Managed identities
A managed identity is a Microsoft Entra principal whose credentials Azure creates, rotates and never shows to anyone. The Azure platform gives every pipeline, controller and workload its own user-assigned managed identity, trusted through federated credentials where the caller runs outside Azure, so nothing in the platform stores a client secret.
What it does
A system-assigned identity belongs to one resource and is deleted with it. A user-assigned identity is a standalone resource that one or more resources can use, and it outlives them. Either one receives role assignments like any principal. A federated identity credential on a user-assigned identity trusts tokens from an external issuer for one exact subject: a GitHub Actions job, or a Kubernetes service account through the cluster's OIDC (OpenID Connect) issuer. The caller presents its own token, Entra exchanges it for one issued to the identity, and no secret changes hands. On Azure Kubernetes Service (AKS) this is Microsoft Entra Workload ID.
How BuiltForProd uses it
Pipelines (Azure Enterprise Baseline). One identity per repository, id-acme-<repository>-deployer in acme-core-auto, federated to that repository's GitHub workflows; GitHub OIDC covers them. The secrets repository has its own, id-acme-secrets-syncer in acme-core-security (modules/federated-identity), trusted only for environment:<stage> subjects and holding Key Vault Crypto User on each stage's SOPS key.
Platform services (Azure Enterprise Baseline).
| Identity | Where | What it does |
|---|---|---|
id-acme-github-runners | acme-core-auto | Runs the Container Apps runner job: pulls the runner image (AcrPull), resolves the GitHub App credentials from the CI platform vault as Key Vault references (Secrets User) |
| CMK identity of the audit storage | acme-core-audit | Wraps and unwraps the account key with the audit key (Key Vault Crypto Service Encryption User) |
| Policy assignment identities | mg-acme | System-assigned: the tag policy's Modify remediation (Tag Contributor) and the Activity Log backstop (Monitoring and Log Analytics Contributor) |
Web App Blueprint. The AKS cluster runs with Workload ID and its OIDC issuer on, and local accounts off.
| Identity | Federated with | Roles |
|---|---|---|
id-<prefix>-aks (control plane) | none | Network Contributor on the spoke VNet, the stage route table and the cluster's resource group; Managed Identity Operator on the kubelet identity; Private DNS Zone Contributor on the API server zone |
id-<prefix>-aks-kubelet | none | AcrPull on the platform registry |
id-<prefix>-eso | the External Secrets Operator service account | Key Vault Secrets User on the stage application vault |
id-<prefix>-cert-manager | the cert-manager service account | DNS Zone Contributor on the stage public zone |
id-<prefix>-app | the application's service account | Key Vault Secrets User on the application vault; a database user on the MongoDB cluster and an access policy on the Redis cache |
The application signs in to Cosmos DB for MongoDB vCore and Azure Managed Redis with its workload identity token; both accept Entra authentication only.
Data and ETL Blueprint. id-<prefix>-etl-trigger is one user-assigned identity for the whole trigger path: KEDA (Kubernetes Event-driven Autoscaling) reads the queue length with it, the Container Apps job dequeues messages, pulls its image, reads the job ID from the contract vault, and calls the Databricks Jobs API with an Entra token as a registered workspace service principal. Each role is scoped to the one resource it needs. The Unity Catalog access connector <prefix>-dbac uses a system-assigned identity with Storage Blob Data Contributor and Storage Queue Data Contributor on the lake.
In every table <prefix> is the stage's name_prefix, such as acme-eus2-prd.
Terms you will see
| Term | Meaning |
|---|---|
| User-assigned identity | A standalone identity resource, assigned to whatever needs it. |
| System-assigned identity | An identity tied to one resource's lifecycle. |
| Federated identity credential | Trust in an external token for one exact issuer, subject and audience. |
| Microsoft Entra Workload ID | Federation between a Kubernetes service account and a managed identity on AKS. |
| OIDC issuer | The cluster endpoint that signs service account tokens Entra can verify. |
| Principal ID | The object ID role assignments are made to. |
Where to read more
- Azure Enterprise Baseline overview, Azure Web App Blueprint overview and Data and ETL Blueprint overview.
- Azure RBAC for how the roles above are scoped.
- Least privilege for one identity per job.