Review managed identity use for App Service slots

Reduce long-lived secrets when a slot accesses Azure resources.

Description

A managed identity lets a deployment slot access supported Azure resources without storing long-lived credentials in app code or settings. Identity configuration is slot-specific, so review the permissions needed by the production app and staging slot separately.

Potential impact

Separate secrets or access keys increase credential-management work and the risk of exposure or missed replacement.

Remediation

Configure identity for slots accessing resources that support managed identities. Choose SystemAssigned or UserAssigned to suit operations and grant only required permissions on the target resources. Update the app to obtain tokens through that identity, then remove old secrets.

Examples

These excerpts compare only the identity setting of a Windows Web App slot. The parent app and target-resource permissions are separate.

Before

hcl
resource "azurerm_windows_web_app_slot" "example" {
  name           = "staging"
  app_service_id = azurerm_windows_web_app.example.id

  site_config {}
}

After

hcl
resource "azurerm_windows_web_app_slot" "example" {
  name           = "staging"
  app_service_id = azurerm_windows_web_app.example.id

  site_config {}

  identity {
    type = "SystemAssigned"
  }
}

The revision enables the slot’s system-assigned identity. Creating an identity alone neither grants data access nor changes how existing application code authenticates.

References