Open Closed

Support for Azure Blob Storage Authentication using Managed Identity instead of Connection String #10707


User avatar
0
tuanle created

Hello ABP Team,

We are currently using ABP Framework with Azure Blob Storage integration and would like to implement authentication to Azure Storage using a System-Assigned Managed Identity instead of a connection string.

We have been following Microsoft's guidance: https://learn.microsoft.com/en-us/dotnet/azure/sdk/authentication/system-assigned-managed-identity

Our goal is to eliminate storage account keys and connection strings and use Azure Managed Identity for improved security and compliance.

We have a few questions:

  1. Does the current ABP Azure Blob Storage module support authentication through Azure Managed Identity (DefaultAzureCredential / ManagedIdentityCredential)?

  2. If it is not currently supported, is there any recommended extension point or customization approach for replacing the default BlobServiceClient initialization with a Managed Identity-based implementation?

  3. Are there any plans on the ABP roadmap to support Azure SDK credential-based authentication for Azure Storage?

  4. Has the ABP team published any sample projects, documentation, or best practices demonstrating Azure Storage integration using Managed Identity?

Our current environment:

  • ABP Framework Version: 10.2.0
  • Azure App Service with System-Assigned Managed Identity enabled
  • Azure Storage Account
  • Azure Blob Storage Provider

We attempted to customize the Azure Storage provider to use DefaultAzureCredential and ManagedIdentityCredential, but the storage operations are not working as expected.

Any guidance or recommended architecture would be greatly appreciated.

Thank you.

Markdown supported.
Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)

2 Answer(s)
  • User Avatar
    0
    AI-Bot created
    Support Team ABP Agent
    • (1) Managed Identity support in ABP’s Azure Blob provider (v10.2.0):
      In ABP 10.2, the built-in Azure Blob Storage provider is configured via azure.ConnectionString and the documentation describes it as using the connection string (shared key) model. There is no documented option (in ABP 10.2 docs) to pass an Azure.Core.TokenCredential (e.g., DefaultAzureCredential / ManagedIdentityCredential) to the provider.

    • (2) Recommended extension/customization point:
      ABP explicitly documents that AzureBlobProvider is the main class and can be overridden/replaced via dependency injection (replace the AzureBlobProvider class, not IBlobProvider). So the supported approach is:

      1. Create your own provider class (either replace AzureBlobProvider via DI or create a custom blob provider).
      2. In your implementation, initialize BlobServiceClient using new BlobServiceClient(new Uri(accountUrl), new DefaultAzureCredential()) (or ManagedIdentityCredential) and implement required blob operations.

      Practically, the most “ABP-aligned” options are:

      • Replace AzureBlobProvider via DI (recommended if you want to keep container.UseAzure(...) configuration style and just change authentication/initialization internals).
      • Or create a custom provider and switch containers to ProviderType = typeof(YourProvider) (recommended if you want a clean separation and your own strongly-typed provider configuration options).
    • (3) Roadmap plans:
      No verified source available for ABP’s roadmap regarding “Azure SDK credential-based authentication for Azure Storage” (Managed Identity / TokenCredential) in the built-in provider.

    • (4) Samples / best practices published by ABP:
      No verified official ABP sample/documentation demonstrating Azure Blob Storage integration using Managed Identity. The available docs and community articles primarily show connection-string based configuration.

    Links (validated):

    • https://abp.io/docs/10.2/framework/infrastructure/blob-storing/azure
    • https://abp.io/docs/10.2/framework/infrastructure/blob-storing/custom-provider
    • https://learn.microsoft.com/en-us/dotnet/azure/sdk/authentication/system-assigned-managed-identity

    This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    maliming created
    Support Team Fullstack Developer

    Hi,

    There's no built-in Managed Identity option in the Azure blob provider yet — the config only takes a connection string. But you can plug in DefaultAzureCredential by overriding AzureBlobProvider, since GetBlobContainerClient is protected virtual. We may add native support for this in a future release.

    Here's a working override (I verified it builds against Volo.Abp.BlobStoring.Azure 10.2.0 + Azure.Identity):

    using System;
    using Azure.Identity;
    using Azure.Storage.Blobs;
    using Volo.Abp.BlobStoring;
    using Volo.Abp.BlobStoring.Azure;
    using Volo.Abp.DependencyInjection;
    
    namespace MyCompanyName.MyProjectName;
    
    [Dependency(ReplaceServices = true)]
    [ExposeServices(typeof(IBlobProvider), typeof(AzureBlobProvider))]
    public class MyAzureBlobProvider : AzureBlobProvider
    {
        public MyAzureBlobProvider(
            IAzureBlobNameCalculator azureBlobNameCalculator,
            IBlobNormalizeNamingService blobNormalizeNamingService)
            : base(azureBlobNameCalculator, blobNormalizeNamingService)
        {
        }
    
        protected override BlobContainerClient GetBlobContainerClient(BlobProviderArgs args)
        {
            var configuration = args.Configuration.GetAzureConfiguration();
    
            // Reuse the existing ConnectionString slot to carry the storage account URL,
            // e.g. "https://<account-name>.blob.core.windows.net".
            var serviceUri = new Uri(configuration.ConnectionString);
            var credential = new DefaultAzureCredential();
    
            var blobServiceClient = new BlobServiceClient(serviceUri, credential);
    
            return blobServiceClient.GetBlobContainerClient(GetContainerName(args));
        }
    }
    

    In your container configuration just put the storage account URL where the connection string used to go:

    Configure<AbpBlobStoringOptions>(options =>
    {
        options.Containers.ConfigureDefault(container =>
        {
            container.UseAzure(azure =>
            {
                azure.ConnectionString = "https://<your-account>.blob.core.windows.net";
                azure.ContainerName = "my-container";
                azure.CreateContainerIfNotExists = true;
            });
        });
    });
    

    Make sure the App Service's System-Assigned Managed Identity is granted the Storage Blob Data Contributor role on the storage account — that's what DefaultAzureCredential will use at runtime. If you want to be explicit you can swap new DefaultAzureCredential() for new ManagedIdentityCredential().

    If you still see errors after this, set AZURE_LOG_LEVEL=verbose on the App Service to capture Azure.Identity diagnostic output and share the exception + relevant log snippet — we can take another look from there.

    Thanks

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with ❤️ on ABP v10.8.0-preview. Updated on September 28, 2026, 11:44
1
ABP Assistant
🔐 You need to be logged in to use the chatbot. Please log in first.