It's used in combination with Azure Active Directory, so the modality isn't 1:1 with AWS. But Managed Identities[3] is a feature that's rolling out across Azure which simplifies the model a bit, since it negates the need to create service principles in AAD beforehand.
[1] https://docs.microsoft.com/en-us/azure/role-based-access-con...
[2] https://docs.microsoft.com/en-us/azure/role-based-access-con...
[3] https://docs.microsoft.com/en-us/azure/active-directory/mana...