Skip to content
Security id

Managed identity naming convention

The CAF abbreviation for Managed identity is id. Names can be 3 to 128 characters long and allow alphanumerics, hyphens and underscores. The name must be unique within the resource group.

Naming rules

CAF abbreviation id
Length 3 to 128 characters
Allowed characters Alphanumerics (a-z, A-Z, 0-9), hyphens, underscores
Scope of uniqueness Unique within the resource group
CAF pattern id-{workload}-{environment}-{region}-{instance}

Rules follow Microsoft's resource naming rules and CAF abbreviations. Some resource types have extra start/end character restrictions, so verify against the official docs before locking in a convention.

Naming Security resources

Key Vault has its own guide covering its strict 24 character global uniqueness and soft delete name reservation. Managed identities are cheap to create and usually provisioned per app or per function rather than shared, so unlike most of this list, their naming should tie tightly to the specific workload they are attached to.

VPN Gateway and Bastion resources are typically one per hub or region rather than one per environment, name them for the network boundary they protect. The common mistake is naming managed identities generically, id-prod for example, when dozens end up in the same subscription and it becomes impossible to tell which resource an identity actually belongs to.

Example names

Generated by the same engine as the name generator, so length and character rules are already applied.

Scenario Generated name Length
Payments API, production id-payments-prod-eus-001 24/128
Web app, development id-webapp-dev-weu-002 21/128
Analytics with company prefix id-contoso-analytics-stage-uks-001 34/128

Naming in Terraform and Bicep

Build the name from variables so one module produces the right name in every environment.

Terraform
locals {
  managed_identity_name = "id-${var.workload}-${var.environment}-${var.region}-001"
}
Bicep
var managedIdentityName = 'id-${workload}-${environment}-${region}-001'

Generate Managed identity names for your workload

Free, no login. Validation and Terraform, Bicep, or CSV export included.

Open in the generator →

Related Security resources

See the full list of Azure resource naming rules or read the complete CAF naming guide.