Concept and mechanism
Authenticating a person or application does not define every operation they may perform. Azure roles control Azure resources, while Microsoft Entra roles control directory functions. Choose the role family and scope appropriate to the task. In PIM, an eligible assignment requires activation before use, with conditions such as approval or MFA according to configuration. An approved change window does not remove those conditions. Report-only Conditional Access evaluates impact without enforcing that policy’s controls; a Failure result in that mode can coexist with a successful sign-in. Validation should also consider enforced policies and the population actually observed.
Guided application
For workloads, managed identity avoids directly managing credentials but still needs target authorization. A system-assigned identity follows its resource: deleting and recreating a VM with the same name does not preserve the previous principal. A user-assigned identity has an independent lifecycle and can serve several resources, requiring review before removal. For APIs, distinguish delegated access, involving client and user, from app-only access, suitable for a noninteractive service where supported. At handover, record principals, grants, owners, and activation procedures. Test the minimum operation using the actual consumer identity instead of always using an administrator account.
A recreated VM receives403 despite the same name. With networking validated, compare its new principal with the principal still authorized at the target.
Common pitfalls
Eligibility treated as active access; report-only treated as blocking; same name treated as same identity.
Related topics: Network boundaries and private access · Compute and operational access · Data protection and use
Demonstrate authorization for the effective identity at the required scope and time.
Reference: PIM eligible and active Azure resource roles · AZ-500 objectives2026-01-22; retired2026-08-31