Identity and Access Management
Identity in prod: Live-debugging AADSTS errors & building secretless architectures that don’'t break
📅 Wednesday, 27 May 2026🕐 13:30–14:20📍 Room 3
Most sign-in outages are self-inflicted; wrong tenant; expired secrets; bad redirect URIs; missing consent; misapplied Conditional Access. We will debug the top AADSTS errors live and then redesign the apps to avoid them. You will see working patterns for secretless server-to-server calls with Managed Identity; secure CI/CD using workload identity federation from GitHub; reliable interactive auth using Authorization Code + PKCE; and robust API-to-API with On-Behalf-Of. We will use Entra sign-in logs; Kusto; MSAL logs; App Insights; and Azure CLI. You will leave with all new insights to use less secrets and a minimal repo you can clone to reproduce the demos.


