<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Wif on Trust Anchor</title><link>https://trustanchor.pro/tags/wif/</link><description>Recent content in Wif on Trust Anchor</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 George Vaculik</copyright><lastBuildDate>Sat, 25 Jul 2026 10:00:00 +0200</lastBuildDate><atom:link href="https://trustanchor.pro/tags/wif/index.xml" rel="self" type="application/rss+xml"/><item><title>Secret-less auth for Azure DevOps runners with WIF</title><link>https://trustanchor.pro/posts/secretless-ado-runners-wif/</link><pubDate>Sat, 25 Jul 2026 10:00:00 +0200</pubDate><guid>https://trustanchor.pro/posts/secretless-ado-runners-wif/</guid><description>A build pipeline is one of the most privileged identities in your tenant — the service principals and managed identities behind it form a perimeter into the platform. Workload Identity Federation makes the pipeline auth to Azure, Microsoft Graph, other API endpoints, and Azure DevOps secret-less on any runner; a user-assigned managed identity does the same for registering a self-hosted runner. This post covers both, and why PATs, client secrets, and certificates are the credentials to design out.</description></item></channel></rss>