Quick answer: A user-assigned managed identity is a standalone Azure resource that can be assigned to one or more supported Azure resources. Create it from Azure portal > Managed Identities > Create, then assign it to the resources that need to use the identity.

Managed identities let Azure resources authenticate to services that support Microsoft Entra authentication without storing credentials in application code or configuration.

Benefits of user-assigned managed identity

  • The identity lifecycle is independent of the Azure resources that use it.
  • A single user-assigned identity can be associated with multiple supported resources.
  • Applications can authenticate without managing passwords or client secrets.

System-assigned vs. user-assigned managed identity

A system-assigned identity is tied to the lifecycle of one Azure resource. A user-assigned identity is created as a separate Azure resource and can be assigned to multiple supported resources. For a detailed comparison of lifecycle, sharing, deletion, and common use cases, see System-Assigned vs User-Assigned Managed Identity in Azure.

Create a user-assigned managed identity in Azure

1. Sign in to the Azure portal.

2. Search for Managed Identities and open the service.

3. Select Create.

4. Select the subscription and resource group, choose the region, and provide a name for the user-assigned managed identity.

5. Select Review + create, then select Create.

Create a user-assigned managed identity in Azure portal

After creation, you can assign the identity to supported Azure resources and grant it the permissions required to access services such as Azure Key Vault, Azure Storage, or Azure SQL.

Pro tips:
Keep the identity permissions to the minimum required by the workload. A user-assigned managed identity is particularly useful when the same identity needs to be reused across multiple resources.

See more

Visual Studio Marketplace

SSIS Catalog Migration Wizard

Extend Visual Studio with an easy way to migrate SSIS Catalog projects.