Run As Account vs Managed Identities

Bombbe 1,611 Reputation points
2021-11-08T13:46:09.447+00:00

I just saw update that Azure Automation support for Managed Identities is now generally available (azure-automation-managed-identities-ga). What are real benefits using Managed Identities vs Run As accounts? I still need to give permission to mg/subscription/rg level if I want control resources in many subscriptions. One benefit that I came up with is that if you use managed identities you don't need to renew certificates like you need to do with run as account and I don't have to specify the Run As connection object in your runbook code but that's like few lines of code which is really easy to copy + paste to new runbooks.

So do Managed Identities in reality offer something really good benefits so we could considered to migrate existing Run As accounts to Managed identities?

Azure Automation
Azure Automation
An Azure service that is used to automate, configure, and install updates across hybrid environments.
1,114 questions
0 comments No comments
{count} votes

Accepted answer
  1. Alan Kinane 16,786 Reputation points MVP
    2021-11-08T20:04:58.78+00:00

    I think you've answered your own question. Managed Identities require less maintenance than run as accounts as the credentials are managed for you by Azure. You enabled the managed identity and just assign the required access, Azure will look after the rest including renewals like you said.

    0 comments No comments

0 additional answers

Sort by: Most helpful