logo

Database

Azure Api Management Managed Identity Not Used

Description

Detects Azure API Management services that are not configured to use managed identities. Managed identities provide a secure way for API Management services to access other Azure resources without storing credentials, reducing security risks from exposed secrets and improving access management.

Weakness:

446 - Insecure service configuration - Azure

Category: Functionality Abuse

Detection Strategy

    Scans all API Management services in the Azure subscription

    Reports a vulnerability when an API Management service has no identity configuration (identity field is missing or null)

    Each reported vulnerability includes the service's resource ID and current identity configuration state