GuideInformationCybersecurityIT

Map both identities in the managed-application storage encryption recipe

Which grant connects a managed application's identity to the separate identity that can use its storage encryption key?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Which grant connects a managed application's identity to the separate identity that can use its storage encryption key?

Potentially affected

The documented preview user-assigned identity path for a managed application deploying CMK-encrypted storage from an existing key vault.

DSE recommendation

DSE recommends drawing the two identity-to-resource grants explicitly before approving this deployment.

Source facts

For storage deployed in a managed application’s resource group with a customer-managed key, Microsoft’s recipe requires a user-assigned identity. The managed application’s identity needs Managed Identity Operator on the separate identity that accesses the existing key vault. The example gives that key-access identity the Key Vault Crypto Service Encryption User role on the vault. The documented user-assigned identity interface is labeled preview. Microsoft Learn.

Applicability

Keep this review within the documented preview identity-integration path. Distinguish the managed application’s principal from the principal that uses the key. Do not substitute the deployment operator’s own vault access for either runtime identity or assume that a shared display name makes them equivalent.

DSE recommendation

DSE recommends drawing the two identity-to-resource grants explicitly before approving this deployment. Record the application identity, key-access identity, vault and key identifiers, and the scope of each approved role. Have both the application and key owners confirm the relationship. Review the source’s remaining vault and deployment prerequisites separately; this grant map does not replace that preparation.

Verification

In a controlled deployment, inspect the identity assigned to the managed application and the identity selected in the storage account’s encryption configuration. Compare their actual role assignments with the approved map, then exercise an authorized storage operation. Keep only identifiers and permission evidence, never key values. Resolve any mismatched principal or scope before broader rollout.

Official references

Microsoft Learn. Source retrieved September 9, 2026.

Primary reference

Review the official source

Create Azure Managed Application that deploys storage account encrypted with customer-managed key - Azure Managed Applications | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE