Skip to content

Commit 7a6fc3b

Browse files
authored
Merge pull request #230843 from MicrosoftDocs/release-workload-identities
Release workload identities--scheduled release ASAP
2 parents d348de5 + 2aaf46b commit 7a6fc3b

30 files changed

+314
-119
lines changed

.openpublishing.redirection.active-directory.json

Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -160,6 +160,46 @@
160160
"redirect_url": "/azure/active-directory/develop/workload-identity-federation-create-trust",
161161
"redirect_document_id": false
162162
},
163+
{
164+
"source_path_from_root": "/articles/active-directory/develop/workload-identities-overview.md",
165+
"redirect_url": "/azure/active-directory/workload-identities/workload-identities-overview",
166+
"redirect_document_id": false
167+
},
168+
{
169+
"source_path_from_root": "/articles/active-directory/develop/workload-identities-faqs.md",
170+
"redirect_url": "/azure/active-directory/workload-identities/workload-identities-faqs",
171+
"redirect_document_id": false
172+
},
173+
{
174+
"source_path_from_root": "/articles/active-directory/develop/workload-identity-federation.md",
175+
"redirect_url": "/azure/active-directory/workload-identities/workload-identity-federation",
176+
"redirect_document_id": false
177+
},
178+
{
179+
"source_path_from_root": "/articles/active-directory/develop/workload-identity-federation-create-trust.md",
180+
"redirect_url": "/azure/active-directory/workload-identities/workload-identity-federation-create-trust",
181+
"redirect_document_id": false
182+
},
183+
{
184+
"source_path_from_root": "/articles/active-directory/develop/workload-identity-federation-create-trust-user-assigned-managed-identity.md",
185+
"redirect_url": "/azure/active-directory/workload-identities/workload-identity-federation-create-trust-user-assigned-managed-identity",
186+
"redirect_document_id": false
187+
},
188+
{
189+
"source_path_from_root": "/articles/active-directory/develop/workload-identity-federation-create-trust-gcp.md",
190+
"redirect_url": "/azure/active-directory/workload-identities/workload-identity-federation-create-trust-gcp",
191+
"redirect_document_id": false
192+
},
193+
{
194+
"source_path_from_root": "/articles/active-directory/develop/workload-identity-federation-block-using-azure-policy.md",
195+
"redirect_url": "/azure/active-directory/workload-identities/workload-identity-federation-block-using-azure-policy",
196+
"redirect_document_id": false
197+
},
198+
{
199+
"source_path_from_root": "/articles/active-directory/develop/workload-identity-federation-considerations.md",
200+
"redirect_url": "/azure/active-directory/workload-identities/workload-identity-federation-considerations",
201+
"redirect_document_id": false
202+
},
163203
{
164204
"source_path_from_root": "/articles/active-directory/develop/active-directory-v2-limitations.md",
165205
"redirect_url": "/azure/active-directory/develop/v2-overview",

articles/active-directory/conditional-access/concept-continuous-access-evaluation-workload.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Respond to changes to applications with continuous access evaluatio
44

55
services: active-directory
66
ms.service: active-directory
7-
ms.subservice: conditional-access
7+
ms.subservice: workload-identities
88
ms.topic: conceptual
99
ms.date: 07/22/2022
1010

articles/active-directory/conditional-access/workload-identity.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Protecting workload identities with Conditional Access policies
44

55
services: active-directory
66
ms.service: active-directory
7-
ms.subservice: conditional-access
7+
ms.subservice: workload-identities
88
ms.topic: how-to
99
ms.date: 01/05/2023
1010

@@ -19,7 +19,7 @@ ms.collection: M365-identity-device-management
1919

2020
Conditional Access policies have historically applied only to users when they access apps and services like SharePoint online or the Azure portal. We're now extending support for Conditional Access policies to be applied to service principals owned by the organization. We call this capability Conditional Access for workload identities.
2121

22-
A [workload identity](../develop/workload-identities-overview.md) is an identity that allows an application or service principal access to resources, sometimes in the context of a user. These workload identities differ from traditional user accounts as they:
22+
A [workload identity](../workload-identities/workload-identities-overview.md) is an identity that allows an application or service principal access to resources, sometimes in the context of a user. These workload identities differ from traditional user accounts as they:
2323

2424
- Can’t perform multifactor authentication.
2525
- Often have no formal lifecycle process.

articles/active-directory/develop/TOC.yml

Lines changed: 2 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -62,9 +62,7 @@
6262
- name: Application model
6363
href: application-model.md
6464
- name: Workload identities
65-
href: workload-identities-overview.md
66-
- name: Workload identities FAQs
67-
href: workload-identities-faqs.md
65+
href: ../workload-identities/workload-identities-overview.md
6866
- name: Applications and service principals
6967
href: app-objects-and-service-principals.md
7068
- name: How and why apps are added to Azure AD
@@ -162,16 +160,6 @@
162160
href: howto-handle-samesite-cookie-changes-chrome-browser.md
163161
- name: Connect
164162
items:
165-
- name: Workload identity federation
166-
href: workload-identity-federation.md
167-
- name: Configure an app to trust an external identity provider
168-
href: workload-identity-federation-create-trust.md
169-
- name: Configure a managed identity to trust an external identity provider
170-
href: workload-identity-federation-create-trust-user-assigned-managed-identity.md
171-
- name: Access identity platform-protected resources from GCP
172-
href: workload-identity-federation-create-trust-gcp.md
173-
- name: Block creation of federated credentials
174-
href: workload-identity-federation-block-using-azure-policy.md
175163
- name: Exchange AD FS SAML for Microsoft Graph access token
176164
displayName: exchange, swap, SAML token, OAuth token
177165
href: v2-saml-bearer-assertion.md
@@ -804,9 +792,7 @@
804792
- name: Signing key rollover
805793
href: active-directory-signing-key-rollover.md
806794
- name: UserInfo endpoint (OIDC)
807-
href: userinfo.md
808-
- name: Federated identity credentials considerations and limitations
809-
href: workload-identity-federation-considerations.md
795+
href: userinfo.md
810796
- name: SAML 2.0
811797
items:
812798
- name: How Azure AD uses the SAML protocol

articles/active-directory/develop/workload-identities-overview.md

Lines changed: 0 additions & 56 deletions
This file was deleted.

articles/active-directory/identity-protection/concept-workload-identity-risk.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Workload identity risk in Azure Active Directory Identity Protectio
44

55
services: active-directory
66
ms.service: active-directory
7-
ms.subservice: identity-protection
7+
ms.subservice: workload-identities
88
ms.topic: conceptual
99
ms.date: 11/10/2022
1010

@@ -16,7 +16,7 @@ ms.reviewer: etbasser
1616
ms.collection: M365-identity-device-management
1717
---
1818

19-
# Securing workload identities with Identity Protection
19+
# Securing workload identities
2020

2121
Azure AD Identity Protection has historically protected users in detecting, investigating, and remediating identity-based risks. We're now extending these capabilities to workload identities to protect applications and service principals.
2222

Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
- name: Microsoft Entra Workload Identities documentation
2+
href: index.yml
3+
- name: Overview
4+
expanded: true
5+
items:
6+
- name: What are workload identities?
7+
href: workload-identities-overview.md
8+
- name: Workload identities FAQs
9+
href: workload-identities-faqs.md
10+
- name: Concepts
11+
items:
12+
- name: Applications and service principals
13+
href: ../develop/app-objects-and-service-principals.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json
14+
- name: Managed identities
15+
href: ../managed-identities-azure-resources/overview.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json
16+
- name: Workload identity federation
17+
href: workload-identity-federation.md
18+
- name: Securing workload identities
19+
href: ../identity-protection/concept-workload-identity-risk.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json
20+
- name: Conditional Access for workload identities
21+
href: ../conditional-access/workload-identity.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json
22+
- name: Conditional access evaluation for workload identities
23+
href: ../conditional-access/concept-continuous-access-evaluation-workload.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json
24+
- name: How-to guides
25+
items:
26+
- name: Connect workloads without managing secrets
27+
items:
28+
- name: Configure an app to trust an external identity provider
29+
href: workload-identity-federation-create-trust.md
30+
- name: Configure a managed identity to trust an external identity provider
31+
href: workload-identity-federation-create-trust-user-assigned-managed-identity.md
32+
- name: Access identity platform-protected resources from GCP
33+
href: workload-identity-federation-create-trust-gcp.md
34+
- name: Block creation of federated credentials
35+
href: workload-identity-federation-block-using-azure-policy.md
36+
- name: Create an access review
37+
href: ../privileged-identity-management/pim-create-azure-ad-roles-and-resource-roles-review.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json
38+
- name: Manage custom security attributes for an app
39+
href: ../manage-apps/custom-security-attributes-apps.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json
40+
- name: Reference
41+
items:
42+
- name: Federated identity credentials considerations and limitations
43+
href: workload-identity-federation-considerations.md
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
- name: Azure
2+
tocHref: /azure/
3+
topicHref: /azure/index
4+
items:
5+
- name: Active Directory
6+
tocHref: /azure/active-directory/
7+
topicHref: /azure/active-directory/index
8+
- name: Active Directory
9+
tocHref: /azure/active-directory/develop/
10+
topicHref: /azure/active-directory/index
11+
- name: Active Directory
12+
tocHref: /azure/active-directory/managed-identities-azure-resources/
13+
topicHref: /azure/active-directory/index
14+
- name: Active Directory
15+
tocHref: /azure/active-directory/identity-protection/
16+
topicHref: /azure/active-directory/index
17+
- name: Active Directory
18+
tocHref: /azure/active-directory/conditional-access/
19+
topicHref: /azure/active-directory/index
20+
- name: Active Directory
21+
tocHref: /azure/active-directory/privileged-identity-management/
22+
topicHref: /azure/active-directory/index
23+
- name: Active Directory
24+
tocHref: /azure/active-directory/manage-apps/
25+
topicHref: /azure/active-directory/index
Lines changed: 82 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,82 @@
1+
### YamlMime:Landing
2+
3+
title: Microsoft Entra Workload Identities documentation
4+
summary: Microsoft Entra Workload Identities helps you manage and secure identities for digital workloads, such as apps and services.
5+
6+
metadata:
7+
author: rwike77
8+
description: "Learn how to manage and help secure identities for digital workloads, such as apps and services."
9+
manager: celested
10+
ms.author: ryanwi
11+
ms.date: 03/02/2023
12+
ms.service: active-directory
13+
ms.subservice: workload-identities
14+
ms.topic: landing-page
15+
services: active-directory
16+
17+
# linkListType: architecture | concept | deploy | download | get-started | how-to-guide | learn | overview | quickstart | reference | tutorial | video | whats-new
18+
19+
landingContent:
20+
# Card
21+
- title: About workload identities
22+
linkLists:
23+
- linkListType: overview
24+
links:
25+
- text: What are workload identities?
26+
url: workload-identities-overview.md
27+
- text: Frequently asked questions about license plans
28+
url: workload-identities-faqs.md
29+
# Card
30+
- title: Secure risky workload identities
31+
linkLists:
32+
- linkListType: overview
33+
links:
34+
- text: Secure workload identities
35+
url: ../identity-protection/concept-workload-identity-risk.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json
36+
# Card
37+
- title: Connect workloads without managing secrets
38+
linkLists:
39+
- linkListType: overview
40+
links:
41+
- text: What is workload identity federation?
42+
url: workload-identity-federation.md
43+
- linkListType: video
44+
links:
45+
- text: Learn why you would use workload identity federation
46+
url: https://www.microsoft.com/en-us/videoplayer/embed/RWXamJ
47+
- linkListType: how-to-guide
48+
links:
49+
- text: Configure an app to trust an external identity provider
50+
url: workload-identity-federation-create-trust.md
51+
- text: Configure a managed identity to trust an external identity provider
52+
url: workload-identity-federation-create-trust-user-assigned-managed-identity.md
53+
# Card
54+
- title: Apply Conditional Access policies to service principals
55+
linkLists:
56+
- linkListType: how-to-guide
57+
links:
58+
- text: Conditional Access for workload identities
59+
url: ../conditional-access/workload-identity.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json
60+
# Card
61+
- title: Enable real-time enforcement of Conditional Access location and risk policies
62+
linkLists:
63+
- linkListType: how-to-guide
64+
links:
65+
- text: Continuous access evaluation for workload identities
66+
url: ../conditional-access/concept-continuous-access-evaluation-workload.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json
67+
# Card
68+
- title: Contain threats and reduce risk to workload identities
69+
linkLists:
70+
- linkListType: how-to-guide
71+
links:
72+
- text: Identity Protection
73+
url: ../identity-protection/concept-workload-identity-risk.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json
74+
# Card
75+
- title: Review service principals and applications privileged directory roles
76+
linkLists:
77+
- linkListType: how-to-guide
78+
links:
79+
- text: Access reviews for service principals
80+
url: ../privileged-identity-management/pim-create-azure-ad-roles-and-resource-roles-review.md?toc=/azure/active-directory/workload-identities/toc.json&bc=/azure/active-directory/workload-identities/breadcrumb/toc.json)
81+
82+

0 commit comments

Comments
 (0)