Endpoint at the non-routable address 169.254.169.254, reachable only from within a VM, that returns metadata about the VM and issues managed identity tokens. An outbound NSG rule denying the AzurePlatformIMDS tag cuts off access.
Also called IMDS, IMDS.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-700SC-500SC-300AZ-802
Each book explains Azure Instance Metadata Service in context, with comparison tables and the common traps.
Terms in this definition
- Metadata
Describes data rather than being the data itself, for instance how a file is laid out or what rows each chunk contains, so tools can read things efficiently.
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
- Default security rules
Built-in NSG rules at priorities 65000-65500: AllowVnetInBound, AllowAzureLoadBalancerInBound and DenyAllInBound, plus AllowVnetOutBound, AllowInternetOutBound and DenyAllOutBound. Removal is impossible; custom rules at 100-4096 take precedence.
- Tag
Key-value label on compute (for cost tracking) or on a Unity Catalog securable or column, applied with
SET TAGorSET TAGSand requiringAPPLY TAG. Governed tags restrict allowed keys, values and assigners across the account.
Related terms
- AzurePlatformIMDS (service tag)
Service tag for the Instance Metadata Service at 169.254.169.254, meaningful only outbound. Denying it in an outbound NSG rule stops the VM reaching IMDS; inbound rules using it do nothing.
- DefaultAzureCredential
Credential type in the Azure SDKs that works through several sources in turn: a developer's own sign-in on a workstation, or the managed identity through IMDS when hosted in Azure. No keys or secrets need storing.