Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

An organization is migrating its applications to a cloud environment. They need a mechanism for these cloud applications to securely access other cloud resources (e.g., storage accounts, databases) without embedding credentials directly in the application code. This mechanism should manage identity automatically for the application. Which type of identity should they use?

  1. AGuest Identity
  2. BService Account
  3. CUser Identity
  4. DManaged Identity
Show answer & explanation

Correct answer: D. Managed Identity

Managed Identities provide an automatically managed identity for Azure services, allowing them to authenticate to cloud services that support Azure AD authentication without developers needing to manage credentials in code. This directly addresses the need for secure application access without embedded credentials.

Why the other options are wrong

  • A. Guest Identities are for external users collaborating, not for applications accessing resources.
  • B. Service Accounts are a broader concept for non-human identities, but Managed Identities are a specific, more secure, and automated implementation within Azure.
  • C. User Identities are for human users, not applications.

Managed Identity

An Azure Active Directory feature that provides an automatically managed identity to Azure services, allowing them to authenticate to cloud services without embedding credentials in code.

  • Eliminates the need for developers to manage credentials.
  • Identities are managed by Azure AD.
  • Can be assigned to Azure resources (VMs, App Services, etc.).

Memory trick: Managed Identity: Azure takes care of the robot's ID.

More Describe the concepts of security, compliance, and identity questions