All skills
lukemurraynz avatar

/identity-managed-identity

@2cc2455

Azure service-to-service (workload) identity: managed identity, user-assigned identity, Azure RBAC, passwordless Azure SDK connections, AKS workload identity, Azure DevOps Workload Identity Federation, GitHub Actions OIDC to Azure, and federated credential troubleshooting. Use when the user says "use managed identity", "passwordless Azure auth", "remove connection strings or keys", "federated credential", "workload identity federation", "GitHub Actions OIDC to Azure", "AKS workload identity", or "DefaultAzureCredential". Do NOT use for human sign-in, MFA, Conditional Access, or B2C / External ID consumer login ; use a human-identity (Entra) skill instead.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/identity-managed-identity

This session only. Nothing lands on disk.

referencespolicy-guardrails.md

≈656 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Policy and Governance Guardrails

For new Azure projects, prevent credential-bearing patterns from being created rather than relying only on code review.

Recommended policy intents

Apply these at management group or subscription scope as appropriate for the landing zone:

Resource Policy intent
Storage accounts Deny or audit allowSharedKeyAccess not set to false for workloads that support Microsoft Entra auth
Cosmos DB accounts Deny or audit disableLocalAuth not set to true
Service Bus namespaces Deny or audit disableLocalAuth not set to true
Event Hubs namespaces Deny or audit disableLocalAuth not set to true
Key Vault Require RBAC authorization model, purge protection, and soft delete for production vaults
App Service / Functions / Container Apps Audit workloads without managed identity enabled
Role assignments Audit broad data-plane roles at subscription scope
Pipeline service connections Require workload identity federation for new Azure deployment connections where the platform supports it

Use built-in Azure Policy definitions where available. Use custom policies only to cover gaps or organization-specific standards.

Azure Resource Graph checks

Storage shared key

resources
| where type =~ 'microsoft.storage/storageaccounts'
| project id, name, resourceGroup, allowSharedKeyAccess = tostring(properties.allowSharedKeyAccess)
| where allowSharedKeyAccess != 'false'

Cosmos DB local auth

resources
| where type =~ 'microsoft.documentdb/databaseaccounts'
| project id, name, resourceGroup, disableLocalAuth = tostring(properties.disableLocalAuth)
| where disableLocalAuth != 'true'

Service Bus and Event Hubs local auth

resources
| where type in~ ('microsoft.servicebus/namespaces', 'microsoft.eventhub/namespaces')
| project id, name, type, resourceGroup, disableLocalAuth = tostring(properties.disableLocalAuth)
| where disableLocalAuth != 'true'

Workloads without managed identity

resources
| where type in~ ('microsoft.web/sites', 'microsoft.app/containerapps', 'microsoft.compute/virtualmachines')
| project id, name, type, resourceGroup, identityType = tostring(identity.type)
| where isempty(identityType) or identityType =~ 'None'

Exception handling

Every exception must include:

  • Business justification.
  • Owner.
  • Expiry date.
  • Compensating controls.
  • Migration issue or backlog item.
  • Evidence that the service currently lacks a supported identity-based alternative or that migration cannot happen safely yet.

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The skill is a professional toolset for managing Azure identities and promotes security best practices such as passwordless authentication. It includes utility scripts for diagnostic purposes. A low-risk surface for indirect prompt injection exists due to the processing of user-supplied identifiers into shell and cloud management commands.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
cowork
{
  "category": "automation"
}
metadata
{
  "last_verified": "2026-08-25"
}
Other metadata
compatibility
Azure CLI, Bicep or Terraform, Azure Identity SDK, Microsoft Entra workload identity federation

README badge

README badge for lukemurraynz/hve-agent-skills/identity-managed-identity