Add Microsoft Entra ID Service Principal authentication support for Azure OpenAI plugin #778

Closed
opened 2026-02-16 10:20:29 -05:00 by yindo · 0 comments
Owner

Originally created by @Nov1c444 on GitHub (Nov 6, 2025).

Originally assigned to: @Nov1c444 on GitHub.

Self Checks

  • I have read the Contributing Guide and Language Policy.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report, otherwise it will be closed.
  • Please do not modify this template :) and fill in all the required fields.

1. Is this request related to a challenge you're experiencing? Tell me about your story.

The Azure OpenAI plugin currently only supports API Key authentication, which requires storing sensitive keys in the configuration. Microsoft Entra ID (Azure AD) Service Principal authentication provides a more secure approach by using Application (Client) ID, Directory (Tenant) ID, and Client Secret for identity management. This enhancement would enable enterprise users to leverage Azure's role-based access control (RBAC) and centralized identity management, allowing each workspace to use different credentials without relying on shared API keys.

2. Additional context or comments

https://learn.microsoft.com/en-us/azure/ai-foundry/foundry-models/how-to/configure-entra-id?tabs=python&pivots=ai-foundry-portal

3. Can you help us with this feature?

  • I am interested in contributing to this feature.
Originally created by @Nov1c444 on GitHub (Nov 6, 2025). Originally assigned to: @Nov1c444 on GitHub. ### Self Checks - [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify-official-plugins/issues), including closed ones. - [x] I confirm that I am using English to submit this report, otherwise it will be closed. - [x] Please do not modify this template :) and fill in all the required fields. ### 1. Is this request related to a challenge you're experiencing? Tell me about your story. The Azure OpenAI plugin currently only supports API Key authentication, which requires storing sensitive keys in the configuration. Microsoft Entra ID (Azure AD) Service Principal authentication provides a more secure approach by using Application (Client) ID, Directory (Tenant) ID, and Client Secret for identity management. This enhancement would enable enterprise users to leverage Azure's role-based access control (RBAC) and centralized identity management, allowing each workspace to use different credentials without relying on shared API keys. ### 2. Additional context or comments https://learn.microsoft.com/en-us/azure/ai-foundry/foundry-models/how-to/configure-entra-id?tabs=python&pivots=ai-foundry-portal ### 3. Can you help us with this feature? - [x] I am interested in contributing to this feature.
yindo added the enhancement label 2026-02-16 10:20:29 -05:00
yindo closed this issue 2026-02-16 10:20:29 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify-official-plugins#778