Step in a GitHub Actions workflow that authenticates to Azure, either as the service principal of an Entra app or as a user-assigned managed identity; using OpenID Connect avoids storing any secret.
Also called azure/login.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure Login action in context, with comparison tables and the common traps.
Terms in this definition
- GitHub Actions workflow
An automated process, defined in YAML in .github/workflows, that runs one or more jobs when triggered by an event, on a schedule or by hand. It is GitHub's equivalent of a pipeline in Azure Pipelines.
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- UAMI
A user-assigned managed identity: an Azure resource of its own that can be attached to services. Mirroring Azure SQL Database requires the logical server to have a primary identity enabled, which may be its system-assigned identity or, in preview, a UAMI.
- OIDC
OpenID Connect, an OAuth 2.0-based identity standard that issues JSON ID tokens. VCF Identity Broker supports it, alongside SAML 2.0, for external IdPs.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
Related terms
- Personal access token (GitHub)
Token for authenticating against GitHub's own APIs. Workflows should not use it to sign in to Azure; the Azure Login action with OpenID Connect is the right approach.