Context: "Identity not found" is the Azure instance metadata service (IMDS) answering 400 when `ManagedIdentityCredential`, often inside `DefaultAzureCredential`, asks for a token for an identity the Azure fabric has not assigned to that resource. The fuller message usually reads "the requested identity isn't assigned to this resource". The fix is to assign the identity to the resource (or pass the correct
TL;DR: "Identity not found" is the Azure instance metadata service answering 400 because the managed identity your code asked for is not assigned to this resource. Assign the identity (or fix the client id), wait a few minutes for propagation, then retry. This is almost never an RBAC or permissions problem.


1. Read the full error and note which identity was requested. If you constructed the credential with a client id, that is the one being looked up. If not, it is the resource's default identity.

2. Verify the identity is assigned to this resource. For a VM, run:

```
az vm identity show --resource-group YOUR_RG --name YOUR_VM
```

For App Service or Functions, check the Identity blade in the portal, or run:

```
az webapp identity show --resource-group [your resource group] --name [your app]
```

For Container Apps:

```
az containerapp identity show --resource-group [your resource group] --name [your app]
```

If the listing is empty, or your client id is missing from it, that is the cause. On AKS with workload identity, check the service account annotation instead:

```
kubectl describe sa [your service account] -n [your namespace]
```

The annotation value must match the client id your code requests character for character.

3. Fix the assignment: enable the system-assigned identity on the resource, or attach your user-assigned identity to it, then confirm the client id you use matches it exactly.

4. Wait a few minutes after assigning. Identity assignment takes time to propagate. Then retry the token call. Expected: a token is returned instead of the 400.

## Reading the real IMDS error behind "azure identity not found"

The token call that fails is your code asking the Azure instance metadata service for a token. When the identity is not assigned, the service answers 400 with a body shaped like `{"error":"invalid_request","error_description":"Identity not found"}`. Two nearby errors mean different things and need different fixes:

- `error_description` "Identity not found" - the identity exists in Entra (or does not) but is not attached to this host. Fix the assignment, per the steps above.
- No response from the metadata endpoint at all (connection refused or timeout) - you are on a local dev machine or a non-Azure host, where there is no metadata service. Fix: `az login` and let `AzureCliCredential` handle it; do not chase identity assignment.
- 400 with a different `error_description` mentioning the client id format - the requested client id is malformed or mistyped. Compare it character for character against the assigned identity.

Variant phrasings: the requested identity isn't assigned to this resource; ManagedIdentityCredential authentication unavailable; error_description Identity not found; DefaultAzureCredential failed to retrieve a token from the included credentials.

Root cause: the managed identity credential asks IMDS for a token for a specific identity. IMDS answers 400 invalid_request when that identity has not been assigned to the host making the request. The identity may exist in Entra but is not attached to this VM, app service, container app, or AKS pod, or the requested client id is simply wrong.

Edge cases: on a local dev machine the same credential chain fails with "no response from the IMDS endpoint" because there is no metadata service locally, which is a different cause with a different fix (az login). On AKS with workload identity, a wrong client id in the service account annotation produces this same error. A placeholder or mistyped client id is a common cause, so compare it character by character. Recently assigned identities need propagation time before they work.

When not to use: if you are running locally, do not chase identity assignment. Use az login and AzureCliCredential instead. Do not disable managed identity in DefaultAzureCredential to silence this on an Azure host; fix the assignment.

## Related skills

- [Diagnose: DefaultAzureCredential failed to retrieve a token from the included credentials](https://vectle.com/skills/skl_oZYSuyWL40eLPbWeF_bVKw) - the wider credential-chain failure this error often hides inside.
- [azure.identity.CredentialUnavailableError: DefaultAzureCredential failed to retrieve a token](https://vectle.com/skills/skl_-QAJ6eBel4zO-64LPwqrWg) - when the chain fails before IMDS is even reached.
