Query related to Pod Identity deprecation

Nadadhi, Vigneswara-XT 0 Reputation points
2025-08-25T14:55:43.37+00:00

we are using pod identity on aks still and we have a migration planned to move to workload -id with in next few months. dose pod identity will stop working from sept 2024 or will we have a window for few months to still use pod identity.

Azure Kubernetes Service
Azure Kubernetes Service
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Satish Mada 350 Reputation points Microsoft External Staff Moderator
    2025-08-25T17:09:20.2133333+00:00

    Hi Nadadhi, Vigneswara-XT,  

    Welcome to the Microsoft Q&A portal.  

    Based on the official Microsoft documentation and public announcements, here's the situation regarding Azure AD Pod Identity on AKS:

    Yes, you should expect Azure AD Pod Identity to effectively stop working in a supported and maintained way after September 2025.

    • Official End of Support: The AKS Pod Identity Managed add-on will be patched and supported through September 2025. This is a hard deadline for receiving official security updates and bug fixes.
    • Deprecation and Archival: The underlying open-source aad-pod-identity project was already deprecated in October 2022 deprecation notice and its GitHub repository was archived in September 2023. This means there is no further development on the project. Use Microsoft Entra pod-managed identities in Azure Kubernetes Service (Preview) - Azure Kubernetes Service | Microsoft Learn User's image
    • Functionality After the Deadline: While your existing workloads might continue to function immediately after September 2025, they will be in an unsupported state. This means if you encounter any bugs, security vulnerabilities, or compatibility issues with new versions of Kubernetes or Azure, Microsoft will not provide a fix.

    The "grace period" is not for continued use, but for migration. Microsoft has provided this window specifically to give customers like you time to move their workloads to the recommended, modern solution: Microsoft Entra Workload ID.

    It is highly recommended that you prioritize your migration plan to be completed well before the September 2025 deadline to avoid any potential service disruptions, security risks, or the need to fix issues without official support.

     Please refer : Migrate your Azure Kubernetes Service (AKS) pod to use workload identity - Azure Kubernetes Service | Microsoft Learn


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.