Werk #19473: Azure App Registrations: Add maximum credential validity check
| Component | Checks & agents | ||||
| Title | Azure App Registrations: Add maximum credential validity check | ||||
| Date | Apr 7, 2026 | ||||
| Level | Prominent Change | ||||
| Class | New Feature | ||||
| Compatibility | Compatible - no manual interaction needed | ||||
| Checkmk versions & editions |
|
The Microsoft Azure App Registrations check now supports alerting when credentials (secrets or certificates) have an excessively long validity period.
The ruleset Microsoft Azure App Registrations now offers two threshold groups per credential type:
- Remaining validity: Alert when a credential is about to expire (existing behavior)
- Maximum allowed validity: Alert when a credential's total lifespan exceeds a threshold — useful for enforcing policies that require short-lived credentials
By default, the max validity check warns and goes critical at 6 months and 1 day.
Existing rule configurations are migrated automatically.