← cd ~/learn
// learning path · intermediate to advanced
Automating Entra and Azure safely
Scripts and pipelines without stored secrets, and the queries to keep an eye on them.
0 of 5 read · about 10 minutes in total
- 01Managed identities vs service principals: which should your workload use?Both let code authenticate to Azure and Microsoft Graph. One needs you to manage secrets; the other doesn't. A simple guide to choosing.2 min✓ read
- 02Unattended Graph PowerShell scripts with certificate authenticationScheduled scripts can't answer an MFA prompt. App-only authentication with a certificate is the right way to run Microsoft Graph PowerShell unattended.2 min✓ read
- 03Deploy from GitHub Actions to Azure without storing a single secretWorkload identity federation lets GitHub Actions sign in to Azure with short-lived tokens instead of a stored client secret. Here's the full setup.2 min✓ read
- 04Find expiring app secrets and certificates before they biteExpired client secrets cause some of the most avoidable outages in Entra. A short Graph script shows what's about to expire across the tenant.2 min✓ read
- 05Six KQL queries for Entra sign-in logs every admin should keepOnce sign-in logs flow into Log Analytics, a few queries answer most of the questions you'll get. Copy these into a workbook or saved searches.2 min✓ read
Progress is saved in this browser only. A post counts as read once you've scrolled most of the way through it.