CI/CD runners and automation often authenticate with long-lived secrets. Workload Identity Federation replaces those secrets with short-lived OIDC tokens.
Preface
Automated workloads historically used service principals with client secrets or certificates that must be stored and rotated across external systems.
Problem
Static secrets are frequently leaked from repositories, config files, and unrotated environments. Compromise grants the full permissions of the service principal without MFA.
Solution
Align with NIST SP 800-204B:
- Implement federated credentials scoped to repository, environment, or subject.
- Exchange ephemeral OIDC tokens for short-lived Entra access tokens at runtime.
- Continuously audit which repositories and subjects are trusted.
PowerShell: Create a Federated Credential
Connect-MgGraph -Scopes "Application.ReadWrite.All"
$params = @{
Name = "GitHubActionsFederatedCredential"
Issuer = "https://token.actions.githubusercontent.com"
Subject = "repo:enterprise/repo:ref:refs/heads/main"
Description = "Federated trust for main branch deployments"
Audiences = @("api://AzureADTokenExchange")
}
New-MgBetaApplicationFederatedCredential -ApplicationId "your-app-id" -BodyParameter $params