DefaultAzureCredential failed 🔷 Azure

DefaultAzureCredential failed to retrieve a token from the included credentials / ManagedIdentityCredential authentication unavailable

The Azure SDK tried every credential source (env vars, workload identity, managed identity, CLI…) and none worked.

Seen on: Azure

Meaning

Locally it usually means you’re not logged in to Azure CLI/VS; in Azure it means managed identity isn’t enabled on the resource, or the env vars for a service principal are incomplete. The message lists why each credential failed.

Common causes

  • Managed identity not enabled on the App Service/VM/Container App
  • Local machine not signed in to Azure CLI/VS Code
  • AZURE_CLIENT_ID/TENANT_ID/SECRET partially set
  • User-assigned identity without AZURE_CLIENT_ID

⚡ Quick fix

  1. Enable managed identity and grant it roles
  2. Locally run az login
  3. Set AZURE_CLIENT_ID for user-assigned identities; remove half-set env vars

Detailed fix by platform

Azure CLI

  1. bash
    az webapp identity assign -g rg-app -n my-api
    az role assignment create --assignee <principal-id> --role "Key Vault Secrets User" --scope <vault-id>

Python

  1. python
    from azure.identity import DefaultAzureCredential
    cred = DefaultAzureCredential(logging_enable=True)   # logs each credential attempt

How to diagnose

  1. Attempts — Per-credential failure lines
  2. Identity — Enabled on the resource?
  3. Env — AZURE_* variables

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.