All skills
lukemurraynz avatar

/identity-managed-identity

@2cc2455

Azure service-to-service (workload) identity: managed identity, user-assigned identity, Azure RBAC, passwordless Azure SDK connections, AKS workload identity, Azure DevOps Workload Identity Federation, GitHub Actions OIDC to Azure, and federated credential troubleshooting. Use when the user says "use managed identity", "passwordless Azure auth", "remove connection strings or keys", "federated credential", "workload identity federation", "GitHub Actions OIDC to Azure", "AKS workload identity", or "DefaultAzureCredential". Do NOT use for human sign-in, MFA, Conditional Access, or B2C / External ID consumer login ; use a human-identity (Entra) skill instead.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/identity-managed-identity

This session only. Nothing lands on disk.

referencesmessaging.md

≈602 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Service Bus and Event Hubs with Managed Identity

Use Microsoft Entra ID and Azure RBAC data-plane roles for new messaging workloads. Disable local/SAS key authentication for namespaces where all clients support identity-based auth.

Service Bus

Roles

Operation Role
Send messages Azure Service Bus Data Sender
Receive messages Azure Service Bus Data Receiver
Administer data plane Azure Service Bus Data Owner; avoid for apps unless required

Code

using Azure.Identity;
using Azure.Messaging.ServiceBus;

var credential = new ManagedIdentityCredential();
var client = new ServiceBusClient("<namespace>.servicebus.windows.net", credential);

Disable local auth

az servicebus namespace update \
  --name "<namespace>" \
  --resource-group "<resource-group>" \
  --disable-local-auth true

Event Hubs

Roles

Operation Role
Send events Azure Event Hubs Data Sender
Receive events Azure Event Hubs Data Receiver
Full data access Azure Event Hubs Data Owner; avoid for apps unless required

Code

using Azure.Identity;
using Azure.Messaging.EventHubs.Producer;

var credential = new ManagedIdentityCredential();
var producer = new EventHubProducerClient(
    "<namespace>.servicebus.windows.net",
    "<event-hub-name>",
    credential);

Disable local auth

az eventhubs namespace update \
  --name "<namespace>" \
  --resource-group "<resource-group>" \
  --disable-local-auth true

Scope guidance

  • Prefer queue/topic/event hub scope when a service only needs one entity.
  • Use namespace scope only when the service needs every entity in the namespace.
  • Do not use namespace owner connection strings for new code.

Common failures

Failure Likely cause Fix
Send fails with unauthorized Missing sender role at queue/topic/namespace scope Assign sender role to workload principal
Receive fails with unauthorized Missing receiver role at subscription/queue/event hub scope Assign receiver role to workload principal
Connection string still works after migration Local auth not disabled Disable local auth and remove keys from configuration
App uses fullyQualifiedNamespace incorrectly Namespace URI includes protocol or entity path Use <namespace>.servicebus.windows.net only

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The skill is a professional toolset for managing Azure identities and promotes security best practices such as passwordless authentication. It includes utility scripts for diagnostic purposes. A low-risk surface for indirect prompt injection exists due to the processing of user-supplied identifiers into shell and cloud management commands.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
cowork
{
  "category": "automation"
}
metadata
{
  "last_verified": "2026-08-25"
}
Other metadata
compatibility
Azure CLI, Bicep or Terraform, Azure Identity SDK, Microsoft Entra workload identity federation

README badge

README badge for lukemurraynz/hve-agent-skills/identity-managed-identity