AZ-DEV-170: Authentication and Identity on Azure
Master modern identity on Azure for .NET developers. Cover Entra ID app registrations, OpenID Connect + MSAL user sign-in, calling downstream APIs with On-Behalf-Of, Managed Identity + DefaultAzureCredential for service-to-service auth, workload identity federation for GitHub Actions and Kubernetes, custom API protection with scopes and roles, Entra External ID for consumer apps, and a zero-secret capstone.
About This Course
Identity is the single most common source of production issues in Azure applications: expired tokens, wrong audiences, missing scopes, misconfigured redirect URIs, and connection strings that shouldn't exist. This course teaches modern .NET auth patterns from the ground up: OAuth 2.0 flows and OpenID Connect fundamentals, ASP.NET Core sign-in with Microsoft.Identity.Web, calling downstream APIs securely with On-Behalf-Of, Managed Identity for every service-to-service call, and workload identity federation to eliminate secrets in CI/CD.Beyond the mechanics, the course goes deep on the design questions: when to use a confidential vs public client, when to add API scopes vs app roles, how to model multi-tenant tokens, and how to handle Conditional Access step-up challenges gracefully. The capstone deploys a full ASP.NET Core app with zero secrets Managed Identity for downstream Azure services, federated credentials for CI/CD, and no client secrets in Entra ID.By the end you can explain OAuth 2.0 auth-code + PKCE, client-credentials and OBO flows, register apps in Entra ID with correct redirect URIs and scopes, add user sign-in to ASP.NET Core with Microsoft.Identity.Web, call downstream APIs using OBO, wire Managed Identity to every Azure resource, configure workload identity federation for GitHub Actions, and build a zero-secret application.
Course Curriculum
20 Lessons
AZ-DEV-170 M1L1 - Identity fundamentals - OAuth 2.0, OpenID Connect, and JWTs
OAuth 2.0 flows, OpenID Connect on top of OAuth, JWT structure and claims, access tokens vs ID tokens vs refresh tokens, delegated vs app-only permissions.
AZ-DEV-170 M1L2 - Decode and verify a JWT from Entra ID - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Acquire an access token from Entra ID, decode the JWT header/payload/signature at jwt.ms, identify audience, issuer, subject, scopes, roles, tenant, and expiry. Verify the token signature with the tenant's public keys.
AZ-DEV-170 M2L3 - Entra ID app registrations - confidential vs public, scopes, and app roles
Confidential vs public clients, redirect URIs by app type, client secrets vs certificates vs federated credentials, exposing an API + scopes, and app roles for RBAC.
AZ-DEV-170 M2L4 - Register two Entra ID apps with scopes and roles - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Register a web app (confidential) and a SPA (public) in Entra ID. Configure the web app to expose an API with two scopes (Orders.Read, Orders.Write) and two app roles (Reader, Writer). Grant the SPA delegated permission to Orders.Read.
AZ-DEV-170 M3L5 - ASP.NET Core sign-in with Microsoft.Identity.Web
Microsoft.Identity.Web package for ASP.NET Core, AddMicrosoftIdentityWebApp bootstrap, cookie + OpenID Connect handler pipeline, sign-in/sign-out, token cache (in-memory vs distributed).
AZ-DEV-170 M3L6 - Add Entra ID sign-in to an ASP.NET Core 10 Razor Pages app - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Add Entra ID sign-in to an ASP.NET Core 10 Razor Pages app using Microsoft.Identity.Web. Add [Authorize] on a page, sign in, view the user's claims, and wire a distributed token cache via IDistributedCache (Azure Managed Redis is the recommended production backing store).
AZ-DEV-170 M4L7 - Calling downstream APIs with On-Behalf-Of
OBO flow mechanics, ITokenAcquisition, incremental consent, per-request scope acquisition, token cache patterns, handling MsalUiRequiredException.
AZ-DEV-170 M4L8 - Call Microsoft Graph and a custom API via OBO - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Extend the web app to call Microsoft Graph (GET /me) and a custom downstream Orders API. Request scopes incrementally: initial sign-in grants only User.Read, then request Orders.Read on demand. Handle interactive-consent errors.
AZ-DEV-170 M5L9 - Managed Identity end-to-end - DefaultAzureCredential and RBAC
System vs user-assigned MI, DefaultAzureCredential chain, RBAC scope hierarchy (subscription → RG → resource), cross-tenant MI scenarios.
AZ-DEV-170 M5L10 - Wire a .NET service to five Azure resources via a single User-Assigned MI - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Wire one .NET service to Storage, Key Vault, Azure SQL, Cosmos DB, and Service Bus using a single User-Assigned MI. Verify each downstream call succeeds with zero secrets anywhere in code or configuration.
AZ-DEV-170 M6L11 - Workload identity federation for CI/CD
Federated credentials on Entra ID app registrations, replacing client secrets in GitHub Actions / GitLab CI / Kubernetes with OIDC-issued short-lived tokens, subject claim matching.
AZ-DEV-170 M6L12 - Wire GitHub Actions to Azure via federated credentials - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Register a federated credential subject to a specific GitHub Actions workflow, wire the workflow to az login via OIDC, deploy a Bicep template with zero client secrets in the repo.
AZ-DEV-170 M7L13 - Protecting a custom API with JWT bearer, scopes, and roles
JWT bearer authentication in ASP.NET Core, AddMicrosoftIdentityWebApi, authorization policies on scopes vs roles, delegated vs app-only calls at the API side.
AZ-DEV-170 M7L14 - Protect an Orders API with scopes and app roles - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Add JWT bearer to the Orders API. Require Orders.Read scope on GET, Orders.Write on POST. Add a policy that requires app role Admin on DELETE. Verify with Postman using two different Entra tokens.
AZ-DEV-170 M8L15 - Entra External ID for consumer applications
External ID tenant creation, sign-up + sign-in user flows, social identity providers (Google, Facebook, Apple), custom branding, custom attributes.
AZ-DEV-170 M8L16 - Wire a consumer web app to Entra External ID - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Provision an External ID tenant, configure a sign-up/sign-in flow, register a web app, wire an ASP.NET Core Blazor front-end to it, and capture custom attributes (loyalty tier, preferred boat class) at sign-up.
AZ-DEV-170 M9L17 - Advanced identity - Conditional Access, PoP tokens, and certificate credentials
Conditional Access policies + CA claim handling in apps, proof-of-possession tokens vs bearer, certificate-based client credentials, managed HSM for key custody.
AZ-DEV-170 M9L18 - Handle Conditional Access step-up and swap secret for a cert - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Enforce a CA policy requiring MFA for the Orders.Write scope. Handle the step-up challenge in the app via claims-challenge. Replace an app registration's client secret with a certificate stored in Key Vault.
AZ-DEV-170 M10L19 - Capstone - Zero-secret Azure application design
End-to-end review of a zero-secret architecture: web + API + workers + CI/CD + downstream Azure services. Design tradeoffs, threat modelling, credential hygiene.
AZ-DEV-170 M10L20 - Capstone - Ship the Anchorline Outdoors zero-secret stack - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Deploy a complete Anchorline Outdoors stack: External ID front-end, Entra ID employee web app, Orders API (JWT bearer), background Container Apps worker (MI), all wired to Cosmos, Storage, Service Bus, and Key Vault with zero secrets in any config file. GitHub Actions deploys via federated credentials.