Microsoft Entra Workload ID
General

Managed Identities Faq

In brief

The documentation now states that creating a managed identity is blocked when the resulting directory usage reaches or exceeds 98% of the tenant quota. This applies to new or recreated service principals; existing identities and assignments continue to work.

What Entra admins need to know

Monitor directory object usage when creating or enabling managed identities. Soft-deleted objects count toward the quota; reducing usage or increasing the quota enables retries.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

When a managed identity is deleted, an Azure resource that was previously associated with that identity can no longer request new tokens for that identity. Tokens that were issued before the identity was deleted will still be valid until their original expiry. Some target endpoints' authorization systems may carry out other checks in the directory for the identity, in which case the request fails as the object can't be found. However some systems, like Azure RBAC, will continue to accept requests from that token until it expires.

Next stepsDirectory object quota for managed identities

  • Learn how managed identities work with virtual machines

    Each managed identity has a service principal in Microsoft Entra ID. This service principal counts toward the tenant's directory object quota, together with other directory objects such as users, groups, applications, devices, and service principals.

    To preserve directory capacity for other essential objects, creation of a managed identity is blocked when the new service principal would cause directory usage to reach or exceed 98% of the tenant's total directory object quota.

    The 98% threshold applies to total directory object usage. It isn't a separate quota that counts only managed identities.

    Operations affected by the quota

    The directory quota validation can affect the following operations:

    • Creating a user-assigned managed identity.
    • Enabling a system-assigned managed identity on an Azure resource.
    • Re-enabling a system-assigned managed identity if the operation requires a new service principal.

    Assigning an existing user-assigned managed identity to another Azure resource doesn't create another service principal. Therefore, the assignment doesn't consume another directory object and isn't blocked by this validation.

    How the 98% threshold works

    Before Microsoft Entra creates the service principal for a managed identity, it evaluates the tenant's current directory object usage.

    Creation is blocked if adding the service principal would cause directory usage to reach or exceed 98% of the tenant's total quota.

    For example, if a tenant has a quota of 300,000 directory objects, the managed identity creation threshold is 294,000 objects. A request that would increase usage to 294,000 objects is blocked.

    The remaining capacity is available for other directory operations and essential objects. It doesn't increase the tenant's total directory object quota.

    Error message

    When managed identity creation is blocked, you receive an error similar to the following message:

    The directory object quota limit for the Tenant has been reached. Creation of new managed identities is blocked. Please ask your administrator to increase the directory quota limit or delete objects to reduce the used quota.

    Resolve a blocked managed identity operation

    After directory usage falls below the 98% threshold, or after Microsoft Support increases the tenant's quota, retry creating or enabling the managed identity.

    Next steps

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…