Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
Also called Run As account.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-300AI-103AI-200DP-750SC-900SC-200SC-300AZ-400AZ-802DP-800ALZ
Each book explains Managed identity in context, with comparison tables and the common traps.
Terms in this definition
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
Related terms
- Access Connector for Azure Databricks
An Azure resource, provided by Microsoft, whose job is to carry a managed identity (system-assigned, user-assigned or both) that Unity Catalog can use. Storage credentials point at the connector's resource ID to gain access to ADLS.
- AKS-ACR integration
Running az aks create or az aks update with --attach-acr grants AcrPull to a cluster's kubelet managed identity, letting nodes fetch images with no pull secrets. Registries using ABAC can't use this; grant Container Registry Repository Reader manually there.
- APIM named values
Reusable name/value pairs referenced from API Management policies. A value can be held in plain text, encrypted inside APIM as a secret, or pulled from Key Vault through the instance's managed identity.
- az cognitiveservices account create
Azure CLI command creating a Foundry Tools or Foundry resource based on
--location,--skuand--kind. Customer-managed key configuration belongs in--encryption;--assign-identitymerely creates a managed identity. - Azure Event Hubs Data Sender
Lets a principal send events to an event hub. For change event streaming, the database's managed identity should get this built-in role scoped to the event hub itself, not to its namespace.
- Azure Instance Metadata Service
Endpoint at the non-routable address 169.254.169.254, reachable only from within a VM, that returns metadata about the VM and issues managed identity tokens. An outbound NSG rule denying the AzurePlatformIMDS tag cuts off access.
- BYOC
Option for HTTPS on a Front Door custom domain in which your own certificate sits in Azure Key Vault, read through a managed identity or registered service principal; direct upload isn't possible and the chain must come from a Microsoft Trusted CA.
- Contained user
Database user that authenticates at database level with no login in master, such as an Entra user, group or managed identity added through CREATE USER ... FROM EXTERNAL PROVIDER.