FREE STUDY NOTES · SC-300

System-assigned vs user-assigned managed identities

How the two managed identity types differ in lifecycle and sharing, when to choose each, and the Azure roles needed to manage them.

From Ultra Transcenders SC-300 by Tony Rough (coming November 2026)

A managed identity is a special type of service principal assigned to an Azure compute resource, such as a virtual machine, scale set, App Service app or AKS cluster. Code on that resource gets Microsoft Entra tokens without any secret, and managed identities cost nothing extra.

Property System-assigned User-assigned
Created As part of an Azure resource As a standalone Azure resource (Microsoft.ManagedIdentity/userAssignedIdentities)
Lifecycle Deleted automatically with the resource Independent; must be deleted explicitly
Sharing One resource only Can be assigned to many resources
Service principal name Same as the resource name Name you choose
Best for Single-resource workloads, auditing which resource acted, permissions that must disappear with the resource Replicated workloads, resources that are recreated often, access needed before deployment, rapid creation at scale

A resource can have a system-assigned identity and one or more user-assigned identities at the same time. Microsoft describes user-assigned identities as the recommended type for Microsoft services, mainly because role assignments can be created in advance and fewer identities mean fewer role assignments to manage.

Roles needed

Task Azure role (no Microsoft Entra directory role needed)
Create, delete a user-assigned identity Managed Identity Contributor
Read or list user-assigned identities Managed Identity Operator or Managed Identity Contributor
Enable or disable a system-assigned identity on a VM Virtual Machine Contributor
Assign a user-assigned identity to a VM Virtual Machine Contributor and Managed Identity Operator
Remove a user-assigned identity from a VM Virtual Machine Contributor

Enable a system-assigned identity on a VM in the Azure portal under Security > Identity > System assigned; add a user-assigned identity under the User assigned tab. The portal can’t attach a user-assigned identity while creating a VM, so create the VM first and add it afterwards. User-assigned identity names used with VMs or scale sets are limited to 24 characters.

Behaviour to remember

Common trap: Giving a deployment pipeline only Virtual Machine Contributor and expecting it to attach an existing user-assigned identity - assigning a user-assigned identity also needs Managed Identity Operator on that identity.

Get the whole book

This note is one section of Ultra Transcenders SC-300: Microsoft Identity and Access Administrator, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · SC-300 terms in the glossary · All SC-300 study notes

More SC-300 study notes