Logic App has no managed identity configured

Use managed identity for supported Logic App Standard connections to reduce workflow-managed secrets.

Description

A Logic App Standard workflow that stores access keys or client secrets for other Azure services faces exposure and replacement risks. Managed identity supports authentication without storing those secrets in compatible connectors and actions. Adding an identity does not automatically convert every connection.

Potential impact

  • Long-lived credentials can be exposed in workflow or application settings.
  • Failed secret replacement can cause interruptions or unauthorized access.
  • Consistent least-privilege permissions and access tracking can become harder across workflows.

Remediation

Configure an appropriate identity for Logic App Standard and enable its actual use in connections and actions that support managed identity authentication. Set identity_ids for a user-assigned ID and grant only required target permissions. Test each connection before removing and revoking replaced secrets.

Examples

This example adds a system-assigned managed identity to Logic App Standard. Configure the referenced plan and storage, connectors and target permissions separately.

Before

hcl
resource "azurerm_logic_app_standard" "example" {
  name                       = "example-logic-app"
  location                   = azurerm_resource_group.example.location
  resource_group_name        = azurerm_resource_group.example.name
  app_service_plan_id        = azurerm_service_plan.example.id
  storage_account_name       = azurerm_storage_account.example.name
  storage_account_access_key = azurerm_storage_account.example.primary_access_key
}

After

hcl
resource "azurerm_logic_app_standard" "example" {
  name                       = "example-logic-app"
  location                   = azurerm_resource_group.example.location
  resource_group_name        = azurerm_resource_group.example.name
  app_service_plan_id        = azurerm_service_plan.example.id
  storage_account_name       = azurerm_storage_account.example.name
  storage_account_access_key = azurerm_storage_account.example.primary_access_key

  identity {
    type = "SystemAssigned"
  }
}

The after example adds a SystemAssigned identity but still uses storage_account_access_key. Adding managed identity does not remove the storage key or every connector secret.

References