Pro User
Zeitspanne
explore our new search
​
Microsoft Entra: Kill API Keys & Secrets
Microsoft Entra
5. Okt 2026 23:49

Microsoft Entra: Kill API Keys & Secrets

von HubSite 365 über Merill Fernando

Product Manager @ Microsoft 👉 Sign up to Entra.News my weekly newsletter on all things Microsoft Entra | Creator of cmd.ms & idPowerToys.com

Microsoft Entra explains ditching API keys and secrets via Azure managed identity workload federation and Entra Agent ID

Key insights

  • Problem: Long-lived API keys and client secrets leak, expire, or lose owners, and today coding agents can create credentials automatically.
    These unmanaged secrets increase risk and create hidden technical debt.
  • Microsoft’s approach: Move apps off secrets toward managed identity inside Azure and workload identity federation for other platforms, with Entra Agent ID fitting into that model.
    Microsoft recently made managed identities-as-federated-credentials generally available to enable secret-free access across tenants.
  • Why it matters: Secret-free identity reduces security exposure from leaks and replay, and cuts operational overhead from storing, rotating, and distributing credentials.
    Platform-issued identities remove much of manual credential handling.
  • Key building blocks: Managed identity gives workloads a platform-trusted identity; federated identity credential (FIC) accepts tokens from trusted providers; certificates provide stronger alternatives when secrets remain necessary.
    Use these to replace password-like client secrets whenever possible.
  • Developer guidance: Use managed identities whenever you can; otherwise prefer certificates over secrets and store them in Azure Key Vault.
    Audit, remove orphaned credentials, and limit credential lifetimes and scopes.
  • Agent and risk controls: Agent identities currently can still create or accept client secrets, so monitor automated agents and their keys.
    Enforce least privilege, logging, and regular audits to prevent agents from reintroducing long-lived secrets.

Overview

In a concise YouTube segment highlighted by Merill Fernando, Microsoft engineer Arturo Lucatero urges organizations to move away from long-lived client secrets and API keys in favor of platform-managed identity approaches. He argues that keys and secrets leak, expire, and often lack single ownership, which increases risk and operational load. Consequently, the segment frames a path forward that emphasizes secretless authentication options across cloud and multi-cloud environments. In short, Lucatero makes the case that modern workloads should minimize human handling of credentials whenever possible.


What Microsoft Is Recommending

Microsoft’s guidance, as summarized in the coverage, centers on using managed identities where possible and falling back to stronger alternatives such as certificates when secretless approaches are not feasible. Moreover, the recent change to make managed identities as federated credentials generally available extends secret-free access across tenant boundaries and to a broader set of workloads. As a result, teams can exchange platform-issued tokens for access tokens to resources like Microsoft Graph without storing secrets in application code or configuration. This shift reduces routine credential lifecycle tasks such as rotation and distribution.


Technical Landscape and Key Concepts

The video walks through several technical building blocks, including managed identity, federated identity credentials, and the role of certificates as a stronger fallback than password-like secrets. Additionally, Lucatero touches on a newer construct, Entra Agent ID, which aims to support agent-driven code scenarios. The discussion explains how a managed identity is validated by the platform, enabling workloads to avoid holding secrets locally and thereby improving security posture. Furthermore, when managed identities are not possible, relying on certificates and secure stores like key vaults remains preferable.


Emerging Challenge: Agents Bringing Secrets Back

Despite progress, the segment highlights a new threat vector: coding agents that create API keys and secrets on behalf of developers, effectively reintroducing the very risk Microsoft aims to eliminate. Lucatero shows how a misbehaving agent can fabricate a blueprint and generate a secret that gets hard to trace, which complicates governance. Therefore, even as organizations adopt zero-secret patterns, they must update tooling and policies to govern agent actions and artifact creation. Otherwise, automation can unintentionally return teams to a secrets-heavy model.


Tradeoffs and Practical Challenges

Transitioning to managed identities and federated credentials brings clear security benefits, yet it also introduces tradeoffs organizations must manage. For example, while managed identities reduce credential handling tasks, they require platform support and careful cross-tenant trust configuration, which can add architectural complexity. In addition, some legacy or third-party systems may not support federated flows, obliging teams to maintain mixed authentication environments and adopt robust controls for the remaining secrets. Consequently, teams will need to invest in governance, observability, and migration planning to realize the full benefits.


Recommendations for Developers and Operations

Lucatero and the blog coverage offer practical steps: prioritize platform-managed identities, prefer certificates over password-like secrets when secretless options are unavailable, and treat agent-generated artifacts as first-class governance concerns. Moreover, development teams should harden CI/CD pipelines and enforce approvals so that automated agents cannot provision long-lived credentials without oversight. Finally, operations teams must scale their auditing and revocation capabilities so that identity changes and agent activities are visible and manageable across tenants.


Why This Matters Now

Ultimately, the push to “kill API keys and secrets” reflects a broader industry move toward identity-first security and automation that reduces manual errors. While the guidance reduces two major risks—secret leakage and operational overhead—it also demands new skills, updated policies, and stronger observability in environments where automation plays a major role. Therefore, organizations that balance rapid adoption with thoughtful governance will gain security and operational efficiency, whereas those that adopt automation without checks risk reintroducing legacy vulnerabilities.


Looking Ahead

The video segment, as reported by Merill Fernando, frames a clear roadmap but not an instant fix: managed identities and federated credentials reduce the need for human-managed secrets, yet they must be paired with governance, tooling, and migration plans. Consequently, teams should approach the transition incrementally, validate compatibility with third-party systems, and update their security playbooks to include agent governance. In the end, the work to phase out secrets is both technical and organizational, and success will depend on aligning platform capabilities with disciplined practices.


Microsoft Entra - Microsoft Entra: Kill API Keys & Secrets

Keywords

Microsoft Entra, API keys, secrets management, secretless authentication, managed identities, certificate-based authentication, Azure Key Vault, token-based authentication