Skip to main content

Managed Identity

An automatically managed identity in Entra ID tied directly to an Azure resource (like a VM or App Service), allowing that resource to authenticate to other Azure services without any stored credentials or secrets.

Managed Identity

A Managed Identity is created and rotated automatically by Azure — your code calls the local metadata endpoint to get a token, with no client secret to store or leak anywhere.

Why It Matters in Production

CRED's App Service instances use a system-assigned Managed Identity to authenticate to Key Vault, meaning there's no database password or API key stored in application config at all.

Bash
az webapp identity assign --resource-group cred-prod-rg --name cred-api
az keyvault set-policy --name cred-prod-kv \
--object-id <managed-identity-id> --secret-permissions get list
Tip

Prefer system-assigned Managed Identities for single-resource use cases and user-assigned ones when multiple resources need to share the same identity.

Frequently Asked Questions

What problem does a Managed Identity actually solve versus a service principal with a secret?

A traditional service principal needs a client secret or certificate stored somewhere — in a pipeline variable, a config file, a key vault reference — that has to be rotated and can leak. A Managed Identity is provisioned and rotated automatically by Azure, tied to the lifecycle of the resource it's attached to, so there's no credential to store, copy, or expose. It's Azure's version of AWS IAM roles for EC2 instances.

System-assigned vs user-assigned Managed Identity — when do you pick which?

System-assigned identities are created and destroyed with the resource itself, which is simplest for a single VM or function app but means the identity disappears if the resource is deleted, breaking any role assignments tied to it. User-assigned identities exist independently and can be attached to multiple resources, which is the better choice when several App Services or VMs need to share the same permission set, or when you want the identity's lifecycle decoupled from any one resource.