entra1-4 Exercise 2: Audit the Credential Register (as at 2026-10-01) ====================================================================== DAYS REMAINING (from 1 October 2026) ------------------------------------ # Item Expires Days Status - ------------------------------------- ----------- -------- --------------------- 1 Acme sign-in secret (Fabrikam) 2026-10-20 19 Renew now (inside 30 days) 2 Acme SAML signing cert (Contoso) 2026-11-25 55 Not yet urgent; see emails 3 Directory sync secret (Fabrikam) 2026-09-28 -3 ALREADY EXPIRED 4 User provisioning SCIM credential 2027-03-01 151 Fine for now 5 Reporting API certificate (Contoso) 2027-02-14 136 Fine for now 6 Test app secret (Fabrikam) 2028-12-01 792 Cannot be right (below) (Day counts: Oct 1 to Oct 20 is 19; Oct 1 to Nov 25 is 55; Sep 28 was 3 days ago; Oct 1 to 1 March 2027 is 151; to 14 Feb 2027 is 136; to 1 Dec 2028 is about 792.) ALREADY EXPIRED --------------- Item 3, the Fabrikam directory sync secret, expired on 28 September. If a nightly job relies on it, the job has been failing since then. This matches the kind of report in Exercise 3(a). TO RENEW WITHIN 30 DAYS ----------------------- Item 1, the Acme sign-in secret, expires on 20 October (19 days away). This is the one that will make everyone at Fabrikam fail at once if it is missed. It is also exactly the kind of credential Entra's "Renew expiring application credentials" recommendation would flag, since it expires within 30 days. SAML NOTIFICATION EMAILS FOR ITEM 2 (expires 25 November 2026) -------------------------------------------------------------- Microsoft says Entra emails 60, 30 and 7 days before expiry. 60 days before: 26 September 2026 -> should already have been sent 30 days before: 26 October 2026 -> not yet 7 days before: 18 November 2026 -> not yet If nobody at Contoso remembers seeing a 26 September email, check who is on the notification list. By default only the administrator who added the application is notified, and that person may have left. THE ENTRY THAT CANNOT BE RIGHT ------------------------------ Item 6: a client secret created on 30 September 2026 and expiring on 1 December 2028 would last about 26 months. Microsoft says a client secret's lifetime is limited to 24 months and can't be set longer. So either the expiry date was mistyped, or it isn't really a client secret (check the type), or it came from somewhere other than the portal's secret creation. Verify against the portal before relying on the register. WHAT TO DO NEXT --------------- 1. Today: item 3 (expired) and item 1 (19 days left). 2. Put the SAML certificate (item 2) on the calendar with dates for the 30-day and 7-day warnings. 3. Correct or remove item 6. 4. Record who owns each item and who to contact, so the register is usable when a person leaves. WHY THIS WORKS AS AN ANSWER --------------------------- It turns a list of dates into actions, uses the documented notification dates and the 24-month limit as checks, and shows how a register can contain an entry that is impossible. A register you don't verify gives false comfort.