Azure Conditional Access + Risky Workload Identity (Premium Licenses)

Derek Gorman 0 Reputation points
2023-02-17T11:22:31.4666667+00:00

Hoping someone might have some further insight on Workload Identity Premium Licenses and Conditional Access Policies + Identity Protection Risk detections.

1.Have signed up & enabled Workload identity premium Trial

2.Created a "Review Only" Block High Risk Policy scoped at all service principals

  1. Risky SP logs are being sent to log analytics workspace.

4.Looking at insights & reporting Workbook - it has detected a "High Risk" Sp and action "reportonlyfailure" for this app.

Issue is that nothing is being reported in identity protection under "Risky Workload identities" or Risk detections which means we cannot click on any detection to get further insight /additional details .

Am I missing something here - Do the Workload identity premium Licences have to be assigned to an app and if so how can they be assigned to an app.?

Thanking you all in advance :)

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,701 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.