All skills
lukemurraynz avatar

/identity-managed-identity

@2cc2455

Azure service-to-service (workload) identity: managed identity, user-assigned identity, Azure RBAC, passwordless Azure SDK connections, AKS workload identity, Azure DevOps Workload Identity Federation, GitHub Actions OIDC to Azure, and federated credential troubleshooting. Use when the user says "use managed identity", "passwordless Azure auth", "remove connection strings or keys", "federated credential", "workload identity federation", "GitHub Actions OIDC to Azure", "AKS workload identity", or "DefaultAzureCredential". Do NOT use for human sign-in, MFA, Conditional Access, or B2C / External ID consumer login ; use a human-identity (Entra) skill instead.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/identity-managed-identity

This session only. Nothing lands on disk.

referencesazure-sql.md

≈835 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure SQL with Managed Identity

Azure SQL application access is not completed by Azure RBAC alone. The workload identity must authenticate with Microsoft Entra ID and also exist as a contained database user in each target database with the required database roles or grants.

Required design decisions

  1. Configure Microsoft Entra authentication for the logical server or managed instance.
  2. Decide whether the app uses system-assigned or user-assigned managed identity.
  3. Create a contained database user for the identity in every target database.
  4. Grant the smallest database permissions required.
  5. Use a managed identity connection mode in the application.

Contained database user

Run this while connected as a Microsoft Entra principal that can create users in the database.

CREATE USER [<managed-identity-name>] FROM EXTERNAL PROVIDER;
ALTER ROLE db_datareader ADD MEMBER [<managed-identity-name>];
ALTER ROLE db_datawriter ADD MEMBER [<managed-identity-name>];

Use only the roles required. For read-only workloads, do not grant db_datawriter. Prefer explicit grants for tightly scoped production databases:

CREATE USER [<managed-identity-name>] FROM EXTERNAL PROVIDER;
GRANT SELECT ON SCHEMA::[reporting] TO [<managed-identity-name>];

Connection strings

System-assigned managed identity

Server=tcp:<server>.database.windows.net,1433;Database=<database>;Authentication=Active Directory Managed Identity;Encrypt=True;

User-assigned managed identity

For Microsoft.Data.SqlClient versions that support user-assigned managed identity client ID in the connection string:

Server=tcp:<server>.database.windows.net,1433;Database=<database>;Authentication=Active Directory Managed Identity;User Id=<managed-identity-client-id>;Encrypt=True;

Alternative: acquire a token with ManagedIdentityCredential and pass it to the SQL client using supported token APIs.

Note: Starting with Microsoft.Data.SqlClient 7.0, the Microsoft Entra authentication dependencies were removed from the core package, so Entra auth modes (including Active Directory Managed Identity) now require the separate NuGet package Microsoft.Data.SqlClient.Extensions.Azure. Upgrading a project to 7.0 without adding this package silently breaks Entra authentication. (Verified 2026-06-16.)

Common failures

Failure Likely cause Fix
Login failed for user '<token-identified principal>' Token is valid, but database user is missing or not granted access Create contained user and grants in the target database
Works locally but not in Azure Developer identity has DB access; workload identity does not Create/grant the workload identity user
User-assigned identity not used Missing or wrong client ID Set AZURE_CLIENT_ID or use explicit client ID in credential/connection
App can manage SQL but cannot query data Management-plane role assigned, but DB permissions missing Add contained database user and database permissions

Do not

  • Use SQL authentication username/password for new application code.
  • Assume Azure SQL DB Contributor gives query access to application data.
  • Use a shared migration identity as the runtime identity.
  • Grant db_owner unless the application administers the database.

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The skill is a professional toolset for managing Azure identities and promotes security best practices such as passwordless authentication. It includes utility scripts for diagnostic purposes. A low-risk surface for indirect prompt injection exists due to the processing of user-supplied identifiers into shell and cloud management commands.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
cowork
{
  "category": "automation"
}
metadata
{
  "last_verified": "2026-08-25"
}
Other metadata
compatibility
Azure CLI, Bicep or Terraform, Azure Identity SDK, Microsoft Entra workload identity federation

README badge

README badge for lukemurraynz/hve-agent-skills/identity-managed-identity