Azure Active Directory Workload Identity Federation with external OIDC IdP

  Рет қаралды 3,463

Arsen Vladimirskiy

Arsen Vladimirskiy

Күн бұрын

In this video, we experiment with the Azure Active Directory Workload Identity Federation using external OpenID Connect identity provider (OIDC IdP) including our own fake JWT token, another AAD tenant, Auth0, and GCP. As of February 2022, AAD Workload Identity Federation is in "preview". We use Azure Portal to create "federatedIdentityCredential" for Azure AD application registration and use Postman to invoke various OAuth2 endpoints and discuss various error messages and responses.
/ azure-active-directory...
00:00 Introduction
02:05 Create AAD application
04:00 Fake JWT token
10:30 Another AAD tenant as IdP is not supported
13:55 Auth0 as IdP
20:18 GCP as IdP
25:28 List Azure Resource Groups via ARM API
27:00 Another fake JWT token

Пікірлер: 11
@mystiqkc
@mystiqkc Ай бұрын
Excellent video!
@tubebha
@tubebha 2 жыл бұрын
Thanks Arsen for such a wonderful explanation, especially the approach of step-by-step evolution of the concepts. I am really a big fan of approach that shows the error and then what those error means and then the right approach to solve that error scenario. A big thumbs-up and a big thanks to you.
@ArsenVlad
@ArsenVlad 2 жыл бұрын
Thank you Arvind!
@Philip-Fourie
@Philip-Fourie 9 ай бұрын
@Arsen, I totally agree with @tubebha. Thanks for making this video, I really enjoyed it.
@akashkarve1991
@akashkarve1991 Жыл бұрын
I really like this video. Simple explanation with demo of complex topic. Keep it up Arsen.
@ArsenVlad
@ArsenVlad Жыл бұрын
Thank you Aakash!
@sanppatil
@sanppatil Жыл бұрын
Wow, You simplified this stuff with so much clarity. Love this video.
@ArsenVlad
@ArsenVlad Жыл бұрын
Thank you Sandip! Glad you found it useful.
@user-kd4lr5oi9e
@user-kd4lr5oi9e Жыл бұрын
Hi, I liked your video. I have a question.. If I am using external Idp and my client(or client-id) is kubernetes.local (AKS cluster) , then how I can configure it? Thanks.
@gurusworld8226
@gurusworld8226 11 ай бұрын
Good one, you save my time, I was struggling to make a configuration. I can visualize how much effort you put into this. Thanks for sharing us. I am trying to authenticate external oauth token which is also hosted in Azure but in a different Tenant, could you help me to Authenticate that. I am getting below error. "AADSTS700222: AAD-issued tokens may not be used for federated identity flows.
@ArsenVlad
@ArsenVlad 11 ай бұрын
Thank you! Glad this was helpful for you. I mentioned about 10:30 min into the video that using another AAD tenant as the IdP is not currently supported.
Azure DevOps Workload Identity Federation with Azure Overview. NO MORE SECRETS!
21:56
John Savill's Technical Training
Рет қаралды 12 М.
Understanding Azure AD Conditional Access Workload Identities
19:48
John Craddock Identity and Access Training
Рет қаралды 1 М.
New model rc bird unboxing and testing
00:10
Ruhul Shorts
Рет қаралды 24 МЛН
Slow motion boy #shorts by Tsuriki Show
00:14
Tsuriki Show
Рет қаралды 8 МЛН
I Can't Believe We Did This...
00:38
Stokes Twins
Рет қаралды 133 МЛН
OIDC and Workload Identity in Kubernetes - Ashutosh Kumar, Elastic & Anish Ramasekar, Microsoft
35:25
CNCF [Cloud Native Computing Foundation]
Рет қаралды 1,7 М.
Azure AD App Registrations, Enterprise Apps and Service Principals
33:44
John Savill's Technical Training
Рет қаралды 214 М.
Workload Identity (OIDC) for AKS
15:18
Houssem Dellai
Рет қаралды 6 М.
Learn Microsoft Azure Active Directory in Just 30 Mins (May 2023)
38:05
Andy Malone MVP
Рет қаралды 126 М.
How to use Github Actions with Google's Workload Identity Federation
11:33
Managed Identities with Azure AD (Active Directory) Tutorial
31:54
Adam Marczak - Azure for Everyone
Рет қаралды 142 М.
Introducing Microsoft Entra Workload Identities | OD28
15:27
Microsoft Ignite
Рет қаралды 3,1 М.
Google Cloud Certified Security Engineer - Workload Identity Federation
13:40
Cloudy Security with a chance of an attack
Рет қаралды 263
Todos os modelos de smartphone
0:20
Spider Slack
Рет қаралды 60 МЛН
Как бесплатно замутить iphone 15 pro max
0:59
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 4,3 МЛН
АЙФОН 20 С ФУНКЦИЕЙ ВИДЕНИЯ ОГНЯ
0:59
КиноХост
Рет қаралды 1,1 МЛН
Худшие кожаные чехлы для iPhone
1:00
Rozetked
Рет қаралды 1,6 МЛН
Копия iPhone с WildBerries
1:00
Wylsacom
Рет қаралды 6 МЛН
Как распознать поддельный iPhone
0:44
PEREKUPILO
Рет қаралды 2,1 МЛН