Identity that a role assignment grants access to. It can be a user, a group, a managed identity or a service principal, which represents an application.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Security principal in context, with comparison tables and the common traps.
Terms in this definition
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- Role assignment
Gives access in Azure RBAC by binding three things together: who (a security principal), what (a role definition) and where (a scope).
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
Related terms
- Login
A server-wide security principal used for connecting to SQL Server or an Azure SQL logical server; users inside each database are linked to it. EXECUTE AS LOGIN can't be used in Azure SQL Database.