Plan and Implement Workload Identities

Plan and implement identities for applications and Azure workloads, integrate enterprise applications, manage app registrations, and monitor app access.

This domain focuses on managing identities for applications and Azure workloads. Candidates must select appropriate identities — managed identities, service principals, user accounts, and managed service accounts — and create, assign, and use managed identities to access Azure resources. The domain covers planning, implementing, and monitoring enterprise application integration including application-level and tenant-level settings, assigning Microsoft Entra roles for app management, designing integration for on-premises apps via Microsoft Entra Application Proxy, integrating SaaS apps, assigning users, groups, and app roles, configuring user and admin consent, and managing application collections. Candidates must also plan and implement app registrations including authentication configuration, API permissions, and app roles. Finally, it covers managing and monitoring app access using Microsoft Defender for Cloud Apps — cloud discovery, connected apps, application-enforced restrictions, Conditional Access app control, access and session policies, OAuth app policies, and the Cloud app catalog. (20–25% of exam)
5 minutes 5 Questions

Plan and Implement Workload Identities refers to the process of managing non-human identities in Microsoft Entra ID (formerly Azure AD) that are used by applications, services, and automated processes to access resources. **What Are Workload Identities?** Workload identities represent software wor…

Concepts covered: Service Principals and Application Identities, Managed Identities for Azure Resources, Enterprise Application Settings and Configuration, SaaS Application Integration, User and Admin Consent Configuration, App Registration and Authentication Configuration, Conditional Access App Control and Session Policies, Managed Identity Assignment and Resource Access, Microsoft Entra Roles for Application Management, On-Premises App Integration with Application Proxy, User, Group, and App Role Assignment, Application Collections Management, API Permissions and App Roles, Defender for Cloud Apps Configuration and Discovery, OAuth App Policies and Cloud App Catalog

Test mode:
More Plan and Implement Workload Identities questions
675 questions (total)