not supported** on user-assigned managed identities created in the following regions:
A Microsoft Entra documentation page was updated: Managed Identity Libraries.
A Microsoft Entra documentation page was updated: Howto Create Service Principal Portal.
Learn about the mitigation steps tenant administrators should perform for the retirement of service principal-less authentication.
As part of increasing the security posture of Microsoft Entra Connect, Microsoft deployed a dedicated first-party application to enable the synchronization between Active Directory and Microsoft Entra ID. This new application will manifest as a first party service principal called the "Microsoft Entra AD Synchronization Service" (Application Id: `6bf85cfa-ac8a-4be5-b5de-425a0d0dc016`) and will be visible in the Enterprise Applications experience within the Microsoft Entra admin center. This application is critical for the continued operation of on-premises to Microsoft Entra ID synchronization functionality through Entra Connect.
Learn how to include or exclude users, groups, and workload identities in Conditional Access policies for secure and flexible access management.
A Microsoft Entra documentation page was updated: Assign App Role Managed Identity.
- If you're unfamiliar with managed identities for Azure resources, see [Managed identity for Azure resources overview](./overview.md).
- If you're unfamiliar with managed identities for Azure resources, see [Managed identity for Azure resources overview](./overview.md).
The steps outlined below show how you grant access to a service using Azure RBAC. Check specific service documentation on how to grant access; for example, check [Azure Data Explorer](/azure/data-explorer/data-explorer-overview) for instructions. Some Azure services are in the process of adopting Azure RBAC on the data plane.
A Microsoft Entra documentation page was updated: How Manage User Assigned Managed Identities.
Deleting a user-assigned managed identity won't remove the reference from any resource it was assigned to. Remove those from the resource itself. For example, for a VM or virtual machine scale set, use the `az vm/vmss identity remove` command.
Step-by-step instructions on using PowerShell to assign a managed identity access to an Azure resource or another resource.
1. Copy user-assigned managed identity assigned permissions. You can list [Azure role assignments](/azure/role-based-access-control/role-assignments-list-powershell) but that may not be enough depending on how permissions were granted to the user-assigned managed identity. You should confirm that your solution doesn't depend on permissions granted using a service specific option.
At a high level, there are two types of identities: human and machine/non-human identities. Machine / non-human identities consist of device and workload identities. In Microsoft Entra, workload identities are applications, service principals, and managed identities.
Create a new Microsoft Entra app and service principal to manage access to resources with role-based access control in Azure Resource Manager.
Learn how to access Azure Storage from a web app in Azure App Service using managed identities. Simplify security and avoid managing secrets.
In this tutorial, you learn how to access data in Microsoft Graph from a web app running in Azure App Service using managed identities.
You can find the list of resources that have a system-assigned managed identity by using the following Azure CLI Command:
Configure Conditional Access user assignments in Microsoft Entra ID. Target specific users, groups, directory roles, and workload identities while avoiding administrator lockout with proper exclusions.
Learn how to configure isolation scope for user-assigned managed identities to improve security and resilience.
- Read the [Isolation scope for user-assigned managed identities](managed-identities-isolation-scope.md) concept article to understand the benefits and implications.
A Microsoft Entra documentation page was updated: Enable Managed Identities Regional Isolation.
Learn about isolation scope for user-assigned managed identities and how it improves security and resilience.
Microsoft Entra ID will block authentication for all non-Microsoft multitenant applications that don't have a service principal in the tenant where they're authenticating. This scenario is also known as service principal-less authentication. This behavior has already been disabled for most non-Microsoft applications. This change addresses a few remaining exceptions and is a preventive security measure.
Describes how to use Azure PowerShell to create a Microsoft Entra application and service principal, and grant it access to resources through role-based access control. It shows how to authenticate application with a certificate.
Learn how to access Azure Storage from a web app in Azure App Service using managed identities. Simplify security and avoid managing secrets.
In this tutorial, you learn how to access data in Microsoft Graph from a web app running in Azure App Service using managed identities.
The audience value must be set to one of the following values:<br/> • **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>• **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>• **Entra ID China operated by 21Vianet**: *api://AzureADTokenExchangeChina* <br/>
- *issuer*, *subject* are the key pieces of information needed to set up the trust relationship. When the Azure workload requests Microsoft identity platform to exchange the managed identity token for an Entra app access token, the *issuer* and *subject* values of the federated identity credential are checked against the `issuer` and `subject` claims provided in the Managed Identity token. If that validation check passes, Microsoft identity platform issues an access token to the external software workload.
Learn how the Microsoft Entra recommendation to renew expiring service principal credentials work and why it's important.
Reference table that maps application IDs to applications and their service principal usage from the sign-in logs.
Learn how to use the sensitive operations report workbook in Microsoft Entra ID to explore suspicious app and service principal activity.
Jason starts his assessment and signs in to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) or the Microsoft Entra admin center. In order to view application and service principal details, he signs in as at least a [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader) and needs an [Microsoft Entra role assignment](../identity/role-based-access-control/permissions-reference.md) of Application Administrator, Cloud Application Administrator, or similar Microsoft Entra administrator role that has permissions to manage application/workload identities in Microsoft Entra.
Users with this role can assign and remove custom security attribute keys and values for supported Microsoft Entra objects such as users, service principals, and devices.
author: barclayn
Learn about the type of information captured in the managed identity sign-in logs in Microsoft Entra monitoring and health.
This is a [privileged role](../privileged-roles-permissions.md). Users in this role can read and update basic information of users, groups, and service principals.
In addition to human and device identities, workload identities such as applications, services, and containers require authentication and authorization policies.
- A service principal of a special type is created in Microsoft Entra ID for the identity. The service principal is tied to the lifecycle of that Azure resource. When the Azure resource is deleted, Azure automatically deletes the service principal for you.
This change to service principal-less authentication will make client service principal a requirement for all applications in order to improve our "Security by default" ([See authentication behaviors](/graph/api/resources/authenticationbehaviors?view=graph-rest-beta&preserve-view=true)). Service principal-less authentication can be abused if the resource applications (i.e. APIs) perform incomplete validations. Microsoft has verified that validations aren't vulnerable to service principal-less authentication. However, with this action, the risk of this gap reappearing in future versions or being exploited in third-party resources outside Microsoft’s control is minimized.
Learn about the activity captured in the service principal sign-in logs in Microsoft Entra monitoring and health.