Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard

A software development team is building a new application that will run on Azure Virtual Machines. The application needs to access secrets stored in Azure Key Vault and also write logs to Azure Storage. The team wants to avoid hardcoding credentials or managing service principal secrets in their application code. Which identity solution should they implement for their application to securely access these Azure resources?

  1. ADevice Identity
  2. BUser Identity
  3. CManaged Identity
  4. DFederated Identity
Show answer & explanation

Correct answer: C. Managed Identity

Managed Identities for Azure resources provide an automatically managed identity in Azure Active Directory for Azure services (like Virtual Machines) to authenticate to services that support Azure AD authentication (like Key Vault and Azure Storage) without needing to store credentials in code. This directly addresses the team's requirement to avoid hardcoding credentials.

Why the other options are wrong

  • A. Device Identity is for registering and managing devices, not for applications authenticating to other services.
  • B. User Identity is for human users, not applications running on VMs.
  • D. Federated Identity is for cross-organizational user access, not for Azure services accessing other Azure services.

Managed Identity

An Azure Active Directory feature that provides Azure services with an automatically managed identity to authenticate to other Azure services without managing credentials.

  • Eliminates the need to store credentials in code.
  • Supports system-assigned and user-assigned identities.
  • Used by Azure services (VMs, App Services, Functions) to access other Azure services (Key Vault, Storage, SQL Database).

Memory trick: Managed Identity: Machines Authenticate Smoothly.

More Describe the concepts of security, compliance, and identity questions