saif-resources / identity
Creates the standard Forge identity pair for services: a User-Assigned Managed Identity (UAMI) for platform concerns and an Entra ID App Registration for runtime concerns.
Usage
module "identity" {
source = "app.terraform.io/SAIFCorp/resources/saif//modules/identity"
version = "~> 1.0.0"
providers = {
azurerm = azurerm
azurerm.shared-services = azurerm.shared-services
azuread = azuread
}
context = module.environment.context
name = var.project_id
# For services needing AI Hub + AI Search access
ai_hub_roles = true
# For services calling Document Intelligence prebuilt models on the AI Hub
document_intelligence_roles = true
# For Teams bots needing admin-consented Graph scopes
grant_admin_consent = true
api_permissions = [
{ api_name = "Microsoft Graph", permission_name = "User.Read", type = "Scope" }
]
}
Outputs
Name
Description
identity
Structured object with UAMI and App Registration references
Identity Object Shape
identity.uami_id / identity.uami_client_id / identity.uami_principal_id
identity.app_client_id / identity.app_object_id
identity.sp_principal_id / identity.sp_object_id
identity.client_secret_kv_ref — @Microsoft.KeyVault() reference string
identity.client_secret_kv_uri — versionless secret URI
Required Providers
azurerm (>= 4.0, < 5.0) — with azurerm.shared-services alias
azuread (>= 3.0, < 4.0)
Providers
Name
Description
Type
Default
Required
ai_hub_roles
Whether to grant AI Hub and AI Search roles to the service principal
bool
false
no
api_permissions
API permissions to request on the app registration
list(object({ api_name = string permission_name = string type = string }))
[]
no
context
Platform context from the environment module
any
n/a
yes
create_client_secret
Whether to create a client secret for the app registration
bool
true
no
document_intelligence_roles
Whether to grant Document Intelligence data-plane access on the AI Hub to the service principal
bool
false
no
enable_agents_sdk
Whether to emit Connections__ServiceConnection__* app settings for the M365 Agents SDK
bool
false
no
enable_oidc
Whether to emit OpenIdConnectClientId_{tenant} / OpenIdConnectClientSecret_{tenant} app settings
bool
false
no
grant_admin_consent
Whether to grant admin consent for API permissions
bool
false
no
microsoft_app_type
Bot Framework app type — set to emit MicrosoftApp* app settings. Values: SingleTenant, MultiTenant.
string
null
no
name
Application name used for identity resources (e.g. project_id)
string
n/a
yes
owners
Map of Entra ID object IDs to set as application owners. Keyed by a stable name. Defaults to the current caller.
map(string)
{}
no
redirect_uris
Redirect URIs for the app registration (e.g. OAuth2 callback URLs)
list(string)
[]
no
resource_group_location
The Azure region for identity resources
string
n/a
yes
resource_group_name
The resource group for identity resources (UAMI)
string
n/a
yes
visible_to_users
Whether the enterprise application appears on users' My Apps page. Controls feature_tags.hide on the service principal. Defaults to hidden, which is correct for APIs, bots, and background consumers; set true only for apps users sign in to directly.
bool
false
no
web_logout_url
Post-logout redirect URL for the app registration
string
null
no
Outputs
Name
Description
app_settings
Map of credential-related app settings, controlled by flag variables. Merge into webapp app_settings.
client_secret_value
The app registration client secret value. Sensitive — use only where the actual value is required (e.g. Bot OAuth connections). Prefer identity.client_secret_kv_ref for app settings.
identity
Identity bundle — UAMI + App Registration references (no sensitive values)
Resources
resource.azurerm_key_vault_secret.client_secret (/terraform-docs/modules/identity/main.tf#41)
resource.azurerm_role_assignment.acr_pull (/terraform-docs/modules/identity/main.tf#66)
resource.azurerm_role_assignment.app_configuration_reader (/terraform-docs/modules/identity/main.tf#76)
resource.azurerm_role_assignment.client_secret_reader (/terraform-docs/modules/identity/main.tf#50)
resource.azurerm_role_assignment.cognitive_services_openai_user (/terraform-docs/modules/identity/main.tf#128)
resource.azurerm_role_assignment.cognitive_services_user (/terraform-docs/modules/identity/main.tf#152)
resource.azurerm_role_assignment.otel_header_np_sp (/terraform-docs/modules/identity/main.tf#109)
resource.azurerm_role_assignment.otel_header_np_uami (/terraform-docs/modules/identity/main.tf#93)
resource.azurerm_role_assignment.otel_header_prod_sp (/terraform-docs/modules/identity/main.tf#117)
resource.azurerm_role_assignment.otel_header_prod_uami (/terraform-docs/modules/identity/main.tf#101)
resource.azurerm_role_assignment.search_index_data_reader (/terraform-docs/modules/identity/main.tf#136)
resource.azurerm_role_assignment.search_service_contributor (/terraform-docs/modules/identity/main.tf#144)
resource.azurerm_user_assigned_identity.main (/terraform-docs/modules/identity/main.tf#14)
View source on GitHub