Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsEasy
A software development company is building a new microservices application in Azure. Each microservice needs to securely access Azure Key Vault to retrieve secrets and Azure SQL Database to store data. The developers want to avoid embedding credentials in their code or managing service principal secrets. Which authentication mechanism should they use for their microservices?
- AAzure Active Directory Application Registrations
- BService Principals with Client Secrets
- CManaged Identities for Azure Resources
- DKey Vault Access Policies
Show answer & explanationAnswer & explanation
Correct answer: C. Managed Identities for Azure Resources
Managed Identities for Azure Resources provide an Azure AD identity for Azure services, eliminating the need for developers to manage credentials. Azure automatically handles the lifecycle of these identities, making them ideal for secure service-to-service communication.
Why the other options are wrong
- A. Application Registrations define the identity of an application in Azure AD but do not, by themselves, eliminate the need for credential management (unless used with Managed Identities).
- B. Service Principals with Client Secrets require manual management of secrets, which the developers want to avoid.
- D. Key Vault Access Policies define *who* can access Key Vault secrets but do not specify the authentication mechanism for the calling service itself.
Managed Identities
Managed Identities for Azure Resources provide an automatically managed identity in Azure Active Directory for applications to use when connecting to resources that support Azure AD authentication.
- Eliminates credential management for developers
- Azure automatically manages identity lifecycle
- Can be assigned to Azure services (VMs, App Services, Functions, etc.)
- Supports System-assigned and User-assigned types
Memory trick: Managed Identities Make Secrets Invisible.