securing-azure-sql-and-storage-with-managed-identitylisted
Install: claude install-skill alexpizarro/azure-lean-stack-skills
# Securing Azure SQL and Storage with Managed Identity
Kill the stored SQL password and the storage account key from the **runtime** auth path. Use the
compute's **system-assigned managed identity** (MI) instead: Entra token auth for Azure SQL,
user-delegation SAS for Blob Storage. Managed identity is **free**. Keep the connection string and
account key present as **instant rollback only** — never the primary auth.
This is the DEFAULT for new deployments. Username/password + account key is legacy / rollback.
> **Scope note.** This is about the app's *data-plane* auth to SQL and to *user* blobs. It is
> separate from FC1's *host* storage MI (`AzureWebJobsStorage__accountName`, the deployment + host
> lease), which [deploying-fc1-flex-consumption-functions](../deploying-fc1-flex-consumption-functions/SKILL.md)
> already covers. Both use the same system-assigned identity; they authorise different things.
>
> **Applies to FC1 / Container Apps / App Service — not SWA managed functions.** SWA managed
> functions have no managed identity and no Key Vault references; if the API lives there, move it
> to FC1 first (the code is the same CommonJS shape).
Proven end-to-end on Azure Functions (Flex Consumption) + Azure SQL + Blob Storage, 2026-07-17.
## Workflow checklist
Copy this checklist and tick items off. **SQL and storage are independent — do SQL fully first.**
```
Managed-identity data-plane auth:
- [ ] Step 1: Add @azure/identity to the api package; ship the flag-gated cod