Recommended way of calling AI services and models: rather than sending an API key, the caller presents a Microsoft Entra ID token and is authorised through an RBAC role.
Also called Microsoft Entra ID authentication.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Keyless authentication in context, with comparison tables and the common traps.
Terms in this definition
- API
Short for application programming interface: a contract that client code calls programmatically, for example a web API secured with tokens or the Files, Images or Responses APIs.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Token
The unit of text an LLM works with, which may be a word, part of a word or punctuation. Billing, limits and context windows are all counted in these units.
- RBAC
Short for role-based access control: Azure role assignments, inherited downward through scopes, that decide who may perform which actions on resources. Resource location and size are outside its control.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
Related terms
- API key (Foundry resource key)
Key generated alongside an Azure OpenAI or Foundry Tools resource and supplied through the api-key header. It is used only when keyless authentication with Microsoft Entra ID cannot be.
- Audience
Setting on a point-to-site VPN gateway using Microsoft Entra ID authentication; it contains the app ID of the Azure VPN Client or of a custom app. Only a single Audience value is allowed per gateway.
- Custom subdomain (Foundry Tools)
Endpoint unique to a resource,
https://<name>.cognitiveservices.azure.com, that Microsoft Entra ID authentication requires because regional endpoints reject Entra tokens; once set, it can't be undone. - OpenVPN
Only this point-to-site tunnel type can use Microsoft Entra ID authentication. It is TLS-based, runs on TCP 443 and has clients for Android, iOS, Linux, macOS and Windows.
- OpenVPN Connect
OpenVPN client from a third party, in 2.x and 3.x versions, that can be used for certificate-authenticated OpenVPN point-to-site but cannot handle Microsoft Entra ID authentication.
- Regional endpoint (Foundry Tools)
Endpoint shared by everyone in a region, for example eastus.api.cognitive.microsoft.com. Keys work with it, but Microsoft Entra ID authentication requires a custom subdomain instead.
- Tunnel type
The point-to-site gateway choice of OpenVPN, IKEv2, SSTP or a mix, which has to suit the client software. Only OpenVPN connections can use Microsoft Entra ID authentication.