
Product Manager @ Microsoft 👉 Sign up to Entra.News my weekly newsletter on all things Microsoft Entra | Creator of cmd.ms & idPowerToys.com
In a concise YouTube segment highlighted by Merill Fernando, Microsoft engineer Arturo Lucatero urges organizations to move away from long-lived client secrets and API keys in favor of platform-managed identity approaches. He argues that keys and secrets leak, expire, and often lack single ownership, which increases risk and operational load. Consequently, the segment frames a path forward that emphasizes secretless authentication options across cloud and multi-cloud environments. In short, Lucatero makes the case that modern workloads should minimize human handling of credentials whenever possible.
Microsoft’s guidance, as summarized in the coverage, centers on using managed identities where possible and falling back to stronger alternatives such as certificates when secretless approaches are not feasible. Moreover, the recent change to make managed identities as federated credentials generally available extends secret-free access across tenant boundaries and to a broader set of workloads. As a result, teams can exchange platform-issued tokens for access tokens to resources like Microsoft Graph without storing secrets in application code or configuration. This shift reduces routine credential lifecycle tasks such as rotation and distribution.
The video walks through several technical building blocks, including managed identity, federated identity credentials, and the role of certificates as a stronger fallback than password-like secrets. Additionally, Lucatero touches on a newer construct, Entra Agent ID, which aims to support agent-driven code scenarios. The discussion explains how a managed identity is validated by the platform, enabling workloads to avoid holding secrets locally and thereby improving security posture. Furthermore, when managed identities are not possible, relying on certificates and secure stores like key vaults remains preferable.
Despite progress, the segment highlights a new threat vector: coding agents that create API keys and secrets on behalf of developers, effectively reintroducing the very risk Microsoft aims to eliminate. Lucatero shows how a misbehaving agent can fabricate a blueprint and generate a secret that gets hard to trace, which complicates governance. Therefore, even as organizations adopt zero-secret patterns, they must update tooling and policies to govern agent actions and artifact creation. Otherwise, automation can unintentionally return teams to a secrets-heavy model.
Transitioning to managed identities and federated credentials brings clear security benefits, yet it also introduces tradeoffs organizations must manage. For example, while managed identities reduce credential handling tasks, they require platform support and careful cross-tenant trust configuration, which can add architectural complexity. In addition, some legacy or third-party systems may not support federated flows, obliging teams to maintain mixed authentication environments and adopt robust controls for the remaining secrets. Consequently, teams will need to invest in governance, observability, and migration planning to realize the full benefits.
Lucatero and the blog coverage offer practical steps: prioritize platform-managed identities, prefer certificates over password-like secrets when secretless options are unavailable, and treat agent-generated artifacts as first-class governance concerns. Moreover, development teams should harden CI/CD pipelines and enforce approvals so that automated agents cannot provision long-lived credentials without oversight. Finally, operations teams must scale their auditing and revocation capabilities so that identity changes and agent activities are visible and manageable across tenants.
Ultimately, the push to “kill API keys and secrets” reflects a broader industry move toward identity-first security and automation that reduces manual errors. While the guidance reduces two major risks—secret leakage and operational overhead—it also demands new skills, updated policies, and stronger observability in environments where automation plays a major role. Therefore, organizations that balance rapid adoption with thoughtful governance will gain security and operational efficiency, whereas those that adopt automation without checks risk reintroducing legacy vulnerabilities.
The video segment, as reported by Merill Fernando, frames a clear roadmap but not an instant fix: managed identities and federated credentials reduce the need for human-managed secrets, yet they must be paired with governance, tooling, and migration plans. Consequently, teams should approach the transition incrementally, validate compatibility with third-party systems, and update their security playbooks to include agent governance. In the end, the work to phase out secrets is both technical and organizational, and success will depend on aligning platform capabilities with disciplined practices.
Microsoft Entra, API keys, secrets management, secretless authentication, managed identities, certificate-based authentication, Azure Key Vault, token-based authentication