Microsoft Entra Workload ID

Assignment restriction for managed identities (preview)

In brief

Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

Note about supported Resource Providers

Assignment restriction for user-assigned managed identities (preview)

Assignment restrictions, also known as resource restrictions, are a security feature for user-assigned managed identities that limit the resource providers an identity can be assigned to. Assignment restrictions are currently in preview. They let you isolate a managed identity to one or more resource providers so that it can't be reused across unrelated services.

When you configure assignment restriction, managed identity usage stays tightly scoped. This scoping reduces the blast radius of a compromised or misconfigured identity and Resource Typeshelps improve both security and resilience.

  • Match managed identity scope to the intended source resources only.
  • Avoid reusing managed identities across unrelated workloads for convenience.

Supported resource providers and resource types in the Azure portal

If the resource provider or resource type you want to configure isn't listed in the Select Resource Types pane, use the Azure CLI. For configuration steps and command examples, see Configure assignment restriction for user-assigned managed identities.

Related content