Description
Without a managed identity, an App Service app may need to manage separate secrets or credentials to access other Azure resources. Managed identity identifies the app for resource access; it does not enable sign-in authentication for visitors. An app that does not access other resources does not necessarily need an identity.
Potential impact
- Credentials stored in code or configuration can be exposed.
- Secret replacement and credential-management work can increase the chance of operational mistakes.
Remediation
- If the destination supports managed identity authentication, configure a SystemAssigned or UserAssigned identity on Microsoft.Web/sites. For a user-assigned type, associate the actual identity through userAssignedIdentities.
- Grant only required permissions and update the app to authenticate with the identity. Verify normal operation, then remove stored secrets and revoke credentials that are no longer used.
Examples
These excerpts add a system-assigned identity to the same app. The App Service plan and runtime configuration are omitted; permissions at the destination must be configured separately.
Before
resource webApp 'Microsoft.Web/sites@2020-12-01' = {
name: 'example-webapp'
location: resourceGroup().location
properties: {
httpsOnly: true
}
}
No managed identity is configured. Check how the app authenticates to other Azure resources.
After
resource webApp 'Microsoft.Web/sites@2020-12-01' = {
name: 'example-webapp'
location: resourceGroup().location
identity: {
type: 'SystemAssigned'
}
properties: {
httpsOnly: true
}
}
An Azure-managed system-assigned identity is enabled. Destination permissions and changes to authentication code are not applied automatically.