← Previous day

Next day →
Day in brief

11 September: Workload ID clarified RBAC boundaries and identity-deletion cleanup; no feature rollout

This was a documentation-focused day, with the most useful updates affecting Microsoft Entra Workload ID managed identities. Updated guidance clarifies service-specific Azure RBAC and data-plane support, and explains that deleting a user-assigned managed identity does not remove its resource references. Three Microsoft Learn pages were removed, but the supplied evidence does not indicate a preview, general-availability launch, security advisory, changed platform behavior, or retirement of an underlying capability.

  • The updated portal guidance says to grant managed-identity access through Azure RBAC and consult the specific service documentation, because some Azure services are still adopting Azure RBAC on the data plane. This is a documentation clarification rather than evidence of a new tenant-wide capability or setting; validate the supported access path for the service being configured.

  • The updated Azure CLI guidance states that deleting a user-assigned managed identity does not remove references to it from assigned resources. Those references must be removed from the resource itself; the page gives VM and virtual machine scale set identity-removal commands as examples. This clarifies operational behavior and is relevant to identity-deletion runbooks.

  • The Microsoft Learn page titled “Assign Access Azure Resource” was removed. The record identifies this as a documentation retirement, not a product-capability retirement, and does not identify a replacement. Administrators who use the page in internal procedures or links should locate and update those references.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

9 updates

1
1
4

Manage User Assigned Managed Identities Azure Cli

Updated

Deleting a user-assigned managed identity won't remove the reference from any resource it was assigned to. Remove those from the resource itself. For example, for a VM or virtual machine scale set, use the `az vm/vmss identity remove` command.

3

Grant Managed Identity Resource Access Azure Portal

Updated

The steps outlined below show how you grant access to a service using Azure RBAC. Check specific service documentation on how to grant access; for example, check [Azure Data Explorer](/azure/data-explorer/data-explorer-overview) for instructions. Some Azure services are in the process of adopting Azure RBAC on the data plane.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…