Entra Workload Identity Reference
Reference for Microsoft Entra Workload Identity. The API variables are listed with the other API environment variables, and the AI system fields are described in Custom API Language Models.
Availability
| Capability | Platform Release |
|---|---|
| Entra workload identity for Custom API Language Models | 3.26.8 |
| Entra for judge, attacker, and evaluation data generation calls | 3.26.8 |
| Entra for DynamoGuard policy data generation | 3.26.9 |
LLM_EXTRA_HEADERS for DynamoGuard policy data generation | 3.26.10 |
| A customer-owned identity per AI system | 3.26.11 |
Identity Used by Each Call
| Call | Token Is Minted As | Configured On |
|---|---|---|
| Requests to the AI system under evaluation | The platform identity, or the customer-owned identity named on the AI system | The AI system |
| Connection test when the AI system is saved | The platform identity; skipped when the AI system names its own identity | The AI system |
| Judge and attacker models, and evaluation data generation | The platform identity | Evaluation worker variables |
| DynamoGuard policy data generation | The platform identity | Data processing variables |
Tokens are requested for the configured scope and refreshed before they expire. The APIM subscription key, when set, is sent as ocp-apim-subscription-key on every call.
Save-Time Behavior
What happens when an AI system that uses Microsoft Entra Workload Identity is created, or its authentication is edited, and how it then behaves during evaluation.
| Managed Identity Client ID and Tenant ID | On Save | During Evaluation |
|---|---|---|
| Neither set (a blank value counts as not set) | The API requests a token as the platform identity, sends a test request, and checks the response against the response transform | Tokens are minted as the platform identity |
| Both set | The configuration, the endpoint host, and the request transform are checked. No token is requested and no test request is sent | Tokens are minted as the named identity; an authentication problem fails the first run |
| Only one set | Rejected: config.client_id and config.tenant_id must be provided together | Not reached |
| A value that is not a GUID | Rejected: config.<field> must be a GUID if provided | Not reached |
Any other configuration key, such as token_file_path | Rejected: config contains invalid fields: <field> | Not reached |
| Edit that removes both | The AI system returns to the platform identity, and the test request runs again | Tokens are minted as the platform identity |
| Edit that leaves the APIM subscription key empty | The stored key is kept | The stored key is sent |
The authentication type of an existing AI system cannot be changed. Create a new AI system to move one from Bearer Token or API Key to Microsoft Entra Workload Identity.
Evaluation Worker Variables
Set these on each evaluation worker job in the DynamoEval chart to route judge, attacker, and evaluation data generation calls to an Entra-protected Azure endpoint. The workers read AZURE_CLIENT_ID, AZURE_TENANT_ID, and AZURE_FEDERATED_TOKEN_FILE from the workload identity webhook.
| Variable | Required | Description |
|---|---|---|
DYNAMOEVAL_JUDGE_MODE | Yes | AZURE routes judge and attacker calls to the endpoint below. |
AZURE_API_BASE | Yes | Endpoint base URL, for example the APIM URL in front of Azure OpenAI. |
AZURE_API_VERSION | Yes | Azure OpenAI API version. |
AZURE_MODEL_NAME | No | Bare deployment name. Routes every judge, attacker, and evaluation data generation call to this deployment. |
AZURE_ENTRA_AUTH | Yes, for Entra | true mints Entra tokens instead of using AZURE_API_KEY. The two are mutually exclusive; leave AZURE_API_KEY unset. |
AZURE_ENTRA_CREDENTIAL | No | workload_identity (default), or client_secret, which also reads AZURE_CLIENT_SECRET. |
AZURE_ENTRA_SCOPE | No | Scope the token is requested for. Defaults to https://cognitiveservices.azure.com/.default; it must match the audience the gateway validates. |
AZURE_APIM_SUBSCRIPTION_KEY | No | APIM subscription key sent with every call. Read it from the azureApimSubscriptionKey key of the common Secret. |
AZURE_APIM_SUBSCRIPTION_KEY_HEADER | No | Header name for the key. Defaults to ocp-apim-subscription-key. |
dynamoai-common:
scaledJobs:
jobs:
<job-name>:
env:
DYNAMOEVAL_JUDGE_MODE:
value: "AZURE"
AZURE_API_BASE:
value: "https://<gateway-host>/<api-path>"
AZURE_API_VERSION:
value: "<api-version>"
AZURE_MODEL_NAME:
value: "<deployment>"
AZURE_ENTRA_AUTH:
value: "true"
AZURE_APIM_SUBSCRIPTION_KEY:
valueFrom:
secretKeyRef:
name: "{{ .Values.global.secrets.common }}"
key: azureApimSubscriptionKey
How evaluation data generation picks its models is covered in DynamoEval Workers.
Data Processing Variables
Set these on the data processing service to generate DynamoGuard policy data through an Entra-protected Azure OpenAI endpoint.
| Variable | Required | Description |
|---|---|---|
SYNDATA_MODEL_PROVIDER | Yes | azure_openai. |
SYNDATA_MODEL_NAME | Yes | Provider-prefixed deployment, for example azure/<deployment>. In the DynamoGuard chart it normally takes the value of global.models.dataGeneration.name. |
AZURE_OPENAI_ENDPOINT | Yes | Azure OpenAI endpoint URL. |
AZURE_OPENAI_API_VERSION | Yes | Azure OpenAI API version. |
AZURE_ENTRA_AUTH | Yes, for Entra | true mints Entra tokens instead of using AZURE_OPENAI_API_KEY. The two are mutually exclusive; leave AZURE_OPENAI_API_KEY unset. |
AZURE_ENTRA_CREDENTIAL, AZURE_ENTRA_SCOPE, AZURE_APIM_SUBSCRIPTION_KEY, AZURE_APIM_SUBSCRIPTION_KEY_HEADER | No | As for the evaluation workers. |
LLM_EXTRA_HEADERS | No | JSON object of extra headers sent on every LLM call, for example {"x-end-user": "dynamoai"}. |