last sync: 2025-Oct-31 18:22:59 UTC

Azure Data Factory linked services should use system-assigned managed identity authentication when it is supported

Azure BuiltIn Policy definition

Source Azure Portal
Display name Azure Data Factory linked services should use system-assigned managed identity authentication when it is supported
Id f78ccdb4-7bf4-4106-8647-270491d2978a
Version 2.1.0
Details on versioning
Versioning Versions supported for Versioning: 1
2.1.0
Built-in Versioning [Preview]
Category Data Factory
Microsoft Learn
Description Using system-assigned managed identity when communicating with data stores via linked services avoids the use of less secured credentials such as passwords or connection strings.
Cloud environments AzureCloud = true
AzureUSGovernment = unknown
AzureChinaCloud = unknown
Available in AzUSGov Unknown, no evidence if Policy definition is/not available in AzureUSGovernment
Mode All
Type BuiltIn
Preview False
Deprecated False
Effect Default
Audit
Allowed
Audit, Deny, Disabled
RBAC role(s) none
Rule aliases IF (9)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.DataFactory/factories/linkedservices/AzureBlobFS.typeProperties.servicePrincipalCredential Microsoft.DataFactory factories/linkedservices properties.typeProperties.servicePrincipalCredential True False
Microsoft.DataFactory/factories/linkedservices/AzureBlobStorage.typeProperties.credential.type Microsoft.DataFactory factories/linkedservices properties.typeProperties.credential.type True False
Microsoft.DataFactory/factories/linkedservices/AzureSqlDW.typeProperties.servicePrincipalKey Microsoft.DataFactory factories/linkedservices properties.typeProperties.servicePrincipalKey True False
Microsoft.DataFactory/factories/linkedservices/AzureStorage.typeProperties.accountKey Microsoft.DataFactory factories/linkedservices properties.typeProperties.accountKey True False
Microsoft.DataFactory/factories/linkedservices/AzureStorage.typeProperties.sasUri Microsoft.DataFactory factories/linkedservices properties.typeProperties.sasUri True False
Microsoft.DataFactory/factories/linkedservices/Hubspot.typeProperties.accessToken Microsoft.DataFactory factories/linkedservices properties.typeProperties.accessToken True False
Microsoft.DataFactory/factories/linkedservices/type Microsoft.DataFactory factories/linkedservices properties.type True False
Microsoft.DataFactory/factories/linkedservices/typeProperties.connectionString Microsoft.DataFactory factories/linkedservices properties.typeProperties.connectionString True False
Microsoft.DataFactory/factories/linkedservices/typeProperties.encryptedCredential Microsoft.DataFactory factories/linkedservices properties.typeProperties.encryptedCredential True False
Rule resource types IF (1)
Compliance
The following 1 compliance controls are associated with this Policy definition 'Azure Data Factory linked services should use system-assigned managed identity authentication when it is supported' (f78ccdb4-7bf4-4106-8647-270491d2978a)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
Azure_Security_Benchmark_v3.0 IM-3 Azure_Security_Benchmark_v3.0_IM-3 Microsoft cloud security benchmark IM-3 Identity Management IM-3 Manage application identities securely and automatically Shared **Security Principle:** Use managed application identities instead of creating human accounts for applications to access resources and execute code. Managed application identities provide benefits such as reducing the exposure of credentials. Automate the rotation of credential to ensure the security of the identities. **Azure Guidance:** Use Azure managed identities, which can authenticate to Azure services and resources that support Microsoft Entra ID authentication. Managed identity credentials are fully managed, rotated, and protected by the platform, avoiding hard-coded credentials in source code or configuration files. For services that don't support managed identities, use Microsoft Entra ID to create a service principal with restricted permissions at the resource level. It is recommended to configure service principals with certificate credentials and fall back to client secrets for authentication. **Implementation and additional context:** Azure managed identities: https://docs.microsoft.com/azure/active-directory/managed-identities-azure-resources/overview Services that support managed identities for Azure resources: https://docs.microsoft.com/azure/active-directory/managed-identities-azure-resources/services-support-managed-identities Azure service principal: https://docs.microsoft.com/powershell/azure/create-azure-service-principal-azureps Create a service principal with certificates: https://docs.microsoft.com/azure/active-directory/develop/howto-authenticate-service-principal-powershell n/a link 15
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type polSet in AzUSGov
[Preview]: Microsoft cloud security benchmark v2 e3ec7e09-768c-4b64-882c-fcada3772047 Security Center Preview BuiltIn unknown
Enforce recommended guardrails for Data Factory Enforce-Guardrails-DataFactory Data Factory GA ALZ
History
Date/Time (UTC ymd) (i) Change type Change detail
2023-09-01 18:00:13 change Minor (2.0.0 > 2.1.0)
2023-01-13 18:06:06 change Version remains equal, old suffix: preview (2.0.0-preview > 2.0.0)
2021-11-12 16:23:07 change Major, suffix remains equal (1.0.0-preview > 2.0.0-preview)
2021-02-10 14:43:58 add f78ccdb4-7bf4-4106-8647-270491d2978a
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC