Managed identity vs service principal vs GITHUB_TOKEN vs OIDC federation
This sheet compares User-assigned MI, System-assigned MI, Service principal + secret, GITHUB_TOKEN, Workload identity federation.
| Criterion | User-assigned MI | System-assigned MI | Service principal + secret | GITHUB_TOKEN | Workload identity federation |
|---|---|---|---|---|---|
| Secret to store or rotate | None; Azure-managed | None; Azure-managed | Yes; expires and pages ops | None; auto-issued per job | None; secretless trust |
The verdict, the full comparison, 5 rules and 4 traps are part of AZ-400 access. Unlock AZ-400.