Policy: Azure > App Service > Web App > Managed Identity > User Assigned Identity
The resource IDs of the user-assigned managed identities required for Azure > App Service > Web App.
Used by the Per Managed Identity > User Assigned Identity values of the Azure > App Service > Web App > Managed Identity policy: the Web App's user-assigned identities must exactly match this list. When enforcing, the missing identities are assigned and identities not in the list are removed. Resource IDs are compared case-insensitively.
Please make sure the Guardrails identity has permission to assign these identities (Microsoft.ManagedIdentity/userAssignedIdentities/assign/action) when enforcing.example: - /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/my-group/providers/Microsoft.ManagedIdentity/userAssignedIdentities/my-identity
Targets
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Controls
Setting this policy configures this control:
Policy Specification
Schema Type | |
|---|
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/iam
- tmod:@turbot/azure-appservice#/policy/types/webAppManagedIdentityUserAssignedIdentity
- turbot graphql policy-type --id "tmod:@turbot/azure-appservice#/policy/types/webAppManagedIdentityUserAssignedIdentity"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-appservice#/policy/types/webAppManagedIdentityUserAssignedIdentity"
Get Policy TypeGet Policy Settings