Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
powershell_heavy
windows_first
missing_linux_example
Summary
The documentation page demonstrates a bias toward Windows environments by providing detailed Azure PowerShell examples for all identity management tasks, while omitting equivalent examples for Linux-friendly tools such as Azure CLI. PowerShell is a Windows-centric tool, and its usage is presented before or instead of alternatives. There are no Linux-specific instructions or examples, and no mention of cross-platform command-line options. The ARM template and portal instructions are platform-neutral, but all scripting guidance is PowerShell-only.
Recommendations
  • Add equivalent Azure CLI examples for all PowerShell commands, as Azure CLI is cross-platform and widely used on Linux and macOS.
  • Explicitly mention that Azure CLI can be used for these tasks, and link to relevant CLI documentation.
  • Where scripting is shown, present both PowerShell and CLI examples side-by-side, or indicate which is recommended for each platform.
  • Consider including Bash shell script snippets for automation scenarios.
  • Review and update any referenced sample links to ensure Linux parity.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-14 00:01 #120 completed Biased Biased
2026-01-13 06:17 #107 completed Biased Biased
2026-01-12 00:00 #99 completed Biased Biased
2026-01-11 06:20 #98 completed Biased Biased
2026-01-11 00:00 #95 cancelled Clean Clean
2026-01-10 00:00 #92 completed Clean Clean
2026-01-09 00:00 #87 cancelled Clean Clean
2026-01-08 00:00 #84 in_progress Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2025-12-29 18:00 #48 cancelled Biased Biased
2025-12-22 00:00 #24 cancelled Clean Clean
2025-12-20 22:24 #14 completed Clean Clean
2025-12-20 00:00 #13 completed Clean Clean
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean

Flagged Code Snippets

### Store and manage named values from Key Vault

You can use a system-assigned managed identity to access Key Vault to store and manage secrets for use in API Management policies. For more information, see [Use named values in Azure API Management policies](api-management-howto-properties.md). 

### Authenticate to a backend by using an API Management identity

You can use the system-assigned identity to authenticate to a backend service via the [authentication-managed-identity](authentication-managed-identity-policy.md) policy.

### Connect to Azure resources behind an IP firewall by using a system-assigned managed identity

API Management is a trusted Microsoft service to the following resources. This trusted status enables the service to connect to the following resources behind a firewall when the firewall enables a setting to **Allow Trusted Microsoft Services to bypass this firewall**. After you explicitly assign the appropriate Azure role to the [system-assigned managed identity](../active-directory/managed-identities-azure-resources/overview.md) for a resource instance, the scope of access for the instance corresponds to the Azure role that's assigned to the managed identity.


- [Trusted access for Key Vault](/azure/key-vault/general/overview-vnet-service-endpoints#trusted-services)
- [Trusted access for Azure Storage](../storage/common/storage-network-security-trusted-azure-services.md?tabs=azure-portal#trusted-access-based-on-system-assigned-managed-identity)
- [Trusted access for Azure Service Bus](../service-bus-messaging/service-bus-ip-filtering.md#trusted-microsoft-services)
- [Trusted access for Azure Event Hubs](../event-hubs/event-hubs-ip-filtering.md#trusted-microsoft-services)


> [!IMPORTANT]
> Starting March 2026, trusted service connectivity to Azure services from the API Management gateway by enabling the **Allow Trusted Microsoft Services to bypass this firewall** firewall setting will no longer be supported. To continue accessing these services from the API Management gateway after this change, ensure that you choose a different supported network access option. For control-plane operations, you can continue to use trusted service connectivity. [Learn more](breaking-changes/trusted-service-connectivity-retirement-march-2026.md).

### Log events to an event hub

You can configure and use a system-assigned managed identity to access an event hub to log events from an API Management instance. For more information, see [How to log events to Event Hubs in Azure API Management](api-management-howto-log-event-hubs.md).

## Create a user-assigned managed identity

> [!NOTE]
> You can associate an API Management instance with as many as 10 user-assigned managed identities.

### Azure portal

To set up a managed identity in the portal, you must first create an API Management instance and [create a user-assigned identity](../active-directory/managed-identities-azure-resources/how-manage-user-assigned-managed-identities.md). Then complete the following steps.

1. Go to your API Management instance in the portal.
1. In the left menu, under **Security**, select **Managed identities**.
1. On the **User assigned** tab, select **Add**.
1. Search for the identity that you created earlier and select it. Select **Add**.

   :::image type="content" source="./media/api-management-howto-use-managed-service-identity/enable-user-assigned-identity.png" alt-text="Screenshot that shows how to enable a user-assigned managed identity." border="true" lightbox="./media/api-management-howto-use-managed-service-identity/enable-user-assigned-identity.png":::

### Azure PowerShell

[!INCLUDE [updated-for-az](~/reusable-content/ce-skilling/azure/includes/updated-for-az.md)]

The following steps lead you through creating an API Management instance and assigning it an identity by using Azure PowerShell.

1. If you need to, install Azure PowerShell by following the instructions in the [Azure PowerShell guide](/powershell/azure/install-azure-powershell). Then run `Connect-AzAccount` to create a connection with Azure.

1. Use the following code to create the instance. For more examples of how to use Azure PowerShell with API Management, see [API Management PowerShell samples](powershell-samples.md).

    
You can also update an existing service to assign an identity to the service: