Give a managed identity a role
Find a workload's principal ID and assign its managed identity a role on a resource, a resource group or a boundary.
Requires: rbac/members/write
A workload can do only what its managed identity's roles allow. Assigning it a role works like assigning one to a person — see Role assignments for who may do it — except that you find the identity by its principal ID, not by its name.
Find the principal ID
- In the portal at https://portal.example.com, open the app, function namespace or container instance.
- On its Overview, the Managed Identity card shows the Principal ID. Copy it.
The Client ID on the same card, mi-…, is not the principal ID and does not work in role
assignments. The card is shown only to people who may read the resource — apps/read for an
app and also for a function namespace, containerinstance/read for a container instance — and
its contents need managedidentities/read.
With the CLI, stsh identity list -g <resource-group> -o json lists the identities in a resource
group with their principalId.
Assign a role on a resource
- Open the resource the workload needs — a vault, say — and its Access Control tab.
- Choose Add role assignment.
- Paste the principal ID into the search field. The identity appears under the resource's name, labelled Service. Searching by the resource's name looks only at the first 20 managed identities on the platform, so it usually misses; use the principal ID.
- Pick the Role — for a vault, Secrets Reader — and choose Add assignment.
To give the identity a role on the whole boundary, do the same on the Access Control tab of the boundary's own page.
Assign a role with the CLI
The CLI can assign at any scope, a resource group included:
stsh iam assignment create \
--set principalId=<principal-id> \
--set principalType=ServicePrincipal \
--set roleDefinitionId=<role-id> \
--set scope=/boundaries/<boundary-id>/resourcegroups/webstsh iam role list shows the role IDs.
Which identities you can assign
You can give roles to the identities of workloads in any boundary of the same tenant. An identity from another tenant's boundary needs a boundary trust — see Tenants and guests.