Workload identities are the identities software uses: service principals for applications and managed identities for Azure resources. They often have powerful permissions, they don't do MFA, and nobody notices when they misbehave, which makes them attractive targets. Attackers who steal a client secret from a code repository can sign in as the app and use its permissions quietly.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.