Confusing Identity Authentication Messages

usabilityActiveRising

The Azure CLI incorrectly states a system-assigned identity is used instead of a user-assigned identity, leading to potential misconfigurations.

Opportunity Score (Heuristic (unvalidated)):64 · High · heuristic
First seen: 6/15/2021
Last seen: 9/3/2026

Score Breakdown

Heuristic ranking from public discussion signals — not a validated prediction of commercial opportunity, demand, or willingness to pay.

Composite 64/100 (High, unvalidated). Top driver: Willingness to pay (30% weight, 19.5 pts).

Frequency · 25% · 13.3 pts · XPS relevance53

Heuristic only — often urgency map or random scaffolding on ingest, not measured mention frequency. Maps to XPS relevance (with market size).

Severity · 25% · 17.5 pts · XPS quality70

LLM/mock judgment of intensity from title/summary text — not ops or ticket data. Maps to XPS quality (with willingness to pay).

Willingness to pay · 30% · 19.5 pts · XPS quality65

LLM/mock purchase-intent guess from text — not invoices, surveys, or paid seats. Maps to XPS quality.

Trend · 10% · 6.8 pts · XPS novelty68

Heuristic/scaffold (often random or fixed on insert) — not a verified mention trajectory. Maps to XPS novelty.

Market size · 10% · 6.7 pts · XPS relevance67

Heuristic/scaffold (often random or fixed) — not TAM research. Maps to XPS relevance (with frequency).

Catalog notes (not predictive analysis)

Confusing Identity Authentication Messages (usability). Catalog heuristic opportunity score: 64/100 — a chosen formula over discussion-signal facets, not evidence of demand, conversion, or willingness to pay. Treat as browsing rank, not a commercial prediction.

The Azure CLI incorrectly states a system-assigned identity is used instead of a user-assigned identity, leading to potential misconfigurations.

Source Examples

azure/azure-cli Issues·Jun 15, 2021
“Response from "az login --identity" can display confusing message > ### `az feedback` auto-generates most of the information requested below, as of CLI version 2.0.62 **Describe the bug** When a managed identity is implicitly used to authenticate, a message can be displayed saying incorrectly, that a system assigned identity is being used, when it should say user-assigned. This only happens when there is a single user-assigned identity and no system-assigned identity <!--- A clear and concise description of what the bug is. ---> **To Reproduce** <!--- Steps to reproduce the behavior. ---> 1. Create an Azure VM 2. Associate it with a single user-assigned identity, ensure that system-assigned identity is not enabled 3. Access VM using shell 4. Install Azure CLI 5. Authenticate using `az login --identity` (as the user-assigned identity is the only one available, it is used) 6. observe that response says that system-assigned identity was used, instead of user-assigned identity ``` azureuser@temp1:~$ az login --identity [ { "environmentName": "AzureCloud", "homeTenantId": "<snip>", "id": "<snip>", "isDefault": true, "managedByTenants": [], "name": "Visual Studio Enterprise Subscription", "state": "Enabled", "tenantId": "<snip>", "user": { "assignedIdentityInfo": "MSI", "name": "systemAssignedIdentity", "type": "servicePrincipal" } } ] ``` 7. Authenticate using `az login --identity -u /subscriptions/<subscriptionId>/resourcegroups/<myRG>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/<myID>` 8. Observe that the response correctly references the user-assigned identity ``` azureuser@temp1:~$ az login --identity -u /subscriptions/<snip>/resourceGroups/Revocation/providers/Microsoft.ManagedIdentity/userAssignedIdentities/RevocationUAM [ { "environmentName": "AzureCloud", "homeTenantId": "<snip>", "id": "<snip>", "isDefault": true, "managedByTenants": [], "name": "Visual Studio Enterprise Subscription", "state": "Enabled", "tenantId": "<snip>", "user": { "assignedIdentityInfo": "MSIResource-/subscriptions/<snip>/resourceGroups/Revocation/providers/Microsoft.ManagedIdentity/userAssignedIdentities/RevocationUAM", "name": "userAssignedIdentity", "type": "servicePrincipal" } } ] ``` 9. Result - can cause confusion for new users whether the correct identity is being used / if the VM does actually have a system-assigned identity that is being used **Expected behavior** When a user-assigned identity is used to authenticate, the response should correctly contain the details of the identity, even if it was not explicitly referenced in the az login command through the `-u` parameter **Environment summary** * VM created from `Ubuntu Server 18.04 LTS` image in portal * Shell type: OSX terminal, connecting to VM by ssh * CLI installed using `curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash` * CLI version: ``` azure-cli 2.25.0 core 2.25.0 telemetry 1.0.6 Python location '/opt/az/bin/python3' Extensions directory '/home/azureuser/.azure/cliextensions' Python (Linux) 3.6.10 (default, Jun 11 2021, 05:19:38) [GCC 9.3.0] Legal docs and information: aka.ms/AzureCliLegal Your CLI is up-to-date. Please let us know how we are doing: https://aka.ms/azureclihats and let us know if you're interested in trying out our newest features: https://aka.ms/CLIUXstu ``` **Additional context** This only happens when there is a single user-assigned identity and no system-assigned identity. The overall behaviour is correct, it's just the message that is returned is confusing, possibly because the user-assigned identity has not been explicitly referenced in the login command. ”
— eoinshanley-microsoft↗

Competitive Landscape

  • Existing solutions are either too expensive or too limited
  • Most competitors target enterprise, leaving mid-market underserved
  • Community scripts and manual processes are the primary alternative

Recommended Next Steps

  1. ✓Validate pain intensity with 5-10 target customer interviews
  2. ✓Build minimal viable solution addressing the core workflow
  3. ✓Test pricing with early adopters from community forums

Related Pain Points

Target Customers

  • IT teams at mid-size organizations (100-2000 employees)
  • MSPs and consultants managing multiple client environments
  • Teams without dedicated specialist staff for this domain

Monetization Ideas

  1. 1SaaS subscription model ($99-$499/month depending on scale)
  2. 2Usage-based pricing aligned with value delivered
  3. 3Freemium tier to drive adoption and prove value