The Azure OIDC Connector needs a federated identity credential to be set up on Entra side . This setup needs a subject identifier which right now should match the harness account identifier which is part of the harness url and is accessible to anyone who has access to the url . The ask is it make the subject identifier more specific and to include project indentifier and pipeline identifier so that the security posture can be improved.