CI/CD runners and automation often authenticate with long-lived secrets. Workload Identity Federation replaces those secrets with short-lived OIDC tokens.

Preface

Automated workloads historically used service principals with client secrets or certificates that must be stored and rotated across external systems.

Problem

Static secrets are frequently leaked from repositories, config files, and unrotated environments. Compromise grants the full permissions of the service principal without MFA.

Solution

Align with NIST SP 800-204B:

  1. Implement federated credentials scoped to repository, environment, or subject.
  2. Exchange ephemeral OIDC tokens for short-lived Entra access tokens at runtime.
  3. Continuously audit which repositories and subjects are trusted.

PowerShell: Create a Federated Credential

Connect-MgGraph -Scopes "Application.ReadWrite.All"
$params = @{
    Name = "GitHubActionsFederatedCredential"
    Issuer = "https://token.actions.githubusercontent.com"
    Subject = "repo:enterprise/repo:ref:refs/heads/main"
    Description = "Federated trust for main branch deployments"
    Audiences = @("api://AzureADTokenExchange")
}
New-MgBetaApplicationFederatedCredential -ApplicationId "your-app-id" -BodyParameter $params