entra-workload-identity
Microsoft Entra Workload Identity
Workload identities are the non-human identities that apps, services, scripts, and pipelines use to access Microsoft Entra-protected resources. They are the #1 source of cloud breach in recent post-incident reports — usually because of leaked client secrets, over-privileged service principals, or unmanaged certificate expiry.
This skill covers picking the right identity type, eliminating secrets via federation, hardening service principals, and applying Workload Identities Premium controls.
When to use
Designing how an Azure resource, GitHub Action, Azure DevOps pipeline, AKS pod, or external workload authenticates to Entra-protected APIs (Azure Resource Manager, Microsoft Graph, Key Vault, Storage, etc.).
Do not use this skill for human identity (entra-id), multi-cloud entitlement
analysis (entra-permissions-management), or AI agent identity governance specifically
(agent-identity-governance).