E2 - workload identity federation

prove identity without storing a long-lived Azure password
workflow starts -> GitHub issues short-lived OICD token -> send token to Entra -> Entra verifies claims -> Entra issues Azure access token -> workflow calls Azure ->  RBAC determines permission
principal + role + scope