Skip to content

Commit e21b8ad

Browse files
authored
Merge pull request #88709 from ebasseri/patch-8
Update concept-workload-identity-risk.md
2 parents 5f0996b + 9f0f8f8 commit e21b8ad

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

articles/active-directory/identity-protection/concept-workload-identity-risk.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,8 @@ To make use of workload identity risk, including the new **Risky workload identi
4141
- Security operator
4242
- Security reader
4343

44+
Users assigned the Conditional Access administrator role can create policies that use risk as a condition.
45+
4446
## Workload identity risk detections
4547

4648
We detect risk on workload identities across sign-in behavior and offline indicators of compromise.
@@ -74,6 +76,10 @@ You can also query risky workload identities [using the Microsoft Graph API](/gr
7476

7577
Organizations can export data by configurating [diagnostic settings in Azure AD](howto-export-risk-data.md) to send risk data to a Log Analytics workspace, archive it to a storage account, stream it to an event hub, or send it to a SIEM solution.
7678

79+
## Enforce access controls with risk-based Conditional Access
80+
81+
Using [Conditional Access for workload identities](../conditional-access/workload-identity.md), you can block access for specific accounts you choose when Identity Protection marks them "at risk." Policy can be applied to single-tenant service principals that have been registered in your tenant. Third-party SaaS, multi-tenanted apps, and managed identities are out of scope.
82+
7783
## Investigate risky workload identities
7884

7985
Identity Protection provides organizations with two reports they can use to investigate workload identity risk. These reports are the risky workload identities, and risk detections for workload identities. All reports allow for downloading of events in .CSV format for further analysis outside of the Azure portal.

0 commit comments

Comments
 (0)