Skip to main content

Managed identities

A managed identity is a Microsoft Entra principal whose credentials Azure creates, rotates and never shows to anyone. The Azure platform gives every pipeline, controller and workload its own user-assigned managed identity, trusted through federated credentials where the caller runs outside Azure, so nothing in the platform stores a client secret.

What it does​

A system-assigned identity belongs to one resource and is deleted with it. A user-assigned identity is a standalone resource that one or more resources can use, and it outlives them. Either one receives role assignments like any principal. A federated identity credential on a user-assigned identity trusts tokens from an external issuer for one exact subject: a GitHub Actions job, or a Kubernetes service account through the cluster's OIDC (OpenID Connect) issuer. The caller presents its own token, Entra exchanges it for one issued to the identity, and no secret changes hands. On Azure Kubernetes Service (AKS) this is Microsoft Entra Workload ID.

How BuiltForProd uses it​

Pipelines (Azure Enterprise Baseline). One identity per repository, id-acme-<repository>-deployer in acme-core-auto, federated to that repository's GitHub workflows; GitHub OIDC covers them. The secrets repository has its own, id-acme-secrets-syncer in acme-core-security (modules/federated-identity), trusted only for environment:<stage> subjects and holding Key Vault Crypto User on each stage's SOPS key.

Platform services (Azure Enterprise Baseline).

IdentityWhereWhat it does
id-acme-github-runnersacme-core-autoRuns the Container Apps runner job: pulls the runner image (AcrPull), resolves the GitHub App credentials from the CI platform vault as Key Vault references (Secrets User)
CMK identity of the audit storageacme-core-auditWraps and unwraps the account key with the audit key (Key Vault Crypto Service Encryption User)
Policy assignment identitiesmg-acmeSystem-assigned: the tag policy's Modify remediation (Tag Contributor) and the Activity Log backstop (Monitoring and Log Analytics Contributor)

Web App Blueprint. The AKS cluster runs with Workload ID and its OIDC issuer on, and local accounts off.

IdentityFederated withRoles
id-<prefix>-aks (control plane)noneNetwork Contributor on the spoke VNet, the stage route table and the cluster's resource group; Managed Identity Operator on the kubelet identity; Private DNS Zone Contributor on the API server zone
id-<prefix>-aks-kubeletnoneAcrPull on the platform registry
id-<prefix>-esothe External Secrets Operator service accountKey Vault Secrets User on the stage application vault
id-<prefix>-cert-managerthe cert-manager service accountDNS Zone Contributor on the stage public zone
id-<prefix>-appthe application's service accountKey Vault Secrets User on the application vault; a database user on the MongoDB cluster and an access policy on the Redis cache

The application signs in to Cosmos DB for MongoDB vCore and Azure Managed Redis with its workload identity token; both accept Entra authentication only.

Data and ETL Blueprint. id-<prefix>-etl-trigger is one user-assigned identity for the whole trigger path: KEDA (Kubernetes Event-driven Autoscaling) reads the queue length with it, the Container Apps job dequeues messages, pulls its image, reads the job ID from the contract vault, and calls the Databricks Jobs API with an Entra token as a registered workspace service principal. Each role is scoped to the one resource it needs. The Unity Catalog access connector <prefix>-dbac uses a system-assigned identity with Storage Blob Data Contributor and Storage Queue Data Contributor on the lake.

In every table <prefix> is the stage's name_prefix, such as acme-eus2-prd.

Terms you will see​

TermMeaning
User-assigned identityA standalone identity resource, assigned to whatever needs it.
System-assigned identityAn identity tied to one resource's lifecycle.
Federated identity credentialTrust in an external token for one exact issuer, subject and audience.
Microsoft Entra Workload IDFederation between a Kubernetes service account and a managed identity on AKS.
OIDC issuerThe cluster endpoint that signs service account tokens Entra can verify.
Principal IDThe object ID role assignments are made to.

Where to read more​