AI Instructor Live Labs Included

AZ-DEV-170: Authentication and Identity on Azure

Master modern identity on Azure for .NET developers. Cover Entra ID app registrations, OpenID Connect + MSAL user sign-in, calling downstream APIs with On-Behalf-Of, Managed Identity + DefaultAzureCredential for service-to-service auth, workload identity federation for GitHub Actions and Kubernetes, custom API protection with scopes and roles, Entra External ID for consumer apps, and a zero-secret capstone.

Intermediate
1d 11h 0m
20 Lessons
AZ-DEV-170

About This Course

Identity is the single most common source of production issues in Azure applications: expired tokens, wrong audiences, missing scopes, misconfigured redirect URIs, and connection strings that shouldn't exist. This course teaches modern .NET auth patterns from the ground up: OAuth 2.0 flows and OpenID Connect fundamentals, ASP.NET Core sign-in with Microsoft.Identity.Web, calling downstream APIs securely with On-Behalf-Of, Managed Identity for every service-to-service call, and workload identity federation to eliminate secrets in CI/CD.Beyond the mechanics, the course goes deep on the design questions: when to use a confidential vs public client, when to add API scopes vs app roles, how to model multi-tenant tokens, and how to handle Conditional Access step-up challenges gracefully. The capstone deploys a full ASP.NET Core app with zero secrets Managed Identity for downstream Azure services, federated credentials for CI/CD, and no client secrets in Entra ID.By the end you can explain OAuth 2.0 auth-code + PKCE, client-credentials and OBO flows, register apps in Entra ID with correct redirect URIs and scopes, add user sign-in to ASP.NET Core with Microsoft.Identity.Web, call downstream APIs using OBO, wire Managed Identity to every Azure resource, configure workload identity federation for GitHub Actions, and build a zero-secret application.

Course Curriculum

20 Lessons
01
AI Lesson
AI Lesson

AZ-DEV-170 M1L1 - Identity fundamentals - OAuth 2.0, OpenID Connect, and JWTs

45m

OAuth 2.0 flows, OpenID Connect on top of OAuth, JWT structure and claims, access tokens vs ID tokens vs refresh tokens, delegated vs app-only permissions.

02
Lab Exercise
Lab Exercise

AZ-DEV-170 M1L2 - Decode and verify a JWT from Entra ID - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Acquire an access token from Entra ID, decode the JWT header/payload/signature at jwt.ms, identify audience, issuer, subject, scopes, roles, tenant, and expiry. Verify the token signature with the tenant's public keys.

03
AI Lesson
AI Lesson

AZ-DEV-170 M2L3 - Entra ID app registrations - confidential vs public, scopes, and app roles

45m

Confidential vs public clients, redirect URIs by app type, client secrets vs certificates vs federated credentials, exposing an API + scopes, and app roles for RBAC.

04
Lab Exercise
Lab Exercise

AZ-DEV-170 M2L4 - Register two Entra ID apps with scopes and roles - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Register a web app (confidential) and a SPA (public) in Entra ID. Configure the web app to expose an API with two scopes (Orders.Read, Orders.Write) and two app roles (Reader, Writer). Grant the SPA delegated permission to Orders.Read.

05
AI Lesson
AI Lesson

AZ-DEV-170 M3L5 - ASP.NET Core sign-in with Microsoft.Identity.Web

45m

Microsoft.Identity.Web package for ASP.NET Core, AddMicrosoftIdentityWebApp bootstrap, cookie + OpenID Connect handler pipeline, sign-in/sign-out, token cache (in-memory vs distributed).

06
Lab Exercise
Lab Exercise

AZ-DEV-170 M3L6 - Add Entra ID sign-in to an ASP.NET Core 10 Razor Pages app - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Add Entra ID sign-in to an ASP.NET Core 10 Razor Pages app using Microsoft.Identity.Web. Add [Authorize] on a page, sign in, view the user's claims, and wire a distributed token cache via IDistributedCache (Azure Managed Redis is the recommended production backing store).

07
AI Lesson
AI Lesson

AZ-DEV-170 M4L7 - Calling downstream APIs with On-Behalf-Of

45m

OBO flow mechanics, ITokenAcquisition, incremental consent, per-request scope acquisition, token cache patterns, handling MsalUiRequiredException.

08
Lab Exercise
Lab Exercise

AZ-DEV-170 M4L8 - Call Microsoft Graph and a custom API via OBO - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Extend the web app to call Microsoft Graph (GET /me) and a custom downstream Orders API. Request scopes incrementally: initial sign-in grants only User.Read, then request Orders.Read on demand. Handle interactive-consent errors.

09
AI Lesson
AI Lesson

AZ-DEV-170 M5L9 - Managed Identity end-to-end - DefaultAzureCredential and RBAC

45m

System vs user-assigned MI, DefaultAzureCredential chain, RBAC scope hierarchy (subscription → RG → resource), cross-tenant MI scenarios.

10
Lab Exercise
Lab Exercise

AZ-DEV-170 M5L10 - Wire a .NET service to five Azure resources via a single User-Assigned MI - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.

Wire one .NET service to Storage, Key Vault, Azure SQL, Cosmos DB, and Service Bus using a single User-Assigned MI. Verify each downstream call succeeds with zero secrets anywhere in code or configuration.

11
AI Lesson
AI Lesson

AZ-DEV-170 M6L11 - Workload identity federation for CI/CD

45m

Federated credentials on Entra ID app registrations, replacing client secrets in GitHub Actions / GitLab CI / Kubernetes with OIDC-issued short-lived tokens, subject claim matching.

12
Lab Exercise
Lab Exercise

AZ-DEV-170 M6L12 - Wire GitHub Actions to Azure via federated credentials - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Register a federated credential subject to a specific GitHub Actions workflow, wire the workflow to az login via OIDC, deploy a Bicep template with zero client secrets in the repo.

13
AI Lesson
AI Lesson

AZ-DEV-170 M7L13 - Protecting a custom API with JWT bearer, scopes, and roles

45m

JWT bearer authentication in ASP.NET Core, AddMicrosoftIdentityWebApi, authorization policies on scopes vs roles, delegated vs app-only calls at the API side.

14
Lab Exercise
Lab Exercise

AZ-DEV-170 M7L14 - Protect an Orders API with scopes and app roles - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Add JWT bearer to the Orders API. Require Orders.Read scope on GET, Orders.Write on POST. Add a policy that requires app role Admin on DELETE. Verify with Postman using two different Entra tokens.

15
AI Lesson
AI Lesson

AZ-DEV-170 M8L15 - Entra External ID for consumer applications

45m

External ID tenant creation, sign-up + sign-in user flows, social identity providers (Google, Facebook, Apple), custom branding, custom attributes.

16
Lab Exercise
Lab Exercise

AZ-DEV-170 M8L16 - Wire a consumer web app to Entra External ID - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Provision an External ID tenant, configure a sign-up/sign-in flow, register a web app, wire an ASP.NET Core Blazor front-end to it, and capture custom attributes (loyalty tier, preferred boat class) at sign-up.

17
AI Lesson
AI Lesson

AZ-DEV-170 M9L17 - Advanced identity - Conditional Access, PoP tokens, and certificate credentials

45m

Conditional Access policies + CA claim handling in apps, proof-of-possession tokens vs bearer, certificate-based client credentials, managed HSM for key custody.

18
Lab Exercise
Lab Exercise

AZ-DEV-170 M9L18 - Handle Conditional Access step-up and swap secret for a cert - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Enforce a CA policy requiring MFA for the Orders.Write scope. Handle the step-up challenge in the app via claims-challenge. Replace an app registration's client secret with a certificate stored in Key Vault.

19
AI Lesson
AI Lesson

AZ-DEV-170 M10L19 - Capstone - Zero-secret Azure application design

45m

End-to-end review of a zero-secret architecture: web + API + workers + CI/CD + downstream Azure services. Design tradeoffs, threat modelling, credential hygiene.

20
Lab Exercise
Lab Exercise

AZ-DEV-170 M10L20 - Capstone - Ship the Anchorline Outdoors zero-secret stack - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.

Deploy a complete Anchorline Outdoors stack: External ID front-end, Entra ID employee web app, Orders API (JWT bearer), background Container Apps worker (MI), all wired to Cosmos, Storage, Service Bus, and Key Vault with zero secrets in any config file. GitHub Actions deploys via federated credentials.

This course includes:

  • 24/7 AI Instructor Support
  • Live Lab Environments
  • 10 Hands-on Lessons
Skill Level Intermediate
Total Duration 1d 11h 0m