Identity Selection Standard
Decision matrix
| Scenario | Identity type | Reason |
|---|---|---|
| One Azure app accesses one or a small set of resources | System-assigned managed identity | Simple lifecycle and least operational overhead |
| Multiple Azure apps need identical access | User-assigned managed identity | One stable principal and reusable role assignments |
| Blue/green deployments, deployment slots, or resource recreation | User-assigned managed identity | Identity survives workload replacement |
| AKS pod accesses Azure resources | Microsoft Entra Workload ID + user-assigned managed identity | No secrets in pods and no deprecated pod-managed identity |
| Azure DevOps deploys to Azure | Azure Resource Manager service connection with Workload Identity Federation | No service principal secret rotation |
| GitHub Actions deploys to Azure | GitHub OIDC federated credential | No long-lived Azure credential in GitHub secrets |
| Local developer runs app | Developer tool credential chain | Human developer identity stays separate from workload identity |
| Cross-tenant or external workload federation | App registration or managed identity federated credential | Requires explicit issuer/subject/audience trust |
System-assigned managed identity
Use when the workload has a single, clear lifecycle and the identity should be deleted with the resource.
resource app 'Microsoft.Web/sites@2024-04-01' = {
name: app_name
location: location
identity: {
type: 'SystemAssigned'
}
}User-assigned managed identity
Use when the identity must be stable, shared, pre-provisioned, or bound explicitly through AZURE_CLIENT_ID.
resource identity 'Microsoft.ManagedIdentity/userAssignedIdentities@2024-11-30' = {
name: 'id-${service_name}-${environment_name}'
location: location
}For production workloads with user-assigned identity, configure the client ID explicitly:
AZURE_CLIENT_ID=<user-assigned-managed-identity-client-id>Workload identity federation
Use when the workload runs outside the direct Azure managed identity runtime or needs a projected OIDC token. Common cases are AKS, Azure DevOps, and GitHub Actions.
Federated credential values must match exactly:
issuersubjectaudience, normallyapi://AzureADTokenExchangefor Azure workload identity federation
Anti-patterns
- Sharing one identity across unrelated applications or environments.
- Using an app registration secret because federation setup is unfamiliar.
- Assigning roles to the wrong principal because display names look similar.
- Depending on local developer permissions to prove production access will work.
- Creating role assignments manually without capturing them in IaC.