Review App Service managed identity use

Reduce stored long-lived credentials when accessing supported Azure resources.

Description

Without a managed identity, an App Service app may need to manage separate secrets or credentials to access other Azure resources. Managed identity identifies the app for resource access; it does not enable sign-in authentication for visitors. An app that does not access other resources does not necessarily need an identity.

Potential impact

  • Credentials stored in code or configuration can be exposed.
  • Secret replacement and credential-management work can increase the chance of operational mistakes.

Remediation

  • If the destination supports managed identity authentication, configure a SystemAssigned or UserAssigned identity on Microsoft.Web/sites. For a user-assigned type, associate the actual identity through userAssignedIdentities.
  • Grant only required permissions and update the app to authenticate with the identity. Verify normal operation, then remove stored secrets and revoke credentials that are no longer used.

Examples

These excerpts add a system-assigned identity to the same app. The App Service plan and runtime configuration are omitted; permissions at the destination must be configured separately.

Before

bicep
resource webApp 'Microsoft.Web/sites@2020-12-01' = {
  name: 'example-webapp'
  location: resourceGroup().location
  properties: {
    httpsOnly: true
  }
}

No managed identity is configured. Check how the app authenticates to other Azure resources.

After

bicep
resource webApp 'Microsoft.Web/sites@2020-12-01' = {
  name: 'example-webapp'
  location: resourceGroup().location
  identity: {
    type: 'SystemAssigned'
  }
  properties: {
    httpsOnly: true
  }
}

An Azure-managed system-assigned identity is enabled. Destination permissions and changes to authentication code are not applied automatically.

References