Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A company is considering migrating its on-premises applications to Azure. They want to ensure that these applications can securely access other Azure resources (like Azure Key Vault or Azure Storage) without needing to manage credentials in their code. Which Azure identity feature should they implement?

  1. AUser Accounts
  2. BManaged Identities
  3. CService Principals
  4. DConditional Access Policies
Show answer & explanation

Correct answer: B. Managed Identities

Managed Identities for Azure resources provide an automatically managed identity in Azure Active Directory for applications to authenticate to cloud services without needing to store credentials in code. This directly addresses the requirement of secure access without credential management.

Why the other options are wrong

  • A. User Accounts are for human users, not applications securely accessing resources.
  • C. Service Principals are identities used by applications and services, but often still require manual credential management.
  • D. Conditional Access Policies define access conditions, but don't provide the identity for the application itself.

Managed Identities

An Azure Active Directory feature that provides an automatically managed identity for Azure resources to authenticate to cloud services that support Azure AD authentication, without storing credentials in application code.

  • Eliminates credential management for applications.
  • Automatically managed by Azure.
  • Enhances security by removing secrets from code.

Memory trick: Managed Identities: The application manages its OWN ID with Azure, no code secrets needed.

More Describe the concepts of security, compliance, and identity questions