Azure Identity library for .NET
Authentication library for Azure SDK clients using Microsoft Entra ID.
Installation
Environment Variables
Service Principal with Secret
Service Principal with Certificate
Managed Identity
DefaultAzureCredential
The recommended credential for most scenarios. Tries multiple authentication methods in order. See DefaultAzureCredential overview for the current credential chain order and defaults.
Basic Usage
ASP.NET Core with Dependency Injection
Customizing DefaultAzureCredential
Credential Types
ManagedIdentityCredential (Production)
ClientSecretCredential
ClientCertificateCredential
ChainedTokenCredential (Custom Chain)
Developer Credentials
Environment-Based Configuration
Sovereign Clouds
Credential Types Reference
Best Practices
1. Use Deterministic Credentials in Production
2. Reuse Credential Instances
3. Configure Retry Policies
4. Enable Logging for Debugging
Error Handling
Key Exceptions
Managed Identity Support
Supported Azure services:
- Azure App Service and Azure Functions
- Azure Arc
- Azure Cloud Shell
- Azure Kubernetes Service (AKS)
- Azure Service Fabric
- Azure Virtual Machines
- Azure Virtual Machine Scale Sets
Thread Safety
All credential implementations are thread-safe. A single credential instance can be safely shared across multiple clients and threads.

