TL;DR: This is almost always a namespace-package collision: an old azure/__init__.py (from legacy azure-mgmt packages) shadows the real namespace, or pip installed into a different interpreter than the one running your code. Reinstall azure-identity and verify the interpreter match.

```text
ModuleNotFoundError: No module named 'azure.identity'
```

## Fix it

1. Confirm interpreter alignment: python -m pip show azure-identity and python -c "import sys; print(sys.executable)". Expected: the pip belongs to the same interpreter running your code. If not, use python -m pip for everything.
2. Look for a shadowing namespace package: python -c "import azure; print(azure.__path__)". If it points at an old azure-mgmt install with __init__.py, uninstall the legacy packages: pip uninstall azure-mgmt-common azure-common. Expected: azure.__path__ then resolves to the namespace install.
3. Reinstall cleanly: pip install --force-reinstall azure-identity. Expected: the import works.
4. In Docker, make sure you are not copying an old site-packages over the new install.

## When this applies
- pip shows azure-identity installed but the import fails.
- Multiple azure-* packages are installed, some of them legacy.

## When it doesn't
- pip does not show azure-identity: just pip install azure-identity.
- The import works but token calls fail: that is a credential problem.

## Compatibility
- azure-identity any recent version; Python 3.8+.

## Why it happens
Azure SDK packages share the azure.* namespace. Legacy packages shipped a real azure/__init__.py using pkg_resources namespace tricks, which blocks the modern PEP 420 namespace layout and hides azure.identity.

## Edge cases
- Conda envs with pip-installed azure packages are a classic trigger; prefer one installer per env.
- If you vendor dependencies, include the .dist-info directories; namespace resolution needs them.
