Lets an outside workload, GitHub Actions or Kubernetes for instance, obtain an Entra token in exchange for its own token, so no secret has to be stored.
Also called workload identity federation.
Read more: Microsoft Learn
In the Ultra Transcenders books
SC-500AI-300AI-200SC-300AZ-400ALZ
Each book explains Federated identity credential in context, with comparison tables and the common traps.
Terms in this definition
- Workload
Also called an experience: a Fabric toolset aimed at one job role, e.g. Data Factory, Data Engineering, Data Warehouse, Real-Time Intelligence or Power BI. Each keeps its data in OneLake.
- GitHub Actions
Event-driven workflow automation in GitHub, started by things like a push or pull request. Typical uses include deploying Bicep or CLI templates and launching Azure Machine Learning jobs with no manual step.
- Token
The unit of text an LLM works with, which may be a word, part of a word or punctuation. Billing, limits and context windows are all counted in these units.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
Related terms
- Microsoft Entra issuer
By default, newly created workload identity federation connections in Azure DevOps take tokens from https://login.microsoftonline.com/{tenant-id}. The previous issuer, https://vstoken.dev.azure.com, retires on 1 July 2027 for managed identities and single-tenant apps.
- OpenID Connect
Sits on top of OAuth 2.0 to handle user sign-in. It also underpins workload identity federation, through which GitHub Actions gets Azure tokens without keeping any secret.
- Personal access token
A token tied to a user that replaces a password when calling GitHub or Azure DevOps APIs, using Git, or reaching package feeds. Keep its scope tight and its lifetime short, and choose Microsoft Entra tokens, workload identity federation or GitHub Apps instead wherever you can.