≈602 tokens on demand. Your agent reads this file only when SKILL.md points to it.
Service Bus and Event Hubs with Managed Identity
Use Microsoft Entra ID and Azure RBAC data-plane roles for new messaging workloads. Disable local/SAS key authentication for namespaces where all clients support identity-based auth.
Service Bus
Roles
| Operation |
Role |
| Send messages |
Azure Service Bus Data Sender |
| Receive messages |
Azure Service Bus Data Receiver |
| Administer data plane |
Azure Service Bus Data Owner; avoid for apps unless required |
Code
using Azure.Identity;
using Azure.Messaging.ServiceBus;
var credential = new ManagedIdentityCredential();
var client = new ServiceBusClient("<namespace>.servicebus.windows.net", credential);
Disable local auth
az servicebus namespace update \
--name "<namespace>" \
--resource-group "<resource-group>" \
--disable-local-auth true
Event Hubs
Roles
| Operation |
Role |
| Send events |
Azure Event Hubs Data Sender |
| Receive events |
Azure Event Hubs Data Receiver |
| Full data access |
Azure Event Hubs Data Owner; avoid for apps unless required |
Code
using Azure.Identity;
using Azure.Messaging.EventHubs.Producer;
var credential = new ManagedIdentityCredential();
var producer = new EventHubProducerClient(
"<namespace>.servicebus.windows.net",
"<event-hub-name>",
credential);
Disable local auth
az eventhubs namespace update \
--name "<namespace>" \
--resource-group "<resource-group>" \
--disable-local-auth true
Scope guidance
- Prefer queue/topic/event hub scope when a service only needs one entity.
- Use namespace scope only when the service needs every entity in the namespace.
- Do not use namespace owner connection strings for new code.
Common failures
| Failure |
Likely cause |
Fix |
| Send fails with unauthorized |
Missing sender role at queue/topic/namespace scope |
Assign sender role to workload principal |
| Receive fails with unauthorized |
Missing receiver role at subscription/queue/event hub scope |
Assign receiver role to workload principal |
| Connection string still works after migration |
Local auth not disabled |
Disable local auth and remove keys from configuration |
App uses fullyQualifiedNamespace incorrectly |
Namespace URI includes protocol or entity path |
Use <namespace>.servicebus.windows.net only |