Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A software development team is building an application that needs to securely access resources in Azure, such as Azure Key Vault and Azure Storage. The team wants to avoid hardcoding credentials in their application code or configuration files. They are looking for a solution that allows their application to authenticate to Azure AD and access resources without managing secrets directly. Which identity concept should they use?

  1. AGuest User
  2. BConditional Access
  3. CManaged Identity
  4. DService Principal
Show answer & explanation

Correct answer: C. Managed Identity

Managed Identities for Azure resources provide an automatically managed identity in Azure Active Directory (Azure AD) for applications, eliminating the need for developers to manage credentials.

Why the other options are wrong

  • A. Guest User refers to external users invited to an Azure AD tenant, not an application identity.
  • B. Conditional Access defines policies for access based on conditions, not a type of identity for applications.
  • D. A Service Principal is an identity for an application, but typically requires manual credential management (e.g., client secrets, certificates).

Managed Identity

An Azure AD feature that provides Azure services with an automatically managed identity, allowing them to authenticate to other services without managing credentials.

  • Eliminates hardcoded credentials.
  • Automatically managed by Azure.
  • Can be assigned to Azure resources like VMs, App Services, Functions.

Memory trick: Managed Identity handles the secrets for your Azure apps.

More Describe the concepts of security, compliance, and identity questions