A managed identity is an Entra service principal that Azure binds to a resource and whose credentials the platform rotates. Any code running on the resource can ask the local metadata endpoint for a token for that identity, so controlling the resource means acting as the identity with all of its RBAC. Managed identities are the engine behind most Azure escalation and lateral movement.
The two kinds#
- System-assigned: created with and tied to one resource, deleted with it.
- User-assigned: a standalone identity that can be attached to many resources, so its compromise is reusable.
Obtaining the token is a credentials technique (the IMDS endpoint); attaching a privileged identity to a resource you control is the managed identity assignment escalation.