An Azure service that is used to send push notifications to all major platforms from the cloud or on-premises environments.
Hi,
Azure Notarization Hubs does not support other authentication method besides SaS.
So to answer your questions:
- Does Azure Notification Hubs support AAD Bearer token / Managed Identity authentication on the data plane (send notifications, manage installations)? - No
- What is the correct RBAC role or permission that must be assigned to a Managed Identity to allow it to call the Notification Hubs REST API with a Bearer token? - There is no such.
- Why do the built-in roles (Azure Notification Hubs Data Owner — GUID 17d1049b-9a84-46fb-8f53-869881c3d3ab) not appear in our subscription? Are they available in all regions/tenants? There is no such role. 17d1049b-9a84-46fb-8f53-869881c3d3ab is Storage Account Contributor role. Source.
- Is https://notificationhubs.azure.net/.default the correct token audience for Notification Hubs Bearer token auth? - No audience as Entra auth is not supported.
- If RBAC data plane is not supported for Notification Hubs, what is the recommended secure alternative to connection strings for a Managed Identity scenario? - Automate the regeneration of SaS and store the SaS on a key Vault as secret. Use user assigned identity to access the secret from the Key Vault. For automation you can use various services like Logic Apps, Functions, Azure Automation, etc.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.