
Protecting Against Workload Identity Risks in Entra ID
Workload identities, such as service principals and managed identities, are essential for enabling seamless application-to-application communication in Microsoft Entra ID. However, these identities are increasingly targeted by attackers due to their elevated privileges and lack of robust security controls.
This session will focus on the unique risks associated with workload identities, including their susceptibility to credential misuse and excessive permissions. We will also explore the parallels between securing workload identities and interactive user accounts, emphasizing the importance of applying consistent security measures across both.
Through practical demonstrations and actionable guidance, participants will discover how to:
- Implement Conditional Access policies tailored for workload identities.
- Enforce least privilege principles to limit the scope of access for service principals.
- Monitor and audit workload identity usage to detect suspicious activity.