It's now possible to configure UMIs as subjects in federated identity credentials. https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-config-app-trust-managed-identity