Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A company is migrating its on-premises applications to Azure. They want to ensure that these applications can securely access other Azure resources (like storage accounts or databases) without needing to store credentials directly in their code or configuration files. Which Azure identity concept should they use?
- AService Principals
- BAzure AD Connect
- CManaged Identities
- DApplication Registrations
Show answer & explanationAnswer & explanation
Correct answer: C. Managed Identities
Managed Identities for Azure resources provide an automatically managed identity in Azure Active Directory for applications to use when connecting to resources that support Azure AD authentication, eliminating the need for developers to manage credentials.
Why the other options are wrong
- A. Service Principals represent applications or services in Azure AD, but still typically require manual credential management (e.g., client secrets, certificates).
- B. Azure AD Connect synchronizes on-premises Active Directory with Azure AD, not for secure application access.
- D. Application Registrations define an application's identity in Azure AD, but don't inherently remove the need for credential management *within* the application code itself for authentication.
Managed Identities
An Azure Active Directory feature that provides Azure services with an automatically managed identity in Azure AD, allowing them to authenticate to services that support Azure AD authentication without managing credentials.
- Eliminates the need for credentials in code.
- Two types: System-assigned and User-assigned.
- Enhances security by reducing credential exposure.
Memory trick: Managed = Magic credentials