Is it safe (from a protocol/compatibiltiy point of view) to retrieve an access token using Azure.Identity and use it with WindowsAzure.Storage?
I am working on an application which use WindowsAzure.Storage to communicate with Azure Storage (blobs+queues). Currently the application use Account Name/AccessKey to authenticate.
I want to migrate from using AccountName/Access Keys to use Managed Service Identity, Interactive Browser Login or Certificate (depending on where the application is running). Main reason bing simplifying credential rotation.
I think the (deprecated) library Microsoft.Azure.Services.AppAuthentication could be used to accomplish this, but I wonder if it's safe to use Azure.Identity to perform the retrieval of the authentication token instead. Microsoft recommends to use Azure.Identity with new applications, but this library seems to be primarily focused on the new Azure.* client SDK:s (as opposed to WindowsAzure.Storage which I am using).
The below code works fine in a simple test, but I don't know if there would be any issues doing this:
var resourceId = "https://storage.azure.com/";
// Request access token via interactive browser
var browserCredential = new InteractiveBrowserCredential();
var accessToken = await browserCredential.GetTokenAsync(
new TokenRequestContext(scopes: new string[] { resourceId + "/.default" }) { }
);
// Use the access token to access Azure Storage
var tokenCredential = new TokenCredential(accessToken.Token);
var storageCredentials = new StorageCredentials(tokenCredential);
var account = new CloudStorageAccount(storageCredentials,"<mystorageaccount>","core.windows.net", true);
var queueClient = account.CreateCloudQueueClient();
var queue = queueClient.GetQueueReference("myqueue");
I know WindowsAzure.Storage is also deprecated and applications should upgrade to Azure.Storage, but it's not something I have to do a bit furher down the road (large application and the above has higher prio).