# Map both identities in the managed-application storage encryption recipe

> Which grant connects a managed application's identity to the separate identity that can use its storage encryption key?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-213-map-both-identities-in-the-managed-application-storage-encryption-recipe/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:23+00:00
- Modified: 2026-09-10T01:20:45+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Which grant connects a managed application's identity to the separate identity that can use its storage encryption key?

## Potentially affected

The documented preview user-assigned identity path for a managed application deploying CMK-encrypted storage from an existing key vault.

## DSE recommendation

DSE recommends drawing the two identity-to-resource grants explicitly before approving this deployment.

## Article

## Source facts

For storage deployed in a managed application’s resource group with a customer-managed key, Microsoft’s recipe requires a user-assigned identity. The managed application’s identity needs Managed Identity Operator on the separate identity that accesses the existing key vault. The example gives that key-access identity the Key Vault Crypto Service Encryption User role on the vault. The documented user-assigned identity interface is labeled preview. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/create-storage-customer-managed-key).

## Applicability

Keep this review within the documented preview identity-integration path. Distinguish the managed application’s principal from the principal that uses the key. Do not substitute the deployment operator’s own vault access for either runtime identity or assume that a shared display name makes them equivalent.

## DSE recommendation

DSE recommends drawing the two identity-to-resource grants explicitly before approving this deployment. Record the application identity, key-access identity, vault and key identifiers, and the scope of each approved role. Have both the application and key owners confirm the relationship. Review the source’s remaining vault and deployment prerequisites separately; this grant map does not replace that preparation.

## Verification

In a controlled deployment, inspect the identity assigned to the managed application and the identity selected in the storage account’s encryption configuration. Compare their actual role assignments with the approved map, then exercise an authorized storage operation. Keep only identifiers and permission evidence, never key values. Resolve any mismatched principal or scope before broader rollout.

## Official references

[Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/create-storage-customer-managed-key). Source retrieved September 9, 2026.

## Primary reference

- Name: Create Azure Managed Application that deploys storage account encrypted with customer-managed key - Azure Managed Applications | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/create-storage-customer-managed-key
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Map both identities in the managed-application storage encryption recipe,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-213-map-both-identities-in-the-managed-application-storage-encryption-recipe/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
