Continue your lesson
Trace the identity, credential, token, assignment, policy decision, resource, and audit record for each access request.
Block 1 of 4Compare System-assigned managed identity · User-assigned managed identity · Managed identity role assignment
Current · 15 min
Compare System-assigned managed identity · User-assigned managed identity · Managed identity role assignment
Optional concept notes
System-assigned managed identity
Creates an Azure workload identity whose lifecycle is tied to one resource.
User-assigned managed identity
Creates a reusable Azure workload identity with an independent lifecycle.
Managed identity role assignment
Grants an Azure role to a managed identity at the intended resource scope.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 2 of 4Compare Service principal · Workload identity federation
12 min
Compare Service principal · Workload identity federation
Optional concept notes
Service principal
Represents an application's identity and permissions inside a Microsoft Entra tenant.
Workload identity federation
Exchanges a trusted external token for Microsoft Entra access without storing a secret.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 3 of 4Understand Conditional Access for workload identities
10 min
Understand Conditional Access for workload identities
Optional concept notes
Conditional Access for workload identities
Applies supported access conditions to service-principal authentication.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 4 of 4Compare Application certificate credential · Application client secret
10 min
Compare Application certificate credential · Application client secret
Optional concept notes
Application certificate credential
Lets an application authenticate with an asymmetric certificate instead of a shared secret.
Application client secret
Provides a shared credential for an app and requires careful storage rotation and expiration.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Practice the reasoning here
Use a fictional tenant. Draw one access path, apply least privilege, test an exception, and name the logs that would confirm the result.
- State the expected result before changing or testing anything.
- Name the observation, command, log, or report that would confirm it.
- Explain why the closest alternative does not fit the same requirement.
Check the whole objective
This unlocks objective 3.1 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.