gpt4 book ai didi

azure-active-directory - Azure Managed IDentity - 本地应用程序

转载 作者:行者123 更新时间:2023-12-05 02:38:29 24 4
gpt4 key购买 nike

  1. 我们有几个使用 .NET 构建的应用程序在 VMS(本地)中运行
  2. 所有应用程序都将注册到 Azure AD。
  3. 我们能否使用用户管理的身份从这些本地应用访问 keystore

提前致谢

最佳答案

不可以,您不能使用本地应用中的托管身份。

[...] a managed identity is a service principal of a special type that may only be used with Azure resources.

Source: What are managed identities for Azure resources?

要查看当前支持的资源列表,请参阅 Services that support managed identities for Azure resources .

但是,您可以使用 Service Principal从本地运行的应用程序连接到 Key Vault。
为此,Use the portal to create an Azure AD application and service principal that can access resources .

对于服务主体,可以通过两种不同的方式进行身份验证:基于密码的身份验证(应用程序 secret )和基于证书的身份验证。建议使用证书,但您也可以创建应用程序 secret 。

To access resources that are secured by an Azure AD tenant, the entity that requires access must be represented by a security principal. This requirement is true for both users (user principal) and applications (service principal). The security principal defines the access policy and permissions for the user/application in the Azure AD tenant. This enables core features such as authentication of the user/application during sign-in, and authorization during resource access.

If you cannot use managed identity, you instead register the application with your Azure AD tenant, as described on Quickstart: Register an application with the Azure identity platform. Registration also creates a second application object that identifies the app across all tenants.

关于azure-active-directory - Azure Managed IDentity - 本地应用程序,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/69542069/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com