Azure Notification Hubs — Managed Identity (System-Assigned)

Jayaram M 0 Reputation points
2026-09-24T10:33:53.9133333+00:00

What we are trying to do

We have an Azure Function App using System-Assigned Managed Identity to authenticate to Azure Notification Hubs without connection strings. we are trying to implement Managed identity is it possible to achive?

What we investigated

  1. We checked Access Control (IAM) on the Notification Hub Namespace — there are no built-in roles for Notification Hubs listed (no Azure Notification Hubs Data Owner, Data Contributor, or Data Reader)
  2. When creating a custom role, the Data Actions tab for Microsoft.NotificationHubs shows "No permissions found" — there are no data plane RBAC actions enumerable for this service in our subscription
  3. The existing custom role assigned to the namespace (Notification Hub Operator) only has actions (management plane) with an empty dataActions array

Our questions

  1. Does Azure Notification Hubs support AAD Bearer token / Managed Identity authentication on the data plane (send notifications, manage installations)?
  2. What is the correct RBAC role or permission that must be assigned to a Managed Identity to allow it to call the Notification Hubs REST API with a Bearer token?
  3. Why do the built-in roles (Azure Notification Hubs Data Owner — GUID 17d1049b-9a84-46fb-8f53-869881c3d3ab) not appear in our subscription? Are they available in all regions/tenants?
  4. Is https://notificationhubs.azure.net/.default the correct token audience for Notification Hubs Bearer token auth?
  5. If RBAC data plane is not supported for Notification Hubs, what is the recommended secure alternative to connection strings for a Managed Identity scenario?

User's image

Azure Notification Hubs
Azure Notification Hubs

An Azure service that is used to send push notifications to all major platforms from the cloud or on-premises environments.


2 answers

Sort by: Most helpful
  1. Stanislav Zhelyazkov 29,826 Reputation points MVP Volunteer Moderator
    2026-09-24T11:38:25.4166667+00:00

    Hi,

    Azure Notarization Hubs does not support other authentication method besides SaS.

    So to answer your questions:

    1. Does Azure Notification Hubs support AAD Bearer token / Managed Identity authentication on the data plane (send notifications, manage installations)? - No
    2. What is the correct RBAC role or permission that must be assigned to a Managed Identity to allow it to call the Notification Hubs REST API with a Bearer token? - There is no such.
    3. Why do the built-in roles (Azure Notification Hubs Data Owner — GUID 17d1049b-9a84-46fb-8f53-869881c3d3ab) not appear in our subscription? Are they available in all regions/tenants? There is no such role. 17d1049b-9a84-46fb-8f53-869881c3d3ab is Storage Account Contributor role. Source.
    4. Is https://notificationhubs.azure.net/.default the correct token audience for Notification Hubs Bearer token auth? - No audience as Entra auth is not supported.
    5. If RBAC data plane is not supported for Notification Hubs, what is the recommended secure alternative to connection strings for a Managed Identity scenario? - Automate the regeneration of SaS and store the SaS on a key Vault as secret. Use user assigned identity to access the secret from the Key Vault. For automation you can use various services like Logic Apps, Functions, Azure Automation, etc.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-24T10:34:17.73+00:00

    Azure Notification Hubs does not support Microsoft Entra ID / Azure AD authentication for data plane access.

    Based on the documented security baseline for Notification Hubs:

    1. Managed identity is not supported for Notification Hubs data plane
      The service explicitly shows Managed Identities: Supported = False for data plane actions.
    2. Service principals are not supported for Notification Hubs data plane
      The service also shows Service Principals: Supported = False for data plane actions.
    3. Azure AD authentication is not supported for Notification Hubs data plane
      The baseline states Azure AD Authentication Required for Data Plane Access: Supported = False.
    4. Azure RBAC for Notification Hubs data plane is not supported
      The baseline states Azure RBAC for Data Plane: Supported = False. That matches what was observed in IAM: no data actions, no usable data-plane RBAC role, and no custom role dataActions for Microsoft.NotificationHubs.
    5. Conditional Access and Key Vault integration are also not supported for Notification Hubs data plane
      The baseline lists both as unsupported for this service.
    6. The supported security model for Notification Hubs is SAS
      Notification Hubs uses an entity-level security scheme called Shared Access Signature (SAS), which is automatically created when creating a hub.

    Answers to the specific questions:

    • Q1: No. Notification Hubs does not support AAD bearer token or managed identity authentication for data plane operations such as sending notifications or managing installations.
    • Q2: There is no RBAC data-plane role or permission to assign for this scenario, because Azure RBAC for Notification Hubs data plane is not supported.
    • Q3: The provided context confirms only that Azure RBAC for Notification Hubs data plane is unsupported. That explains why no data actions appear. It does not provide region or tenant availability details for the role GUID mentioned.
    • Q4: The provided context does not document a bearer-token audience for Notification Hubs, and the service baseline indicates Azure AD data-plane auth is unsupported.
    • Q5: The documented supported alternative is Shared Access Signature (SAS). Notification Hubs does not support managed identity or native Key Vault integration for its data plane, so the secure alternative within supported service capabilities is to use SAS-based access.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.