Has anyone else received emails saying that several production Azure Container Apps environments will be automatically migrated to the new Express offering unless they opt out? We received three notices from the Container Apps team, each requiring a separate opt-out by environment resource ID. The problem is that Express appears to lack much of the functionality we currently rely on, including managed identity-based pulls from Azure Container Registry. The documentation seems to indicate that neither system-assigned nor user-assigned managed identities may be supported, which would leave username-and-password authentication as the fallback. An automatic production migration communicated mainly through an easily missed email seems risky, so I'm trying to understand the scope, the identity limitations, and whether there is an official migration timeline.
2 Answers
It may be worth checking whether the limitation applies specifically to system-assigned identities. User-assigned identities are often supported separately, and they’re generally a better fit for production because their lifecycle isn’t tied to a single resource. Our Azure services use user-assigned identities rather than system-assigned ones.
I haven’t seen a clear public announcement beyond the migration emails. The notice apparently links to an opt-out form where each environment’s resource ID has to be submitted individually, along with the general Express documentation. That makes it especially important to confirm the deadline and review every production environment rather than assuming the opt-out applies globally.
That communication style is worrying. An opt-out migration can easily be missed, and any feature gaps—especially around registry authentication and identity—should be resolved before production workloads are moved automatically.

We don’t use system-assigned identities either, but the current documentation appears to say that user-assigned identities aren’t supported in Express either. It only lists username-and-password authentication, so I’m hoping that documentation is incomplete or will be updated before any migration.