Turbot Guardrails Hub 
Hub
  • Mods
  • Policy Packs
  • Docs
  • Home
ModsPolicy PacksDocsHome
Mods
Azure
Loading policies...

Policy: Azure > App Service > Web App > Managed Identity > User Assigned Identity

The resource IDs of the user-assigned managed identities required for Azure > App Service > Web App.

Used by the Per Managed Identity > User Assigned Identity values of the Azure > App Service > Web App > Managed Identity policy: the Web App's user-assigned identities must exactly match this list. When enforcing, the missing identities are assigned and identities not in the list are removed. Resource IDs are compared case-insensitively.

Please make sure the Guardrails identity has permission to assign these identities (Microsoft.ManagedIdentity/userAssignedIdentities/assign/action) when enforcing.

example: - /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/my-group/providers/Microsoft.ManagedIdentity/userAssignedIdentities/my-identity

Targets

This policy targets the following resource types:

  • Azure > App Service > Web App

Primary Policy

This policy is used with the following primary policy:

  • Azure > App Service > Web App > Managed Identity

Controls

Setting this policy configures this control:

  • Azure > App Service > Web App > Managed Identity

Policy Specification

Schema Type
array

Category

  • IAM

In Your Workspace

  • Policy Settings by Type report

Developers

    Category URI
    • tmod:@turbot/turbot#/control/categories/iam
  • Policy Type URI
    • tmod:@turbot/azure-appservice#/policy/types/webAppManagedIdentityUserAssignedIdentity
  • GraphQL
    • query policyType(id: "tmod:@turbot/azure-appservice#/policy/types/webAppManagedIdentityUserAssignedIdentity") { … }
    • query policySettings(filter: "policyTypeId:'tmod:@turbot/azure-appservice#/policy/types/webAppManagedIdentityUserAssignedIdentity'") { … }
    • query policyValues(filter: "policyTypeId:'tmod:@turbot/azure-appservice#/policy/types/webAppManagedIdentityUserAssignedIdentity'") { … }
  • CLI
    • Get Policy Type
    • turbot graphql policy-type --id "tmod:@turbot/azure-appservice#/policy/types/webAppManagedIdentityUserAssignedIdentity"
    • Get Policy Settings
    • turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-appservice#/policy/types/webAppManagedIdentityUserAssignedIdentity"
Guardrails
Guardrails Hub
  • Hub
  • Docs
  • Blog
  • Changelog
Products
  • GuardrailsGuardrails
  • PipesPipes
  • SteampipeSteampipe
  • PowerpipePowerpipe
  • FlowpipeFlowpipe
  • TailpipeTailpipe
Turbot
  • Home
  • About us
  • We're hiring!
  • Contact us
Community

Our community of practitioners love to discuss cloud governance & security.

Slack logoJoin us on Slack →

System StatusLegalSecurity
Terms of UseSecurityPrivacy
49
Mods
207
Resource Types
3,634
Policies
1,946
Controls
103
Quick Actions
114
IAM