Bird
Raised Fist0
Azurecloud~5 mins

Managed identity integration in Azure - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Managed identity integration lets your Azure services securely access other resources without needing passwords or keys. It solves the problem of safely managing credentials by automatically handling them for you.
When you want an Azure virtual machine to access Azure Key Vault secrets without storing credentials.
When an Azure App Service needs to read data from an Azure Storage account securely.
When you want to grant an Azure Function permission to access a database without embedding connection strings.
When you want to avoid manual credential rotation and reduce security risks.
When you want to simplify authentication between Azure services in your cloud applications.
Config File - azure-pod.yaml
azure-pod.yaml
apiVersion: v1
kind: Pod
metadata:
  name: my-app-pod
  namespace: example-namespace
spec:
  containers:
  - name: my-app-container
    image: mcr.microsoft.com/azure-cli
    command: ["sleep", "3600"]
  identity:
    type: UserAssigned
    userAssignedIdentities:
      /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.ManagedIdentity/userAssignedIdentities/my-identity: {}

This Kubernetes pod manifest shows how to assign a user-assigned managed identity to a pod.

metadata: Names the pod and sets its namespace.

spec.containers: Defines the container image and command.

spec.identity: Assigns the user-assigned managed identity by its full Azure resource ID.

Commands
Create a user-assigned managed identity in the resource group example-rg in the eastus region.
Terminal
az identity create --resource-group example-rg --name my-identity --location eastus
Expected OutputExpected
{ "clientId": "11111111-1111-1111-1111-111111111111", "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.ManagedIdentity/userAssignedIdentities/my-identity", "location": "eastus", "name": "my-identity", "principalId": "22222222-2222-2222-2222-222222222222", "resourceGroup": "example-rg", "type": "Microsoft.ManagedIdentity/userAssignedIdentities" }
→
--resource-group - Specifies the resource group where the identity is created
→
--name - Names the managed identity
→
--location - Sets the Azure region for the identity
Deploy the Kubernetes pod with the user-assigned managed identity attached so the pod can use it to access Azure resources securely.
Terminal
kubectl apply -f azure-pod.yaml
Expected OutputExpected
pod/my-app-pod created
Check that the pod is running and ready to use the managed identity.
Terminal
kubectl get pods
Expected OutputExpected
NAME READY STATUS RESTARTS AGE my-app-pod 1/1 Running 0 10s
Inside the pod, log in to Azure using the managed identity's client ID to authenticate without credentials.
Terminal
kubectl exec my-app-pod -- az login --identity --username 11111111-1111-1111-1111-111111111111
Expected OutputExpected
{ "cloudName": "AzureCloud", "homeTenantId": "33333333-3333-3333-3333-333333333333", "id": "22222222-2222-2222-2222-222222222222", "isDefault": true, "managedByTenants": [], "name": "my-identity", "state": "Enabled", "tenantId": "33333333-3333-3333-3333-333333333333", "user": { "name": "my-identity", "type": "servicePrincipal" } }
→
--identity - Use managed identity for login
→
--username - Specify the client ID of the user-assigned managed identity
Key Concept

If you remember nothing else from this pattern, remember: managed identities let Azure services authenticate securely without storing or managing passwords.

Common Mistakes
Not assigning the managed identity to the resource before trying to use it.
The service cannot authenticate without the identity attached, causing authentication failures.
Always create and assign the managed identity to the resource before using it.
Using the wrong client ID or resource ID when configuring the identity in the pod manifest.
The pod will not be able to find or use the identity, causing login errors.
Copy the exact client ID and resource ID from the Azure identity creation output.
Trying to use managed identity login outside of an Azure environment or without proper permissions.
Managed identity authentication only works within Azure resources that support it.
Use managed identity only inside Azure services that support it, like VMs, App Services, or AKS pods.
Summary
Create a user-assigned managed identity in Azure with az identity create.
Attach the managed identity to your Kubernetes pod in the pod manifest.
Deploy the pod and verify it is running with kubectl commands.
Use az login inside the pod with the managed identity to authenticate securely.

Practice

(1/5)
1. What is the main purpose of using a managed identity in Azure?
Managed Identity helps your app to:
easy
A. Create new Azure subscriptions automatically
B. Access other Azure services securely without storing credentials
C. Run virtual machines faster
D. Manage user passwords in Azure Active Directory

Solution

  1. Step 1: Understand managed identity purpose

    Managed identities provide apps a way to authenticate to Azure services without needing to store credentials like passwords.
  2. Step 2: Identify correct use case

    Among the options, only accessing services securely without credentials matches the purpose of managed identities.
  3. Final Answer:

    Access other Azure services securely without storing credentials -> Option B
  4. Quick Check:

    Managed identity = secure access without passwords [OK]
Hint: Managed identity means no passwords needed for service access [OK]
Common Mistakes:
  • Thinking managed identity speeds up VM performance
  • Confusing managed identity with subscription management
  • Assuming it manages user passwords
2. Which of the following is the correct way to enable a system-assigned managed identity for an Azure Virtual Machine using Azure CLI?
easy
A. az vm identity enable --name MyVM --resource-group MyGroup
B. az vm create --name MyVM --resource-group MyGroup --assign-identity
C. az vm identity assign --name MyVM --resource-group MyGroup
D. az vm identity add --name MyVM --resource-group MyGroup

Solution

  1. Step 1: Recall Azure CLI command for managed identity

    The correct command to assign a system-assigned managed identity to an existing VM is az vm identity assign.
  2. Step 2: Verify command syntax

    az vm identity assign --name MyVM --resource-group MyGroup uses the correct command and parameters. Other options use incorrect commands or flags.
  3. Final Answer:

    az vm identity assign --name MyVM --resource-group MyGroup -> Option C
  4. Quick Check:

    Assign identity command = az vm identity assign [OK]
Hint: Use 'az vm identity assign' to enable system-assigned identity [OK]
Common Mistakes:
  • Using 'az vm create' with wrong flags
  • Using non-existent commands like 'identity enable'
  • Confusing 'assign' with 'add'
3. Consider this Azure CLI command sequence:
az vm create --name MyVM --resource-group MyGroup --image UbuntuLTS --assign-identity
az role assignment create --assignee  --role Reader --scope /subscriptions/123/resourceGroups/MyGroup

What is the expected result?
medium
A. The VM is created with a system-assigned identity and granted Reader role on the resource group
B. The VM is created without any identity and no role assignment is made
C. The VM creation fails due to missing identity parameters
D. The VM is created but the role assignment fails because the principal ID is invalid

Solution

  1. Step 1: Analyze VM creation command

    The --assign-identity flag creates a system-assigned managed identity for the VM.
  2. Step 2: Analyze role assignment command

    The role assignment grants the identity Reader access to the resource group scope using the identity's principal ID.
  3. Final Answer:

    The VM is created with a system-assigned identity and granted Reader role on the resource group -> Option A
  4. Quick Check:

    Assign identity + role assignment = secure access granted [OK]
Hint: Assign identity then grant role for access [OK]
Common Mistakes:
  • Assuming VM creation fails without explicit identity creation
  • Thinking role assignment needs user principal, not identity
  • Ignoring the --assign-identity flag effect
4. You tried to enable a user-assigned managed identity on an Azure App Service but received an error. Which of the following is the most likely cause?
medium
A. The App Service plan is not Premium tier
B. The App Service already has a system-assigned identity enabled
C. The user-assigned identity was not created in the same subscription
D. The user-assigned identity is not assigned to the App Service resource

Solution

  1. Step 1: Understand user-assigned identity attachment

    User-assigned identities must be explicitly assigned to the resource to be used.
  2. Step 2: Identify common error cause

    If the identity exists but is not assigned to the App Service, enabling it will fail.
  3. Final Answer:

    The user-assigned identity is not assigned to the App Service resource -> Option D
  4. Quick Check:

    User-assigned identity must be assigned to resource [OK]
Hint: Assign user identity to resource before enabling [OK]
Common Mistakes:
  • Assuming system-assigned identity conflicts with user-assigned
  • Thinking subscription mismatch causes error
  • Believing App Service plan tier affects identity assignment
5. You want an Azure Function to access a Key Vault securely using a managed identity. Which steps should you follow to set this up correctly?
hard
A. Enable system-assigned identity on the Function, grant it Key Vault access policy, then use identity in code
B. Create a user-assigned identity, assign it to the Function, then store its secret in Key Vault
C. Enable system-assigned identity on the Function, store Function credentials in Key Vault, then access Key Vault
D. Create a user-assigned identity, assign it to the Function, then use a password stored in Key Vault

Solution

  1. Step 1: Enable system-assigned managed identity on Azure Function

    This allows the Function to authenticate without credentials.
  2. Step 2: Grant the Function's identity access to Key Vault

    Set an access policy in Key Vault to allow the identity to read secrets.
  3. Step 3: Use the managed identity in Function code to access Key Vault

    The Function can request tokens and securely retrieve secrets without passwords.
  4. Final Answer:

    Enable system-assigned identity on the Function, grant it Key Vault access policy, then use identity in code -> Option A
  5. Quick Check:

    Enable identity + grant access + use identity = secure Key Vault access [OK]
Hint: Enable identity, grant access, then use it in code [OK]
Common Mistakes:
  • Storing passwords instead of using managed identity
  • Confusing user-assigned identity with storing secrets
  • Not granting Key Vault access to the identity