How the two managed identity types differ in lifecycle and sharing, when to choose each, and the Azure roles needed to manage them.
From Ultra Transcenders SC-300 by Tony Rough (coming November 2026)
A managed identity is a special type of service principal assigned to an Azure compute resource, such as a virtual machine, scale set, App Service app or AKS cluster. Code on that resource gets Microsoft Entra tokens without any secret, and managed identities cost nothing extra.
| Property | System-assigned | User-assigned |
|---|---|---|
| Created | As part of an Azure resource | As a standalone Azure resource (Microsoft.ManagedIdentity/userAssignedIdentities) |
| Lifecycle | Deleted automatically with the resource | Independent; must be deleted explicitly |
| Sharing | One resource only | Can be assigned to many resources |
| Service principal name | Same as the resource name | Name you choose |
| Best for | Single-resource workloads, auditing which resource acted, permissions that must disappear with the resource | Replicated workloads, resources that are recreated often, access needed before deployment, rapid creation at scale |
A resource can have a system-assigned identity and one or more user-assigned identities at the same time. Microsoft describes user-assigned identities as the recommended type for Microsoft services, mainly because role assignments can be created in advance and fewer identities mean fewer role assignments to manage.
| Task | Azure role (no Microsoft Entra directory role needed) |
|---|---|
| Create, delete a user-assigned identity | Managed Identity Contributor |
| Read or list user-assigned identities | Managed Identity Operator or Managed Identity Contributor |
| Enable or disable a system-assigned identity on a VM | Virtual Machine Contributor |
| Assign a user-assigned identity to a VM | Virtual Machine Contributor and Managed Identity Operator |
| Remove a user-assigned identity from a VM | Virtual Machine Contributor |
Enable a system-assigned identity on a VM in the Azure portal under Security > Identity > System assigned; add a user-assigned identity under the User assigned tab. The portal can’t attach a user-assigned identity while creating a VM, so create the VM first and add it afterwards. User-assigned identity names used with VMs or scale sets are limited to 24 characters.
Common trap: Giving a deployment pipeline only Virtual Machine Contributor and expecting it to attach an existing user-assigned identity - assigning a user-assigned identity also needs Managed Identity Operator on that identity.
This note is one section of Ultra Transcenders SC-300: Microsoft Identity and Access Administrator, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-300 terms in the glossary · All SC-300 study notes
How the two hybrid sync engines differ in capability and limits, and where each sign-in method checks the password.
The three ways to switch on MFA across a tenant, compared by licence, flexibility and what each one enforces.
What a TAP is for, its lifetime and length settings, and which role can create one for which users.
Which events and location changes revoke a still-valid token, how long-lived CAE tokens behave, and where CAE falls back to one-hour tokens.
The difference between the two risk types, real-time versus offline detections, and which detections need P2.
How default and per-organisation settings control B2B collaboration and B2B direct connect, and when MFA and device claims are trusted.
Why every app has a global definition and a per-tenant instance, the three service principal types, and what happens when you change or delete one.