A financial services company is developing a new serverless application on Azure that uses Azure Functions to process transactions. The application needs to store sensitive audit logs in a dedicated Azure Storage Account. To meet compliance requirements, all data written to the storage account must be encrypted at rest, and access to the storage account must be restricted to only the Azure Functions application, using a highly secure and auditable method that avoids managing connection strings. Which combination of features ensures this security posture?
- AAzure AD Application Registration with Microsoft-Managed Keys (MMK) for Storage Account Encryption
- BShared Access Signatures (SAS) with Azure Policy
- CStorage Account Access Keys with Service Endpoints
- DManaged Identity for Azure Functions with Customer-Managed Keys (CMK) for Storage Account Encryption
Show answer & explanationAnswer & explanation
Correct answer: D. Managed Identity for Azure Functions with Customer-Managed Keys (CMK) for Storage Account Encryption
Managed Identities for Azure Functions provide a secure, credential-free way for the function app to authenticate to the storage account. Customer-Managed Keys (CMK) ensure that data at rest is encrypted with keys controlled by the customer, meeting the compliance requirement for encryption beyond Microsoft's default. This combination fully addresses the security and compliance needs.
Why the other options are wrong
- A. Azure AD Application Registration is for app identity, but using Microsoft-Managed Keys (MMK) does not meet the implied compliance need for customer control over encryption keys if 'highly secure and auditable' implies key custody.
- B. SAS tokens provide delegated access but are still credentials that need management and rotation, and Azure Policy is for governance, not the primary authentication mechanism or encryption key management.
- C. Access Keys are static credentials and are not recommended for secure access, failing the 'avoids managing connection strings' and 'highly secure' requirements. Service Endpoints help network isolation but don't address the identity aspect.
Managed Identity + CMK
Managed Identity provides an automatically managed, Azure AD-based identity for Azure services, eliminating credential management. Customer-Managed Keys (CMK) allow customers to use their own encryption keys for data at rest in Azure services, providing greater control over encryption.
- Managed Identity: Credential-free authentication for Azure services
- Managed Identity: Azure handles identity lifecycle
- CMK: Customer controls encryption keys in Azure Key Vault
- CMK: Enhances data security and meets regulatory compliance
Memory trick: Managed Identity Guards, CMK Controls the Vault.