Description
Managed identities let apps access supported Azure resources without placing long-lived credentials directly in code or settings. Separate secrets or keys add configuration and secret-protection work. An app that does not access other resources does not automatically need an identity.
Potential impact
- Secrets left in code or settings can be exposed.
- Credential replacement and permission management can require more work.
Remediation
Where the target service supports managed identity authentication, configure identity { type = "SystemAssigned" } or a suitable user-assigned identity. Grant only required permissions and update the app to authenticate with the identity. After testing, remove old secrets and revoke credentials no longer needed elsewhere.
Examples
These legacy AzureRM 3.x azurerm_app_service examples enable a system-assigned identity. Current Linux and Windows Web App resources also support the identity block.
Before
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
}
After
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
identity {
type = "SystemAssigned"
}
}
The revision lets Azure manage the app’s identity. Target permissions and application authentication changes remain separate, as does authentication of users signing in to the app.