Credential type in the Azure SDKs that works through several sources in turn: a developer's own sign-in on a workstation, or the managed identity through IMDS when hosted in Azure. No keys or secrets need storing.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains DefaultAzureCredential in context, with comparison tables and the common traps.
Terms in this definition
- TURN
If a direct link can't be made, RDP Shortpath for Windows 365 relays UDP traffic via Microsoft servers on port 3478 instead.
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
- Azure Instance Metadata Service
Endpoint at the non-routable address 169.254.169.254, reachable only from within a VM, that returns metadata about the VM and issues managed identity tokens. An outbound NSG rule denying the AzurePlatformIMDS tag cuts off access.
Related terms
- AIProjectClient
Starting object of the Microsoft Foundry SDK, constructed from the project endpoint plus a Microsoft Entra credential like DefaultAzureCredential. Because only Entra ID authentication is supported, no project key or SAS exists.
- AzureKeyCredential
Credential type in the Azure SDKs that authenticates with a fixed API key, in contrast to token-based credentials like DefaultAzureCredential.