AZ-500 CHƯƠNG 04 4 Labs App Identity

Enterprise Apps, App Registration & Managed Identity

Bảo mật ứng dụng trong Entra ID: App Registration, OAuth permission grants, admin consent và Managed Identity — loại bỏ credential tĩnh trong ứng dụng Azure.

🎯 Mục tiêu chương

  • Quản lý Enterprise Applications và service principal.
  • Tạo và bảo mật App Registration.
  • Hiểu OAuth permission grants và admin consent.
  • Sử dụng Managed Identity — không cần lưu credential tĩnh.
Cập nhật 2026 — Managed Identity ưu tiên

Microsoft khuyến nghị dùng Managed Identity thay vì client secret/certificate trong mọi workload chạy trên Azure. Workload Identity Federation mở rộng sang GitHub Actions, AKS.

📚 Nội dung chi tiết

4.1 Enterprise Applications

Enterprise App là gì?
  • • Đại diện ứng dụng trong tenant (service principal)
  • • SSO: SAML, OIDC, password-based
  • • User assignment required: kiểm soát ai được dùng
  • • App role assignment
  • • OAuth consent từ user/admin
Service Principal
  • • Tạo tự động khi đăng ký app vào tenant
  • • Danh tính đại diện cho ứng dụng
  • • Có thể gán RBAC role như user
  • • Audit log ghi nhận mọi hoạt động

4.2 App Registration

Thành phần cơ bản
  • • Application (Client) ID
  • • Redirect URI
  • • Certificates & Secrets
  • • Supported account types
API Permissions
  • • Delegated permission: thay mặt user
  • • Application permission: app tự chạy
  • • Admin consent bắt buộc với quyền cao
Bảo mật Secret
  • • Đặt expiry ngắn cho secret
  • • Ưu tiên certificate hơn secret
  • • Ưu tiên Managed Identity nhất

4.3 OAuth Permission Grants & Rủi ro

Rủi ro từ consent không kiểm soát

Attacker tạo app độc hại, dụ user consent quyền Mail.Read hoặc Files.ReadWrite.All. App sau đó đọc email/file không cần password của user.

Admin Consent Workflow

Yêu cầu admin duyệt trước khi user có thể consent quyền cao.

Kiểm tra quyền app

Enterprise Apps → Permissions → xem app nào có quyền cao, ai consent.

Thu hồi consent

Revoke permission grants cho app đáng ngờ, kiểm tra audit log.

4.4 Managed Identity

Managed Identity cung cấp danh tính tự động cho tài nguyên Azure — không cần lưu password, secret, hay certificate trong code.

Loại Đặc điểm Use case
System-assigned Gắn với 1 resource, tự xóa khi resource xóa VM truy cập Key Vault, Storage
User-assigned Tài nguyên độc lập, gán cho nhiều resource App Service, Function Apps dùng chung identity
Quy trình: Bật Managed Identity trên resource → Gán RBAC role (VD: Key Vault Secrets User) → App dùng Azure SDK/IMDS để lấy token → Truy cập resource không cần credential.

🧪 Lab trong chương

✅ Checklist cuối chương

Zalo