Support assuming Entra ID App Registration Service Principals in Teleport Azure app access
Author: smallinskyCreated Aug 27, 2026Updated Sep 15, 2026
Labelsfeature-requestapplication-access
What would you like Teleport to do?
Support Teleport Azure CLI access flow to allow to Teleport users assume a Register App Service Principal Identity via Teleport Azure CLI access flow.
If a workaround exists, please include it.
Create a new user-assigned managed identity, assign it the same Azure RBAC role assignments as the target App Registration SP, and configure Teleport's azure_identities to reference that managed identity.
Source: gravitational/teleport