Free Microsoft Certified: Identity and Access Administrator Associate practice — 6 questions on Plan and implement workload identities, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Plan and implement workload identities
A DevOps team configures a federated credential on an app registration to allow a GitHub Actions workflow to authenticate to Azure without a client secret. Deployments to production must ONLY be triggered by a push to the 'main' branch — pull request builds and other branches must not be able to use this credential. Which subject identifier should be configured on the federated credential?
The subject claim 'repo:org/repo:ref:refs/heads/main' scopes the federated credential's trust to OIDC tokens issued specifically for pushes to the main branch, matching the requirement exactly.
Question 2 of 6 · Plan and implement workload identities
A company's security team mandates that no long-lived secrets exist in any CI/CD pipeline configuration. GitHub Actions workflows currently authenticate to Azure using a stored client secret that must be manually rotated every 90 days. Which change eliminates the stored secret while still allowing the workflow to authenticate?
Workload identity federation lets GitHub Actions exchange a short-lived OIDC token issued by GitHub for a Microsoft Entra access token, removing the need to store any secret or certificate in the pipeline at all.
Question 3 of 6 · Plan and implement workload identities
A Security Operations team wants Microsoft Entra ID Protection to automatically flag service principals whose credentials appear on the dark web (leaked credentials) and to detect service principals signing in with anomalous properties, then apply Conditional Access to block those risky sign-ins. Which license is specifically required to enable risk detection and Conditional Access for these non-human identities?
Microsoft Entra Workload ID Premium is the dedicated add-on license that enables Identity Protection risk detections (e.g., leaked credentials, unusual sign-in properties) and Conditional Access policies scoped specifically to workload identities such as service principals and managed identities.
Question 4 of 6 · Plan and implement workload identities
An organization needs a single managed identity to be assigned to 15 Azure VMs so they can all access the same Key Vault. VMs are frequently decommissioned and recreated, and the identity's Key Vault access policy must NOT be affected when individual VMs are deleted. Which identity type meets this requirement?
A user-assigned managed identity has a lifecycle independent of any single Azure resource. It is created once, can be assigned to multiple resources simultaneously, and continues to exist with its Key Vault access policy intact even if individual VMs are deleted.
Question 5 of 6 · Plan and implement workload identities
Contoso develops a multi-tenant SaaS application and registers it as an app registration in the Contoso Microsoft Entra tenant. An administrator at Fabrikam grants admin consent for the app to access Fabrikam's directory data. What object is created in Fabrikam's tenant as a result of this consent?
Consenting to a multi-tenant application creates a service principal (shown as an Enterprise Application) in the consuming tenant. This service principal represents the app locally, holds the tenant-specific consent grants and assigned permissions, and is what Fabrikam administrators manage.
Question 6 of 6 · Plan and implement workload identities
A tenant administrator discovers that any user in the organization can register new app registrations, creating governance gaps around ownership of workload identities. The administrator wants only a specific security-vetted group to be able to create new app registrations going forward. What is the default value of the relevant tenant setting, and what should the administrator do?
By default, Microsoft Entra ID allows all users to register applications ('Users can register applications' = Yes under User settings). Best practice for least privilege is to set this to 'No' and then explicitly assign the Application Developer role to the vetted users or group who need app registration rights.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.