← ClaudeAtlas

securing-azure-sql-and-storage-with-managed-identitylisted

Moves an Azure Functions app's RUNTIME data-plane auth off the stored SQL password and storage account key onto the compute's system-assigned managed identity — Entra token auth for Azure SQL and user-delegation SAS for Blob Storage. Ships flag-gated (default OFF, old paths byte-identical) so cutover is a no-op until flipped and rollback is one setting. Covers the Entra-admin + MI-DB-user + storage-RBAC one-time setup, the async user-delegation-key priming that SAS signing requires, and the bicep-resets-app-settings durability trap. Use when hardening a deployment off secrets, when a security review flags a stored SQL password / account key, or as the DEFAULT auth for any new Function App + SQL + Blob deployment.
alexpizarro/azure-lean-stack-skills · ★ 1 · Code & Development · score 72
Install: claude install-skill alexpizarro/azure-lean-stack-skills
# Securing Azure SQL and Storage with Managed Identity Kill the stored SQL password and the storage account key from the **runtime** auth path. Use the compute's **system-assigned managed identity** (MI) instead: Entra token auth for Azure SQL, user-delegation SAS for Blob Storage. Managed identity is **free**. Keep the connection string and account key present as **instant rollback only** — never the primary auth. This is the DEFAULT for new deployments. Username/password + account key is legacy / rollback. > **Scope note.** This is about the app's *data-plane* auth to SQL and to *user* blobs. It is > separate from FC1's *host* storage MI (`AzureWebJobsStorage__accountName`, the deployment + host > lease), which [deploying-fc1-flex-consumption-functions](../deploying-fc1-flex-consumption-functions/SKILL.md) > already covers. Both use the same system-assigned identity; they authorise different things. > > **Applies to FC1 / Container Apps / App Service — not SWA managed functions.** SWA managed > functions have no managed identity and no Key Vault references; if the API lives there, move it > to FC1 first (the code is the same CommonJS shape). Proven end-to-end on Azure Functions (Flex Consumption) + Azure SQL + Blob Storage, 2026-07-17. ## Workflow checklist Copy this checklist and tick items off. **SQL and storage are independent — do SQL fully first.** ``` Managed-identity data-plane auth: - [ ] Step 1: Add @azure/identity to the api package; ship the flag-gated cod