Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MT.1005 All CA policies exclude break glass but Workload Identities #491

Open
alexmags opened this issue Oct 8, 2024 · 1 comment
Open

Comments

@alexmags
Copy link

alexmags commented Oct 8, 2024

Some CA policies apply to Workload Identities instead of users. In this mode you can't add break glass. This test should ignore CA policies that apply to Workload Identities.

Background:
App access to EntraID and Office365 uses App registrations often with long lived secrets (passwords) instead of safe MFA.

With additional licence, CA policy can apply to workload identities to apply IP filtrering/network Location control. This reduces risk of compromised creds for app registration being abused from elsewhere on internet.

@BenPennellAviva
Copy link

Also facing this issue

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants