Entra.Chat
Entra.Chat
Entra.Chat·Oct 2, 2026·34m·Episode #76

Your AI Coding Agent Is Creating Secrets You Don’t Know About

Show notes

Ask a coding agent to build something that talks to another service and watch what it does. It creates a client secret. Then another one. As Arturo Lucatero puts it, next thing you know you have ten secrets that were created without you knowing about it. At the speed AI is moving, he thinks we could be cleaning up a few million new secrets within six months.

That would undo a lot of hard work. Under Microsoft’s Secure Future Initiative, Microsoft spent years removing secrets from its own estate and helping customers do the same with managed identities and workload identity federation. The agent era is the window to make secretless the default before the habit sets in.

Arturo is a Principal Product Manager on Microsoft Entra Agent ID, and he helped launch Managed Service Identity, the feature we now call Managed Identities for Azure resources. In this episode he and Merill trace the whole path: why secrets break, how managed identity takes them away inside Azure, how workload identity federation extends that to AWS, GCP, Azure Arc and now AI vendors like Anthropic, and what that means for agents.

Secrets work until they don’t

A service principal with a client secret works. It works right up to the moment it gets leaked, expires in the middle of an important job, or turns out to have no clear owner, no rotation plan and no one who knows where it is stored. Managed identity moves that whole burden to the platform. The secret still exists, but the developer never sees it. The admin’s job shrinks to control-plane questions: which resource, which identity, and what it can access. Arturo also hints at what comes next: binding managed identity tokens to the resource so a leaked token is useless anywhere else.

Beyond Azure

Not every workload or data source lives in Azure. Workload identity federation lets a workload present a token from an identity provider you already trust, such as AWS, Google Cloud, GitHub or Kubernetes, and exchange it for an Entra token with no secret involved. Azure Arc brings managed identity to servers outside Azure, including the one under your desk, which raised a hard design question for the team: what happens to the secret when the machine is in someone’s basement?

Coding agents default to secrets

Coding agents learned from years of examples full of client secrets and Key Vault plumbing, so that is what they produce. Merill has to push his own agents back towards workload identity federation every time. Arturo hit the same problem from the inside: when he asked a coding agent to build with Agent ID, it created a plain service principal and named it “blueprint”. The fix was rewriting documentation and shipping agent skills that teach coding agents the right pattern.

Why agent identities still allow client secrets

Merill asks the obvious question. If secrets are this bad, why can an agent identity have one? Arturo’s answer is compatibility. Agent identities already authenticate through a federated identity credential flow under the hood, but many places that call agents cannot obtain an OIDC token yet. Without secrets or certificates as a fallback, people would simply keep using app registrations.

Open standards are the way out

Agents now cross identity providers and clouds every day. Entra is leaning on open standards so they can do that without secrets or interrupting users: SPIFFE identities that can be exchanged for Entra tokens, and ID-JAG, which lets admins pre-consent so an agent can reach a service like GitHub or Slack without prompting the user.

Arturo’s advice for anyone building today is simple: whatever you can do to avoid having a secret, do it.

Is Each App in Entra ID Still Worth Governing?

App registrations and enterprise applications accumulate. Owners change. Projects and pilots end. Credentials linger. And stale or unused apps and their permissions can continue adding risk and governance overhead long after their purpose is gone.

ENow App Governance Accelerator helps you understand and act on:

* What is in your Entra ID application estate

* Who owns business and technical decisions and management?

* Which apps, permissions, and credentials need attention?

* What can be safely cleaned up to reduce your attack surface on a continuous basis as your tenant grows and changes?

Get the visibility and automated workflows you need to investigate application lifecycles at scale, clear out stale apps, and stop wasting time governing applications that shouldn’t still be there in the first place.

See it in Action

Subscribe with your favorite podcast player or watch on YouTube

About Arturo Lucatero

Arturo Lucatero is a Principal Product Manager at Microsoft working on Microsoft Entra Agent ID, where he focuses on giving agents a strong, governable identity and on the developer experience for building with it, including skills that teach coding agents to use Agent ID correctly. He joined Microsoft’s identity team after a re-org moved him there from Power BI, worked on Connect Health, and then helped Stuart Kwan launch Managed Service Identity, now managed identities for Azure resources. Most of his career has been spent modernising non-human identities, from managed identity and Azure Arc to workload identity federation.

LinkedIn - https://www.linkedin.com/in/arturo-lucatero/

Related Links

* Microsoft Entra Agent ID skill for coding agents, in GitHub Copilot for Azure (mentioned at 32:52) - https://github.com/microsoft/GitHub-Copilot-for-Azure/blob/main/plugins/azure-skills/skills/entra-agent-id/SKILL.md

* AI-guided setup for Microsoft Entra Agent ID, using the skill with GitHub Copilot (mentioned at 32:52) - https://learn.microsoft.com/en-us/entra/agent-id/agent-id-ai-guided-setup

* Ben Reader: Access Azure Key Vault from a local Kubernetes cluster with Azure Arc workload identity (mentioned at 22:32) - https://powers-hell.com/2026/08/26/access-azure-key-vault-from-a-local-kubernetes-cluster-with-azure-arc-workload-identity

* Ben Reader: Run a PowerShell workload on a local Kubernetes cluster that talks to Microsoft Graph (mentioned at 22:32) - https://powers-hell.com/2026/09/08/run-a-powershell-workload-on-a-local-kubernetes-cluster-that-talks-to-microsoft-graph

* Managed identities for Azure resources, formerly Managed Service Identity (mentioned at 04:50) - https://learn.microsoft.com/en-us/entra/identity/managed-identities-azure-resources/overview

* Workload identity federation (mentioned at 15:18) - https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation

* Workload Identity Federation for the Claude API (mentioned at 16:27) - https://platform.claude.com/docs/en/manage-claude/workload-identity-federation

* Agent identity blueprints in Microsoft Entra Agent ID (mentioned at 20:35) - https://learn.microsoft.com/en-us/entra/agent-id/agent-blueprint

* Access Azure resources with managed identity on Azure Arc-enabled servers (mentioned at 23:09) - https://learn.microsoft.com/en-us/azure/azure-arc/servers/managed-identity-authentication

* SPIFFE and SPIRE (mentioned at 27:41) - https://spiffe.io/

* Federate a SPIFFE/SPIRE workload identity with Microsoft Entra ID (mentioned at 29:25) - https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-spiffe-spire

* Pieter Kasselman: SPIFFE at the BotAuth BoF, IETF 123 (mentioned at 29:53) - https://datatracker.ietf.org/meeting/123/materials/slides-123-webbotauth-spiffe-at-the-botauth-bof-pieter-kasselman-00

* Identity Assertion JWT Authorization Grant (ID-JAG), IETF draft (mentioned at 30:21) - https://datatracker.ietf.org/doc/draft-ietf-oauth-identity-assertion-authz-grant/

* Microsoft Secure Future Initiative (mentioned at 06:30) - https://www.microsoft.com/en-us/trust-center/security/secure-future-initiative

Related Entra.Chat Episodes

* One Compromised Agent ID Blueprint Can Cross Tenant Boundaries - https://entra.news/p/one-compromised-agent-id-blueprint

* From Windows Core to Leading Agent ID: Vince Smith’s Microsoft Story - https://entra.news/p/from-windows-core-to-leading-agent

* Attackers Are Targeting the AI Ecosystem You Cannot See - https://entra.news/p/attackers-are-targeting-the-ai-ecosystem

Chapters

00:00 Intro01:19 Arturo’s path from Intel to identity04:50 Launching Managed Service Identity07:06 Why MSI became managed identities09:41 How managed identity removes the secret14:31 Beyond Azure: workload identity federation17:08 Coding agents and the new secret sprawl20:01 When a coding agent fakes an Agent ID blueprint22:32 Managed identity anywhere with Azure Arc24:42 Why agent identities still allow client secrets27:41 Open standards: SPIFFE and ID-JAG31:48 What developers should do today

Podcast Apps

Entra.Chat - https://entra.chat

Apple Podcast - https://entra.chat/apple

YouTube - https://entra.chat/youtube

Spotify - https://entra.chat/spotify

Overcast - https://entra.chat/overcast

Pocketcast - https://entra.chat/pocketcast

Others - https://entra.chat/rss

Merill’s socials

YouTube - youtube.com/@merillx

LinkedIn - linkedin.com/in/merill

Twitter - twitter.com/merill

TikTok - tiktok.com/@merillf

Bluesky - bsky.app/profile/merill.net

Mastodon - infosec.exchange/@merill

Threads - threads.net/@merillf

GitHub - github.com/merill



Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe