Description
The ad_user parameter of azure.azcollection.azure_rm_adserviceprincipal identifies the user Ansible uses to authenticate to Azure. It does not set the Azure SQL administrator account or the name of the service principal being created.
A username is not a secret. A common or hard-to-guess name alone does not establish secure authentication; verify the actual identity, its credentials and its permissions.
Potential impact
- Running automation as an unintended user can cause failures or use unnecessarily broad permissions.
- Relying on an obscure username can distract from exposed credentials and excessive permissions.
Remediation
- When using user authentication, set
ad_userto an approved, existing user and supply the required credentials securely. - Use a supported authentication method suited to the automation environment and grant only the Azure permissions it needs.
- Check Azure SQL administrator settings separately in the server’s administrator configuration.
Examples
These excerpts require an existing application’s app_id, the tenant and supported authentication settings. Changing a username arbitrarily does not create an account or reduce its permissions.
Before
- name: AD 서비스 주체 생성
azure.azcollection.azure_rm_adserviceprincipal:
app_id: "{{ app_id }}"
state: present
tenant: "{{ tenant_id }}"
ad_user: admin
Verify which actual authentication user admin identifies. This value does not configure a SQL administrator account.
After
- name: AD 서비스 주체 생성
azure.azcollection.azure_rm_adserviceprincipal:
app_id: "{{ app_id }}"
state: present
tenant: "{{ tenant_id }}"
ad_user: "{{ azure_auth_username }}"
The azure_auth_username input identifies the approved, existing user. Its authentication method and permissions still need to be managed.