entra1-8 Exercise 1: Fixing a Bad Renewal Plan ========================================================= Source: Microsoft Learn, "Recommendation to renew expiring application credentials" and "Add and manage app credentials". Re-check before relying on any detail. THE PROPOSED PLAN, AND WHAT IS WRONG WITH EACH STEP (1) "Delete the expired secret to avoid confusion" Problem: Removal comes last, not first. Deleting before you have confirmed the cause removes evidence (the audit log will show it, but the portal no longer shows the expiry date) and removes your fallback if the "expired" secret was not actually the problem. Also, it does not fix anything. Principle broken: create, install, PROVE, then remove. Also "confirm the cause in three places" (Step 2) before changing anything. (2) "Create a new one" Fine, but incomplete: it needs a good description (system and date), an expiry under 12 months as Microsoft recommends (never above 24), and the Value must be copied at once because it is shown only once. (3) "Email the Secret ID to you" Two separate errors. a) The Secret ID is not the secret. The Value is what the app presents. Using the ID is a classic cause of AADSTS7000215 (invalid client secret). b) Secrets must not be sent by email. Anyone with access to the mailbox, logs or backups would hold a working credential. Principle broken: the secret travels only through your product's credential field (or an approved secure channel). (4) "Paste it into the product" Fine in principle, if it is the Value. Missing: check for stray spaces or line breaks, and restart or reload anything that caches the credential. (5) "If it works, close the ticket" Problem: no proof beyond "it seems to work", no removal of the old secret, no record, no prevention. A single success may also hide a second instance or cached credential that still uses the old value. CORRECT PLAN (create, install, prove, remove) 0. Preserve: save the failed sign-in entry, correlation ID and a log download. Confirm the cause: sign-in log (7000222?), Certificates & secrets (which secret expired, which one does our system use?), audit log (any recent change?). 1. CREATE (client's administrator or registration owner): App registrations > > Certificates & secrets > Client secrets > New client secret; clear description; expiry under 12 months; Add; copy the Value immediately. 2. INSTALL: the administrator enters the Value directly into our product's credential field (no email, ticket or chat). Restart or reload as needed. 3. PROVE: trigger the connection; the service-principal sign-in log shows a new Success; Key ID matches where shown; real data flows; check again on the next scheduled run. 4. REMOVE: delete the old, expired secret only after a safe period. 5. RECORD and PREVENT: ticket note; expiry reminder in the register (Chapter 9). WHY THIS WORKS AS AN ANSWER --- Each flaw is tied to a named principle (order, value vs ID, secure transfer, proof, record), and the rewrite turns the principles into a plan the team can follow every time.