Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A large enterprise is migrating its applications to Azure. They need a service that allows Azure resources (like Virtual Machines or Azure Functions) to authenticate to other Azure services (like Key Vault or Storage Accounts) without managing credentials in their code. Which identity concept best addresses this requirement?
- AGuest Accounts
- BManaged Identities
- CUser Accounts
- DService Principals
Show answer & explanationAnswer & explanation
Correct answer: B. Managed Identities
Managed Identities for Azure resources provide an automatically managed identity in Azure Active Directory for Azure services. This allows applications to authenticate to other services without needing to manage credentials directly in the code.
Why the other options are wrong
- A. Guest Accounts are for external users accessing an organization's resources, not for Azure services.
- C. User Accounts are for human users, not Azure resources.
- D. Service Principals are application identities, which require manual credential management (client secrets or certificates) unless used with Managed Identities.
Managed Identities
Automatically managed identities in Azure Active Directory for Azure services to authenticate to other services without requiring developers to manage credentials.
- Eliminates credential management in code.
- Integrated with Azure AD.
- Can be system-assigned or user-assigned.
Memory trick: Azure Identity: 'Humans use accounts, apps use principals, resources get managed.'