Description
A managed identity lets a deployment slot access supported Azure resources without storing long-lived credentials in app code or settings. Identity configuration is slot-specific, so review the permissions needed by the production app and staging slot separately.
Potential impact
Separate secrets or access keys increase credential-management work and the risk of exposure or missed replacement.
Remediation
Configure identity for slots accessing resources that support managed identities. Choose SystemAssigned or UserAssigned to suit operations and grant only required permissions on the target resources. Update the app to obtain tokens through that identity, then remove old secrets.
Examples
These excerpts compare only the identity setting of a Windows Web App slot. The parent app and target-resource permissions are separate.
Before
resource "azurerm_windows_web_app_slot" "example" {
name = "staging"
app_service_id = azurerm_windows_web_app.example.id
site_config {}
}
After
resource "azurerm_windows_web_app_slot" "example" {
name = "staging"
app_service_id = azurerm_windows_web_app.example.id
site_config {}
identity {
type = "SystemAssigned"
}
}
The revision enables the slot’s system-assigned identity. Creating an identity alone neither grants data access nor changes how existing application code authenticates.