We have continued to research the topic and propose the following alternative solution. We ask Microsoft kindly to verify the solution described below and to inform whether this is an approperiate solution.
Proposed solution
A service principal is configured to create various resources in a subscription.
This service principal has to be assigned to the Directory Readers
role in the AAD in order to determine the Application Id for a Managed Identity in the context of the deployment process.
The configured “Managed Identity” of the Azure App Service can be registered on the respective Azure SQL database with the following command.