Language Patterns for Azure Identity
Use explicit production credentials and reuse credential instances. These examples are minimal patterns; adapt dependency injection and configuration to the application framework.
.NET
App Service / Container Apps / VM (system- or user-assigned managed identity):
using Azure.Core;
using Azure.Identity;
using Azure.Storage.Blobs;
TokenCredential credential = builder.Environment.IsDevelopment()
? new ChainedTokenCredential(
new AzureDeveloperCliCredential(), // azd auth login
new VisualStudioCredential(),
new AzureCliCredential(),
new AzurePowerShellCredential())
: new ManagedIdentityCredential();
builder.Services.AddSingleton(credential);
builder.Services.AddSingleton(_ => new BlobServiceClient(
new Uri("https://<account>.blob.core.windows.net"),
credential));For user-assigned managed identity:
var credential = new ManagedIdentityCredential(
ManagedIdentityId.FromUserAssignedClientId(configuration["AZURE_CLIENT_ID"]));AKS workload identity with developer fallback (preferred pattern for AKS + azd projects):
Use a single ChainedTokenCredential - no environment check needed. WorkloadIdentityCredential
succeeds in AKS when AZURE_FEDERATED_TOKEN_FILE is injected by the mutating webhook; it fails
fast on a developer workstation, and the chain falls through to the azd or CLI credential.
// Register once and share across all SDK clients.
TokenCredential credential = new ChainedTokenCredential(
new WorkloadIdentityCredential(), // AKS production
new AzureDeveloperCliCredential(), // azd auth login (local dev)
new AzureCliCredential()); // az login fallback
builder.Services.AddSingleton<TokenCredential>(credential);
builder.Services.AddSingleton(_ => new BlobServiceClient(
new Uri("https://<account>.blob.core.windows.net"),
credential));Do not use DefaultAzureCredential in production for AKS deployments. It probes ten credential sources (the exact count and order have changed across Azure.Identity releases, do not hard-code an assumption about it)
and can silently fall through to an unexpected identity (for example, the deploying
service principal's AzureCliCredential) if workload identity is misconfigured, making auth failures
hard to diagnose. WorkloadIdentityCredential at the head of an explicit chain fails loudly when the
AKS mutating webhook has not injected the expected env vars.
Python
from azure.identity import ManagedIdentityCredential
from azure.storage.blob import BlobServiceClient
credential = ManagedIdentityCredential()
client = BlobServiceClient(
account_url="https://<account>.blob.core.windows.net",
credential=credential,
)For AKS workload identity:
from azure.identity import WorkloadIdentityCredential
credential = WorkloadIdentityCredential()For local development only:
from azure.identity import ChainedTokenCredential, AzureCliCredential, VisualStudioCodeCredential
credential = ChainedTokenCredential(VisualStudioCodeCredential(), AzureCliCredential())Node.js / TypeScript
import { ManagedIdentityCredential } from "@azure/identity";
import { BlobServiceClient } from "@azure/storage-blob";
// Pass { clientId } for a user-assigned identity; the bare string overload still works but the options object is the current form.
const credential = new ManagedIdentityCredential({ clientId: process.env.AZURE_CLIENT_ID });
const client = new BlobServiceClient(
"https://<account>.blob.core.windows.net",
credential,
);For AKS workload identity:
import { WorkloadIdentityCredential } from "@azure/identity";
const credential = new WorkloadIdentityCredential();Java
import com.azure.identity.ManagedIdentityCredential;
import com.azure.identity.ManagedIdentityCredentialBuilder;
import com.azure.storage.blob.BlobServiceClient;
import com.azure.storage.blob.BlobServiceClientBuilder;
ManagedIdentityCredential credential = new ManagedIdentityCredentialBuilder()
.clientId(System.getenv("AZURE_CLIENT_ID"))
.build();
BlobServiceClient client = new BlobServiceClientBuilder()
.endpoint("https://<account>.blob.core.windows.net")
.credential(credential)
.buildClient();Rules
- Do not log tokens, connection strings, or authorization headers.
- Do not create credential instances per request.
- Do not mix production managed identity with local developer fallback in the same production runtime.
- Keep local developer identity permissions separate from workload identity permissions.