Lets AKS pods get Entra tokens with no stored secrets by federating their Kubernetes service account with a managed identity or app registration in Entra.
Also called workload identity.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Entra Workload ID in context, with comparison tables and the common traps.
Terms in this definition
- AKS
Short for Azure Kubernetes Service, a managed Kubernetes offering that gives full control of clusters and node pools. Scaling uses the cluster autoscaler and Horizontal Pod Autoscaler; user sign-in is not built in.
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
- Kubernetes Service
Gives a label-selected group of pods a stable DNS name or IP address. AKS offers four types: ClusterIP by default, plus NodePort, LoadBalancer and ExternalName.
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
- App registration
Object in Microsoft Entra ID describing an app's identity, the permissions it needs and which account types it supports; multi-tenant apps and OpenID Connect sign-in depend on it.