Session

Your app has no MFA: securing managed identities and service principals in Azure

Your pipeline has no MFA. Your app cannot approve anything. For people you constrain who gets in, and you have plenty of tools to do it with. For a workload there is nobody to ask, so all you have left is what the identity is, what it can reach, how long its credential lives, and whether it needs a credential at all.

Let's walk through the options. Managed identity or federated credential. System-assigned or user-assigned. Contributor or Owner, and at what scope should that land? Least privilege sounds great, but it is not always the most practical answer, or even the most secure one, and I will show you where it falls apart.

This is a part of Azure access that is ignored far to often. You will leave with a decision tree and practical tips to improve. The more secure option might actually be easier to maintain

Barbara Forbes

Azure Architect @ Zure | Azure MVP | GitHub Star

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top