[Identity] Support Azure Arc user-assigned managed identity (UAMI) via MSAL
Los mantenedores suelen responder en 1 día
@kashifkhan ya está trabajando en esto.
Desde el 24/8/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
Background
MSAL Python now supports acquiring tokens for user-assigned managed identities (UAMI) on Azure Arc (MSAL Python 1.38.0). Historically Azure Arc only supported system-assigned managed identity (SAMI). This issue tracks enabling Arc UAMI in azure-identity (ManagedIdentityCredential and DefaultAzureCredential), for both sync and async.
azure-identity has two independent managed-identity stacks for Arc, and they need different work:
Current behavior
- Sync (MSAL)
AzureArcCredential(azure/identity/_credentials/azure_arc.py) extendsMsalManagedIdentityClientand delegates tomsal.ManagedIdentityClient(acquire_token_for_client,msal.UserAssignedManagedIdentity/SystemAssignedManagedIdentity). UAMI-on-Arc is gated by MSAL, so amsalversion bump is sufficient here. - Async (native, no MSAL)
AzureArcCredential(azure/identity/aio/_credentials/azure_arc.py) extendsAsyncManagedIdentityBaseand drives the customAsyncManagedIdentityClient(aio/_internal/managed_identity_client.py, built onbuild_async_pipeline) plusArcChallengeAuthPolicy. MSAL Python is sync-only, so the async path cannot delegate to MSAL and will NOT inherit Arc UAMI from the dependency bump — it needs its own code change. - Explicit block:
_get_requestin_credentials/azure_arc.py(imported and used by the async credential) raisesClientAuthenticationError("User assigned managed identities are not supported by Azure Arc...")wheneveridentity_configis set.ManagedIdentityClientBase.__init__foldsclient_idintoself._identity_config, so this trips for client id, object id, and resource id. This block is effectively async-only now (the sync credential goes through MSAL and no longer calls_get_request).
Net effect: sync needs only a dependency uptake; async (native) needs the explicit block removed, the id sent as the correct query parameter, and behavior aligned with the MSAL/sync path.
Scope of work
Sync (MSAL)
- Bump
msaldependency to>= 1.38.0. - Verify Arc UAMI token acquisition (client id, and resource/object id as supported).
Async (native, no MSAL)
- Remove the explicit UAMI-on-Arc block in
_get_request(_credentials/azure_arc.py). - Send the user-assigned id as the correct Arc query parameter — map the
resource_idkey to the Arc param name (mi_res_id/msi_res_id);client_id/object_idnames are already correct. Confirm theapi-version(currently2020-06-01) honors UAMI and matches what MSAL sends on the sync side. - (Alternative) Consider delegating the async path to MSAL via
run_in_executorfor behavioral parity with sync, instead of maintaining the native implementation (larger change; adds thread-pool overhead). - Update async tests (e.g.
test_azure_arc*/ aio variants) that currently assert Arc UAMI is rejected.
Shared
- Keep sync (MSAL) and async (native) consistent on query-param names, api-version, and endpoint handling.
- Update CHANGELOG (and README if it documents Arc as system-assigned-only).
Key references
sdk/identity/azure-identity/azure/identity/_credentials/azure_arc.pysdk/identity/azure-identity/azure/identity/aio/_credentials/azure_arc.pysdk/identity/azure-identity/azure/identity/aio/_internal/managed_identity_client.pysdk/identity/azure-identity/azure/identity/_internal/managed_identity_client.pysdk/identity/azure-identity/azure/identity/_internal/msal_managed_identity_client.py
- Lenguaje dominante
- Python
- Estrellas
- 5.6k
- Forks
- 3.4k
- Merge medio
- 1 d 18 h
- PR fusionados (30 d)
- 202
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de Azure/azure-sdk-for-python
-
Evaluation Service Attention
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Azure/azure-sdk-for-python#49190 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Update CODEOWNERSAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
Azure/azure-sdk-for-python#49183 · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Evaluation Service Attention
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Azure/azure-sdk-for-python#49153 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Search Service Attention
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
Azure/azure-sdk-for-python#48555 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Azure.Core customer-reported feature-request needs-team-attention
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Azure/azure-sdk-for-python#47186 ·
Los mantenedores suelen responder en 1 día
Todos los issues de Azure/azure-sdk-for-python
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
PedestrianDynamics/pyFDS-Evac#343 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
theskumar/python-dotenv#708 ·
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
Los mantenedores suelen responder en 2 días
-
Docs Timedelta
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
pandas-dev/pandas#69919 ·
Los mantenedores suelen responder en 1 día
-
API documentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
zephyrproject-rtos/west#1009 · 2 comentarios ·
Los mantenedores suelen responder en 3 días