Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsEasy
A financial institution is deploying a new web application in Azure that will process highly sensitive customer data. They need to ensure that the application can securely access other Azure services, such as Azure Key Vault and Azure SQL Database, without storing credentials directly in the application's code. The application runs on Azure App Service. How should the application be authenticated to Azure services?
- AStore connection strings with credentials in Azure Key Vault.
- BConfigure network access policies to restrict access to Azure services.
- CImplement Managed Identities for Azure Resources.
- DUse service principals with client secrets stored in the application settings.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement Managed Identities for Azure Resources.
Managed Identities for Azure Resources provide an Azure AD identity for Azure services like App Service. This identity can then be used to authenticate to other Azure services that support Azure AD authentication, eliminating the need to store credentials in code or configuration files, which is a best practice for security.
Why the other options are wrong
- A. While Key Vault is for secure storage, the application still needs a way to authenticate to Key Vault itself. Managed Identities solve this initial authentication problem elegantly.
- B. Network access policies control network traffic but do not provide an authentication mechanism for the application to access other services.
- D. Storing client secrets, even in application settings, still involves managing credentials directly and poses a security risk if compromised.
Managed Identities for Azure Resources
Managed Identities for Azure Resources provide an automatically managed identity in Azure Active Directory (Azure AD) for applications to use when connecting to resources that support Azure AD authentication.
- Eliminates the need for developers to manage credentials.
- Identities are managed by Azure, enhancing security.
- Can be assigned to many Azure services, like VMs, App Services, Functions.
Memory trick: Managed Identity: Your app's invisible key to Azure's treasure chest.