All skills
lukemurraynz avatar

/identity-managed-identity

@2cc2455

Azure service-to-service (workload) identity: managed identity, user-assigned identity, Azure RBAC, passwordless Azure SDK connections, AKS workload identity, Azure DevOps Workload Identity Federation, GitHub Actions OIDC to Azure, and federated credential troubleshooting. Use when the user says "use managed identity", "passwordless Azure auth", "remove connection strings or keys", "federated credential", "workload identity federation", "GitHub Actions OIDC to Azure", "AKS workload identity", or "DefaultAzureCredential". Do NOT use for human sign-in, MFA, Conditional Access, or B2C / External ID consumer login ; use a human-identity (Entra) skill instead.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/identity-managed-identity

This session only. Nothing lands on disk.

actionsconfigure-identity.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Action: Configure Identity

Use this action to add passwordless Azure access to a workload.

Step 1 - identify the runtime and target operation

Capture these values before writing code or assigning roles:

runtime="container-app"         # app-service | function | container-app | vm | aks | azure-devops | github-actions
operation="read-key-vault-secret"
resource_scope="/subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.KeyVault/vaults/<vault>"
environment_name="prod"

Step 2 - enable or create the identity

System-assigned identity

# App Service
az webapp identity assign --name "$app_name" --resource-group "$resource_group_name"

# Function App
az functionapp identity assign --name "$app_name" --resource-group "$resource_group_name"

# Container App
az containerapp identity assign \
  --name "$app_name" \
  --resource-group "$resource_group_name" \
  --system-assigned

User-assigned identity

az identity create \
  --name "id-${service_name}-${environment_name}" \
  --resource-group "$identity_resource_group_name" \
  --location "$location"

az containerapp identity assign \
  --name "$app_name" \
  --resource-group "$resource_group_name" \
  --user-assigned "/subscriptions/$subscription_id/resourceGroups/$identity_resource_group_name/providers/Microsoft.ManagedIdentity/userAssignedIdentities/id-${service_name}-${environment_name}"

Set the client ID when the runtime has more than one possible identity:

client_id=$(az identity show \
  --name "id-${service_name}-${environment_name}" \
  --resource-group "$identity_resource_group_name" \
  --query clientId -o tsv)

az containerapp update \
  --name "$app_name" \
  --resource-group "$resource_group_name" \
  --set-env-vars "AZURE_CLIENT_ID=$client_id"

Step 3 - assign least-privilege permissions

principal_id=$(az containerapp show \
  --name "$app_name" \
  --resource-group "$resource_group_name" \
  --query identity.principalId -o tsv)

az role assignment create \
  --assignee-object-id "$principal_id" \
  --assignee-principal-type ServicePrincipal \
  --role "Key Vault Secrets User" \
  --scope "$resource_scope"

Use service-native permissions when Azure RBAC is not the data-plane model. For Azure SQL and Cosmos DB, see:

  • references/azure-sql.md
  • references/cosmos-db.md

Step 4 - disable local authentication

Prefer IaC at resource creation. For existing resources, use CLI remediation carefully after confirming no active consumer still needs local authentication.

# Storage account shared key
az storage account update \
  --name "$storage_account_name" \
  --resource-group "$resource_group_name" \
  --allow-shared-key-access false

# Service Bus namespace
az servicebus namespace update \
  --name "$service_bus_namespace" \
  --resource-group "$resource_group_name" \
  --disable-local-auth true

# Event Hubs namespace
az eventhubs namespace update \
  --name "$event_hubs_namespace" \
  --resource-group "$resource_group_name" \
  --disable-local-auth true

# Cosmos DB account: disable key/local authentication
az resource update \
  --resource-group "$resource_group_name" \
  --name "$cosmos_account_name" \
  --resource-type "Microsoft.DocumentDB/databaseAccounts" \
  --set properties.disableLocalAuth=true

Step 5 - update application code

Replace credential-bearing connection strings with resource URI + credential.

// Bad: embeds a storage account key.
// var client = new BlobServiceClient("DefaultEndpointsProtocol=https;AccountKey=...");

using Azure.Identity;
using Azure.Storage.Blobs;

var credential = new ManagedIdentityCredential();
var client = new BlobServiceClient(
    new Uri("https://<account>.blob.core.windows.net"),
    credential);

Step 6 - verify

az role assignment list \
  --assignee "$principal_id" \
  --all \
  --query "[].{role:roleDefinitionName, scope:scope}" \
  -o table

# Secret/key paths should fail after local auth is disabled.
./scripts/scan-secrets.sh .

Completion criteria

  • Effective identity is known and captured in deployment notes.
  • Least-privilege role or service-native permission is assigned at the smallest practical scope.
  • Local authentication is disabled where supported and safe.
  • Application code uses a deterministic credential in production.
  • No credential-bearing connection strings, secrets, or SAS tokens remain.
  • Verification proves identity-based access works and secret-based access fails.

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The skill is a professional toolset for managing Azure identities and promotes security best practices such as passwordless authentication. It includes utility scripts for diagnostic purposes. A low-risk surface for indirect prompt injection exists due to the processing of user-supplied identifiers into shell and cloud management commands.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
cowork
{
  "category": "automation"
}
metadata
{
  "last_verified": "2026-08-25"
}
Other metadata
compatibility
Azure CLI, Bicep or Terraform, Azure Identity SDK, Microsoft Entra workload identity federation

README badge

README badge for lukemurraynz/hve-agent-skills/identity-managed-identity