[Identity] Support Azure Arc user-assigned managed identity (UAMI) via MSAL
メンテナーはふだん 1 日以内に返信
@kashifkhan がすでに取り組んでいます。
2026年8月24日 から。
評価
この issue はまだ評価されていません。
説明
Background
MSAL Python now supports acquiring tokens for user-assigned managed identities (UAMI) on Azure Arc (MSAL Python 1.38.0). Historically Azure Arc only supported system-assigned managed identity (SAMI). This issue tracks enabling Arc UAMI in azure-identity (ManagedIdentityCredential and DefaultAzureCredential), for both sync and async.
azure-identity has two independent managed-identity stacks for Arc, and they need different work:
Current behavior
- Sync (MSAL)
AzureArcCredential(azure/identity/_credentials/azure_arc.py) extendsMsalManagedIdentityClientand delegates tomsal.ManagedIdentityClient(acquire_token_for_client,msal.UserAssignedManagedIdentity/SystemAssignedManagedIdentity). UAMI-on-Arc is gated by MSAL, so amsalversion bump is sufficient here. - Async (native, no MSAL)
AzureArcCredential(azure/identity/aio/_credentials/azure_arc.py) extendsAsyncManagedIdentityBaseand drives the customAsyncManagedIdentityClient(aio/_internal/managed_identity_client.py, built onbuild_async_pipeline) plusArcChallengeAuthPolicy. MSAL Python is sync-only, so the async path cannot delegate to MSAL and will NOT inherit Arc UAMI from the dependency bump — it needs its own code change. - Explicit block:
_get_requestin_credentials/azure_arc.py(imported and used by the async credential) raisesClientAuthenticationError("User assigned managed identities are not supported by Azure Arc...")wheneveridentity_configis set.ManagedIdentityClientBase.__init__foldsclient_idintoself._identity_config, so this trips for client id, object id, and resource id. This block is effectively async-only now (the sync credential goes through MSAL and no longer calls_get_request).
Net effect: sync needs only a dependency uptake; async (native) needs the explicit block removed, the id sent as the correct query parameter, and behavior aligned with the MSAL/sync path.
Scope of work
Sync (MSAL)
- Bump
msaldependency to>= 1.38.0. - Verify Arc UAMI token acquisition (client id, and resource/object id as supported).
Async (native, no MSAL)
- Remove the explicit UAMI-on-Arc block in
_get_request(_credentials/azure_arc.py). - Send the user-assigned id as the correct Arc query parameter — map the
resource_idkey to the Arc param name (mi_res_id/msi_res_id);client_id/object_idnames are already correct. Confirm theapi-version(currently2020-06-01) honors UAMI and matches what MSAL sends on the sync side. - (Alternative) Consider delegating the async path to MSAL via
run_in_executorfor behavioral parity with sync, instead of maintaining the native implementation (larger change; adds thread-pool overhead). - Update async tests (e.g.
test_azure_arc*/ aio variants) that currently assert Arc UAMI is rejected.
Shared
- Keep sync (MSAL) and async (native) consistent on query-param names, api-version, and endpoint handling.
- Update CHANGELOG (and README if it documents Arc as system-assigned-only).
Key references
sdk/identity/azure-identity/azure/identity/_credentials/azure_arc.pysdk/identity/azure-identity/azure/identity/aio/_credentials/azure_arc.pysdk/identity/azure-identity/azure/identity/aio/_internal/managed_identity_client.pysdk/identity/azure-identity/azure/identity/_internal/managed_identity_client.pysdk/identity/azure-identity/azure/identity/_internal/msal_managed_identity_client.py
- 主要言語
- Python
- スター
- 5.6k
- フォーク
- 3.4k
- 平均マージ
- 1日 18時間
- マージ済み PR(30日)
- 214
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
Azure/azure-sdk-for-python のほかの issue
-
Evaluation Service Attention
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
Azure/azure-sdk-for-python#49190 · コメント 1 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Update CODEOWNERSオープン
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
Azure/azure-sdk-for-python#49183 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Evaluation Service Attention
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
Azure/azure-sdk-for-python#49153 · コメント 1 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Search Service Attention
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
Azure/azure-sdk-for-python#48555 · コメント 1 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Azure.Core customer-reported feature-request needs-team-attention
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
Azure/azure-sdk-for-python#47186 ·
メンテナーはふだん 1 日以内に返信
Azure/azure-sdk-for-python の issue をすべて見る
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
letsencrypt/cp-cps#353 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
PedestrianDynamics/pyFDS-Evac#394 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
DOI-USGS/pywatershed#421 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
python-pillow/Pillow#10087 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信