A user-assigned managed identity: an Azure resource of its own that can be attached to services. Mirroring Azure SQL Database requires the logical server to have a primary identity enabled, which may be its system-assigned identity or, in preview, a UAMI.
Also called user-assigned managed identity.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains UAMI in context, with comparison tables and the common traps.
Terms in this definition
- Mirroring
A way of keeping a copy of an outside database, for example Azure SQL Database, Cosmos DB or Snowflake, continuously up to date in OneLake as Delta tables inside a mirrored database. You query it in T-SQL via its SQL analytics endpoint, and the replication compute costs nothing.
- Azure SQL Database
Platform-as-a-service database offered as a single database or in an elastic pool, sized up to 4 TB or 128 TB on Hyperscale. SQL Agent, CLR and queries across databases aren't available.
- Logical server
In Azure SQL, the parent resource for a set of databases, carrying their logins, Entra admin, firewall rules, auditing and TDE configuration. Think of it as a management boundary; it isn't an instance of SQL Server.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
Related terms
- Azure Login action
Step in a GitHub Actions workflow that authenticates to Azure, either as the service principal of an Entra app or as a user-assigned managed identity; using OpenID Connect avoids storing any secret.
- Client ID
Identifier presented at runtime by an application or user-assigned managed identity when it asks for tokens (acrUserManagedIdentityID, for instance). Role assignments use a different value, the principal or object ID, and the resource ID is different again.
- Intermediate CA certificate
Used by Azure Firewall Premium to sign server certificates on the fly during TLS inspection, this CA certificate must be exportable and is kept as a Key Vault secret. A user-assigned managed identity gives the firewall access, and clients need to trust the root above it.
- Key Vault integration (Application Gateway)
Application Gateway v2 feature that pulls listener certificates out of Key Vault, signing in with a user-assigned managed identity. HSM-protected certificates aren't supported, only software-protected ones.
- Kubelet identity
AKS nodes pull container images using this user-assigned managed identity, so AcrPull on the registry must be granted to it rather than to the control plane identity.