Skip to content
Stackship documentation Svenska

Managed identitiesUsers

Permissions

The actions that govern managed identities, and the roles that hold them.

Actions

Action Allows
managedidentities/read Listing the identities in a resource group and viewing one — the Managed Identity card
managedidentities/write Creating an identity for a resource directly. The platform does this itself when the resource is created
managedidentities/delete Deleting an identity directly. The platform does this itself when the resource is deleted
managedidentities/readSecrets Reading an identity's client ID and client secret — a data action

managedidentities/readSecrets hands out a credential that does not expire and lets the holder act as the workload, with every right the identity's roles give. Workloads do not need it: they get short-lived tokens without it — see Use a managed identity in code.

Roles

Role read write, delete readSecrets
Reader Yes No No
The Apps, Functions, Jobs, Databases and Storage Reader and Operator roles, Blueprint Reader, Blueprints Operator Yes No No
Contributor, Owner Yes Yes Yes
Platform Reader Yes No No
Platform Contributor, Platform Owner Yes Yes Yes

Owner, Contributor and the two platform roles hold managedidentities/readSecrets through their data-action wildcard. To keep it from someone who needs Contributor otherwise, exclude it with a deny assignment.